![]() |
| Source |
The blog post is more accessible, so that's what I will quote from. But for the details you need to read the paper. The blog post's TL;DR is:
First, we explore the empirical reality of OFAC’s blacklisting efforts. The results there are stark: nearly all addresses are completely empty by the time OFAC manages to blacklist them. This result is robust across time, attacker and type of attack. Second, we construct a simple model to explain why this outcome is inevitable with competent attackers. Evasion strategies which work in our model match those we find employed in the wild.Below the fold, I start from Datafinnovation's work and explore its context.


























