4 ms·
Wasn't IPv6 suppose to solve all this? I don't understand why that stalled. Also considering the state of iot security its probably not a great idea to have e
by VagabundoP 2y ago
Wasn't IPv6 suppose to solve all this?
I don't understand why that stalled.
Also considering the state of iot security its probably not a great idea to have everything accessible anyway. But that's a slightly different problem to solve.
- chgs 2y agoIt’s not going to solve a stateful firewall timing out. You try to continue a tcp session that’s timed out on my firewall and the packets will be dropped. This applies a fair amount t to me when I suspend my laptop, my ssh session will drop as both the server and the firewalls drop the session while it sits there peacefully. When it comes back the tcp packets get sent into the void. Meanwhile my WireGuard connection which runs through two separate ipv4 nats works just fine, as it doesn’t rely on sessions or a server timing out a socket. Nat is irrelevant to the problem.
- VagabundoP 2y agoWhy not let through all ipv6 traffic? It seems improbable that your device is going to get caught up in a ipv6 scan; the address space is too vast - I'm assuming here. Just have relatively secure devices using ipv6 - not shipping with standard default admin passwords would nearly be enough if there aren't obvious vulnerabilities.