[ratelimits] can't make qps-scale change effective slip

Paul Vixie paul at redbarn.org
Mon Jan 7 16:32:04 UTC 2013

Vernon Schryver wrote:
> Perhaps responses limited by all-per-second should not slipped. 

+1, now that you say it that way.

> I think diffuse reflection attacks are an open problem.

also +1. explicitly so. diffuse attacks will require a distributed
algorithm. that's beyond DNS RRL's present scope.

