FINDING · EVALUATION
Using a simple dialup connection, the CleanFeed oracle scan enumerated IP addresses at up to 98 addresses/second. At this rate, the ~8.3 million Russian IP addresses (the IWF reported 25% of known illegal sites were hosted in Russia) could be scanned in under 24 hours, and the full routable IPv4 space (32% of 2^32 addresses) in approximately 160 days. A suitable filtered dialup account was available for free, with phone costs under £15.
From 2006-clayton-failures — Failures in a Hybrid Content Blocking System · §5.2 · 2006 · Privacy Enhancing Technologies
Implications
- IP-address-based blocklist enumeration is practical on consumer-grade connectivity; any system whose structure leaks blocklist membership should assume adversaries will enumerate the full list within days.
- Rate-limiting or behavioral anomaly detection on low-TTL probe traffic is a necessary (though not sufficient) mitigation — the paper notes active detection and account termination as the most practical countermeasure.
Tags
Extracted by claude-sonnet-4-6 — review before relying.