4 ms·
So in essence privacy extensions (hiding of internal network) are available, but disabled and unsupported by default. Another thing are incoming connections -
by hatch_q 5y ago
So in essence privacy extensions (hiding of internal network) are available, but disabled and unsupported by default.
Another thing are incoming connections - first thing i do with new router is disable UPnP, so clients cannot drill ad-hoc holes into my private network. How to do that with ipv6 network?
- fulafel 5y agoThat's not correct. Privacy extensions are supported and on by default in Windows, macOS, mobile stuff and on generally in desktop Linux setups. Not sure what the author is running as they claim it's off by default in Ubuntu, as that's contrary to my experience. (Guessing they have a server install as they talk about netplan instead of NetworkManager?)
- jeroenhd 5y ago> So in essence privacy extensions (hiding of internal network) are available, but disabled and unsupported by default On Ubuntu Server: probably. Why would you want a randomized IP address on a server, anyway? Netplan doesn't seem to be designed for desktop, so I don't think it's a problem in most cases. Perhaps you want to add privacy to a raspberry Pi running a scraper or something, but there aren't many use cases I can think of that require privacy extensions in a headless system. On user-facing operating systems (Windows, Ubuntu, Manjaro, Android, probably macOS/iOS/ipadOS as well) privacy extensions are enabled by default AFAIK. They're also completely supported. In fact, I can find more posts online about people wanting to _disable_ the feature rather than how to enable it. > How to do that with ipv6 network? Any decent router will put a firewall between you and the internet, blocking incoming traffic. Your IP may be publicly routable, but it's not reachable by default in most consumer appliances. You shouldn't need to disable anything. Many people will confuse NAT with a firewall, but those are two entirely different things! NAT makes devices unreachable by breaking the internet, but there are many NAT loopholes (port knocking, NAT slipstreaming, etc.) that will bypass NAT if you can get a user to install software or even open a website from inside the network. In the IPv4 world the firewall and NAT setup are often combined, leading to a broken firewall in many cases because they automatically add the necessary firewall exceptions to make NAT work. UPnP generally does two things: it sets up NAT _and_ it adds a firewall exception. Reserving a port on the router's public IP address (NAT) is of little use if you don't accept traffic on that port (firewall), after all. On IPv6 there's no need to bother with NAT, but the firewall exception still needs to be added for a port to be reachable. Effectively, the difference is that if you have three smart lightbulbs that are all reachable on port 80, you don't need to forward port 80, 81 and 82 to different IP addresses to make them available to the internet; you need to add three firewall rules for port 80 and then just use their real IP addresses instead. That's exactly how IPv4 was always designed to work before the IP address shortage began and NAT became the standard. For rare exceptions, there are some forms of NAT available on IPv6, but they're only designed in circumstances where your network design is basically flawed (like for those ISPs that hand out a /128 address instead of a /48 or /56 like they're supposed to, forcing routers to do NAT for no good reason).
- hatch_q 5y agoYou're assuming that smart lightbulbs are to be trusted. You can't trust them, neither can you trust most of the software you run in your home network. Take a simple app crash report on your desktop computer. Assuming i'm using VPN (but even without it, it's an issue)... With NAT, your crash report will contain network adapter address: 192.168.0.x. With ipv6, you're disclosing your /56 (or /64) ip range... disclosing your physical location, your ISP, ...