Live data from Hacker News

By installing NAT, MIT stifles innovation

blog.achernya.com

81–90 of 188 posts

Re: By installing NAT, MIT stifles innovation

#81
post #69
post #8

I'm all for supporting innovation and community services, but I think author is not mentioning other possible causes, like DMCAs, malware and spam (including unintended), which could have damaged the reputation. I just wonder why MIT didn't give more time to move and why it doesn't provide a replacement in eg cloud credits.

Many years ago in a past life, I worked on the network security team at the University of Chicago. We had a similar policy (and they may still for all I know) of just being able to requisition publicly routable IPs and run whatever you wanted on them with no default firewall rules applied at the border. Not for nothing did we call this a "target rich environment". For all of the cool things I got to do (troubleshoot…

> behind NAT/firewalls

These are two separate things.

There is no security difference between "route port 80 of one of our public IPs through to my NATted address" and "open port 80 for my public address".

The public addresses are easier to administrate, troubleshoot, log, etc.

Re: By installing NAT, MIT stifles innovation

#82
post #41

Earlier quoted context omitted.

MIT doesn't have IPv6 everywhere yet? That's lame.

MIT just sold off half of its class A subnet. MIT was always going to be the last place on earth to go total IPv6

They'll get to IPv6 faster than the DOD, I guarantee it.

Re: By installing NAT, MIT stifles innovation

#83
post #77

Earlier quoted context omitted.

Indeed! If anyone needs to feel the squeeze for IPv4 to make a move to IPv6, it is AWS... which MIT is conveniently selling the IPv4 addresses to!

AWS does support ipv6 everywhere; the problem is that many consumers do not (I can't access ipv6 on my current provider w/o doing work on my side, for example) and so the need for public ipv4 is going to continue for years. I would be really happy to have only ipv6 addresses in my VPC, as that would make connecting up multiple VPCs much easier since I know their ip space won't overlap.

That's new. Last time I tried to get an IPv6 address for an EC2 instance it was either impossible or you had to set up this complicated virtual network thing depending on where your EC2 instance was physically hosted.

Re: By installing NAT, MIT stifles innovation

#84
post #79

Earlier quoted context omitted.

NAT is not an additional layer of security. I run our servers on public IP addresses, behind a firewall. Troubleshooting and debugging is made much easier, and there's never any conflict with VPNs etc. > It's likely that the only difference is that you'd also have to specify what ports you want exposed to the outside world Port 80, please. With NAT, you can't offer that to more than one computer.

But you can, a simple reverse proxy can let the same port be used for multiple servers and pick based on hostname or query (for http). reverse proxies like nginx also have plain tcp support so it allows you to easily run several services

You have to scale the reverse proxy, and you've added another point of failure.

Not to mention - who runs it? It needs to be trusted to terminate TLS or do 5-tuple proxying based on the SNI destination (not all clients send SNI). Also if the MIT student is doing something akin to protocol level development it's possible a middle proxy will prevent them from doing their work.

There is also the hassle factor. You may stop people from ever trying something because of the added hoops they must go through.

Re: By installing NAT, MIT stifles innovation

#85
post #79

Earlier quoted context omitted.

NAT is not an additional layer of security. I run our servers on public IP addresses, behind a firewall. Troubleshooting and debugging is made much easier, and there's never any conflict with VPNs etc. > It's likely that the only difference is that you'd also have to specify what ports you want exposed to the outside world Port 80, please. With NAT, you can't offer that to more than one computer.

But you can, a simple reverse proxy can let the same port be used for multiple servers and pick based on hostname or query (for http). reverse proxies like nginx also have plain tcp support so it allows you to easily run several services

So, now I have to run a reverse proxy -- another point of failure, another thing to debug when something's not working.

That's a hack to work around a shortage of IP addresses. Why would I use one, when I don't have that shortage?

Re: By installing NAT, MIT stifles innovation

#86
post #70

Earlier quoted context omitted.

But that would just be ridiculous, considering that experimenting with Tor relays is like a favorite student passtime...

And hosting websites is? I don't see the average student doing that either. I do, but then I also hosted hidden services, relays and exit nodes...

Yes! An average student can learn to host their server very easily with public addresses, and that was how I got started.

Re: By installing NAT, MIT stifles innovation

#87
post #77

Earlier quoted context omitted.

Indeed! If anyone needs to feel the squeeze for IPv4 to make a move to IPv6, it is AWS... which MIT is conveniently selling the IPv4 addresses to!

AWS does support ipv6 everywhere; the problem is that many consumers do not (I can't access ipv6 on my current provider w/o doing work on my side, for example) and so the need for public ipv4 is going to continue for years. I would be really happy to have only ipv6 addresses in my VPC, as that would make connecting up multiple VPCs much easier since I know their ip space won't overlap.

The situation over here is quite the opposite, if you're using the regular plans of the major ISPs (which is most people) you have IPv6.

Free ADSL, which has been providing IPv6 access via 6rd for like 10 years, even started deployment of IPv6 only DSLAMs in April.

This makes the absence of IPv6 on major platforms and sites very visible. There is no excuse not to have IPv6 today, especially for market leaders, and its lack thereof is definitely a showstopper WRT services we choose to use.

As an anecdote, we have seen some constantly increasing traffic over IPv6 in our logs, and our customers are definitely not on the technical side, very far from it.

http://m.universfreebox.com/article/38742/Free-deploie-ses-p...

Re: By installing NAT, MIT stifles innovation

#89
post #77

Earlier quoted context omitted.

AWS does support ipv6 everywhere; the problem is that many consumers do not (I can't access ipv6 on my current provider w/o doing work on my side, for example) and so the need for public ipv4 is going to continue for years. I would be really happy to have only ipv6 addresses in my VPC, as that would make connecting up multiple VPCs much easier since I know their ip space won't overlap.

That's new. Last time I tried to get an IPv6 address for an EC2 instance it was either impossible or you had to set up this complicated virtual network thing depending on where your EC2 instance was physically hosted.

Yup, they rolled out IPv6 support across several services in January 2017: https://aws.amazon.com/blogs/aws/aws-ipv6-update-global-supp...

Re: By installing NAT, MIT stifles innovation

#90
post #62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

Google is known to be against new and safe technologies. Google Finance still uses Flash, and Android has the worst IPv6 support despite it being based on Linux. What's your point?
Post reply on HN