4 ms·
How does that protect privacy of the private network? I don't want to divulge any information about internal topology.
by gxt 4y ago
How does that protect privacy of the private network? I don't want to divulge any information about internal topology.
- adgjlsfhk1 4y agowhat do you mean by topology? the only information leaked would be the number of computers making requests.
- Faark 4y agoAnd what computer is making what requests. Now that i think about it, this cloud be the reason why youtube started making recommendations based on stuff i just watched in private browser tabs...
- CaliforniaKarl 4y agoThat's a very strong claim to make. I'd appreciate if you could provide a source to that statement!
- ipaddr 4y agoYour chrome build id is available in both areas. Not really a secret.
- CaliforniaKarl 4y agoI'd be really surprised if I've got a chrome build ID on my browser.
- throitallaway 4y agoLook at what Android does with MAC address randomization on wireless networks. We will probably see something similar with IPv6.
- CaliforniaKarl 4y ago> We will probably see something similar with IPv6. It's been available for some time: https://www.internetsociety.org/resources/deploy360/2014/privacy-extensions-for-ipv6-slaac/ https://www.internetsociety.org/resources/deploy360/2014/pri... On my macOS system, I currently have four IPv6 IPs (excluding the link-local IP), all of which are random.
- gerdesj 4y agoNot just Android. My laptop does it too (NetworkManager). That's just IPv4 on devices designed to travel so it seems a fair thing to do. Bloody pain to diagnose why a static DHCP lease isn't working the first time, after that you find the mechanisms to turn it off. Nearly everything does it for IPv6, for a given value of everything! For decades we have generally allowed all outbound and worried and fretted about and filtered inbound. I think it is time for us all to get a grip and do the job properly. However, with the delights of DNS over http and the like, the horse has not only bolted but has a new paint job, far better shoes than you can afford, eats grass that was prepared by a Michelin starred chef and belongs to someone else now. We all need to be far more sophisticated about how traffic (knowledge/ideas/data) flows in and out of our networks/lives. Packet filtering is just one tool in the box and worrying about an addressing scheme being global (IPv6) instead of a weird hybrid (IPv4) is completely missing the real issue stabbing you in the nadgers.
- josephg 4y agoI have multiple computers in the house, mostly not logged in to Google. YouTube recommendations spill between devices all the time - like, if I watch a video on one device, I’ll see the same video recommended on another. Or if my partner watches something, YouTube will recommend it to me. They’re obviously doing recommendations based on IP address. (And this is purely over ipv4).
- throw0101c 4y ago> They’re obviously doing recommendations based on IP address. (And this is purely over ipv4). I have IPv6 at home and connect to Youtube over IPv6 (that's generally the default behaviour on macOS and many other OSes). I reboot my DSL modem-router every night and get a new IPv4 address and new IPv6 prefix every day. Now: I live in Ontario, and my ISP is based in Ontario, but they serve clients in Quebec. Every so often, when surfing Youtube, I get served ads in French because according to my (IPv6) address I am "in" Quebec. And, while I am not logged into any Google service, I do not block cookies. So even with cookies, Youtube seems to be fairly dumb about serving ads correctly just based on IP addresses (or at least IPv6 addresses and/or IPv6 prefixes), since cookies don't seem to be useful. So I'm not quite sure about what people are talking about when they say "IPv6 tracking" if even Google/Youtube can't get their act together.
- zeristor 4y agoI live just outside London and have been wondering why I’ve been getting ads from More4 for Wales and Cardiff. Iechyd Da!
- Springtime 4y ago> They’re obviously doing recommendations based on IP address eBay uses IPs showing content, too. I see 'items you've viewed recently' show items I've never looked at, since when on a mobile connection my IP changes fairly frequently and eBay carries over the recently viewed state from whoever else was previously using that IP. It had puzzled me until I came across this[1] eBay topic where others had experienced this, from shared offices to spouses, etc. [1] https://community.ebay.com/t5/Share-eBay-Technical-Issues/Recently-Viewed-Items-Not-Mine/td-p/26634723/page/2 https://community.ebay.com/t5/Share-eBay-Technical-Issues/Re...
- lloeki 4y agothat's not even true with slaac temporary (a.k.a privacy) or secured addresses. the only thing you'd "leak" is the prefix, which is no different than a IPv4 WAN address that you'd get with a v4 NAT.
- gxt 4y agoThat is information about the topology.
- CaliforniaKarl 4y agoIt's fairly limited, without a lot of time and effort, or information from inside the network. I assume you're not acting as an AS, doing BGP, etc; and that you're just getting an IP allocation from a single ISP. In that case, you're probably getting an entire IPv6 subnet (like a /48) allocated to you. Ideally, you make the entire subnet available to your systems. Assuming you block unsolicited packets (that is, packets not related to existing connections/streams) at your border (the connection to your ISP), then outsiders won't be able to use tools like traceroute to learn anything. All that an outsider has is an IPv6 IP, and since you're not doing BGP with anything, all they'll know to do is to send the traffic to your ISP.
- throw0101c 4y ago> How does that protect privacy of the private network? I don't want to divulge any information about internal topology. I'm curious to know: what (attack) do you hope to protect against? I would think that most attacks come in two fashions: the first being that you run a service of some kind and that there's some JSP/PHP/whatever exploit for a public facing service, and someone does a 'magic' PUT/GET that has the application server execute some code, which downloads a larger malware attack package. After which point the black hats start scanning from the inside. The second being that someone clicks on a link in a phishing e-mail or executes some attachment, after which malware code starts scanning from the inside and phones home. (A third being an insider attack, who presumably know about internal topology.) What attack are you thinking to protect against by hiding subnet and VLAN topology?
- gxt 4y agoThis isn't about an attack scenario from this vector, it's about preventing reconnaissance that might yield helpful results to an adversary that can exploit it via any other vector.
- throw0101c 4y ago> […] that can exploit it via any other vector. And what are those vector(s)? Besides compromising a machine that is already inside per the above (which can then do scanning / lateral moves), or perhaps physically getting inside the premises (in which case a scanner can be physically installed to examine the network), what attack are you protecting against? Can you give me a link about an attack that knowing the topology of the network ahead of time would allow, but that not knowing would prevent?
- Retric 4y agoAn example of security being sidestepped is Network intrusion detection. An adversary who knows your network architecture can avoid poking around your network which looks really suspicious.
- deleted 4y ago[deleted]
- yrro 4y agoSee RFC 8981 (and that which it made obsolete, RFC 4941).