Re: ipfw syntax clarification

From: Steve O'Hara-Smith <steve_at_sohara.org>
Date: Thu, 30 Dec 2021 08:11:00 UTC
On Wed, 29 Dec 2021 23:16:45 -0800
Michael Sierchio <kudzu@tenebras.com> wrote:

> On Wed, Dec 29, 2021 at 11:05 PM Steve O'Hara-Smith <steve@sohara.org>
> wrote:
> 
> > On Wed, 29 Dec 2021 22:32:20 -0800
> > Michael Sierchio <kudzu@tenebras.com> wrote:
> >
> > > Actual location of IP addresses
> > > is something known to the CDNs (Akamai, Cloudflare, AWS, etc.) and is
> > > somewhat proprietary.
> >
> >         Even they only guess based on what they can find out about who
> > controls which block,
> 
> 
> Not so – the location DB used by the large CDNs are empirical, and based
> on RTT of probes which happen all the time from many different geo
> locations. It's pretty easy to infer where the targets are.  These are

	This is what I call guessing based on what they can find out -
nobody tells them where the IP addresses are used and if the fibre running
out of a router near a border happens to cross that border (or the block
of IPs routed down it is spread across that border by a VPN) then there's no
way to tell by RTT measurements and the CDN will guess wrong, which happens
all the time.

--  
Steve O'Hara-Smith
Odds and Ends at http://www.sohara.org/