IP bans are innefective.
We need to employ mac address bans.
English
-
lol what? MAC addresses don't apply outside of a network. When it reaches a router the next destination MAC address becomes the port of the next router. MAC addresses are a layer 2 concept, they don't apply in the sense that you think they do. Besides, it's just as easy, if not easier to spoof a MAC address.
-
Edited by U920628: 4/22/2014 2:07:01 AMYou can ping a mac on a single system level, and instead of blocking access to the gateway, you detect whether or not the mac is blacklisted from a remote ping, and then access is granted if they are not. This means we ban one device instead of all connected to that router. And you can't change a MAC address...
-
Edited by ABotelho: 4/22/2014 11:22:12 PMWhat are you talking about? A device on another network should not know the MAC addresses of devices on another network. Routers separate broadcast domains and thus do not forward MAC addresses. The only MAC address you can know is the MAC addresses of the devices on your broadcast domain and the MAC address of your default gateway. And you absolutely can change a MAC address. They aren't "burned" on cards like they may have once been.
-
[quote]You can ping a mac on a single system level, and instead of blocking access to the gateway, you detect whether or not the mac is blacklisted from a remote ping, and then access is granted if they are not. This means we ban one device instead of all connected to that router.[/quote]None of this makes any sense whatsoever. [quote]And you can't change a MAC address...[/quote]Yes you can.
-
Edited by Security Officer: 4/21/2014 10:52:17 PMA long long time ago, someone suggested an [url=http://www.bungie.net/en/Forum/Post?id=32666191&path=1]idea involving "baked cookies" and the membership trust system[/url]. I don't know if it would work, it was suggested long before .Next (back when we had titles and trust values), but it still is an interesting idea. Sort of a way to throw out "spike strips" for those with alt armies, but a typical member would never notice.
-
Edited by ABotelho: 4/21/2014 10:57:37 PMMight work, for a little bit. The big tech companies are trying to slowly replace cookies. I feel like simply forcibly having to associate at the very least gamertag, PSN name, or Facebook account would help a lot. Wouldn't make it impossible, but definitely more trouble.