4 ms·
This trope needs to die. Just because a device has a publicly-routable IP does not mean that it’s freely-accessible. That’s why we have stateful firewalls. The
by anderiv 8y ago
This trope needs to die. Just because a device has a publicly-routable IP does not mean that it’s freely-accessible. That’s why we have stateful firewalls.
There are millions of IPv4 systems at large enterprises and educational institutions that have public addresses, and do you think they’re accessible from the internet? Didn’t think so. They’re behind a default-deny stateful firewall, very similar in function to the stateful firewall that’s present on every single consumer router you can buy.
NAT is a hack that breaks things, and imposes un-needed performance bottlenecks.
- marvy 8y agoI'm not so sure that this trope needs to die; it has a grain of truth to it, at least for home users. Consider this situation: I'm browsing the web on my laptop at home. Meanwhile, someone wants to hack into my laptop. Suppose they want to start with a simple port scan. If my ISP only gave me an IPv4 address, the attacker is out of luck: my laptop HAS NO NAME. They can send IP packets to my router, but unless the router itself has unusually serious security holes (such as remote code execution), the router will not send packets to arbitrary ports on my laptop, because there is no way to even ask it to do so. The best they can try to do is inject content into web pages I'm browsing, and https prevents even that. Now I get IPv6. The attacker now has a perfectly reasonable way to send packets to my laptop. The router's job is to look at these packets and drop some of these packets while not dropping those that I rely on to browse the web, or whatever. Result: I am one bad config away from having my laptop be accessible from the internet. You mention large enterprises. Sure, they can afford good sys admins. But the average computer user is their own sys admin. Are they ready for this job? And if you say "yes", then here's the follow-up question: are they ready to administer the use-cases in sliken's comment, and still remain secure? https://news.ycombinator.com/item?id=17140187 https://news.ycombinator.com/item?id=17140187
- anderiv 8y agoIs Jane user ready for the job? Of course not. Good thing she doesn’t have to be. Fortunately nearly all consumer-grade routers ship with sane defaults, and make it difficult (if possible at all) to change the settings such that the security of the network is severely compromised.
- nanamo 8y ago>Fortunately nearly all consumer-grade routers ship with sane default Please don’t make me laugh.
- zAy0LfpBZLC8mAC 8y ago> it has a grain of truth to it, at least for home users No, it doesn't. > Suppose they want to start with a simple port scan. Then they shouldn't find any services running on your laptop? > If my ISP only gave me an IPv4 address, the attacker is out of luck: my laptop HAS NO NAME. Yes, it does. It's called an IPv4 address. If you also happen to use NAT (which you didn't specify--believe it or not, but you can actually use IPv4 without NAT!), it happens to be a globally ambiguous address. Which doesn't change that it's a name. Also, your computer has tons of other names via which it can be reached: email addresses, ad networks that your browser loads from, any other ways to send you messages with URIs for you to open and load code from to be executed inside your browser and thus on your LAN, and also all the ports on the NAT gateway's globally unique address that all your outbound connections have been mapped to. Those are all ways to access both attack surface on your machine, and potentially also on other devices on your LAN. > They can send IP packets to my router, but unless the router itself has unusually serious security holes (such as remote code execution), the router will not send packets to arbitrary ports on my laptop, because there is no way to even ask it to do so. There is a completely trivial way: You address it to the (globally ambiguous) address of your laptop. That is, unless there happens to be a stateful firewall on that router. But that stateful firewall would work just as well without NAT. Also, why are you even so afraid of sending packets to "arbitrary ports"? Is your system drowning in malware that opens backdoors left and right? What is so dangerous about your system sending a few TCP resets and ICMP port unreachables? > Now I get IPv6. The attacker now has a perfectly reasonable way to send packets to my laptop. The router's job is to look at these packets and drop some of these packets while not dropping those that I rely on to browse the web, or whatever. Result: I am one bad config away from having my laptop be accessible from the internet. In other words: Just as with IPv4. Also, no you are not. There is nothing dangerous about receiving a packet. That seems to be some sort of irrational fear of some people, but it's really just bullshit. The attack surface reachable via email and browsers tends to be magnitudes larger than "oh my god, they can send me packets!!111". > You mention large enterprises. Sure, they can afford good sys admins. But the average computer user is their own sys admin. Are they ready for this job? They are as ready as they are for IPv4. They buy or rent a router from their ISP, and the ISP hopefully will continue to supply properly configured devices. They largely managed to do so with IPv4, so there is little reason to think they couldn't do so with IPv6. > And if you say "yes", then here's the follow-up question: are they ready to administer the use-cases in sliken's comment, and still remain secure? https://news.ycombinator.com/item?id=17140187 https://news.ycombinator.com/item?id=17140187 Are they managing to prevent incompetent or malicious cloud providers from misusing or mishandling their data? Is their current setup as secure as you seem to assume it is? Also, why should there even be anything "to administer" in the first place? Just because NAT requires port forwarding, which then requires "administration", doesn't mean one has to continue this idiotic tradition with IPv6.
- kbaker 8y agoAre you sure your router has PCP or NAT-PMP disabled, which _could_ expose ports on your external IPv4 IP without any interaction? Do you expect the average computer user to configure PCP securely on their router? Various NAT traversal options are already pretty widespread. Having only a firewall keeps things much simpler.
- craftyguy 8y ago> Having only a firewall keeps things much simpler. Yes, for you and for attackers. Security strategies require layers, since no one layer can be depended upon to stand on its own. Removing NAT is removing a layer of security. Suddenly your firewall has to stand on its own. Good luck! Edit: Why is my comment bad?
- zAy0LfpBZLC8mAC 8y agoNAT is not a layer of security. At all. A billion layers of no security is still no security. (And actually, NAT is a negative contribution to security as it hides the lack of a firewall when it isn't there or doesn't work, which would be trivial to detect without NAT.)
- zAy0LfpBZLC8mAC 8y ago> public addresses That is part of the problem. Just as "private addresses". They are globally unique and globally ambiguous addresses. There is nothing "public" or "private" about them.
- blackflame7000 8y agoI would argue that these are private addresses: Class A Networks 10.0.0.0 to 10.255.255.255 with /8 Class B Networks 172.16.0.0 to 172.31.255.255 with /12 Class C Networks 192.168.0.0 to 192.168.255.255 with /16
- zAy0LfpBZLC8mAC 8y agoSo, if you would argue ... where is your argument then? Also, IPv4 hasn't had address classes for a quarter of a century.