6 ms·
How is a local network different from the internet, presuming there is no firewall or nat between the client and the server ?
by generatorguy 7y ago
How is a local network different from the internet, presuming there is no firewall or nat between the client and the server ?
- cwyers 7y agoOn a local network, you make the assumption that there are only authorized users.
- bayindirh 7y agoUh oh, that assumption is a big no no.
- gsich 7y agodepends
- bayindirh 7y agoCan you elaborate? Honestly asking.
- labawi 7y agoI wouldn't recommend it with PCs, notebooks, phones, random crapware, but: When you control¹ all the devices on the network, the network is small enough and the danger from the non-authenticated protocols isn't too high, then I would say it is reasonable to assume being present in the network is sufficient authentication. Not saying it could not be improved, but there are probably many more pressing concerns. ¹ you don't fully control anything anymore, but you're not going to fix that either.
- bayindirh 7y agoThanks a lot. That gave some perspective. I'll keep that in mind.
- generatorguy 7y agoThe air gapped power plant networks I work on have unused Ethernet ports shut off and the ones in use only accept traffic from the MAC address of the device that is meant to be there. So you can’t just show up and plug in.
- antonvs 7y ago> presuming there is no firewall or nat between the client and the server That's one of the issues though. If you can't access a machine via its internal IP, many useful usage patterns break. Someone complained that the issue is that services aren't secure, but there's more to it than that: good security depends on defense in depth, and firewalls are an important part of that.