5 ms·
Even Apple got bit by this issue. They sold an Airport home router which by default provided full v6 connectivity. They were promptly lambasted in the press for
by DanielDent 10y ago
Even Apple got bit by this issue. They sold an Airport home router which by default provided full v6 connectivity. They were promptly lambasted in the press for "putting their users at risk by not having a proper firewall!". :(
There was a time when perimeter security was seen as an adequate and acceptable technique.
- geofft 10y agoYeah, that's where the discussion gets confusing. I will totally agree that a world without NAT would be better, but I will not agree that a world without home routers that drop all inbound connections would be better. If the ISP gives out /64s, the right behavior for the home router is to assign addresses in that /64, but keep doing stateful tracking of outbound connections just like a NAT would, and drop everything else on the floor. Of course, at this point you've broken end-to-end connectivity (P2P apps don't work, active-mode FTP doesn't work, etc.) so this may not actually resolve the reason people wanted to get rid of NAT. Maybe a good portion of the the no-NAT-in-IPv6 crowd wants inbound routes to people's homes so apps work, and the "but you don't need NAT for security" crowd is misunderstanding them
- DanielDent 10y ago"but keep doing stateful tracking of outbound connections just like a NAT would, and drop everything else on the floor" Here are two important behaviours which come with "just like a NAT would". 1) UPNP - a protocol which allows an application to request it be exposed to the internet 2) Hole punching. E.g. two hosts send packets with matching ip/port values to cause a direct connection to be established between them Applications don't really do those things on v6... And, FWIW, ISPs should be giving residential users at least a /56 - if not a /48. Sites should be able to have enough address space to route within the site and still use the features of IPv6 which require a /64. Route aggregation and routing table size is the constraint of the v6 world, not address space.
- api 10y agoHole punching still exists in the V6 world if you want an app to do P2P from behind stateful V6 firewalls. It requires a three party handshake just like V4 NAT traversal. But unlike NAT traversal it nearly always works since there are no symmetric NAT nightmares. V6 should make all this cruft go away but it doesn't.
- api 10y agoI really passionately hate clueless security FUD.
- detaro 10y agoDid it have a proper firewall with sensible defaults? (I wouldn't be surprised if some vendors shipped IPv6-enabled routers without a firewall for IPv6)
- DanielDent 10y agoThere's a reasonable argument to be made that router-based firewalls shouldn't be necessary for a home user to have a secure configuration. If it's not safe to expose a service to the internet, it's also not safe to have it exposed within your LAN without access controls. NAT-based 'firewalls' can have holes in punched in them in a variety of ways - they are specifically designed to allow holes to be punched, because it's necessary for many applications to work. It's also possible to take advantage of a user's browser as a relay. Combine that with the ability to use ad networks to target HTML to be served to the IP of an attacker's choosing, and the illusion that a perimeter firewall will prevent an attacker from initiating connections to your network starts to shatter. I agree that in practice, in many cases today the stateful firewall-like functionality provided by a NAT device will provide a net security improvement. But that's not a situation we should continue to allow. It's unrealistic to expect users to manually create firewall holes. That's why default configurations tend to include UPNP (which, naturally, introduce a new set of security and DoS concerns) - which will automatically open holes in the 'firewall'. Google has published some of their thinking on this topic under the 'beyondcorp' moniker. The summary is there is no "safe" and "unsafe" - you need to do a risk evaluation of each attempt to access a service, and "this is coming from inside our network" in inadequate.
- detaro 10y agoDe-facto they are necessary, because people expect their networks to be safe, run all kinds of not-great things in there and sort-of got used to configuring port-forwarding. Attacks that can go from inside the network are in practice quite rare (AFAIK), and are a reason to add more security between network devices, not to expose them to the public net. I'd love if we could trust most devices to be publicly exposed, but IMHO we can not. If router manufacturers could be trusted one could add all kinds of clever things there, but ...