Earlier quoted context omitted.
I’ve seen this sentiment repeated over and over in this thread without a single explanation. Please explain how NAT on IPv4, as used in practice, does not increase security vs connecting machines each directly to a publicly accessible Internet address? I’m having a hard time understanding how this statement can possible be true.
Here is the very simple but practical explanation why: https://0day.work/an-example-why-nat-is-not-security/ And more high-level explanation as well: https://www.f5.com/resources/white-papers/the-myth-of-networ...
The IPv6 Transition
421–430 of 433 posts
Re: The IPv6 Transition
#422Earlier quoted context omitted.
Yes, and? Don't make excuses for shitty technology. The mental model of what the "future Internet" (aka the one we're using now) would look like is completely insane in IPv6.
I am saying a lot of "IPv6 issues" are not because of the protocol itself, but rather it is self-inflicted pain. You quickly assuming IPv6 is a "shitty technology" means that you are part of the problem . Congratulations, you just proved my point. >the one we're using now The one we are using now is held by a bandaid. It's insane that, for me to connect to other computer, I need a middleman (STUN or other coordinatio…
It's not insane, it's the default and correct assumption. I certainly don't want random computers connecting to mine just because they want to.
STUN is a shitty solution to this problem, but IPv6 doesn't provide any solution at all, so a shitty solution wins here. Sorry.
Re: The IPv6 Transition
#423Earlier quoted context omitted.
Nah, many carriers don’t support it. I’ve always had to resort to STUN
STUN also isn’t guaranteed if the router is strict. IPv6 removes a lot of these unknown and strange ways that IPv4 infrastructure can break things.
Re: The IPv6 Transition
#424My ISP has given me a quite stable /64 network that's lasted for months and months. I am curious though: my IPv6 network begins with 2600::, which I feel is not an accident or mere coincidence. For a long time, Facebook would never "trust" my device, and I suspected it was because of the IPv6 thing. Now, "2600" is actually a hex number and doesn't mean 2600 decimal, but 2600 is an interesting prefix for a stable addr…
Re: The IPv6 Transition
#425Earlier quoted context omitted.
> Just the idea of having an always-on computer anywhere in your home excludes probably more than 80% of everyone who has ever written a blog. I have yet to meet someone who turns off the router at night, although I have heard of such people. Then if you think about it, TVs, washing machines, etc. people are too lazy to turn them off, and OLED TVs even require being turned on while not being used.
He obviously meant a general-purpose PC, the type of thing you might host a blog from.
Re: The IPv6 Transition
#426Earlier quoted context omitted.
I am saying a lot of "IPv6 issues" are not because of the protocol itself, but rather it is self-inflicted pain. You quickly assuming IPv6 is a "shitty technology" means that you are part of the problem . Congratulations, you just proved my point. >the one we're using now The one we are using now is held by a bandaid. It's insane that, for me to connect to other computer, I need a middleman (STUN or other coordinatio…
> It's insane that, for me to connect to other computer, I need a middleman It's not insane, it's the default and correct assumption. I certainly don't want random computers connecting to mine just because they want to. STUN is a shitty solution to this problem, but IPv6 doesn't provide any solution at all, so a shitty solution wins here. Sorry.
1. Reject the IPv6 solution
2. Say IPv6 doesn't have a solution
3. ???
4. Profit
Sigh.
Re: The IPv6 Transition
#427Earlier quoted context omitted.
It's likely the web itself has been shaped by the technology underpinning it. The article would seem to suggest something similar. Look at email. Now we all connect to the central email servers at Google and they handle most of everything else. Perhaps on the IPv6 internet, you would be able to buy a USB stick that handles all your emails for you. No more centralised mail, you just have a small server in your house t…
> Perhaps on the IPv6 internet, you would be able to buy a USB stick that handles all your emails for you. You are too optimistic. Poeple can't be bothered to migrate off the google to some alternative provider (also free) and you expect them to buy a "usb stick" for local (mail) server? And then have to keep their machines up all the time and also connected constantly? (not everyone lives in the USA and have FTTH)..…
The idea would be that you plug the stick into a USB port, then it just draws power from the wall and serves files over WiFi. Similar to the Amazon Fire TV stick, it would be a full computer in a small form-factor.
> and everyone use single instance
I wonder if this has anything to do with how difficult it would be to set up your own instance? We already have distributed social media, it's called websites. I think having your own website is pretty appealing to a lot of people. BlueSky is really just a worse version of HTTP with page indexers, which only needs to be that way because of NAT.
> All in all - people don't care about it, they want convenience and nothing else...
I know that people will not bother to migrate off their current software, but the product has its own pros and cons. Perhaps if they were presented with both options when they first obtained an email address, they would have made different choices.
And actually, I think people do care quite a lot. Even something as simple as sending a file to someone is massively complicated by NAT. People don't like the fact that they need to trust their digital lives to a handful of massive American companies. That people lack knowledge of the alternatives is not a sign that there are no better alternatives. See Ford on cars, Jobs on phones, etc.
Re: The IPv6 Transition
#428Earlier quoted context omitted.
He obviously meant a general-purpose PC, the type of thing you might host a blog from.
so when you can have a TV for movies, why can't you have a server for a blog?
[1]: Yes I know cinemas exist but they are very expensive and don't show content on demand.
Re: The IPv6 Transition
#429Earlier quoted context omitted.
Here is the very simple but practical explanation why: https://0day.work/an-example-why-nat-is-not-security/ And more high-level explanation as well: https://www.f5.com/resources/white-papers/the-myth-of-networ...
That's bullshit. "Security" is not a binary switch. NAT is a useful tool in your security toolbox when you want a more nuanced take than either "ban all ports" or "let every port flap open on the internets, #yolo".
Re: The IPv6 Transition
#430Earlier quoted context omitted.
Applications don't support it either, and if the hardware is seeing normal v4 then you're limited to sending to v4 destinations. How is this helping?
It would help everything else, applications are not the only part of the network (and many already support socks), there are middle boxes, DHCP, NAT, firewalls, reverse proxies, LAN services and what not that don't need to be aware of new addressing scheme. Firewalls might benefit from it, but even they would still mostly work, even if with less than perfect precision. And even applications can benefit from simplific…
If you just want to transport v6 over an existing v4 network there are already approaches to do that in v6.