3 ms·
If I’m following your logic, you’re saying you trust tplink etc to keep Grandma safe, but only for IPv4, and not IPv6? Why?
by KerrAvon 4y ago
If I’m following your logic, you’re saying you trust tplink etc to keep Grandma safe, but only for IPv4, and not IPv6? Why?
- phpisthebest 4y agoI am not trusting them, behind a ipv4 nat inbound connections are by default inaccessible ipv6 most configuration end up with all devices publically routable and must have a firewall deny policy inplace to block inbound connection Shodan is filled with people with misconfigured ipv4 routers that end up with all kinds of device that should not be on the public internet (webcams, printers etc) out there for anyone to connect to. This requires a user to actively do something on the device (most likely following a bad online tutorial) in order to port something though the NAT. with IPv6 this problem will get FAR FAR FAR FAR worse.
- lmm 4y ago> I am not trusting them, behind a ipv4 nat inbound connections are by default inaccessible No they're not. They're by default obscured, but anyone can guess your internal IP and send a packet for it, and the router will happily forward it on unless its firewalling tells it not to. And that's without even even getting into all the extra attack surface opened up by legitimate and not-so-legitimate workarounds for the issues NAT causes.