3 ms·
Yeaaah. TCP hole punching is goofy and unreliable, last I checked. You have to do some arcane ritual of having both peers start a three-way handshake to each ot
by foundry27 2y ago
Yeaaah. TCP hole punching is goofy and unreliable, last I checked. You have to do some arcane ritual of having both peers start a three-way handshake to each others’s public endpoints simultaneously, relying on NATs to accept inbound SYN packets if they match the outgoing SYN. And nobody’s NAT devices implement simultaneous-open the same way, so all your connections just fail.
Naturally this leads to slapping even more arcane fixes on top of that, like NAT port assignment oracles to adversarial interoperate with different port allocation strategies (random, sequential, single, etc.) by analyzing patterns in previous port assignments. Networking sucks.
- beeflet 2y agohttps://xkcd.com/2044/ https://xkcd.com/2044/
- paulddraper 2y agoActuate
- ionspin 2y agoI presume you meant to say "Accurate", but it made me think of a off-brand Picard that says "Actuate" instead of "Engage".
- gtirloni 2y agoIf the new technology referenced in the comic provides a way to securely connect, including auditing, I don't see how it applies to the hole punching hack.
- beeflet 2y agoPeople (like ISPs offering routers) set up NAT, often justifying it on the basis of security. Application developers use hole-punching techniques to get past NAT (including stuff like UPnP that requires cooperation from the NAT). The end product is: #1 A sandboxing system that cannot reliably sandbox. #2 A connection system that cannot reliably connect. So now you have two problems.
- dev_hugepages 2y agoNAT is not a security measure but a way to save on IP space or avoid remaking a topology on network addresses changes. For actual security you need a firewall