3 ms·
> Update me - am I crazy? Is this old info or a bad take? 1. NAT does nothing to prevent network egress. NAT is not a firewall--it monitors outgoing connectio
by labcomputer 4y ago
> Update me - am I crazy? Is this old info or a bad take?
1. NAT does nothing to prevent network egress. NAT is not a firewall--it monitors outgoing connection to remember how to re-write incoming packets. Any IoT shit or malware that wants to call home to a control server is free to do so.
2. Most consumer-NAT implementation have a facility for "inside" hosts to map "outside" ports to "inside" IP address-port combinations (for games). The facility has no authentication, other than (usually) ignoring packets from "outside". So a single infected device on your network can poke arbitrary holes in your "firewall".
3. Most modern IPv6 stacks create new auto-configured addresses and rotate them on a regular basis (the address space is big enough to do that). So "your address" is constantly in flux. Obscurity isn't good security, but at least it makes it harder for the bad guys to know where to send the packets.
4. The IPv6 packet structure is simpler, so, in theory, you might expect fewer vulnerabilities in your IP stack.