6 ms·
> NAT, port forwarding, SNI, masquerading, tunneling, VPNs, etc. All that stuff is mostly done for security purposes, not because we ran out of IP addresses.
by otabdeveloper1 9y ago
> NAT, port forwarding, SNI, masquerading, tunneling, VPNs, etc.
All that stuff is mostly done for security purposes, not because we ran out of IP addresses. (And before you reply: yes, it really works and is a valid security tool.)
- zAy0LfpBZLC8mAC 9y agoPlease explain the security purpose of four of those six.
- otabdeveloper1 9y agoNot being to address a corporate or home network computer from the outside is a feature, not a bug. Doubly so for the datacenter. Corporate IT doesn't want random internet hackers accessing sensitive information on the local corporate network. Yes, you can theoretically migrate everyone to IPv6 and implement some sort of firewall system to block outside access, but now you're effectively duplicating NAT in IPv6. Worse, due to second-system effect you're bound to end up with something even stupider and nastier than the existing stupid and nasty NAT solutions.
- zAy0LfpBZLC8mAC 9y ago> Not being to address a corporate or home network computer from the outside is a feature, not a bug. What does that have to do with any of the technologies you cited as being used for security purposes?
- Symbiote 9y ago> some sort of firewall system It's called a firewall, and you already have one when you use IPv4. The IPv6 one is much simpler, as there's no address translation (NAT).
- zAy0LfpBZLC8mAC 9y ago> It's called a firewall, and you already have one when you use IPv4. Unless you don't. In any case that doesn't have anything to do with the technologies they cited, as a firewall was not listed among them.
- otabdeveloper1 9y agoAny such firewall will need to: a) Mask end-user addresses somehow. You wouldn't want everyone on your corporate network to get a globally unique, trackable ID. b) Allow outgoing connections in arbitrary ways but forbid random incoming connections. c) Some sort of central, highly secured network node where your admins can configure this stuff. At this point you're close to reinventing NAT, except crappier.
- zAy0LfpBZLC8mAC 9y ago> a) Mask end-user addresses somehow. You wouldn't want everyone on your corporate network to get a globally unique, trackable ID. Everyone on your corporate network has tons of globally unique, trackable IDs. They're called cookies. Also, there are IPv6 privacy extensions. > b) Allow outgoing connections in arbitrary ways but forbid random incoming connections. Just as with IPv4? > c) Some sort of central, highly secured network node where your admins can configure this stuff. That's called a firewall. You need one with IPv4 as well. > At this point you're close to reinventing NAT, except crappier. None of that has anything to do with NAT.
- Symbiote 9y agoa) Do you provide privacy plugins to users' web browsers, and require they use them? If not, the concern is close to irrelevant, but there are privacy-minded ways to assign IPv6 addresses. b) is a basic feature of the crappiest firewall (the free router from my ISP includes it) c) is a standard feature of a business-level firewall; secure network access (e.g. with a VLAN) is orthogonal to the choice of IP protocol.
- guelo 9y agoIPV6 firewalls can do NAT in the same way IPV4 ones can.
- p1mrx 9y agoNAT66 is possible, in the sense that the protocol won't stop you from implementing or using it. But in practice it's relatively rare, because once you have a nearly-unlimited supply of addresses, NAT typically has more drawbacks than benefits.
- ra1n85 9y agoBut why use them when you don't have to? There's benefits to operating a network that handles as little state as necessary. Running internal services on address space that's not routable on the public internet has its advantages. You can do this with IPv6, but not as easily as you can with IPv4.
- zAy0LfpBZLC8mAC 9y ago> You can do this with IPv6, but not as easily as you can with IPv4. It's as trivial as not setting up a route for the address range at your inbound router. Bonus: If you ever discover that you need to have some service globally routable, it's as easy as adding a route. Try that with your IPv4 NAT setup.
- rnhmjoj 9y agoNAT being a security feature is a myth[1][2][3]. Please stop saying this. > but now you're effectively duplicating NAT in IPv6 No, you are not. If you set up a firewall there still is no translation in IPv6, and it's not needed because the network is end-to-end connected. > even stupider and nastier than the existing stupid and nasty NAT solutions. NAT is expensive for both memory and CPU usage, particularly when there is a large number of hosts, and it's not a security feature by itself. In no way can IPv6 with a simple firewall be worse than NAT. [1]: https://f5.com/resources/white-papers/the-myth-of-network-address-translation-as-security https://f5.com/resources/white-papers/the-myth-of-network-ad... [2]: https://blog.webernetz.net/2013/05/21/why-nat-has-nothing-to-do-with-security/ https://blog.webernetz.net/2013/05/21/why-nat-has-nothing-to... [3]: https://security.stackexchange.com/a/8773 https://security.stackexchange.com/a/8773
- otabdeveloper1 9y ago> NAT being a security feature is a myth It isn't. The arguments that it is a 'myth' boil down to arguments that it isn't perfect and doesn't protect against every attack. Well, guess what: no security measure is perfect and no security measure protects against every attack. At the very least, a secure IPv6 network will need to hide end user addresses somehow, because giving everyone a unique, globally-addressable and trackable ID is a security showstopper. At this point you're going to wonder if you considered all the contradicting requirements properly in your enthusiasm to roll out the next great shiny technology.
- zAy0LfpBZLC8mAC 9y ago> It isn't. The arguments that it is a 'myth' boil down to arguments that it isn't perfect and doesn't protect against every attack. Well, guess what: no security measure is perfect and no security measure protects against every attack. Except NAT provides absolutely no security, and complicates your network setup, thus making it more prone to configuration errors and other attack vectors due to complexity. > At the very least, a secure IPv6 network will need to hide end user addresses somehow, because giving everyone a unique, globally-addressable and trackable ID is a security showstopper. That is called privacy extensions. Also, it's pointless if you allow cookies in the browser.
- ancarda 9y agoNAT is not a firewall or security solution. For one thing, it can be opened with UPnP.
- tomjen3 9y agoVPNs are easy: you have all your services exposed, then you need to update every one stat when a bug is released and you are screwed if for some reason some of your services uses broken (or no) crypto, and it becomes more of a chore to decide which users gets access to what services. With VPN you have more time in case of an attack, everything is encrypted by default and you only have to watch one basket of eggs.
- zAy0LfpBZLC8mAC 9y agoWhich is one of six ... not quite "most" in my book. Yeah, that's the only one where I can see a use for security purposes, but even then, that's not the only reason why it's used.
- belorn 9y agoThe claim that SNI is a security feature is based on the assumption that it is more common to sniff the wire and collect the IP header rather than doing deep package inspection. I don't see this to be true with modern surveillance equipment and raw network taps. Additionally, you could create a setup where every visitor dynamically get a ip address from a pool (shared between multiple websites) when asked over encrypted dns. This kind of setup would clearly be superior over SNI's plain text issue.
- SwellJoe 9y agoThe thing is, the security elements of those things are often only marginal and were not the purpose of their existence (in most cases), and they mostly (though not all) boil down to security-through-obscurity. We're all mostly agreed that security-through-obscurity generally only provides a false sense of security and isn't the real deal. So, what if instead of working around an IP limit with all this complicated technology, the same folks had instead been working on good point-to-point encryption for everything all this time? And, what if all that complexity didn't have to exist in every device? Every line of code increases the likelihood of a security bug, and a network stack with all this extra stuff has a lot of extra lines of code. I dunno if NAT code has been responsible for exploits, but I'd be shocked if it hasn't. NAT didn't come into common use for security purposes. It just didn't. It came into common use because not every company owns a big enough sub-network for every device to have an IP and no individual household does. It would require completely rewriting history to suggest NAT is and has been used primarily as a security feature. Certainly, VPNs have a useful purpose other than dealing with the IP shortage of IPv4, but a lot of VPNs at the corporate level are used to tie two private networks together. And, a lot of development has gone into that purpose. I'm just saying that in a world without a strictly limited set of IPs over the past decade or two, we would likely have a very different looking internet, and I think it'd be a better internet than what we have, because of how much effort has gone into dealing with the complexity of NATted/tunneled/VPNed/etc. networks.