5 ms·
I never realized an IPv6 likely contains the MAC address of the host, how did people not realized how terrible this design is.
by aboutruby 8y ago
I never realized an IPv6 likely contains the MAC address of the host, how did people not realized how terrible this design is.
- zamadatix 8y ago> When IPv6 was developed in the mid-90s, the Internet was not accessed by a large number of mobile devices and privacy was not the priority it has become today. To address these privacy concerns, the SLAAC protocol was updated with mechanisms that were termed “Privacy Extensions for Stateless Address Autoconfiguration in IPv6”, codified in RFC 4941. This allows for the IPv6 address interface identifier to be generated randomly. If the same interface identifier is generated for two devices in the same local area network, the Duplicate Address Detection (DAD) function of the IPv6 Neighbor Discovery Protocol (NDP) will resolve the situation. Prior to those times tracking protection wasn't critical in protocol design (or most people's minds in general) and so using the MAC was a great way to self select an address without extra steps.
- throwaway2048 8y agoMost OSes use opaque identifiers that are per prefix these days thankfully, that can not be tracked across networks or tied to mac addresses.
- sliken 8y agoIPv6 Privacy Extension as defined in RFC 4941 is commonly implemented and prevents this from being an issue.
- JohnFen 8y ago"Prevents" is overstating this a bit. The IPv6 Privacy Extension is a hack that doesn't completely mitigate this sort of problem. It's just better than nothing, and is all we have.
- sliken 8y agoHow so? With IPv4 you reveal the IP of your IP Masq/Nat router, which is often inside your home/business. It can be dynamic or static, but generally changes pretty slowly. There might be a single person behind that IP, or 100s. With IPv6 your /64 is often inside your home/business. It can be dynamics or static, but generally changes pretty slowly. There might be a single person behind that /64, or 100s. Different outgoing connections see different IPv6 addresses, and they change over time (slowly). Most importantly just like a mac address, the outgoing connections never use the IPv6 address based on mac address. So how does the privacy extension not protect the privacy of users by hiding the mac address?
- JohnFen 8y ago> So how does the privacy extension not protect the privacy of users by hiding the mac address? I never said it didn't. I stated that people overstate the protection the facility provides, not that it didn't provide protection. The deficiencies of the privacy extensions have been discussed widely for years. A quick internet search will show the various criticisms and responses better than any reply I can make here will. I should, however, clarify what I was trying to say -- I was not trying to say the privacy extensions aren't worthwhile. They're great, and people should use them! What I was trying to say is that people often think of them as a panacea or a 100% solution. They aren't exactly that (what is?), and the nature of the design of the privacy extensions are such that they make other important network management activities more difficult. My main criticism of PE (and it's not a showstopper sort of criticism) is that the extensions are hacky and it shows. They were thought up after-the-fact to try to mitigate a security mistake made in the original IPv6 protocol.
- sliken 8y agoSure, but the original parent was complaining about the mac address (not any larger privacy issues) and the PE does a good job of hiding the mac address and is enable by default in many common operating systems (Mac, Windows, Ubuntu, etc.)
- cesarb 8y agoIPv6 is old. Back then, not only servers but also desktops were commonly on a fixed public IP address, accessible from anywhere on the Internet. Hiding the MAC address would gain very little, since the IP address was enough to uniquely identify a host.
- icedchai 8y agoBack in the mid 90's, before NAT was common, we had public IP's everywhere, even with IPv4! Even my home network was on a /24 class C.
- subway 8y agoEven now, some large traditional sites put static public IPs on workstations. When I was a lbl.gov, you got a (minimally firewalled) public ip via dhcp, and the hostname sent by your workstation was used to create a dns record of foo.dhcp.lbl.gov. You could request a static address for your host, and you'd be assigned an even less firewalled ip along with a foo.lbl.gov record. A decade later this still seems to be at least partly in place, as I'm able to browse the webserver running on an old colleague's desktop.
- 0xffff2 8y agoWow. I work for another US government agency down the road from LBNL, and here I can't even see many internal servers from my laptop because there is a firewall between the (wired!) laptop-accessible network and the inner ring that the servers are on. I think my sysadmin group would have a collective heart attack if they saw that setup! It's quite incredible to me how independent various parts (and pseudo parts like the national labs) are from each other.
- subway 8y agoLBNL is an incredibly open, yet monitored network (in the spirit of the collaborative research that goes on there.) You can be certain that most every packet in, out, or through the place gets captured and inspected by Bro (errr, I guess Zeek now. https://www.zeek.org/ https://www.zeek.org/ ) I should also mention that not every host had a public IP. I worked with the group that managed midrange compute clusters, which were always behind NAT, with bastion login nodes.
- cm2187 8y agoOnly if the network admin configures the DHCP to do so. I believe the default on most OS is a random suffix.
- api 8y agoIPv6 was designed long before surveillance capitalism was a concern and before security in general was as much of a concern as it is today. Addresses don't have to be assigned that way. There are other ways of assigning addresses including privacy addresses and DHCPv6. The address space is so big that just generating a random address, while not RFC, is "okay" on all but huge networks if you're working in a /64.