4 ms·
They can intercept the unencrypted section of encrypted connections, such as TLS ServerName, and the source and destination of every IP datagram which already p
by stevewatson301 4y ago
They can intercept the unencrypted section of encrypted connections, such as TLS ServerName, and the source and destination of every IP datagram which already provides a lot of information to profile individual citizens.
QUIC moves to a model where everything except the Connection ID is encrypted[1], but it is also apparently being blocked in India[2]. The mandated transition to IPv6 in India[3] would also take away the need to track 5-tuples to identify individual customers, easing the scaling of monitoring.
[1] https://datatracker.ietf.org/doc/html/rfc8999 https://datatracker.ietf.org/doc/html/rfc8999
[2] https://github.com/kelmenhorst/quic-censorship/issues/2 https://github.com/kelmenhorst/quic-censorship/issues/2
[3] https://dot.gov.in/ipv6-transition https://dot.gov.in/ipv6-transition
- lakomen 4y agoHow would ipv6 "take away the need to track 5-tuples" and what does that even mean? That sentence doesn't make sense
- stevewatson301 4y agoNATing IPv4 traffic requires maintaining a 5-tuple of connection state[1], which means the ISP must log these 5-tuples to be able to track citizens individually. Further, if there's another layer of NAT (such as a free WiFi service in an airport or a WiFi router in a citizen's home), cooperation is needed at that NAT layer too. IPv6 obviates the need to maintain these 5-tuples since it has a larger IP address space. Each citizen can then be assigned an unique IP address which makes it easier to distinguish traffic without the cooperation of each NATing layer. [1] https://support.huawei.com/enterprise/en/doc/EDOC1100055044/a9c9d8ca/nat-address-pool-and-its-conversion-basis https://support.huawei.com/enterprise/en/doc/EDOC1100055044/...
- huggingmouth 4y agoWouldn't people just continue using consumer-grade routers which operate their own nat anyway? Even with ipv6, the traffic generated by all hosts behind a single isp subscription would appear to originate from a single ipv6 host, no?
- staringback 4y agoI highly doubt any consumer grade router is using NAT66. You shouldn't use NAT whatsoever with IPv6 and doing so is just asking for client's network functionality to break.
- fomine3 4y agoPeople who live in developing country like India may use internet connection with CGNAT even for residential connection.
- staringback 4y ago> Each citizen can then be assigned an unique IP address You don't understand how IPv6 works.
- ljlolel 4y agoYou would want to use NAT with ipv6 if you want to hide somewhat your traffic— say at university as one example. Couldn’t reply to other comment
- staringback 4y agoNo you wouldn't. You would use temporary privacy addresses in your SLAAC prefix (this is the default for a few operating systems)
- fomine3 4y agoIPv6 prefix is enough for tracking
- staringback 4y agoIPv6 prefix is assigned on a per router basis, you know, like how IPv4 and NAT already works.
- stevewatson301 4y agoThe feedback is fair enough given my phrasing. Of course, IPv6 can't give you a fixed IP address everywhere you go; because that's determined by network topology and IP assignment. All I'm saying is that there's better segregation of the traffic from each IP resulting in easier analysis without the cooperation of NATing layers.
- AgrMohit 4y agoThe blocking being observed might be one off issues. I can use QUIC just fine on Reliance Jio's network. This page [1] shows I am using HTTP/3 which unless I am mistaken requires QUIC to work. [1] https://cloudflare-quic.com https://cloudflare-quic.com