Live data from Hacker News

IP Addresses Through 2025

potaroo.net

141–150 of 158 posts

Re: IP Addresses Through 2025

#141
post #83

Earlier quoted context omitted.

For some background why IoT products will stop being insecure: if you sell one in the EU, you're liable for all the damage your botnet causes. Luckily, common EU home routers have firewalls, even for IPv6. And it's so much easier to punch holes on purpose! Instead of messing with port forwarding and internal and external IP addresses, you can just say "this device is a server, please allow traffic on port 80 and 443,…

I don't see how the logistics for that would work. Even when you know what devices are part of a botnet, which itself is no easy task, each device in a botnet is only doing cents worth of damage, and mostly to the target, but product liability only applies to the owner of the product. Also, everyone I know that lives in Europe (although most of them not within EU countries) imports their IoT controllers directly from…

[dead]

Re: IP Addresses Through 2025

#142
post #94
post #89

Earlier quoted context omitted.

> NAT is not the firewall. NAT _is_ a firewall. And a much safer one than IPv6 firewalls, because NAT will fail safe if misconfigured.

NAT is not a firewall: all it does is rewrite packets, it does not drop them.

A NAT will drop all packets, until something upstream opens a port. Dropping packets is the default behavior of a NAT.

Re: IP Addresses Through 2025

#143

Earlier quoted context omitted.

India does it too. You see it on all socials as well as reddit. Brain dead posts and comments praising the current govt or gate against anyone criticising.

> You see it on all socials as well as reddit Almost all the Indian subreddits are against the current government. You will be banned from a subreddit even if you rightly speak in support of current government on Reddit. It's hard to take your rest of your comment seriously if you are blatantly dishonest about this.

The official one isn’t but there are a lot more in support of it. They are just named differently. Local language (we have a lots of them) or endonyms etc.

Re: IP Addresses Through 2025

#144

Earlier quoted context omitted.

The CGNAT point is underrated. Carriers have zero incentive to move away from it - thousands of users per public IP, no transition cost. The interesting downstream effect is on IP reputation systems. Traditional detection assumed 1 IP = 1 user. CGNAT breaks that entirely - platforms can't aggressively filter mobile carrier IPs without blocking legitimate customers by the thousands. Makes sense the IPv4 price dropped…

Anecdotally on how this affects the day to day user experience: I just deployed T-Mobile 5G Business Internet to a temporary pop-up art space (it's only active for a few months) and I'd say twice daily I get a CAPTCHA challenge on Google search.

I would have thought that a 5G connection would have IPv6 and wouldn't need CGNAT to Google properties

Re: IP Addresses Through 2025

#145

I'm interested in any new successful startups going full IPV6 from the beginning. Once we cross that bridge, where your internal IPV4 knowledge is equivalent to token ring knowledge, there's nothing else to watch.

Relatedly: wouldn't there be many applications for which ipv4 isn't needed? For example, Walmart has electronic eink shelf tags they can update remotely. Each one needs a unique address. I wouldn't think it needs ipv4. It doesn't have to connect to the SpaceJam website. I would think that as time goes by, the number of these new devices would swamp the number of old ones that need ipv4. v4 would still be around and m…

An example of this is Matter, the new industry standard for IoT devices. It uses IPv6 addressing, so if you want your IoT devices bridged onto your LAN, your LAN needs to support IPv6.

https://en.wikipedia.org/wiki/Matter_(standard)

Re: IP Addresses Through 2025

#146

It always sends me to sleep when IP enthusiasts lament the lack of adoption for IPv6. It's obvious to anyone that looks at the two formats that any kind of hacky workaround like NAT gateways will be preferable indefinitely to actually adopting the monstrosity that is IPv6.

The real hacky workaround that we have adopted is just centralizing the whole internet in like 5 giant companies and making everyone else into passive consumers who can't even make a voice call to each other without giving some form of payment to a cloud giant.

Re: IP Addresses Through 2025

#147
post #128
post #94

Earlier quoted context omitted.

NAT is not a firewall: all it does is rewrite packets, it does not drop them.

You have to squint a little and see they mean that most consumer routers don't map inbound unsolicited packets to anything internal unless the user specifically configured it to. Which is basically a firewall.

That's not true in my experience, consumer grade routers will often happily route packets with rfc1918 destination addresses from the WAN to the LAN interface all day. The "firewall" is only that nobody can get packets with those destination addresses to the home router's WAN interface through the internet.

Re: IP Addresses Through 2025

#148
post #128
post #94

Earlier quoted context omitted.

NAT is not a firewall: all it does is rewrite packets, it does not drop them.

You have to squint a little and see they mean that most consumer routers don't map inbound unsolicited packets to anything internal unless the user specifically configured it to. Which is basically a firewall.

This is because most consumer routers have a firewall, which is separate from the NAT. Creating NAT mappings also creates firewall entries.

Otherwise, the router would happily pass the packet along to any IP address it finds in a packet it receives. That's the job of a router, after all.

Re: IP Addresses Through 2025

#149
post #94

Earlier quoted context omitted.

NAT is not a firewall: all it does is rewrite packets, it does not drop them.

A NAT will drop all packets, until something upstream opens a port. Dropping packets is the default behavior of a NAT.

Nope, it's the default behavior of a typical firewall. NAT rewrites packets but it never drops packets. An un-rewritten packet may fail to route (i.e. "destination unknown".) But that depends on the destination in the packet.

Re: IP Addresses Through 2025

#150

Earlier quoted context omitted.

> You see it on all socials as well as reddit Almost all the Indian subreddits are against the current government. You will be banned from a subreddit even if you rightly speak in support of current government on Reddit. It's hard to take your rest of your comment seriously if you are blatantly dishonest about this.

The official one isn’t but there are a lot more in support of it. They are just named differently. Local language (we have a lots of them) or endonyms etc.

All national subreddits are anti-government. The popular regional ones like r/delhi is anti-government too. If you know any pro-government subreddits let me know, I would love to join.
Post reply on HN