3 ms·
The limit of changing addresses once every N seconds as N approaches 0 is equal to offline. With any usable N, a clever observer would still easily work out wh
by waych 4y ago
The limit of changing addresses once every N seconds as N approaches 0 is equal to offline.
With any usable N, a clever observer would still easily work out what you were doing and still map out your infrastructure.
- ianburrell 4y agoWhy would changing N seconds break network? It would presumably keep active addresses until connections finish. IPv6 requires supporting multiple addresses per interface. More reasonable is to use new address for each connection. Then nobody can tell if 10 addresses and 10 connections are one device or ten.
- waych 4y agoThis looks like NAT pushed down to the endpoint itself. You've saved the translation in the router, but now routing lookups and ARP caches have grown by TEMP_VALID_LIFETIME / TEMP_PREFERRED_LIFETIME. What are valid values in the scenario you are proposing? The defaults are 1 week / 1 day, so 7X. If you chose to rotate each second, and say allowed addresses to only be valid for say 20 minutes, this still appears to be a ~1200X blowup in routing overheads.
- kazen44 4y ago> You've saved the translation in the router, but now routing lookups and ARP caches have grown by TEMP_VALID_LIFETIME / TEMP_PREFERRED_LIFETIME. They have not? The global routing table size for ipv6 at max is a /32 (if i remember correctly) every customer gets a /56 prefix to use in their network, so the routing table entry would still be the same, no matter how many addresses you use to cycle through in your /64. ARP caches do not exist in IPv6, and Neighbour discovery does not have the same "cache" mechanism as ARP does, it uses an entirely different mechanism for neighbour discovery. (which is also far more lightweight considering it is using multicast, compared to the broadcast of ARP).
- waych 4y agoI don't understand what you mean. Neighbor Discovery Caches certainly are a thing.
- justeleblanc 4y agoWhat kind of observer is 1. able to listen to the entirety of your network's outside communications, 2. interested at all in it, 3. harm you only on the condition that they "map out" your internal infrastructure? This isn't a novel, the goal is not to solve intricate security non-problems.
- waych 4y ago"The network is secure" is a common fallacy.
- justeleblanc 4y ago"Those who don't know what to say quote adages" is a common saying.
- Spivak 4y agoYour ISP, "mapping your network" means being able to take data that was previously an amalgam of a household and reliably split it into the individual members and devices for better targeting.
- kmbfjr 4y agoTake a moment and learn about Nokia’s Deepfield or Kintec. The ISPs have the ability to see what is on your network by IPv4 egress. They have been able to do this for a decade. Worrying that an IPv6 address divulges the network forgets that IPv4 devices betray their existence through DNS, their destinations and other network behavior. The ISPs know.