Live data from Hacker News

IPv6 address, as a sentence you can remember

sentence2ipv6.tib3rius.com

141–143 of 143 posts

Re: IPv6 address, as a sentence you can remember

#141
post #140

Earlier quoted context omitted.

> Like I said, not public. Outside the home, in other words in networks other than at home. Potentially without VPNs. Accessible from other public IP addresses, potentially limited scopes of those. It seems you're thinking that allowing the traffic from other public networks is an all or nothing thing. That either you allow all public network traffic or none of it. That's just not true. If I know my office network is…

> If I know my office network is one prefix, and I know my friend's house is another prefix, and I know my cellular carrier in my city is usually this prefix, I can greatly limit the scope of access. But it's still private use, not a public service. The fact that you access it from the internet side doesn't make it public. What you are describing here is in stark contradiction with your claimed easy to use IPv6. Why…

> The fact that you access it from the internet side doesn't make it public

A service I'm using its public IP for, routing through public network connections over the public internet, but somehow its not public networking its private networking despite private networks not really being involved. Got it. Having firewall rules suddenly makes it private networking, somehow.

> remember or bookmark a port number for each service

Or just don't, because I've got quintillions of public IP addresses just lying around. I can even have multiple instances of the same service running on the same box all running the same standard port numbers because I can just grab yet another IP address all day long. Why limit myself to having to memorize weird ports when I can just use the standard ones?

Re: IPv6 address, as a sentence you can remember

#142
post #140

Earlier quoted context omitted.

> If I know my office network is one prefix, and I know my friend's house is another prefix, and I know my cellular carrier in my city is usually this prefix, I can greatly limit the scope of access. But it's still private use, not a public service. The fact that you access it from the internet side doesn't make it public. What you are describing here is in stark contradiction with your claimed easy to use IPv6. Why…

> The fact that you access it from the internet side doesn't make it public A service I'm using its public IP for, routing through public network connections over the public internet, but somehow its not public networking its private networking despite private networks not really being involved. Got it. Having firewall rules suddenly makes it private networking, somehow. > remember or bookmark a port number for each…

> A service I'm using its public IP for, routing through public network connections over the public internet, but somehow its not public networking its private networking despite private networks not really being involved. Got it. Having firewall rules suddenly makes it private networking, somehow.

It's a private service exposed to public networks when it shouldn't be. That's not how it's done. You are taking risks. I'm sure others would agree with me if this article wasn't this old.

> Why limit myself to having to memorize weird ports when I can just use the standard ones?

For the reasons I explained before, mainly LAN security and DNS not working with dynamic IP allocations. But, go ahead, have it your way. Each of us have our own priorities in life. Convenience is a valid choice. Keep those offline backups updated.

Re: IPv6 address, as a sentence you can remember

#143
post #142

Earlier quoted context omitted.

> The fact that you access it from the internet side doesn't make it public A service I'm using its public IP for, routing through public network connections over the public internet, but somehow its not public networking its private networking despite private networks not really being involved. Got it. Having firewall rules suddenly makes it private networking, somehow. > remember or bookmark a port number for each…

> A service I'm using its public IP for, routing through public network connections over the public internet, but somehow its not public networking its private networking despite private networks not really being involved. Got it. Having firewall rules suddenly makes it private networking, somehow. It's a private service exposed to public networks when it shouldn't be. That's not how it's done. You are taking risks.…

> That's not how it's done.

Its not how it was done because of NAT. You just couldn't have done it that way for a long time. We don't need NAT anymore.

> For the reasons I explained before, mainly LAN security and DNS not working with dynamic IP allocations

But once again, its not actually changing the security characteristics at all compared to choosing weird ports and having to deal with reflection issues. The service is still opened either way, just one requires you to choose other ports.

Post reply on HN