6 ms·
The fact that every device in your network is given a publicly reachable IP address is not something to brag about. It’s a security problem. I’ll stick to my N
by nanamo 8y ago
The fact that every device in your network is given a publicly reachable IP address is not something to brag about. It’s a security problem.
I’ll stick to my NAT, thank you.
- zlynx 8y agoImplement security properly and stop worrying about it. If your devices have open services with vulnerabilities. AND You completely forgot or didn't bother to use a firewall. AND Your devices are using permanent instead of temporary IPv6 addresses. THEN you might have a problem. But it's more likely that your badly protected IoT devices are downloading their software updates from a HTTP site without SSL or checksum verification while using a DNS vulnerable to cache poisoning.
- AstralStorm 8y agoTemporary v6 addresses are not a security measure, they're a privacy measure. (And a weak one at that.) An attacker can get route advertisements from your subnet if something is misconfigured on ISP side so they get out and do a tiny bit of inference to figure out which device it is.
- AceJohnny2 8y agoNAT accidentally and poorly gives you security through obscurity. Use a firewall.
- zAy0LfpBZLC8mAC 8y agoNo, it doesn't. NAT alone does not prevent inbound connections. You need a stateful firewall in addition to the NAT for that. And if you have that, well, yeah, you obviously don't need NAT.
- jandrese 8y agoNAT is stateful, at least in the most common configuration. Static NAT is not something a home user needs to worry about. Honestly, if you have NAT you almost certainly have a firewall because NAT is nearly always implemented as part of the firewall. It may not be a properly configured firewall, but the functionality is there.
- X-Istence 8y agoIf send a packet destined for "10.10.10.11" to "71.28.10.10", your router would happily figure out "what interface do I forward 10.10.10.11 to" and it would happily send it to the connected device, because NAT is not a firewall. There is no rule stating that "packets destined for 10.10.10.11 on eth0 should not be forwarded to eth1". That's what a firewall is for. And yes, your little router, is actually a router. It will dutifully take packets from one interface, look at it's routing table and figure where to spit it out. That's what it is supposed to do, NAT just adds a rule that says if a packet comes from eth1 and is destined for 0.0.0.0/0 (default route) out interface eth0 then we (the router) want to masquerade as if we are the source of that packet, so that this entire network looks as if it is coming from one single IP. No firewall involved, and packets arriving on eth0 are going to get routed to eth1 all the same, since after all, we are a faithful little router. This is how routing has worked since the dawn of time. Adding a firewall means we can say "but I should never see traffic destined to 10.10.10.0/24 on eth0, so drop it". --- Either way, NAT may be part of the firewall but there is no requirement for it to be part of the firewall. When it comes to IPv6, just like IPv4, a firewall is required, and as soon as you have a firewall that blocks incoming traffic, then NAT becomes meaningless.
- blackflame7000 8y agoSo if I'm understanding correctly, by spoofing the destination IP you can effectively manipulate the routing pathway and bypass the NAT to communicate with devices on the LAN?
- zAy0LfpBZLC8mAC 8y agoThere is no "spoofing" or "manipulation" or "bypassing", it's simply sending a packet to the address and a router doing what a router does, in a use case that simply doesn't involve the NAT. The idea that NAT prevents inbound connections is simply a myth believed by tons of people who have no clue how IP works. It simply doesn't. So you don't need to do any "spoofing" or "manipulation" to "bypass" something that NAT simply doesn't do. You might as well say that you can bypass a P.O. box by spoofing the destination address and thus effectively manipulating the snail mail routing. No, it's simply the case that you can address letters to street addresses and the postal service will deliver them to the address written on the envelope. Your mistake is in the completely baseless assumption that a P.O. box is supposed to prevent letters from being delivered to your street address.
- dorfsmay 8y agoTrue, although ipv6 adds privacy concern as each device can now be identified by its IP, you need to make sure your OSes are configured to request different IP on each renegotiation.
- anderiv 8y agoThis trope needs to die. Just because a device has a publicly-routable IP does not mean that it’s freely-accessible. That’s why we have stateful firewalls. There are millions of IPv4 systems at large enterprises and educational institutions that have public addresses, and do you think they’re accessible from the internet? Didn’t think so. They’re behind a default-deny stateful firewall, very similar in function to the stateful firewall that’s present on every single consumer router you can buy. NAT is a hack that breaks things, and imposes un-needed performance bottlenecks.
- marvy 8y agoI'm not so sure that this trope needs to die; it has a grain of truth to it, at least for home users. Consider this situation: I'm browsing the web on my laptop at home. Meanwhile, someone wants to hack into my laptop. Suppose they want to start with a simple port scan. If my ISP only gave me an IPv4 address, the attacker is out of luck: my laptop HAS NO NAME. They can send IP packets to my router, but unless the router itself has unusually serious security holes (such as remote code execution), the router will not send packets to arbitrary ports on my laptop, because there is no way to even ask it to do so. The best they can try to do is inject content into web pages I'm browsing, and https prevents even that. Now I get IPv6. The attacker now has a perfectly reasonable way to send packets to my laptop. The router's job is to look at these packets and drop some of these packets while not dropping those that I rely on to browse the web, or whatever. Result: I am one bad config away from having my laptop be accessible from the internet. You mention large enterprises. Sure, they can afford good sys admins. But the average computer user is their own sys admin. Are they ready for this job? And if you say "yes", then here's the follow-up question: are they ready to administer the use-cases in sliken's comment, and still remain secure? https://news.ycombinator.com/item?id=17140187 https://news.ycombinator.com/item?id=17140187
- anderiv 8y agoIs Jane user ready for the job? Of course not. Good thing she doesn’t have to be. Fortunately nearly all consumer-grade routers ship with sane defaults, and make it difficult (if possible at all) to change the settings such that the security of the network is severely compromised.
- Sami_Lehtinen 8y agoThere are several address scopes available. You don't need to use globally unique addresses, if you don't like. This seems to be very common misunderstanding. * https://en.wikipedia.org/wiki/IPv6_address#Address_scopes https://en.wikipedia.org/wiki/IPv6_address#Address_scopes
- wmf 8y agoNot really. To access the Internet you either need to use global addresses or you need "illegal" NAT66. And consumer ISPs are definitely giving people global IPv6 addresses by default.
- Sami_Lehtinen 8y agoEven if the device has global unique address for accessing Internet, it doesn't mean that you would need to bind the services you're providing to that address. It's totally normal with IPv6 for any device to have multiple addresses, which have different scopes. If you're using privacy addressing you probably have already several addresses in use, then you got the local addresses and you might as well configure ULA for local communication as I've done for services which I don't want to be Internet accessible.
- zAy0LfpBZLC8mAC 8y agoNAT does not prevent inbound connections, and noone is giving devices "publicly reachable IP address". The only thing a sensible IPv6 setup does is that it gives every device a unique address. And the stateful firewall that you also need with IPv4 to prevent inbound connections works just as well with IPv6, so no need to add a pile of NAT crap.
- jandrese 8y ago> NAT does not prevent inbound connections True, but it also doesn't route them anywhere unless you've explicitly configured it to OR there was outbound traffic on that 5-tuple recently, so it's also wrong. The NAT functionality drops the errant packet on the floor just as much as a traditional firewall. Note: this is referring to dynamic NAT, which is the kind of NAT that every SOHO router supports by default out of the box and is the only kind normal users ever use.
- X-Istence 8y agoNAT doesn't prevent someone from sending a packet to your external interface (eth0) saying "this is destined for 10.10.10.9" which happens to be a 10.10.10.0/24 that you have assigned to eth1. Routers gonna route. Firewall is the one that would block that by saying "Sorry, but I shouldn't ever see packets destined for 10.10.10.0/24 on my eth0 interface".
- jandrese 8y agoYes, but if someone has managed to convince the internet to route a packet addressed to 10.10.10.0/24 to your subnet then you've got bigger issues. Also, every competently designed router has a rule that blocks that address range on the external interface. The whole NAT isn't a firewall meme is pendantry at its finest since NAT is implemented as part of the firewall.
- zAy0LfpBZLC8mAC 8y ago> Yes, but if someone has managed to convince the internet to route a packet addressed to 10.10.10.0/24 to your subnet then you've got bigger issues. It's not necessarily the whole internet. If someone wants to compromise you, they only need to gain access to a router at your ISP. Also, ISPs do misconfigure stuff and allow direct layer 2 communication from neighbours, or accept routing protocol advertisements from customer-facing ports. Whether you like it or not, those things just happen, and a well-secured network has a firewall that makes sure it is completely inconsequential to you, so, no, you actually don't have "bigger issues", you have an absolute non-issue. > Also, every competently designed router has a rule that blocks that address range on the external interface. So, like those with hard-coded default passwords and shell injection vulnerabilities in the web admin interface? Is that the kind of competently designed router that you are talking about? Noone claims that a properly configured firewall isn't part of a "competently designed router". The question is how many of the routers out there are competently designed. If anything, this idea of "NAT implies a firewall" is one reason why border gateways end up "incompetently designed", because it doesn't, but if you believe that when designing such a device (be it for mass production or as an individual manual configuration), chances are you'll end up with a completely unprotected network. > The whole NAT isn't a firewall meme is pendantry at its finest since NAT is implemented as part of the firewall. That is like saying that saying "Word isn't Excel" is pedantry because Word is implemented as part of Excel. It's just nonsense. Both share some common technical foundation, and even code for common functionality. That doesn't make one "implemented as part of the other".
- urda 8y agoStop acting like a NAT is going to save you. Protip: it isn't. You need proper firewalls, NAT, and physical network design. It's an entire security package, you don't just slap NAT on it and call it done.
- blackflame7000 8y agoCould you help me understand some of the weaknesses of NAT vs a firewall? I was under the impression they were almost synonymous
- buzer 8y agoWith just NAT someone who is on same L2 domain as you could you packet that has private IP address in the destination address. If there's no firewall (i.e. no deny rules for packets coming from outside interface directed to private addresses or more commonly just blanket deny for all non-established/related packets), router would happily forward the packet. The return packet may end up being weird (router may or may not change the source IP & port), but the attacker would be able to talk to the given host. Firewalls may not even have NAT functionality. They are used to figure decide if packet coming from interface with some flags (source, destination, ip, protocol, port, tcp flags etc.) is allowed to be passed to another interface. These days virtually all routers have at least basic firewall support & firewalls have at least basic NAT support.
- X-Istence 8y agoI tried to explain it here in case someone wants a little more information with some "real" examples: https://news.ycombinator.com/edit?id=17141287 https://news.ycombinator.com/edit?id=17141287