4 ms·
>to anything inside my home network from anywhere on the internet When you put it like that, it sounds kind of scary.
by VectorLock 5y ago
>to anything inside my home network from anywhere on the internet
When you put it like that, it sounds kind of scary.
- mulmen 5y agoWhy? This is what firewalls are for.
- drsnow 5y agoBecause a firewall exploit means your thermostat is now controllable over the internet and you can conveniently preheat your oven over the internet too and now your house is burning down
- kungito 5y agohow is that worse than ipv4 firewall exploit?
- aaomidi 5y agoIt's actually better because you actually get obscurity with ipv6.
- aaomidi 5y agoHave you considered how much of a pita/impossibility scanning an ipv6 space is?
- deadbunny 5y agoNo different than NAT and forwarding a port which people have been doing for decades. Hell if you have a firewall exploit then exposing stuff to the internet doesn't matter.
- dehrmann 5y agoIt's very different because NAT blocks by default. You either need to manually set up a forwarded port or the app needs to use UPNP.
- icehawk 5y agoI'd not be too confident about that, this is a thing that keeps happening: https://www.anvilsecure.com/blog/dhcp-games-with-smart-router-devices.html https://www.anvilsecure.com/blog/dhcp-games-with-smart-route...
- deadbunny 5y agoEvery consumer router/firewall drops incoming packets by default, why would this be different for ipv6?
- zinekeller 5y ago> Every consumer router/firewall drops incoming packets by default, why would this be different for ipv6? Sadly, this is very far from the truth. Most routers do not filter IPv6 by default, mainly because IPv6's design assumes a per-device firewall. This means that literally you need to ensure that every device supports a firewall or otherwise operates in such a way that it is safe for public access.
- deadbunny 5y ago> Most routers do not filter IPv6 by default. This isn't my experience. If you are correct however, that is a failure of the ISP/CPE provider, not a flaw of IPv6. > mainly because IPv6's design assumes a per-device firewall I don't see a single mention of firewalls in the RFC[1]. But then neither did the ipv4 spec. Why would we suddenly stop using firewalls though? They have been standard on networks for decades. 1. https://datatracker.ietf.org/doc/html/rfc2460 https://datatracker.ietf.org/doc/html/rfc2460
- zinekeller 5y ago> This isn't my experience. If you are correct however, that is a failure of the ISP/CPE provider, not a flaw of IPv6. First, I'm excluding enterprise firewall here. I've verified this with multiple non-CPE routers, and except for the router itself (for obvious reasons), no, IPv6 traffic isn't really filtered. The "firewall" is laughable on some routers (including some assuming /64 filters which isn't necessarily true for some servers like OVH's). The only non-enterprise one that's working as much as an IPv4 system is Asus'. Some routers tries to filter out DoS attacks. Those are rather confusingly called a "Firewall", but it's not really a controllable firewall per se, allowing "normal" but otherwise a malicious-if-DPIed traffic. A tell-tale sign that this is the "firewall" you have is that you cannot set IPv6 whitelists on your router. > I don't see a single mention of firewalls in the RFC[1]. But then neither did the ipv4 spec. Why would we suddenly stop using firewalls though? They have been standard on networks for decades. The RFC? Yeah, both IPv6 and IPv4 have evolved in the years so that there's multiple RFCs about them. For example, IPv4 don't promote ICMP firewalls but details what ICMP messages must you allow if you deploy one (unless you wholesale block that IP). IPv6 instead never allows you to block any ICMP messages except if you wholesale block an IPv6 address.
- IshKebab 5y agoBecause NAT is secure by default, whereas IPv6 is insecure by default. In other words, if you have internet and you're using NAT then unless you have done some complicated stuff (port forwarding) you're probably safe. If you have internet and you're using IPv6 then unless you have done some complicated stuff (enabling a firewall) then you're probably not safe. I guess eventually IPv6 enabled routers will come with a firewall enabled by default but let's not hold out breaths!
- brendoelfrendo 5y agoOnly when you're dependent on NAT for security. NAT isn't intended to be a security tool, and is pretty bad at mitigating against attacks that aren't just "log into this device directly." As others have said, a robust firewall and some good access controls and you'll be fine.
- VectorLock 5y ago"anything inside my home network from anywhere on the internet" doesn't sound much like robust access controls. I wouldn't trust the horrible default passwords and lax security built into most devices for home use to be exposed directly to the Internet even with a firewall.
- brendoelfrendo 5y agoRobust access controls would be things like certificate auth, MFA is cool, fail2ban is good, maybe throw in some roles there; whatever floats your boat. So yeah, your security model should involve not using default passwords and not using devices that have unchangeable default passwords. Again, people are depending on something that isn't really designed to provide security to provide security. Devices that have horrible default passwords aren't secure in any environment. We need to a) do better in picking what we run on our networks and b) hold manufacturers accountable for setting sane defaults.
- VectorLock 5y agoIf your threat model involves baby sitting every device in your network and making sure they're robustly secure. Some people just want their lightswitches to work.