4 ms·
> One of the things that I take away from this is that I may not want to put servers on these low IPv6 addresses in the future. Certainly one should have firewa
by k_roy 2y ago
> One of the things that I take away from this is that I may not want to put servers on these low IPv6 addresses in the future. Certainly one should have firewalls and so on, even on IPv6, but even then you may want to be a little less obvious and easily found
And my takeaway here is that "Security through Obscurity" isn't actually that secure is it?
> Certainly one should have firewalls and so on
Just because every device has a public IP doesn't mean every device is available publicly. Your public little IPv6 network still goes through a router and that device can control the flow of traffic, through routing and firewalling.
This whole read really just feels like someone discovering IPv6 for the first time and fundamentally not understanding basic networking.
- sedatk 2y agoI also thought that, but the discoverability of internal addresses used to open up new attack vectors like having the users in the same network click to URLs pointing to those internal addresses to exploit them, so, hiding the network topology may not always be solely for obscurity, but for security to some degree too.
- k_roy 2y agoagain though, the fallacy that's repeated over and over again with IPv6 is that just because you have a public IP, suddenly everything is exploitable. If you have an IPv4-only network, you still have firewall and routing. This is what protects your router, allows ports to be forwarded, etc. Literally nothing changes. You still need routing, just not the NAT/PAT part of it. You still need a firewall.
- sedatk 2y agoYeah, no arguments about that. But, maybe, still, don't give your IPv6 devices predictable addresses?
- bustling-noose 2y agoThe idea of IPv6 is that every few hours or so my iPhone gets a new set of IPv6 addresses (usually 4 at a time I don't exactly know my currently config but they keep changing always). So the obscurity is from the fact that you have ipv6 ips shuffling all the time. Since the /64 address space is so vast for a home network you will ideally not notice someone targeting your IP because it may not be worth the effort for those targeting it. Now if you pin a ::1/64 to a machine or lets say some low addresses that you did because you remember them easily (or even if you pin any address lets say thats /64) you are now no longer using the obscurity part. This means your IPv6 /64 is basically just IPv4 now for that one machine. The whole problem here is that you got a public IP (because now thats hard for home networks with ipv4). It's going to behave like any public IP, get targeted by attackers to see if some port is open or if there are any issues with security. IPv6 doesn't bring any advantage here unless you actually use its features like SLAAC and rotating IPs.
- immibis 2y agoIt's more of an accidental side effect than an intentional feature. The actual reason the customer gets 2^64 addresses is to make sure they have enough addresses and don't need NAT. And SLAAC (also an accidental feature) ossified it at 2^64 - a good ossification, for once. And then, if you have so many addresses, may as well rotate through them so it's hard for anyone to observe how many separate devices from your network are accessing their server.
- k_roy 2y agonot at all an "accidental side effect" though. By any stretch of the imagination. Very purposeful
- k_roy 2y ago> The idea of IPv6 is that every few hours or so my iPhone gets a new set of IPv6 addresses (usually 4 at a time I don't exactly know my currently config but they keep changing always). So the obscurity is from the fact that you have ipv6 ips shuffling all the time. Since the /64 address space is so vast for a home network you will ideally not notice someone targeting your IP because it may not be worth the effort for those targeting it. This is fundamentally not a part of IPv6. It was an extension added later for privacy, but doesn't really accomplish too much in that regard except for the simplest of detection. My home address space is a /48. And when do some really simple subnet math on my IPs, you can easily identify my addresses. And again, the point is, just because you live out in the country, doesn't mean you shouldn't lock your doors. Even though right now it's impossible to feasibly to even really scan a /64, that may not be true in a week.
- scarfaceneo 2y agoThank you. The whole read indeed feels like not understanding IPv6. Just like people advertising not broadcasting SSID, or changing the SSH port, this is just a false sense of security.
- wolrah 2y agoTo be fair, changing the SSH port does MASSIVELY cut down on the amount of log spam from low-effort scans. Obscurity isn't security, but hiding still makes you harder to find. In other words the lock is just as good or bad as it always was but a lot less people are going to jiggle the handle. Changing default service ports is a good thing and is one of the reasons everyone should be in favor of software supporting SRV/SVCB records so services can be hosted on arbitrary ports while still being accessible with a plain DNS name everyone's used to using. That shouldn't be lumped in with pure idiocy like disabling SSID broadcast or believing that IPv6 inherently exposes your network to the world. Ironically disabling SSID beaconing on wireless APs actually results in clients configured to use those networks broadcasting looking for them wherever they go, for those who want to hide a network it's the literal opposite of their desired result.
- sfink 2y agoYeah, I changed my SSH port for the same reason. I don't feel any more secure as a result, but now I can just watch the raw logs to see the incoming probes. They trickle in slowly, rather than being a constant flood, so I can watch the raw log for other purposes without it being inundated with noise that I have to filter out in order to be able to pay attention to anything else. That, and the logs use less space on disk.
- k_roy 2y agoI don’t agree. Because the minute you change the port, you just become of more interest. As you said, only the low effort bots scan the standard ports. But venture anywhere off the beaten path, and a place like shodan is the most benevolent of those kind of places, and it still takes about an hour for your IP and newly opened SSH port to be indexed.
- Tractor8626 2y ago> Your public little IPv6 network still goes through a router and that device can control the flow of traffic, through routing and firewalling. And you can't setup neither routing nor firewalling because of random ip addresses. There are two types of people: 1) excited about ipv6 2) actually managing networks