OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [ANN] ShadeList: DNS-based white/blacklist policy server

From: mouss (usebsdfree.fr)
Date: Wed Feb 08 2006 - 15:39:47 CST


Victor Duchovni a écrit :
> On Wed, Feb 08, 2006 at 08:38:25PM +0100, mouss wrote:
>
>
>>I have a problem understanding the options. my opinion is that there is
>>no need to make anything configurable here (too much flexibility kills
>>usability). if the lists are unavailable, then mail should be deferred
>>until the problem is solved.
>
>
> This is very much false for public blacklists. Perhaps that should not
> be configurable. Also perhaps silent skipping of whitelists should not
> be configurable. Protecting the user from shooting themselves in the
> foot may well be appropriate here. In any case the "defer on failure"
> approach is not correct for (public) blacklist lookups, it may be
> appropriate if the blacklists are internally maintained.
>

For some reason, I was thinking of whitelists. this is obviously bad for
black lists as it will amplify DDos (unless, as you say, they are
internal).