Earlier quoted context omitted.
> Since /64 is smallest network in IPv6 A /64 is not the smallest network in IPv6. Nothing stops you having a /112 or a /126 or whatever you like. It is the only network size on which SLAAC works however, so it's a good choice for lan sizes.
I'm talking practical. I know you can reduce networks further BUT there is plenty of stuff that could break.
Bruteforcing the phone number of any Google user
181–190 of 204 posts
Re: Bruteforcing the phone number of any Google user
#182Earlier quoted context omitted.
I'm talking practical. I know you can reduce networks further BUT there is plenty of stuff that could break.
GCP for example hands out /96s to each VM, so this isn’t a theoretical or niche usecase.
So from the point of abuse logic it's appropriate to treat the whole /64 as a single unit. (That was the starting point of the thread, even though I realize that due to thread drift that's probably not what your comment was about.)
Re: Bruteforcing the phone number of any Google user
#183Earlier quoted context omitted.
not so long ago practically everyone's name and phone number was available publicly for free in any phone box
people always trot this out, but it was very possible to have your information unlisted so it was not printed in the book. you could also use a different name. an old coworker selected to have his name listed as David King so that when found in the book it would show up as King David. having an unlisted number wasn't uncommon. for privacy minded people, it was a simple phone call to make it unlisted, and most just di…
Re: Bruteforcing the phone number of any Google user
#184This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.
The same is true now with NAT (where they're all behind a single ip or a very small pool of IPs), but IPv6 should make these things better.
Re: Bruteforcing the phone number of any Google user
#185Earlier quoted context omitted.
They can just take your number anyway if you ever insert a SIM, since they control "your" phone.
Interestingly, your phone number is actually not stored on the SIM card. It instead holds a globally unique ICCID number which your operator links to your account (phone number) on their systems. This actually makes it possible to transfer your phone number between SIM cards or even operators, and means your cell phone is blissfully unaware of its own phone number.
Re: Bruteforcing the phone number of any Google user
#186These bug bounties pay peanuts. Sad.
Corporate greed sucks for all
Re: Bruteforcing the phone number of any Google user
#187This article highlights something interesting... it is quite common to get at least one /64 IPv6 block from a hosting provider or ISP. Yet most of the rate-limiting and IP blocking is done for a single IP. Sounds like when dealing with IPv6, an entire block of /64 should be rate-limited or blocked.
I'm on a relatively large Indian ISP, and my home network gets an IPv6 network assigned, which is directly routable. Didn't think about it until tailscale told me it was connecting over a direct IPv6 connection and I wondered how that was possible. Sounds like 90s network rampage may be back here.
Re: Bruteforcing the phone number of any Google user
#188It must be a daunting chore to maintain all the legacy pages. The amount of now-years-old stuff that long-standing sites have to maintain, or choose to maintain, is shockingly high, and testing the combination of all that stuff is impossible. If you want an example of how diverse in age these apps are, dig around in the Gmail settings panel. Eventually you will land on a popup that uses the original Gmail look and fe…
Bug bounty program appears to be an efficient spend. For a few thousand dollars they mobilize unpaid people looking for extreme edge cases and then surface these issues. It would’ve cost way more to pay an employee to search for this.
Re: Bruteforcing the phone number of any Google user
#189Earlier quoted context omitted.
Google's main search page is the slowest page & UI I have found on the internet today (not accounting for bandwidth limits). Even on modern devices it lags at text entry and even rearranges characters in the text box so you have to wait 10+ seconds for it to finish loading or it will go haywire. The shopping and other pages are actually worse. So it appears you're right, $350B isn't enough money to maintain a web pag…
There is something wrong with your computer.
Re: Bruteforcing the phone number of any Google user
#190Earlier quoted context omitted.
not so long ago practically everyone's name and phone number was available publicly for free in any phone box
Not to mention that these "phone books" also included everyone's address, and married couples were usually listed together.
Being unlisted was sometimes devastating to a 1980s kid’s social life… I missed out on multiple birthday parties and other invitations. My sisters probably lost out on some dating opportunities.