HNHacker News
TopNewBestAskShowJobs

jkalbfeld

5 karma · joined September 28, 2026

Working on multiple projects, and open to accredited investors.
submissionscomments
jkalbfeld··on Show HN: I created a BGP-based blackhole system that you can set up in minutes
It's not blackholing anything for anyone other than the subscriber, so this doesn't cause a block for anyone who isn't participating
jkalbfeld··on Show HN: I created a BGP-based blackhole system that you can set up in minutes
RPKI is great, and I use it for everything except for two /24's that I got pre-ARIN. However, RPKI won't help with the situation where some kind of compromised host is worming its way through the internet running nmap against everything. Most of the IP addresses showing up in our dragnet are in fact announced by the very ISPs that own them. Most of these do not appear to be bogons.
jkalbfeld··on Show HN: I created a BGP-based blackhole system that you can set up in minutes
Since you wouldn't be running transit through us, the traffic would still reach you, and you can use uRPF to block it in-situ.
jkalbfeld··on Show HN: I created a BGP-based blackhole system that you can set up in minutes
You're right. I fixed the copy to clarify its functionality. The blackhole feed doesn't actually sit in your traffic path; it tells your own router what to drop by creating longer CIDRs. Traffic still reaches you over your real ISP connection same as always - your router just can't send an ACK reply back, so it kills the handshake and prevents brute force attacks. If you also set up uRPF (covered in our setup docs), it goes a step further and drops their packets on arrival instead of just failing your reply. In this case, since we're not a transit provider, preventing volumetric attacks can be a little bit tricky since we're not actually in your upstream. However, it is possible to ETL chain data and generate a filter list. I figured at this price point, volumetric protection is a little bit hard to implement.