4 ms·
People who block ping should get swirlies
by bogantech 2y ago
People who block ping should get swirlies
- LargoLasskhyfv 2y agoI'd rather swirl pings from the outside, from people who have no business at all to know about my internal infrastructures. Just GTFO.
- bogantech 2y agoIf your internal infrastructure is not internet routable nobody would be able to ping it anyway
- LargoLasskhyfv 2y agoMy comment wasn't about 'if's, but the thought of entitlement to mess around with other peoples stuff, or at least try 'look' at it. That deserves to be flushed down the drain, or the kitchen sink.
- yjftsjthsd-h 2y agoHow would somebody ping your internal network from the outside? Your firewall should block the ping getting past the router, regardless of the external interface responding. That said: Who cares? Even if you published exact list of every single IP on your network, it doesn't do an attacker any good, because again, there's a firewall between them and your devices.
- HeatrayEnjoyer 2y agoNetwork metadata is sometimes valuable all by itself. Investment firms buy satellite imagery to identify the number and models of cars in corporate parking lots, for better inferring internal business conditions. Frequency of pizza deliveries to the Pentagon revealed when major ops were taking place. A private network will ideally present as an opaque black box to the outside.
- deleted 2y ago[deleted]
- peanut-walrus 2y agoThis site is about securing consumer level routers. Nobody using one of those has a network where the internal layout is valuable to a bad guy.
- throw0101b 2y ago> A private network will ideally present as an opaque black box to the outside. Good luck (trying to) scanning a IPv6 /64 subnet. I've been in IT for 20+ years, and I have yet to find a situation where blocking ICMP(v6) caused more benefits than problems. Ditto for my home network: my last ISP had IPv6, and I had an Asus router which blocked unsolicited incoming connections: I could not SSH to any of my Macs from the outside (by default), but could ping if I knew the address (but good luck guessing 2^64). If you want to try to enumerate the equivalent of 4.3 billion IPv4 Internets that is a single IPv6 subnet, have fun.
- ectospheno 2y agoRFC 4890 is a long read but the end result for home networks does have you block a handful of them.
- nickburns 2y agoWhat do you think about black box/IoT/whatever hosts on your LAN pinging external hosts with unknown payloads while you're not using them? Best security practice is obviously to block any/all ping not intentionally sent by you, whoever the local network admin is, or otherwise only whoever or whatever is explicitly allowed to.
- yjftsjthsd-h 2y ago> What do you think about black box/IoT/whatever hosts on your LAN pinging external hosts with unknown payloads while you're not using them? I think that 1. they can connect out via TCP or UDP much more easily than ICMP, 2. that blanket blocking outbound connections is a short path to madness, 3. if you don't trust a device on your LAN you should unplug it or isolate it, both of which are more effective and less disruptive, and 4. depriving yourself of the most fundamental network diagnostic tool in the name of security is cutting off your nose to spite your face.
- nickburns 2y ago1.) Carried out, that logic suggests not performing any outbound filtering because LAN hosts could simply find another way, protocol or port, out? I understand that 99.9% of LANs are configured default-allow LAN outbound. But the premise of your statement is untrue if the firewall is configured default-deny in all directions on all interfaces. 2.) I've not suggested 'blanket blocks' (nor 'blanket allows' for that matter). Specifically, both ingress and egress ICMP should be filtered by type code. 3.) In a zero trust model[1], every LAN device is untrusted. One should perform as much isolation and filtering as possible at all the relevant network layers. Network security is "disruptive" by definition. 4.) The second paragraph of my comment suggested that ping should be explicitly allowed for anyone/any device on the LAN legitimately utilizing it. [1] https://en.wikipedia.org/wiki/Zero_trust_security_model https://en.wikipedia.org/wiki/Zero_trust_security_model