On Tue, 28 Jul 2026 at 16:33, David Bass <davidbass570@gmail.com> wrote:
It’s a part of a security response plan, and the more tools you have the better.
Please satisfy my curiosity.
1. I don’t think this is the case, but more a question for the guys who deal with this. Definitely subjective. 2. I don’t agree with this statement, but for sure it depends on the infrastructure being attacked, and how resilient it is to attack.
How are they not objective facts? 1. achieves 100% denial through that path, exactly what attacker was trying to do, it guarantees perfect execution of attack. Compared to downgrade, where it has to compete with legitimate traffic that can be still forwarded to destination 2. how can we withdraw the blackhole the moment the attack is over? We don't have signal to observe, so we necessarily create delay between attack over and outage over? With traffic downgrade, we can still observe traffic, and tell exactly when attack is over and stop downgrading it, but even without stopping downgrade, good traffic will pass in absence of other congestion or filters.
3. This is true. 4. Also true
Like I said, it’s a tool in the toolbox available for use. Is it the best option: depends on the situation.
I'm not against providing it, and have provided it since maybe late 90s or early 00. I just think that for most use-cases, downgrade is what is wanted. -- ++ytti