9 ms·
NSA CSI IPv6 Security Guidance (2023) [pdf]
- codesniperjoe 4y agoTLDR: Avoid it if you can!
- ZeroSolstice 4y agoAren't these comments getting a bit old at this point? Running dual-stack should not be any more difficult than just running IPv4. There is a plethora of automated deployment tools and I'd hardly think people are DHCP'ng addresses to their servers. You don't have to use SLAAC and can statically assign addresses just like IPv4. Even for your dual stacked devices getting IPv6 addresses via RA can be tracked back to their IPv4 DHCP bootp requests. I'm making the assumption here that anyone concerned about their network attack surface is actively capturing network or netflow data in which tools like openargus[1] or Arkime[2] make all of this collectable/searchable. Additionally most network devices support mirror/monitoring to offload data if you aren't working on the scale of needed dedicated taps/aggregators. [1] https://openargus.org/ https://openargus.org/ [2] https://arkime.com/ https://arkime.com/
- sn0wf1re 4y agoThey do feel a bit old. Especially considering that is not the "TL;DR" of the paper. The paper makes no statement on whether or not it is a good idea to use ipv6, only that the US Government is transitioning and some guidelines on how to do that.
- yonz 4y agoIn the context of network intrusion detection and providing secure online services, I agree with you. However, if this guidance is trying to influence government office routers and internet gateways... It's a different story. A transition from IPV4 to IPV6 creates a new per device tracking capability that leaks internal network structure. This in my opinion is worse than internal domains getting certs from Let's Encrypt https://crt.sh/?q=twitter.com https://crt.sh/?q=twitter.com cr: https://shkspr.mobi/blog/2022/01/should-you-use-lets-encrypt-for-internal-hostnames/ https://shkspr.mobi/blog/2022/01/should-you-use-lets-encrypt... The dual stack, DHCP and SLAAC can go a long way in adding some anonymity.
- ZeroSolstice 4y agoRealistically though what information can you glean from a hosts IPv6 address that wouldn't already be part of WHOIS? With IPv4 you already know there are only (3) rfc1918 reserved ranges. Anyone can use them as they see fit so seeing a 10/8 address in a email header doesn't automatically mean the company is huge its just what they picked. Myself, i've just never really bought into the whole "dns naming" or discovering private address ranges giving anything away. With existing NAT device tracking moved onto more unique features such as browser, screen size, etc. such that IP address tracking is probably not as accurate.
- jeroenhd 4y ago> A transition from IPV4 to IPV6 creates a new per device tracking capability that leaks internal network structure. I doubt it. Your load balancers will be the only addresses that will be addressable anyway. Your IPv4 load balancers will also be "leaking" IP addresses.
- wmf 4y agoYou're thinking of the server side, not clients.
- jiggawatts 4y agoClients use random IPv6 suffixes.
- jeroenhd 4y agoClients that aren't misconfigured will use random IPv6 addresses that rotate. The usual default is once per day but that's a mere preference, you can make your computer take a new IP every minute if you want.
- wmf 4y agoYou can still see subnets though which was the original point.
- deleted 4y ago[deleted]
- exitheone 4y agoThat's not at all what I got from this. Ipv4 security guidelines do not look much different. TLdr: be aware of the differences and prefer ipv6-only instead of dual stack if you can, to reduce complexity.
- _8j50 4y agoYou are getting downvoted but ipv6 was ratified in 1998. The sunken cost fallacy is real here. At what point or threshold should there be a proposal for a simple address length extension of IPv4. Even in cloud providers who have an army of sysadmins and netadmins they don't support v6 in private networks. Let's be very honest here, does anyone have a good reasom to believe another 25 years would mean ipv6 would displace ipv4 or even solve the address shortage when cgnat and other workarounds are profitable to network vendors? https://en.m.wikipedia.org/wiki/Sunk_cost_fallacy https://en.m.wikipedia.org/wiki/Sunk_cost_fallacy ----- My controversial solution is to stop using numbers for addressing on layer3. A new IP protocol should have hierarchial domain name addressimg. So google.com would have .com as the top domain you would have routes for each TLD with non-ISPs default routing tlds like .com, ISP networks would resolve the route for .google under the .com routing table and so on. Upper layers would be oblivious except that you have less code now. On LANs you can create whatever domain hierachy works for you so long as the TLD is part of a predefined list. TLDs will have a fixed maximum length of 128bits for routing performance amd such. PKI/TLS would work just fine except now you have an extra layer of security in that ISP routing tables would have to also route to the wrong AS and can implement source route (customer1244.telecast.isp) validation to make mitm only slightly harder and address spoofing ddos impossible. So forget about numbers, ascii is also numbers. You are already doing this with v6 and 2600:: and other prefixes. As for layer3 translation, I have an even more controversial idea that will also solve wifi security and lan based mitms for good but for another comment.
- doublepg23 4y ago> ratified in 1998 While this is true World IPv6 Launch Day in 2012 is the date most people point to for earnest IPv6 deployments. It was also not completely ratified until 2017. > At what point or threshold should there be a proposal for a simple address length extension of IPv4. If you pass a IPv4v2 packet it will not be routed. You'll need to replace all networking equipment to support IPv4v2...which is what we've done/currently doing w.r.t. IPv6. The engineers who wrote the spec were very much aware of how much "we've got one shot at this" was. > another 25 years would mean ipv6 would displace ipv4 We're at over 50% deployment in the US. Again, it's closer to 10 years.
- CircleSpokes 4y agoThat is the exact opposite off what it says. The US government has actually mandated IPV6 only networks in the next few years. >At least 20% of IP-enabled assets on Federal networks are IPv6-only by the end of FY 2023;9 >b. At least 50% of IP-enabled assets on Federal networks are IPv6-only by the end of FY 2024; >c. At least 80% of IP-enabled assets on Federal networks are IPv6-only by the end of FY 2025 https://www.cio.gov/assets/resources/internet-protocol-version6-draft.pdf https://www.cio.gov/assets/resources/internet-protocol-versi...
- sn0wf1re 4y agoInteresting that they prefer dual stack to tunnel. I would have thought running your own 6to4 at the network edge would have been more preferential.
- ZeroSolstice 4y agoWhat would be the advantages of running 6to4 on your network edge?
- sn0wf1re 4y agoMy thinking was that it would be a single point of ipv4 traffic, rather than having to maintain all the components for dual stack. But thinking about it more, 6to4 probably increases the complexity of firewalls.
- ZeroSolstice 4y agoAh, yes I see what you were thinking.
- yonz 4y agoSlightly off topic but IPV6 is a massive security hole for regular consumers. NATs sucked when you trying to connect to your favorite MMO but that is because they created a default drop rule for all special inbound ports. I was shocked to see that as soon as your ISP switched to IPV6, your host is now directly addressed. As a by product of skipping NAT you are now relying on every machine having proper firewall settings. [UPDATE: or the router drops incoming IPV6 connections w/ it's firewall] Just think about how many windows machines out there have Remote desktop enabled but were only safe because they were not publicly accessible or the hospital machines that are still running windows XP. God help us.
- johnnyapol 4y agoIPv6 not having NAT doesn’t make it incompatible with stateful firewalls. You can still have routers doing drop inbound by default.
- deleted 4y ago[deleted]
- mnd999 4y agoAnd ISP supplied devices generally are. I don’t really know why people think this is an issue.
- yonz 4y agoMight have learned something today, I always replace the stock router from ISPs. Easy to test, can someone on a cable box try to reach an open port on their host on IPV6 vs IPV4. My belief is that a majority of setups (maybe not HN hackers) will able to hit a host's open port on v6 and fail on v4. NAT is definitely an added layer though.
- Symbiote 4y ago> Might have learned something today Yet you continue to speculate about it and spread baseless FUD. Consumer ISPs supporting IPv6 provide routers blocking inbound access by default. The interface to open IPv6 ports is usually labelled "IPv6 Pinholes" or similar, and you'll find hundreds of web pages on ISP websites describing the functionality -- just as they have pages on IPv4 port forwarding. The extraordinary claim that ISPs are supplying routers with such a dangerous default configuration requires evidence.
- simoncion 4y agoFrom the recommendations document: > The assigned IPv6 address incorporates media access control (MAC) address information from the network interface and may allow for host identification via interface ID, network interface card, or host vendor. How long has it been since NSA has looked at generally-available OSs with IPv6 support? IPv6 "Privacy Addresses" are a thing that's on-by-default everywhere (and a damn thorn in my side). SLAAC has been using a identifier that's a combination of a randomly-generated ID and the subnet that the address is being generated for rather than the MAC address of the NIC for address generation for ages. (This is yet another thing that I revert back to the old behavior.) They go on to recommend disabling SLAAC and using only DHCPv6. Does NSA know something exploitable about common DHCPv6 implementations that we don't? ;) > ...a dual stack DNS implementation may need to support both A and AAAA records. It's weird to say "dual stack DNS implementation". DNS servers can store A and AAAA records, regardless of whether their host is doing "dual stack" addressing or not. (If yours cannot, then by golly, you fucked up when you wrote your DNS server.)
- zokier 4y ago> They go on to recommend disabling SLAAC and using only DHCPv6. Does NSA know something exploitable about common DHCPv6 implementations that we don't? ;) This is what they say > NSA recommends assigning addresses to hosts via a Dynamic Host Configuration Protocol version 6 (DHCPv6) server to mitigate the SLAAC privacy issue. Alternatively, this issue can also be mitigated by using a randomly generated interface ID (RFC 4941 – Privacy Extensions for Stateless Address Auto-configuration in IPv6) [1] that changes over time, making it difficult to correlate activity while still allowing network defenders requisite visibility
- aaronax 4y agoDebian 11 VMs that I was setting up last week were getting non-privacy SLAAC addresses. So I am skeptical of how common it is to default to privacy addresses.
- throw0101c 4y agoStrange: > A solution to this are IPv6 privacy extensions (which Debian enables by default if IPv6 connectivity is detected during initial installation), which will assign an additional randomly generated address to the interface, periodically change them and prefer them for outgoing connections. Incoming connections can still use the address generated by SLAAC. * https://debian-handbook.info/browse/stable/sect.ipv6.html https://debian-handbook.info/browse/stable/sect.ipv6.html * https://manpages.debian.org/bullseye/ifupdown/interfaces.5.en.html#privext https://manpages.debian.org/bullseye/ifupdown/interfaces.5.e...
- pm2222 4y agoPiece of advice: setup a dedicated firewall’d vlan for iot and obsolete Lin/win devices, regardless of v4 or v6.
- deleted 4y ago[deleted]