Live data from Hacker News

My NAS exposes itself over the internet without permission

kn100.me

271–280 of 311 posts

Re: My NAS exposes itself over the internet without permission

#271
post #269

Earlier quoted context omitted.

I don’t think that is the goal, no.

There was always a tension between the Internet and Ethernet guys, the Internet guys have won, so Ethernet-specific concept like MAC adresses are on their way out ?

Not at all - MAC is layer 2, IP is layer 3.

Re: My NAS exposes itself over the internet without permission

#272
post #271

Earlier quoted context omitted.

There was always a tension between the Internet and Ethernet guys, the Internet guys have won, so Ethernet-specific concept like MAC adresses are on their way out ?

Not at all - MAC is layer 2, IP is layer 3.

Yes, and the two layers are represented by different political groups, each of which is trying to dominate.

Re: My NAS exposes itself over the internet without permission

#273

Earlier quoted context omitted.

>Without UPnP, you specifically have to configure your NAT for this... While I realize that configuring nftables/iptables is beyond most folks, there are many firewalls out there that have a GUI/webui which makes this dead simple. Not sure why this should be an issue in 2021, except for users' trained-in helplessness.

Since this is 2021, you should use IPv6, which doesn't need NAT.

Alas, many ISP's don't offer it yet. Give it a few decades more and we might get that.

Re: My NAS exposes itself over the internet without permission

#274
post #207

Earlier quoted context omitted.

Why not? Which consumer software breaks? Normally people say games. I have disabled upnp on my firewall and there're two gaming PCs, a PS3, a PS4 and a PS5 running happily behind it. I just finished a Demon Soul's session with voice chat with friends with no problems. NAT type 2, because I managed my firewall to enable this.

Have you tried a client/server style game not relying on Steam multiplayer?

It makes no difference since as I wrote I manage the firewall to allow this. But yes, since none of the games on consoles use Steam. If NAT wasn't set up I would get NAT type 3 on the PlayStations for example.

ETA: My point was to get an example of something that breaks "because it doesn't work without upnp". I have yet to see a game that doesn't support a fixed set of ports.

Re: My NAS exposes itself over the internet without permission

#275
post #24

Earlier quoted context omitted.

You mean "enable them all over again for every new DHCP assignment, unless you insist on static IP assignments".

Why wouldn't I use static dhcp?

You? You should. Random consumers on the other hand, are usually not capable enough to set up port forwarding, or manage a network.

UPnP might not be the right solution, but there is a clear and definite usability issue when it comes to networking and online gaming.

Re: My NAS exposes itself over the internet without permission

#276

Earlier quoted context omitted.

I live in France and work in IT and never heard about this "best practice". Who claims that? In use the highest fibre offering from Orange and have a dynamic IP. Fixed IP is for "professionals".

RIPE : https://www.ripe.net/publications/docs/ripe-690#5-2--why-non... That's funny, because I kind of have the "lowest" fiber offering from Orange, and I don't think my IP ever changed ? (I wouldn't bet on it thought.)

The RIPE article is about IPv6. I use only v4

I monitor closely my Internet connection (since I serve stuff on it, and also because why not) and I saw my IP changing and wandering throughout the Ile-de-France. I would say that the changes are every 6 months or so (since one of my domain is with Gandi I had to write a checker and change the assignment through their API)

Re: My NAS exposes itself over the internet without permission

#278

Earlier quoted context omitted.

IPv6 can be a privacy issue, sure, but it's no less secure, my firewall is still blocking all incoming IPv6 traffic. The issues with IPv6, in my experience come from its relative complexity, compared to IPv4, and also from forgetting to manage it at all, as it often uses different tools, firewalls, e.g. ip6tables vs iptables, or the fact that Ubiquiti EdgeRouters don't expose ANY IPv6 firewall configuration in the GU…

No firewall or opt-in firewall (which only a tiny fraction of people turn on) is pretty common for IPv6. It's also somewhat an open question whether router firewalls are even a good idea on IPv6 (since the security advantages are not that certain, and it can prevent the adoption of new protocols).

> pretty common for IPv6

Source? Every consumer router I've ever seen that supported IPv6 also had a firewall covering IPv6. Given the crapshot routers tend to be I wouldn't be surprised if some messed that up, but "pretty common" seems unlikely.

Re: My NAS exposes itself over the internet without permission

#279

Earlier quoted context omitted.

Since this is 2021, you should use IPv6, which doesn't need NAT.

Alas, many ISP's don't offer it yet. Give it a few decades more and we might get that.

At some point the governments should forbid them from calling themselves "I"SPs. This has already started with the 5G.

Re: My NAS exposes itself over the internet without permission

#280
post #278

Earlier quoted context omitted.

No firewall or opt-in firewall (which only a tiny fraction of people turn on) is pretty common for IPv6. It's also somewhat an open question whether router firewalls are even a good idea on IPv6 (since the security advantages are not that certain, and it can prevent the adoption of new protocols).

> pretty common for IPv6 Source? Every consumer router I've ever seen that supported IPv6 also had a firewall covering IPv6. Given the crapshot routers tend to be I wouldn't be surprised if some messed that up, but "pretty common" seems unlikely.

https://lafibre.info/ipv6/ipv6-le-firewall/

For context, Free recently boasted reaching 99% IPv6 coverage. On their (now) midrange Freebox Revolution router, the IPv6 firewall is (AFAIK still today) opt-in.

Post reply on HN