8 ms·
This is possible. Many users can be sharing the same IPv4 using CG-NAT. I have found that when using mobile internet, every site that uses IP bans has already b
by PurpleFoxy 5y ago
This is possible. Many users can be sharing the same IPv4 using CG-NAT. I have found that when using mobile internet, every site that uses IP bans has already banned me for a previous users actions.
It’s incredibly irresponsible to take action against someone based on their IP address alone.
- olyjohn 5y agoStarlink uses CG NAT for IPv4 and just recently started dishing out IPv6 addresses.
- kaliszad 5y agoProbably didn't want to go the AWS route of just buying a pile of IPv4 space from established organizations.
- floatingatoll 5y agoFrom an IT operator perspective, IPv4 bans are essentially the only recourse available for many — if not most — abuse/attack scenarios. They're unfair and unjust, but this is the price we pay of making tracing identities inaccessible to online abuse enforcement. If you have an idea on how abusive actors behind CG-NAT can be identified and blocked without blocking the entire CG-NAT, and that idea is not morally unacceptable to the hacker community (as captchas, fingerprinting, and IP bans are), then you can make a billion dollars on that idea. But it's been twenty years now that we've needed that idea, and I'm not holding my breath. Tech continues to insist that anonymity is more important than accountability. Our users pay the price of our insistence to this day.
- MathCodeLove 5y agoInstead of a permanent IPv4 ban consider issuing a temporary one just long enough to dissuade the aggressor from continuing their behavior. This would be just as effective, and is far less likely to impact others down the road.
- missingcolours 5y agoAlmost every time I start a new job I find a list of "blacklisted IPs" in the firewall and no one seems to know from whence they came, they've just always been there. It's a perfectly reasonable short term solution in some situations where there are few options, but like, expire them after some period of time, don't leave random IPs blocked for years.
- rootw0rm 5y agothat's insane. i block IPs for 10 minutes to start. not a big fan of the abuse IP databases either after I leased a server that was blacklisted before I even got it.
- kaliszad 5y agoWell, at my previous job, the company was blackholing 1.1.1.0/24 and others in the 1.0.0.0/8 subnet because that was the previous LAN. Thankfully, I have done an audit and removed this nonsense.
- floatingatoll 5y agoI agree, timers are generally a sound approach. I would personally go with 36 hours to wait out the typical human attention span.
- deleted 5y ago[deleted]
- musicale 5y ago> If you have an idea on how abusive actors behind CG-NAT can be identified and blocked without blocking the entire CG-NAT, and that idea is not morally unacceptable I don't think a general solution would be required in this instance. In this case, as I understand it, the abusive actors did the following: 1) tried to join with an abusive name 2) impersonated a student login and yelled abusive things in chat It seems that (1) could be solved by blocking connections from any user name that is not on a whitelist of approved student names and nicknames, and (2) is most likely an issue of someone else accessing the student's login credentials, so it could potentially be mitigated by multifactor authentication.
- nieve 5y agoIf I understand the article correctly they didn't even have evidence his credentials were used. All they had was a shared IP address. Given that his teachers testified in his favor I have to wonder if there was some specific grudge against the kid. Alternatively they were incompetent about the IP thing from the beginning and as soon as they realized they might be wrong went into full cover-up & deny everything mode.
- cdsmith 5y agoKeep in mind that this article was written by a reporter who was unable to talk to the district, and got all their information from a lawyer representing the kid who was suspended. The district itself is prohibited from releasing any information about the case by privacy laws, no matter what the family says or how accurate it is. The same evidence was presented to the school board in an appeal hearing, and they (granted, probably not technical people) did not find it convincing. That doesn't mean the family's lawyer is wrong, but it is worth keeping in mind as you evaluate this. We don't have the whole story here.
- michaelmrose 5y agoIt's extremely likely that nobody wants to rock the boat and give an injured party evidence to be used against their employer. Their employer would almost certainly prefer to wrongly punish a student if it has a fraction of a chance at getting them out of a lawsuit. It's also likely that there isn't a single person in a leadership position with the entire school board who is even slightly technically competent. Next we already have precedent that IP addresses don't uniquely identify people for the purposes of law. It is incredibly likely that such an action wouldn't pass the sniff test if the IP addresses given were entirely correct. Lastly even if he actually did try to log in with "i will murder u all of u" no reasonable person would consider this an actual threat without talking with the student. Kids are stupid, and kids say stupid things. Time and again schools fail to address the real problem children before things blow up and then use their persistent failures to justify overreaction to the detriment of students.
- foobar33333 5y agoShort term IP blocks can be fine but to take real world action like the OP post based on a very weak data source is irresponsible.
- vitus 5y ago> If you have an idea on how abusive actors behind CG-NAT can be identified and blocked without blocking the entire CG-NAT Working with the carrier? Depending on the kind of abuse, it could very well be against the ISP's ToS, and the ISP hopefully doesn't want its users blocked wholesale just because of a few bad actors dragging down the reputation of its IP blocks.
- floatingatoll 5y agoIs the carrier willing to work with any website who is abused by their customer? Is their barrier to accountability the demand for a civil or criminal lawsuit? Can sites with mouth legal presence in the same country as the provider seek accountability? Must sites have vast monetary resources sufficient to survive the provider’s attempt to protect their customer from being held accountable under the banner of privacy? How can the provider defend themselves against abusive and falsified requests for identification? Is there an agreement that can be reached to protect identities while still stopping ongoing willful abuse by anonymous customers? I appreciate the theory that you’re sketching, and I think it certainly has potential. But we already have the theoretical capability you describe today, and have had it for decades, and yet online abuse continues unchecked — so you’ll have to talk more about how and why your recommendation improves on what we have today.
- vitus 5y agoOh, I agree that the carrier isn't going to work with just any website. But companies like Zoom (as would be relevant in this scenario) might hold more sway, especially if the looming threat is "deal with this on your end, or we will, with the blunt instrument that is IP banning". (Now, whether Zoom would engage in an IP ban just for abuse affecting a single school is a different story. But I imagine they must have some motivation to deal with zoombombing. Right??) The school itself might not have the resources to engage in a legal battle, but they could certainly get law enforcement involved, especially if the abuse enters, say, hate crime territory, as it seems like it may have in this case. (Granted, the privacy concerns that you raise are an entire issue in themselves, and I don't have any answers there.) To be clear -- this isn't a novel proposal, per se, unless talking to other people is novel :) But, it's just a suggestion that while circumventing CG-NAT is technologically infeasible from the outside, technical solutions are not the only option. And if it's not possible from the outside, well, there's one entity who's positioned to further trace the abusive users...
- u801e 5y agoCertificate based authentication would work in combination with a username and password. The private key could be stored on the school issued device. I'm not sure why anonymity would play any role in terms of connecting to an online class.
- curryst 5y agoI thought the same thing as you, but many students use their personal devices. I can't imagine the pain of trying to get all the students to set that up correctly, and the security implications of managing certificate stores is not something I would want to hand over to a lowest-bidder contractor for a school district. I don't really love that Microsoft/Linux distros manage them as is (although I'm admittedly too lazy to manage them manually).
- tinus_hn 5y agoHere’s the one billion dollar idea: per person authentication instead of one code per room.
- croutonwagon 5y agoWhois abuse reporting is the solution that is already in place and comes to mind. If you NAT segments of your network and mask your userbase from the greater internet, you inherit some responsibility for their actions, same with smtp spam as any other service. But many carriers simply ignore or don’t respond, much less investigate. To the point that people regularly take to other means to establish backend contact with larger carriers like Comcast, resorting to list serves like nanog. Ultimately it’s on the carriers to doll out the money to support it. But they could easily implement strike policies like DMCA reports have for many. Against both customers engaging in malicious activity snd reporters abusing the system or making spurious reports that waste resources. However that would mean carriers like comcast would need to stop their efforts to completely frustrate communication with other NOC's etc.
- tomjen3 5y agoIt seems we need something that is difficult/expensive to create, but which does not permit anybody to trace the owner. We either need something provided by the government that is unique to each recipient and services tuple (so it can't be used to trace anything), but will be the same each time, and so can be banned. Else we need something like a proof of work, but that would either have to so expensive to create that we would have to reuse it across all the end points. I guess we could also mandate ipv6, but then blocking the addresses wouldn't be very useful. Finally I guess we could mandate that all IPs be treated equally and then companies that can't handle that would have to close down.
- kaliszad 5y agoA case could be made that sharing an IP address is like sharing a cell phone number, only that you don't get to make the decision directly. By choosing a provider that has not enough IP addresses to hand out/ hasn't implemented IPv6 and using a site that doesn't use IPv6 either, you make the decision indirectly. (Else you would most likely end up communicating with it over IPv6.) You can also use a VPN to somewhere with a static IPv4 for a few dollars a month. I know, the reality is most of the world is just stuck with IPv4 in some capacity. It is probably good that using IPv4 starts to hurt else we will never migrate. Btw. HackerNews is stuck with IPv4 only in 2021 still...
- harikb 5y ago> It is probably good that using IPv4 starts to hurt else we will never migrate. Not sure what you meant by this comment. The kid whose life is ruined won’t know what this is. The people who care about ipv4 vs v6 is unlikely to act based on this incident.
- kaliszad 5y agoI was replaying to a different anecdote. The kid is another casualty of us engineers and managers not doing our job in migrating to IPv6 in the last ~20 years or so. The world IPv6 launch was actually 10 years ago, there was plenty time to migrate. The kid might actually do quite ok as I have suggested in other comments. Really depends on the family and its personality.
- harikb 5y agoOk, thanks for the clarification What we really should do though is help make clear to the non-tech world what part of what they see in TV is real and fake science IP address is like the hair analysis of 70s / 80s https://en.wikipedia.org/wiki/Hair_analysis https://en.wikipedia.org/wiki/Hair_analysis
- TomSwirly 5y ago> The kid is another casualty of us engineers and managers not doing our job in migrating to IPv6 in the last ~20 years or so. Absolutely wrong. The kid is a victim of an incompetent and unfair school system. > The kid might actually do quite ok as I have suggested in other comments. He might well recover from this serious loss, yes. Will his mother, who was stricken when this happened, recover her health? A cruel injustice is not acceptable just because the victim "might actually do quite OK".