# NTP pool squatting

**URL:** <https://community.ntppool.org/t/ntp-pool-squatting/2731>\
**Category:** Server operators\
**Created:** [February 27, 2023, 9:33pm UTC](https://community.ntppool.org/t/ntp-pool-squatting/2731 "2023-02-27T21:33:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ebahapo](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ebahapo/32/1152_2.png) [@ebahapo](https://community.ntppool.org/u/ebahapo)\
**Post date:** [February 27, 2023, 9:33pm UTC](https://community.ntppool.org/t/ntp-pool-squatting/2731/1 "2023-02-27T21:33:56Z")

</div>

It seems that some operators added servers to the pool that don’t seem to be under their control, such as `time.apple.com`, among others. Should @ask regularly bring more such servers under his control? What could be done to curb such practice by such operators?

---

<div class="post-metadata">

**Author:** ![stevesommars](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/stevesommars/32/2075_2.png) [@stevesommars](https://community.ntppool.org/u/stevesommars)\
**Post date:** [February 27, 2023, 11:17pm UTC](https://community.ntppool.org/t/ntp-pool-squatting/2731/2 "2023-02-27T23:17:24Z")

</div>

Ask already does this for some servers. See [this example](https://manage.ntppool.org/scores/216.239.35.8). There are over 100 monitor-only servers; the scores page shows " _Not active in the pool, monitoring only_" The list can be grown as needed.

---

<div class="post-metadata">

**Author:** ![ebahapo](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ebahapo/32/1152_2.png) [@ebahapo](https://community.ntppool.org/u/ebahapo)\
**Post date:** [February 28, 2023, 6:16pm UTC](https://community.ntppool.org/t/ntp-pool-squatting/2731/3 "2023-02-28T18:16:09Z")

</div>

@ask should regularly reserve more IP addresses, as I found other IP addresses belonging to `ntp.ubuntu.com` in the pool: [1](https://www.ntppool.org/scores/91.189.91.157), [2](https://www.ntppool.org/scores/2620:2d:4000:1::40), [3](https://www.ntppool.org/scores/2620:2d:4000:1::3f), [4](https://www.ntppool.org/scores/2620:2d:4000:1::41).

---

<div class="post-metadata">

**Author:** ![ask](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ask/32/907_2.png) [@ask](https://community.ntppool.org/u/ask)\
**Post date:** [March 13, 2023, 6:45pm UTC](https://community.ntppool.org/t/ntp-pool-squatting/2731/4 "2023-03-13T18:45:10Z")

</div>

yeah, I clean those up now and then. I like to think people are well meaning, but it’s obviously misguided.

My plan is to have a mechanism to require validation of new servers added. Maybe not do it on every server add, but if you have more than X servers in the account, set the bandwidth to 1000, try adding some of the well-known IPs / hosts, etc.
