Live data from Hacker News

By installing NAT, MIT stifles innovation

blog.achernya.com

61–70 of 188 posts

Re: By installing NAT, MIT stifles innovation

#62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever.

Forcing people to use anything is never a good way to promote innovation.

I went to MIT for my undergrad and doctoral studies. One of the main reasons I chose MIT over other schools was the ease of availability of static IP addresses, unlimited symmetric gigabit bandwidth, no port restrictions, and other things. I even mentioned this in my undergrad application essay. I built a lot of things with it and learned a lot in my time there. I probably learned more outside of classes than in classes, and I think that's one of the distinguishing aspects of MIT culture.

Re: By installing NAT, MIT stifles innovation

#63

Earlier quoted context omitted.

> Actually... MIT forcing an entire generation of future engineers to deal with IPv6 Then why are they doing NAT? Edit: Although moving to NAT might push innovation too, or at least some clever hacks. Speaking of that, if you want use a relay to do NAT traversal then is TCP over ARQ (on UDP) as bad as TCP over TCP?

> Then why are they doing NAT? Because they sold their IPv4 addresses.

Indeed! The only reason they're doing this is clearly that they want to sell even more IPv4 addresses. Because even with the current /9, it's more than enough to go around the campus.

Re: By installing NAT, MIT stifles innovation

#65
"The Library has the entire Net 18 address space registered at many hundreds of publishers of licensed e-resources. With no prior notice, we have been forced into non-compliance with our licenses with every such provider." I wonder what if the publishers actually sued MIT and Amazon, with maybe a injunction preventing Amazon from using the space.

Re: By installing NAT, MIT stifles innovation

#66

I wonder if any of this is related to the new NIST Standards[1], which have to be followed by research labs who receive government funding. I could see MIT, already having to retrofit a lot of their research networks, also changing around the network architecture in other places aswell. [1]: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP...

Nah, NAT doesn't provide the security; firewalling does.

Besides, what kind of controlled unclassified information could possibly be residing on dormitory networks?

Re: By installing NAT, MIT stifles innovation

#67
post #43

Earlier quoted context omitted.

Would the logic not be that the money will be spent on more useful things for students?

Perhaps. I haven't seen public discussion on the plans to use the fund though, other than vague promise that it will be used on Internet things.

> Net proceeds from the sale will cover our network upgrade costs, and the remainder will provide a source of endowed funding for the Institute to use in furthering its academic and research mission.

Source: https://gist.github.com/simonster/e22e50cd52b7dffcf5a4db2b8e...

Re: By installing NAT, MIT stifles innovation

#68

I wonder if any of this is related to the new NIST Standards[1], which have to be followed by research labs who receive government funding. I could see MIT, already having to retrofit a lot of their research networks, also changing around the network architecture in other places aswell. [1]: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP...

PDF is titled "Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations"

Re: By installing NAT, MIT stifles innovation

#69
post #8

I'm all for supporting innovation and community services, but I think author is not mentioning other possible causes, like DMCAs, malware and spam (including unintended), which could have damaged the reputation. I just wonder why MIT didn't give more time to move and why it doesn't provide a replacement in eg cloud credits.

Many years ago in a past life, I worked on the network security team at the University of Chicago. We had a similar policy (and they may still for all I know) of just being able to requisition publicly routable IPs and run whatever you wanted on them with no default firewall rules applied at the border. Not for nothing did we call this a "target rich environment".

For all of the cool things I got to do (troubleshoot a breakin at the South Pole, send the RIAA a DMCA takedown notice when they stole our content (absolutely the highlight of my career), etc.), we spent the vast majority of our time on nonsense. We processed dumb breakins by the hundreds, had to enforce DMCA takedowns, and the like.

I'm also all for innovation and giving people the freedom to deploy services and innovate, but I would have killed to deploy all IPs by default behind NAT/firewalls and work with researchers to help them understand their responsibilities before giving them public IPs.

Re: By installing NAT, MIT stifles innovation

#70

Perhaps doing it over .onion? Actually I have been experimenting this for my pet projects. Downside is that it's relatively slow but getting "global" address is click (well a few lines of config) away...

But that would just be ridiculous, considering that experimenting with Tor relays is like a favorite student passtime...

And hosting websites is? I don't see the average student doing that either.

I do, but then I also hosted hidden services, relays and exit nodes...

Post reply on HN