7 ms·
You need a firewall if your end points are publicly reachable, not NAT.
by ipv6_or_nat 5y ago
You need a firewall if your end points are publicly reachable, not NAT.
- raxxorrax 5y agoCompletely true, I wasn't too serious about that, just pointing out that there were unintended benefits.
- tekknik 5y agoNAT still provides some layer of protection, especially if you don’t trust the firewall software. This is going to open up a can of worms once everybody gets global addresses and can’t figure out how to configure their firewall.
- ipv6_or_nat 5y agoWhat?! You don’t trust the firewalls software so you are good to trust the NAT software?
- tekknik 5y agoWindows firewall? no. iptables? yes. Why? because I know how to configure one and not the other. Also because of things like this: https://www.enterprisenetworkingplanet.com/security/qa-behind-the-windows-firewall-exploit/ https://www.enterprisenetworkingplanet.com/security/qa-behin...
- Dagger2 5y agoIt actually doesn't. NAT just changes the apparent source address of outbound connections; it doesn't do anything to inbound ones. In any case, people manage to do both NAT and firewalls on v4 today so I don't see why they'd suddenly be unable to do firewalls in v6, especially since you don't have the complication of needing to figure out NAT as well. The large address space also helps a lot, because it makes it much harder to find servers on v6 (including deliberately exposed servers, e.g. cameras or NASs that people want to access from a different network), compared to v4 where you can enumerate all active servers over the entire internet without much trouble.
- tekknik 5y agoNAT prevents an external host from making arbitrary connections to a host behind the NAT without further configuration. This is something your average person doesn’t need to know or really care about. But once every device they have is globally routable they will have to care and ensure their machines are secure and behind a firewall. And if that firewall should fail then you’re sitting on the public network with your pants down. Your other part is security through obscurity, and I can think of at least 2 ways to scan the entire address space in a short amount of time. So nope doesn’t count either.
- Dagger2 5y agoIt doesn't do that. How can rewriting the source address of outbound connections prevent inbound connections? You're not going to exhaustively scan the entire v6 space in any short amount of time. It is possible to whittle down the space you need to scan, but only moderately. It's still rather unviable compared to v4.
- tekknik 5y agoPick any network doing NAT, attempt to make a connection. It will be denied. NAT devices are both firewalls and translators and if you don’t have a configuration for port forwarding, be it via established connection or manual configuration, the connection won’t get through. And importantly this is a configuration the user doesn’t touch. And scanning IP spaces is insanely easy to parallelize and uses so few resources an arduino can be used to scan. Given enough nodes it’s instant. And with every windows box on the planet globally routable, bonets will never be stronger. But let’s pretend this is true and say it takes too much time. What about when it doesn’t? What happens to your security via obscurity then?
- Dagger2 5y agoI've tested it before, multiple times; NAT won't deny an inbound connection. A router that's NATing outbound connections will allow inbound connections through unless there's also a firewall. Of course it's very common for there to be a firewall as well, but they're still a separate thing to NAT. > And scanning IP spaces is insanely easy to parallelize and uses so few resources an arduino can be used to scan. Given enough nodes it’s instant. You're underestimating how big v6 is. Scanning a single /64 takes ~737 million terabytes of traffic. If you used a trillion Arduinos in parallel you could scan 2^40 /64s simultaneously, and it would only take 1870 years for the scan to complete, assuming that every single one of both the Arduinos and the target networks have a 100 Gbit/s internet connection each. Your power consumption would be... about the same as Italy's, which is actually the most reasonable part of all this (except I assumed the 100 GBit/s network connections would take no power). > And with every windows box on the planet globally routable, bonets will never be stronger. You're thinking about botnets that spread by brute force scanning, right? But as mentioned, this will be substantially more difficult on v6, to the point that network scanning won't be a very viable technique for spreading a botnet. On top of that, most Windows machines will be behind two separate firewalls, so I don't see how them being globally routable will make botnets stronger. Given that it'll be harder to find targetable hosts, I'd instead expect botnets to be weaker than ever. Also, remember that a lot of botnets spread by exploiting servers that were deliberately exposed to the internet. Making these hard to find is the only defence they have, and it's not possible on v4. NAT can't help either, however it works. An insecure, hard-to-find machine is still an insecure machine, but making it difficult to find vulnerable hosts makes it harder to build a botnet, which leads to a very real increase of security on the internet as a whole. Even if a few machines are found, nothing much happens to the overall security so long as it remains hard enough on average. Think of it as being something like vaccination for the internet.