Earlier quoted context omitted.
Yeah I get it. At an organization your size, you want IPv6. I was illustrating why there is zero incentive for 99.99% of people to not care, which is the reason why it isn't getting adopted. If moving my home network to IPv6 came along with some incentives -- e.g. significant tax breaks, free symmetric gigabit for a year for IPv6 traffic, discounts on rent, tax-free early IRA distributions to buy networking equipment…
The point is until everyone moves to IPv6, the rest of us are stuck having to support dual stack - which is expensive (see the recent story about an ISP supporting a tribal reservation who had to spend an extra $300k and wait 11 months to support legacy IP) and introduces complexity/risk. For a small network it makes no difference, everything is auto configured, mdns is used to lookup names, you can makes your hosts…
I spent a week without IPv4 to understand IPv6 transition mechanisms
491–500 of 511 posts
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#492Earlier quoted context omitted.
Similarly, your comment is a good example of the anti NAT cargo cult mentality that people think is smart but really isn’t. The reality is that NAT has greatly improved the security of the internet, because before NAT people were exposing everything, including services like Windows file sharing, to the internet. NAT enabled those people to use multiple devices in their home and in return prevented them from unwitting…
Slammer (and other worms) propagated heavily despite NAT. If anything NAT made it worse, because once a single internal host got infected the worm now has a predictable and well known address space to scan for other devices it can infect. NAT created a false sense of security, while also breaking a lot of other things. It is quite easy for the defaults to be wrong, you can end up with all kinds of unexpected scenario…
NAT is bad because somehow magically a machine with an unroutable address can become routable. Because magically UPnP forwards every protocol in existence, not only a select group of programs that explicitly support it. And of course a connection opening up a theoretical hole to a specified host is just as bad (actually worse!) as opening it up to the whole internet.
Yet all routers have the right defaults and nobody ever makes a mistake. Oh and there’s so many addresses it’s so obscure it’s secure, and noone would guess to scan one’s own subnet in the absence of NAT.
These arguments are really grasping for straws, mostly nonsensical and the rest describes attacks so impractical they are pretty much impossible to carry out and are so much harder than simply sending a thousand emails with a link to an executable that pretty much nobody ever bothers.
Note I never said that IPv6 is worse, I said that NAT has relevant advantages and mostly irrelevant disadvantages. I really don’t care ftp doesn’t work with NAT.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#493Earlier quoted context omitted.
Most people don't buy their own router, the ISPs bulk buy thousands of routers at a time. The ISPs make up most of the market. Many of these routers are managed by the ISP using protocols such as TR-069, several ISPs have already been found to not only manage the devices but also monitor certain data including what devices are present.
This is pure anecdata, but almost everyone I know, include the people who aren't particularly computer-savvy, owns their own router and cable modem so that they don't have to pay a rental fee to their ISP.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#494Earlier quoted context omitted.
The words "local" or "home" network with IPv6 are an illusion, this is what I wanted to show with my examples, Firstly one ceases to have control of its own home network, what now have to rely on the ISP for to receive the "local" IPs, what are part of internet. And in addition each machine leaves a trace of its "local" ip on the Internet. This if one want internet access in the device, due the absence of NAT in the…
I still don't think you're really providing any examples or arguments that make your point, though. You're just coming across as really salty about IPv6. I'm not downvoting you. IPv6 has link-local addresses that aren't routable, so you can't really get more local than that. Unlike a typical IPv4 setup, typical IPv6 hosts have multiple addresses, and you can make your own for local traffic and only rely on ISP prefix…
I put the CVE links with the generic word "firewall" because it is the point where the "local" vs "internet" resides with blind faith within IPv6 (without indicating an specific exploit, just vulnerabilities exist). For this case, the DDOS and buffer overflows that force the firewall to shut down, or code execution, what are periodically discovered, is what I wanted to show for being considered as a serious problem. Not everyone reports firewall bugs, and others I guess even wickedly insert them.
With NAT setups, the local and internet networks are different between them, what requires the packets to be filtered and rewritten by NAT for the address what solicited it, while unsolicited packages are discarded. The NAT in consumer gear is run mainly by software, but a poisoned packet will not aim to shut it down for network penetration because it would be the end. If the NAT stops working, the doors close for everyone.
It is about the double checking,
-IPv6 without NAT: If the firewall stop working, opened doors. Feast.
-IPv6 with NAT: If the firewall stop working, many rules get unfiltered, wild. But NAT keeps the local/internet separation besides filtering unsolicited packages. Not absolutely secure, nevertheless keeps being a complex target.
Like all of we, I suffered some problems that NAT can bring losing countless hours trying to make work some specific services, but when I first read IPv6 didn't implemented NAT nor something similar in the protocol (for whom whish to use it at least...) and what the supposed local IPs are merely part of internet (link-local addresses that aren't routable as first target, devices with internet connection are), each device with its own public address, I doubted seriously about what was going on.
Given that even Mikrotik RouterOs periodically have security vulnerabilities related with the firewall, I can't conceive the idea of people relying on firewalls rules to do the home/internet separation within IPv6 (plus the public address of each device gives me also anxiety), as it is a matter of time before such separation ceases to exist; it is like the crossing of fingers.
I mean, it is not a matter of misfit, it is more like the users will not even notice the router's firewall was shut down.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#495Earlier quoted context omitted.
> There is no downside to everything to be globally routable. Yes there is. I sure as fuck don't want random people from the Internet to know how many devices and what kind populate my home LAN.
If an adversary knowing your IP address scheme it’s so bad to you, you’re not doing it right. Security through obsecurity is not security.
Yes, let's just flash a giant "welcome, nobody is home right now" sign to burglars whenever you leave the house unlocked.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#496Earlier quoted context omitted.
The point is until everyone moves to IPv6, the rest of us are stuck having to support dual stack - which is expensive (see the recent story about an ISP supporting a tribal reservation who had to spend an extra $300k and wait 11 months to support legacy IP) and introduces complexity/risk. For a small network it makes no difference, everything is auto configured, mdns is used to lookup names, you can makes your hosts…
Do you have a link to the tribal reservation ISP story? I can't find anything about it.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#497Earlier quoted context omitted.
IPv4 cuts it everywhere. IPv6 does not do anything to save the planet. IPv6 does have privacy concerns stated by many on this page. IPv6 could be shut down tomorrow and the Internet would continue working well.
No it wouldn't. Basically all mobile networks would break and have to do even more layers of NAT to meet demand. > IPv6 does not do anything to save the planet. The world doesn't have enough IPV4 addresses. It literally solves the problem. It is crazy to me so many people here are arguing for multileveled NAT instead of the obvious solution we have had for 20 years.
If 8 billion people wanted to host their own email and web, yes, we'd not have enough addresses for each person to have one. That isn't the case though. It will never be the case. If we look into the future and say well in 2023 5% of the world's population ran their own email and web for personal or business purposes and that number were to grow by 5% every year then in 20 years we would run out. That's a worse case, contrived scenario but even in that case, we'd still have 20 years to come up with something better than IPv6 that truly respects privacy and doesn't track each person.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#498Earlier quoted context omitted.
There is no downside to everything to be globally routable. It's completely orthogonal to firewalling. What is the risk you're picturing here? I'm really curious. Features like RFC4941/8981 mean nobody can infer anything about your network from the source addresses they see making requests out if it. If you want to use link-local V6 addresses and NAT to a global one, you can do that. But IMHO that's sacrificing one o…
> There is no downside to everything to be globally routable. Yes there is. I sure as fuck don't want random people from the Internet to know how many devices and what kind populate my home LAN.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#499Earlier quoted context omitted.
No it wouldn't. Basically all mobile networks would break and have to do even more layers of NAT to meet demand. > IPv6 does not do anything to save the planet. The world doesn't have enough IPV4 addresses. It literally solves the problem. It is crazy to me so many people here are arguing for multileveled NAT instead of the obvious solution we have had for 20 years.
> The world doesn't have enough IPV4 addresses. If 8 billion people wanted to host their own email and web, yes, we'd not have enough addresses for each person to have one. That isn't the case though. It will never be the case. If we look into the future and say well in 2023 5% of the world's population ran their own email and web for personal or business purposes and that number were to grow by 5% every year then in…
Try starting a new ISP. You’ll either do CGNAT on a single /24 of v4 space, or you’ll have to spend tens of millions for some pointless, legacy IP addresses.
Re: I spent a week without IPv4 to understand IPv6 transition mechanisms
#500Earlier quoted context omitted.
I use a public VPS and Wireguard. Costs $3.50 for the VPS which has a static IP. I host on my laptop. I can take my laptop anywhere in the world there's an Internet connection and my email and web sites continue to work right from the same VPS IP because my laptop connects to the Wireguard server on my VPS when it comes up.
That $3.50 will go up and up as IPv4 addresses get scarcer.