Filtering the bogons does help, and everyone should perform anti-spoofing in the appropriate places. It isn't, however, a silver bullet.
it's necessary but not sufficient. but if we knew the source addresses were authentic, then some pressure on the RIRs to make address block holders reachable would yield entirely new echelons of accountability. with the current anonymity of ddos sources, it's not possible to file a class action lawsuit against suppliers of the equipment, or software, or services which make highly damaging ddos's a fact of life for millions of potential class members. so please focus on "anti-spoofing"'s *necessity* and not on the fact that by itself it won't be sufficient. "anti-spoofing" will enable solutions which are completely beyond consideration at this time. (we'll know the tide has turned when BCP38 certifications for ISPs are available from the equivilent of "big 8" ("big 2" now?) accounting firms, and these certifications will be prerequisite to getting BGP set up.) -- Paul Vixie