21 ms·
Exactly. In many implementations I’ve seen the user’s MAC address ends up getting exposed to the WAN. I suppose this is the wet dream of Google, and that’s why
by kabwj 7y ago
Exactly. In many implementations I’ve seen the user’s MAC address ends up getting exposed to the WAN. I suppose this is the wet dream of Google, and that’s why they want to push ipv6 adoption.
- sneak 7y agoMost systems use the privacy extensions that randomize addresses to prevent that.
- kabwj 7y agoYes, I’m sure those iot devices will use infallible privacy extensions... Nah, they’ll probably expose their mac, which will make it trivial to scan for them. Truth is, right now iot devices are protected by nat (your router) and maybe cgnat too (if your isp is good enough and provides that service). With ipv6 those devices will lie exposed to the wan. I hardly see how that’s an improvement. Also don’t trust regular devices. Windows disabled privacy extensions because of a bug (not sure if it’s fixed already). https://social.technet.microsoft.com/Forums/windows/en-US/57925467-2b8d-4c2d-b1f2-b0402581a30e/how-does-one-get-the-system-to-actually-use-the-ipv6-temporary-addresses?forum=win10itpronetworking https://social.technet.microsoft.com/Forums/windows/en-US/57... — I trust my router’s nat much more: it can’t be disabled because of a bug ;-)
- berti 7y ago> Truth is, right now iot devices are protected by nat (your router) and maybe cgnat too (if your isp is good enough and provides that service). With ipv6 those devices will lie exposed to the wan. I hardly see how that’s an improvement. You're planning to just get rid of your firewall when you don't need it for NAT anymore?
- cm2187 7y agoThe problem is many of these IoT pierce holes in the firewall (upnp) to expose themselves to the WAN.
- sneak 7y agoSome will, some won’t. Most will. Some machines’ TCP stacks can be crashed with a single packet. Some IoT devices can be added to botnets. Some get patched. I think you are blaming too much on ipv6, much of which exists today in the ipv4 world. You can always set up your router to be a stateful v6 firewall and block wan-to-lan accesses you don’t like or want, much the same way NAT works today, on an outbound-before-inbound model.