Suggesting to replace RTBH with flowspec will not be marketable, many people, rightly, are worried about flowspec, because it has a huge bug surface and some serious design mistakes and implementation mistakes which make it poor fit for environments which lack in trust. Replacing blackhole community with QoS downgrade community is much more marketable in comparison, and infact one large tier1 used to offer this on a beta basis maybe 15-20 years ago. Sadly it is not commonly available. On Tue, 28 Jul 2026 at 11:15, Barry Greene <bgreene@senki.org> wrote:
Suggestion …. Walk through the APRICOT 2022 talks with DDoS.
[image: hqdefault.jpg]
APRICOT 2022 - DDoS Resiliency Workshop <https://www.youtube.com/playlist?list=PLTAhO9aX5q8X5IS9M3m4fLtvQdjBp1UZ0> youtube.com <https://www.youtube.com/playlist?list=PLTAhO9aX5q8X5IS9M3m4fLtvQdjBp1UZ0> <https://www.youtube.com/playlist?list=PLTAhO9aX5q8X5IS9M3m4fLtvQdjBp1UZ0>
What I’m seeing in this conversation is the missing tools in the DDoS Toolkit that get integrated into DDoS playbooks.
RTBH was just the first element. We then had sRTBH when we created loose uRPF. Then we taught peers how to take dRTBH and sRTBH and redirect traffic to a network sinkhole set up to track the attacks once redirected. Then we had BGP community-based rate limiting. Chris Morrow (UUNET) and Job Snijders (NTT) then set up customer-based RTBH - where you, as a customer, can set up a BGP community and have it blocked at your upstream edge (giving you space to work the attack).
Then we had work at Cisco and Arbor on industry-wide mitigation approaches. This would take time, so Flow-Spec was created as a stopgap. That Cisco/Arbor work was migrated into DOTS in the IETF.
Listen to the sessions, especially the interviews.
-- ++ytti