4 ms·
Because a firewall exploit means your thermostat is now controllable over the internet and you can conveniently preheat your oven over the internet too and now
by drsnow 5y ago
Because a firewall exploit means your thermostat is now controllable over the internet and you can conveniently preheat your oven over the internet too and now your house is burning down
- kungito 5y agohow is that worse than ipv4 firewall exploit?
- aaomidi 5y agoIt's actually better because you actually get obscurity with ipv6.
- aaomidi 5y agoHave you considered how much of a pita/impossibility scanning an ipv6 space is?
- deadbunny 5y agoNo different than NAT and forwarding a port which people have been doing for decades. Hell if you have a firewall exploit then exposing stuff to the internet doesn't matter.
- dehrmann 5y agoIt's very different because NAT blocks by default. You either need to manually set up a forwarded port or the app needs to use UPNP.
- icehawk 5y agoI'd not be too confident about that, this is a thing that keeps happening: https://www.anvilsecure.com/blog/dhcp-games-with-smart-router-devices.html https://www.anvilsecure.com/blog/dhcp-games-with-smart-route...
- deadbunny 5y agoEvery consumer router/firewall drops incoming packets by default, why would this be different for ipv6?
- zinekeller 5y ago> Every consumer router/firewall drops incoming packets by default, why would this be different for ipv6? Sadly, this is very far from the truth. Most routers do not filter IPv6 by default, mainly because IPv6's design assumes a per-device firewall. This means that literally you need to ensure that every device supports a firewall or otherwise operates in such a way that it is safe for public access.
- deadbunny 5y ago> Most routers do not filter IPv6 by default. This isn't my experience. If you are correct however, that is a failure of the ISP/CPE provider, not a flaw of IPv6. > mainly because IPv6's design assumes a per-device firewall I don't see a single mention of firewalls in the RFC[1]. But then neither did the ipv4 spec. Why would we suddenly stop using firewalls though? They have been standard on networks for decades. 1. https://datatracker.ietf.org/doc/html/rfc2460 https://datatracker.ietf.org/doc/html/rfc2460
- zinekeller 5y ago> This isn't my experience. If you are correct however, that is a failure of the ISP/CPE provider, not a flaw of IPv6. First, I'm excluding enterprise firewall here. I've verified this with multiple non-CPE routers, and except for the router itself (for obvious reasons), no, IPv6 traffic isn't really filtered. The "firewall" is laughable on some routers (including some assuming /64 filters which isn't necessarily true for some servers like OVH's). The only non-enterprise one that's working as much as an IPv4 system is Asus'. Some routers tries to filter out DoS attacks. Those are rather confusingly called a "Firewall", but it's not really a controllable firewall per se, allowing "normal" but otherwise a malicious-if-DPIed traffic. A tell-tale sign that this is the "firewall" you have is that you cannot set IPv6 whitelists on your router. > I don't see a single mention of firewalls in the RFC[1]. But then neither did the ipv4 spec. Why would we suddenly stop using firewalls though? They have been standard on networks for decades. The RFC? Yeah, both IPv6 and IPv4 have evolved in the years so that there's multiple RFCs about them. For example, IPv4 don't promote ICMP firewalls but details what ICMP messages must you allow if you deploy one (unless you wholesale block that IP). IPv6 instead never allows you to block any ICMP messages except if you wholesale block an IPv6 address.