6 ms·
Not being to address a corporate or home network computer from the outside is a feature, not a bug. Doubly so for the datacenter. Corporate IT doesn't want rand
by otabdeveloper1 9y ago
Not being to address a corporate or home network computer from the outside is a feature, not a bug. Doubly so for the datacenter. Corporate IT doesn't want random internet hackers accessing sensitive information on the local corporate network.
Yes, you can theoretically migrate everyone to IPv6 and implement some sort of firewall system to block outside access, but now you're effectively duplicating NAT in IPv6. Worse, due to second-system effect you're bound to end up with something even stupider and nastier than the existing stupid and nasty NAT solutions.
- zAy0LfpBZLC8mAC 9y ago> Not being to address a corporate or home network computer from the outside is a feature, not a bug. What does that have to do with any of the technologies you cited as being used for security purposes?
- Symbiote 9y ago> some sort of firewall system It's called a firewall, and you already have one when you use IPv4. The IPv6 one is much simpler, as there's no address translation (NAT).
- zAy0LfpBZLC8mAC 9y ago> It's called a firewall, and you already have one when you use IPv4. Unless you don't. In any case that doesn't have anything to do with the technologies they cited, as a firewall was not listed among them.
- otabdeveloper1 9y agoAny such firewall will need to: a) Mask end-user addresses somehow. You wouldn't want everyone on your corporate network to get a globally unique, trackable ID. b) Allow outgoing connections in arbitrary ways but forbid random incoming connections. c) Some sort of central, highly secured network node where your admins can configure this stuff. At this point you're close to reinventing NAT, except crappier.
- zAy0LfpBZLC8mAC 9y ago> a) Mask end-user addresses somehow. You wouldn't want everyone on your corporate network to get a globally unique, trackable ID. Everyone on your corporate network has tons of globally unique, trackable IDs. They're called cookies. Also, there are IPv6 privacy extensions. > b) Allow outgoing connections in arbitrary ways but forbid random incoming connections. Just as with IPv4? > c) Some sort of central, highly secured network node where your admins can configure this stuff. That's called a firewall. You need one with IPv4 as well. > At this point you're close to reinventing NAT, except crappier. None of that has anything to do with NAT.
- Symbiote 9y agoa) Do you provide privacy plugins to users' web browsers, and require they use them? If not, the concern is close to irrelevant, but there are privacy-minded ways to assign IPv6 addresses. b) is a basic feature of the crappiest firewall (the free router from my ISP includes it) c) is a standard feature of a business-level firewall; secure network access (e.g. with a VLAN) is orthogonal to the choice of IP protocol.
- guelo 9y agoIPV6 firewalls can do NAT in the same way IPV4 ones can.
- p1mrx 9y agoNAT66 is possible, in the sense that the protocol won't stop you from implementing or using it. But in practice it's relatively rare, because once you have a nearly-unlimited supply of addresses, NAT typically has more drawbacks than benefits.
- mgbmtl 9y agoOn tracking: - You can use IPv6 privacy extensions to randomize your IP address. Your computer can have a dozen IP addresses at a given moment, using a different one to access different services, as addresses are being rotated. - Most corporate networks have static IPs. So while a specific IP might be shared with 100 devices, it's usually easy to fingerprint a visitor uniquely. - There are tons of other ways to track people, other than their IP. Besides, you want to track them across networks, as they move around. I'm also very sensitive to tracking, but I think at this point you have to start looking at how to improve your privacy with IPv6, sharing/encouraging good privacy-sensitive practices on IPv6.. not spreading FUD.
- ra1n85 9y agoBut why use them when you don't have to? There's benefits to operating a network that handles as little state as necessary. Running internal services on address space that's not routable on the public internet has its advantages. You can do this with IPv6, but not as easily as you can with IPv4.
- zAy0LfpBZLC8mAC 9y ago> You can do this with IPv6, but not as easily as you can with IPv4. It's as trivial as not setting up a route for the address range at your inbound router. Bonus: If you ever discover that you need to have some service globally routable, it's as easy as adding a route. Try that with your IPv4 NAT setup.
- rnhmjoj 9y agoNAT being a security feature is a myth[1][2][3]. Please stop saying this. > but now you're effectively duplicating NAT in IPv6 No, you are not. If you set up a firewall there still is no translation in IPv6, and it's not needed because the network is end-to-end connected. > even stupider and nastier than the existing stupid and nasty NAT solutions. NAT is expensive for both memory and CPU usage, particularly when there is a large number of hosts, and it's not a security feature by itself. In no way can IPv6 with a simple firewall be worse than NAT. [1]: https://f5.com/resources/white-papers/the-myth-of-network-address-translation-as-security https://f5.com/resources/white-papers/the-myth-of-network-ad... [2]: https://blog.webernetz.net/2013/05/21/why-nat-has-nothing-to-do-with-security/ https://blog.webernetz.net/2013/05/21/why-nat-has-nothing-to... [3]: https://security.stackexchange.com/a/8773 https://security.stackexchange.com/a/8773
- otabdeveloper1 9y ago> NAT being a security feature is a myth It isn't. The arguments that it is a 'myth' boil down to arguments that it isn't perfect and doesn't protect against every attack. Well, guess what: no security measure is perfect and no security measure protects against every attack. At the very least, a secure IPv6 network will need to hide end user addresses somehow, because giving everyone a unique, globally-addressable and trackable ID is a security showstopper. At this point you're going to wonder if you considered all the contradicting requirements properly in your enthusiasm to roll out the next great shiny technology.
- zAy0LfpBZLC8mAC 9y ago> It isn't. The arguments that it is a 'myth' boil down to arguments that it isn't perfect and doesn't protect against every attack. Well, guess what: no security measure is perfect and no security measure protects against every attack. Except NAT provides absolutely no security, and complicates your network setup, thus making it more prone to configuration errors and other attack vectors due to complexity. > At the very least, a secure IPv6 network will need to hide end user addresses somehow, because giving everyone a unique, globally-addressable and trackable ID is a security showstopper. That is called privacy extensions. Also, it's pointless if you allow cookies in the browser.
- ancarda 9y agoNAT is not a firewall or security solution. For one thing, it can be opened with UPnP.