5 ms·
I want ipv6 as much as anyone, but we are not spending enough time preparing for NATs death. It's responsible for far more security than we as a collective woul
by therealx 6y ago
I want ipv6 as much as anyone, but we are not spending enough time preparing for NATs death. It's responsible for far more security than we as a collective would like to admit and there's a lot more we could be doing now to get ready.
- PurpleFoxy 6y agoMost routers I have seen do not leave ipv6 unprotected. By default they block incoming connections like nat would.
- globular-toast 6y agoThat's a common misconception. NAT isn't a security feature but rather a feature of a stateful firewall, which is. There's no reason to remove the firewalls that are in place now when ipv6 happens.
- BlueTemplar 6y agoIf firewalls are even needed, a recent poll on an IPv6 professional forum ended with 50/50 split between opt-in and opt-out for IPv6 firewalls in routers of consumer ISPs...
- globular-toast 6y agoThat's surprising and quite concerning. Imagine all the insecure IoT devices running ancient software having a direct connection to the Internet... It would be even more concerning if they were shipping routers without any firewall functionality at all. NAT basically requires a firewall. I hope the thinking isn't if you can do away with NAT you can do away with the firewall.
- BlueTemplar 6y agoThe thinking of the opt-inners seems to be (roughly) that : -IPv6 is fundamentally much more secure than IPv4 (no scanning, etc.) -opt-out is bad for innovation, especially since the cheap default ISP router firewall software is likely to not even allow opt-out for any other protocols than TCP and UDP. (Heck, these days on IPv4 even anything different than HTTPS can be problematic...) -reliance on router firewalls is bad because they incentivize sloppy device security - the manufacturers should be instead liable when they are at fault for screwing it up (also, how many of these "insecure IoT devices running ancient software" are even able to run IPv6 ?) source : https://lafibre.info/ipv6/ipv6-le-firewall/msg704095/#msg704095 https://lafibre.info/ipv6/ipv6-le-firewall/msg704095/#msg704... (fr) Incidentally, one of the "big 4" French ISPs "Free" didn't even have an IPv6 firewall on its customers routers between 2008 and 2019, and it's probably still opt-in : 4 months ago : https://fr.answers.yahoo.com/question/index?qid=20200812110733AA8WakU https://fr.answers.yahoo.com/question/index?qid=202008121107... (fr) So I guess that we're going to see in practice the problems that having no IPv6 firewall causes (most customers not having any idea about what even is a firewall) as it gets more popular... and since Free this summer boasted about reaching 99% IPv6 coverage, and is enabled by default, and can NOT be disabled...
- deadbunny 6y ago> IPv6 is fundamentally much more secure than IPv4 (no scanning, etc.) The same was true for ipv4 until about a decade ago. > opt-out is bad for innovation, especially since the cheap default ISP router firewall software is likely to not even allow opt-out for any other protocols than TCP and UDP. (Heck, these days on IPv4 even anything different than HTTPS can be problematic...) I can't wait for conficker6 to innovate it's way around the ipv6 net. > reliance on router firewalls is bad because they incentivize sloppy device security - the manufacturers should be instead liable when they are at fault for screwing it up (also, how many of these "insecure IoT devices running ancient software" are even able to run IPv6 ?) Sounds like an excellent reason for an opt-out by standard. 99% of the world's internet users wouldn't have a clue how to manage a firewall. Directly connecting all their devices to the internet is an awful idea for 99% of the world. Your 50/50 example is hugely biased, first it's on a Telco discussion forum so that clearly selects for technical users, then it's on ipv6 which is going to further select for technical people. Go canvas 100 random people outside a supermarket if they want to have to manually manage a firewall for every device they connect to their network. If they don't give you a blank stare at that question remind them that includes everything from lightbulbs, washing machines, "smart" speakers, to their computers/phones (likely the only thing they think of as being connected to the internet). If you find more than 1 I'll eat my hat. I don't own a hat.
- BlueTemplar 6y ago> Your 50/50 example is hugely biased, first it's on a Telco discussion forum so that clearly selects for technical users, then it's on ipv6 which is going to further select for technical people. As you can see I'm aware of that, they are also aware of that, and the discussion is not so much about themselves (since they know how to configure a firewall or even to install their own router), but about what your "average grandma" should get.
- therealx 6y agoIf only average grandma's were just limited to grandma's. I don't know a single person who isn't a gamer or IT person that can properly use a firewall as they exist now.
- therealx 6y agoI'm well aware it's not a security feature and I know there are ways to punch holes, but in practice, a lot of machines are still relying on it. The number of IoT devices alone that would be screwed if they were public is massive. Yes, everyone should have a hardware firewall, but we both know most people just buy the cheapest thing, and by bad large, real firewall features are mostly targeted toward higher end devices.
- CKN23-ARIN 6y agoI think we'll still see some people doing NAT66, unfortunately.
- deadbunny 6y ago20+ years isn't enough? More seriously; for 99% of people their ISP router handles NAT and firewall duties. Adding DENY ALL inbound and ALLOW ALL outbound isn't a great stretch for them on ipv6.
- therealx 6y agoOf course it's more than enough, but it's still barely done. We should have co2 emissions under control too, but we don't.