Live data from Hacker News

Why IPv6 is so complicated

github.com

211–220 of 519 posts

Re: Why IPv6 is so complicated

#211
post #197
post #53

Earlier quoted context omitted.

The nice thing about NAT is it makes the security model easier to reason about. By this, I don’t mean it’s more secure, because I know it isn’t. But it is a lot easier to see and to explain what has access to what. And the problem with enterprise is that 80% of the work is explaining to other people, usually non-technical or pseudo-technical decision makers, why your design is safe. I really do think IPv6 missed a tr…

NAT is a statefull firewall with a trick. One is exactly as complicated to reason about as the other. Except on one you don't need the trick.

Not in the context I was describing.

Re: Why IPv6 is so complicated

#213
post #197
post #53

Earlier quoted context omitted.

The nice thing about NAT is it makes the security model easier to reason about. By this, I don’t mean it’s more secure, because I know it isn’t. But it is a lot easier to see and to explain what has access to what. And the problem with enterprise is that 80% of the work is explaining to other people, usually non-technical or pseudo-technical decision makers, why your design is safe. I really do think IPv6 missed a tr…

NAT is a statefull firewall with a trick. One is exactly as complicated to reason about as the other. Except on one you don't need the trick.

NAT is state tracking with a trick, but not firewalling. It doesn't block connections, so it's not a firewall.

Re: Why IPv6 is so complicated

#214

Earlier quoted context omitted.

Can you just NAT66?

Have you tried it? NAT66 implies using fd00::/8, which then gets deprioritized in all devices below ipv4, in accordance with RFC 3484. The end result: all devices revert to using ipv4 on dual stack lan. Ipv6 is fundamentally broken for failover scenarios.

> NAT66 implies using fd00::/8

No it doesn't. Use the GUA from your primary ISP.

Re: Why IPv6 is so complicated

#215

Earlier quoted context omitted.

Misconfigured firewall is a gaping hole. Misconfigured NAT is not letting data from outside into your local network. So firewall is actually worse than NAT.

Even a correctly-configured NAT will let connections in from outside, and a lot of people don't understand this. Personally I'd count "your security thing doesn't actually do the thing it's supposed to do" as being pretty bad on the security scale. At least people understand firewalls.

> Even a correctly-configured NAT will let connections in from outside, and a lot of people don't understand this.

Yes, that's called port forwarding and it is normal thing. You actually want that.

Re: Why IPv6 is so complicated

#216

> Incidentally, "IPv8" proponents often ask why IPv6 didn't simply stick some extra bits on the front of IPv4 addresses, instead of inventing a whole new format. Actually, we tried that: the "IPv4-Compatible IPv6 address" format was defined in {{RFC3513}} but deprecated by {{RFC4291}} because it turned out to be of no practical use for coexistence or transition. Any tl;dr on why/how the simplest solution imaginable w…

TL;DR: because it doesn't actually solve anything. Being able to jam an IPv4 address into an IPv6 packet header doesn't mean you can send that packet to an IPv4-only host and have it be understood. You still need an IPv6 stack on both endpoints, and on all the routers in the middle - and at that point, why not just use IPv6 addresses?

Also, it already exists. The IPv4 range is included in the IPv6 range. 0000:0000:0000:0000:0000:ffff:0a00:0001 is the official IPv6 representation of 10.0.0.1.

As you can see, it doesn't actually solve anything.

It makes some APIs more convenient! You can pass this address to Linux for an IPv6 socket and it will secretly open an IPv4 connection to 10.0.0.1, so your code only has to support IPv6 sockets to support IPv6 and IPv4 connections.

It seems I've been rate limited to post every 12 hours, instead of five times per three hours. It must be either because I said interpreters don't emit native instructions, or because I said America had to buy TikTok to maintain American propaganda, or because I said you can make money gambling if your bets are the same as insiders. Or maybe I'm being punished for voting. I don't think dang will ever confirm what the reason was. Hacker News is so intransparent.

Re: Why IPv6 is so complicated

#217
post #192

At a high level one of the sad things about IPv6 is that it surrenders a wierd, valuable and emergent property of IPv4 for the average home user in $random_country: IPv4 addresses in logs are not super helpful in tracking a specific person and household’s behavior long term (NAT, reuse etc.) Almost every end user oriented IPv6 deployment makes it significantly easier to use IPv6 addresses to persistently track indivi…

At home, my external IPv4 address was the same for extended periods of time even though I never paid for a static IP. You could have figured the traffic was coming from the same location.

The one external IP to many internal devices relationship does help with privacy.

But once you enable those IPv6 privacy extensions, I have so many devices bouncing between IPs I’m not sure how you’d even know how many devices I have, let alone which device is which.

Re: Why IPv6 is so complicated

#218
post #53

Earlier quoted context omitted.

The nice thing about NAT is it makes the security model easier to reason about. By this, I don’t mean it’s more secure, because I know it isn’t. But it is a lot easier to see and to explain what has access to what. And the problem with enterprise is that 80% of the work is explaining to other people, usually non-technical or pseudo-technical decision makers, why your design is safe. I really do think IPv6 missed a tr…

Nope, it doesn't. The security model is based on your firewalls and routing, not on NAT. NAT just gets in the way and makes it harder to understand what's going on. For example, on a normal home network, if you don't have a firewall on your router then your ISP can connect to anything on your network. Even when they don't control the router and even if you're NATing. If you didn't realize this then apparently NAT did…

Can you say more about the ISP connecting to any computer on your network? I can’t find any references to this aspect in googling the right terms and the concept is foreign to me.

There are a bunch of ways to break it, or misconfigure it. But I have idea what this isp method is.

Re: Why IPv6 is so complicated

#219
post #53

Earlier quoted context omitted.

The nice thing about NAT is it makes the security model easier to reason about. By this, I don’t mean it’s more secure, because I know it isn’t. But it is a lot easier to see and to explain what has access to what. And the problem with enterprise is that 80% of the work is explaining to other people, usually non-technical or pseudo-technical decision makers, why your design is safe. I really do think IPv6 missed a tr…

Nope, it doesn't. The security model is based on your firewalls and routing, not on NAT. NAT just gets in the way and makes it harder to understand what's going on. For example, on a normal home network, if you don't have a firewall on your router then your ISP can connect to anything on your network. Even when they don't control the router and even if you're NATing. If you didn't realize this then apparently NAT did…

[deleted]

Re: Why IPv6 is so complicated

#220
Most of the bitching about IPv6 is from those who really, really want IP addresses to identify machines or users. IP addresses (including IPv4) were never intended to do that and it was never a good idea to put them in that position.

There was a time when most devices had 1 network interface and didn't move. But that was never a guarantee. People thought it was a guarantee when your $400-in-1988-dollars Madge ISA full-height full-width token-ring NICs with dangling AUI dongles next to your tank of an ST225 hard drive were a thing, but we're past that. Today most things that aren't servers have at least 2 - wired/Wi-Fi for laptops, Wi-Fi/cellular for phones. You can talk about NAT and security and mapping all you want, but if I can bypass your corporate internal network security simply by turning off my phone's Wi-Fi, yet still get to your resources - then NAT is a legacy chore that IPv6 makes unnecessary.

Post reply on HN