3 ms·
> NAT being a security feature is a myth It isn't. The arguments that it is a 'myth' boil down to arguments that it isn't perfect and doesn't protect against e
by otabdeveloper1 9y ago
> NAT being a security feature is a myth
It isn't. The arguments that it is a 'myth' boil down to arguments that it isn't perfect and doesn't protect against every attack. Well, guess what: no security measure is perfect and no security measure protects against every attack.
At the very least, a secure IPv6 network will need to hide end user addresses somehow, because giving everyone a unique, globally-addressable and trackable ID is a security showstopper.
At this point you're going to wonder if you considered all the contradicting requirements properly in your enthusiasm to roll out the next great shiny technology.
- zAy0LfpBZLC8mAC 9y ago> It isn't. The arguments that it is a 'myth' boil down to arguments that it isn't perfect and doesn't protect against every attack. Well, guess what: no security measure is perfect and no security measure protects against every attack. Except NAT provides absolutely no security, and complicates your network setup, thus making it more prone to configuration errors and other attack vectors due to complexity. > At the very least, a secure IPv6 network will need to hide end user addresses somehow, because giving everyone a unique, globally-addressable and trackable ID is a security showstopper. That is called privacy extensions. Also, it's pointless if you allow cookies in the browser.
- simias 9y agoOnly Siths deal in absolutes. NAT has the side effect of behaving like a crappy firewall, so it gives you the added security of a crappy firewall. It's not much but it's something. But in the end I agree that it's a bit silly to use that as an argument in favor of NAT, if you want a firewall then use a firewall. I guess the advantage of NAT is that while you could forget to setup a firewall and not notice, you'll definitely notice it pretty quickly if you have a few computers on your LAN and you don't have a NAT...
- zAy0LfpBZLC8mAC 9y ago> NAT has the side effect of behaving like a crappy firewall, so it gives you the added security of a crappy firewall. No, it doesn't. Unless by "crappy firewall" you mean "a firewall that doesn't firewall". > I guess the advantage of NAT is that while you could forget to setup a firewall and not notice, you'll definitely notice it pretty quickly if you have a few computers on your LAN and you don't have a NAT... ... and you could then set up a NAT and still forget the firewall. Especially so if you mistakenly believe that NAT provides firewall functionality. There is absolutely nothing that prevents your ISP, and by extension anyone who happens to compromise your ISP('s router) from connecting to your RFC1918 addresses through your NAT gateway if you don't also have a firewall.
- simias 9y agoYou're really splitting hairs here. A NAT prevents direct access from the outside to the LAN, except is certain situations. That's part of a firewall's functionality. It's actually probably the first rule you'd set up on most firewalls, then you'd open select ports as necessary (which you do with port forwarding on NATs). A firewall can do a whole lot more of course, but there is some overlap. Anyway, I think we're in agreement on the core of the issue, it's just a matter of definition. Praising NATs for security is like praising a snowstorm because it makes it harder to steal my car. I guess some people really like to see the glass half-full.
- zAy0LfpBZLC8mAC 9y ago> A NAT prevents direct access from the outside to the LAN, except is certain situations. Well, an unreliable link prevents direct access from the outside to the LAN, except is certain situations!? Yes, there are certain scenarios of remote access that are prevented by NAT. But they are a lot less than what people generally think. ISPs' networks not being configured particularly securely is not exactly unheard of, from default passwords on routers to broken VLAN setups in FTTC/B/H setups where people could talk directly on the same ethernet to their neighbours' routers. And even if that is all configured perfectly, you still add their network and their staff to your trusted base. That might not be a big concern for home networks, but this subthread was also and in particular about corporate networks, where targeted attacks are much more likely, and in that case, NAT is in no way a "good enough" solution.
- pilif 9y ago> At the very least, a secure IPv6 network will need to hide end user addresses somehow, because giving everyone a unique, globally-addressable and trackable ID is a security showstopper. this is a solved problem now. All modern OSes either create short-lived temporary addresses or they hash some machine-unique information with the public prefix (that will change in the same frequency as your current V4 address changes).