Skip to content

docs(prd): add PRD 0015 — Report abuse without becoming a source of it - #64

Merged
ralyodio merged 1 commit into
masterfrom
docs/prd-0015-abuse-reporter
Jul 28, 2026
Merged

docs(prd): add PRD 0015 — Report abuse without becoming a source of it#64
ralyodio merged 1 commit into
masterfrom
docs/prd-0015-abuse-reporter

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Specification for the abuse-reporter core module, listed in PRD.md and not yet specified.

Attack sources are usually compromised third-party machines whose owners do not know. Reporting to the provider is the only mechanism that gets them cleaned up rather than merely blocked, and shared feeds are how small operators benefit from each other's observations.

The problem is that an automated reporter makes PUBLIC ACCUSATIONS about other people's infrastructure, and every failure mode lands on someone else. Reporting a CGNAT or corporate NAT range attributes an attack to thousands of innocent users, and feeds propagate it. Worse, an attacker who can generate traffic appearing to come from a competitor can weaponize the reporter into a distributed reputation attack — the reporter becomes the abuse.

So the central requirement is an evidentiary bar, not throughput: corroboration from a high-precision detector, a completed TCP handshake so spoofed sources are structurally unreportable, carrier ranges never reported, off by default, dry-run first, and retraction available because the module will eventually be wrong.

Spec only — no implementation in this PR.

Attack sources are usually compromised third-party machines whose owners do not know. Reporting to the provider is the only mechanism that gets them cleaned up rather than merely blocked, and shared feeds are how small operators benefit from each other's observations.

The problem is that an automated reporter makes PUBLIC ACCUSATIONS about other people's infrastructure, and every failure mode lands on someone else. Reporting a CGNAT or corporate NAT range attributes an attack to thousands of innocent users, and feeds propagate it. Worse, an attacker who can generate traffic appearing to come from a competitor can weaponize the reporter into a distributed reputation attack — the reporter becomes the abuse.

So the central requirement is an evidentiary bar, not throughput: corroboration from a high-precision detector, a completed TCP handshake so spoofed sources are structurally unreportable, carrier ranges never reported, off by default, dry-run first, and retraction available because the module will eventually be wrong.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@ralyodio
ralyodio merged commit d12b514 into master Jul 28, 2026
8 checks passed
@ralyodio
ralyodio deleted the docs/prd-0015-abuse-reporter branch July 28, 2026 17:46
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant