7 ms·
Internet centralization and the original sin of NAT
- deleted 1mo ago[deleted]
- Sha1rholder 1mo agoTime to set up IPV6.
- TZubiri 1mo agoOr just use an ipv4 address. It works I swear
- Sha1rholder 1mo agoIn regions where IPv4 addresses are scarce, you may not even have a single public IPv4 address. I'm fortunate to have one, but still needs NAT.
- hdgvhicv 1mo agoIPv4 costs are tiny compared to the cost of providing an internet connection.
- Sha1rholder 1mo agoNot every place is the same.
- TZubiri 1mo agoDo you have any example where leasing an ipv4 block from a NIC directly costs more than 5$ per IPv4 address per year?
- litoE 1mo agoYes. My ISP will rent me a single IPv4 address for $10 per month. Or I can use DHCP, where my IPv4 address can change at their whim.
- TZubiri 1mo ago> Yes. My ISP will rent me a single IPv4 address for $10 per month. At that price point you can get a small vm, but if you have a dedicated server you want to use on-prem, 10$/mo seems like a reasonable price. > Or I can use DHCP, where my IPv4 address can change at their whim. Check the dhcp.lease to make sure, I used to think that, then I looked at the dhcp lease and the IP was being reserved for up to 48 hours of disconnection. I went years without it ever being released. Phone operators won't necessarily transmit this information to you, the true ISP operator is the DHCP server. Not only is it more knowledgeable, but DHCPd has no incentive to upsell you, just provides you with what it is configured to. I'd even go as far as checking if you can send parameters during the dhcp lease request, maybe you can request a longer lease on the IP. There's a right way to do things, it's not trivial to discern from the wrong way to do it, but once you see it, you notice that you lose almost nothing, it's not like the 'wrong' way is simpler, it's just 'wronger', all the way through. I guess the reason they persist is sunk-cost fallacy, the businesses and people that went with NAT then developed STUN, and then they developed ICE, and then they develop Tailscale, every time you need to invent a bigger spade to dig you out of the hole and into a deeper one. Or you can just use IPv4. But aghast, you have to pay 10$/month (or learn DHCP)
- vel0city 1mo ago> or learn DHCP There's nothing to learn here in the end. Its just rules imposed by the ISP. I've had places where the leases expired weekly, and I'd often get a different public IP address when renewed. No amount of learning will change this. If I want out of that, I'd have to pay extra money every month. I've also had ISPs where I've had the same IPv4 address for years. So long as I was online around the time of the lease renewal, I was pretty much guaranteed to get the same IP. YMMV. > At that price point you can get a small vm, but if you have a dedicated server you want to use on-prem, 10$/mo seems like a reasonable price. So I can spend $10/mo for each IP address I want, or I can just use IPv6 where my ISP gives me 295,147,905,179,352,825,856 IP addresses (a /60) by default for free. Hmm...which to choose...
- Dylan16807 1mo agoIt's free money to your ISP. A lot of ISPs us CGNAT.
- kazen44 1mo agoCGNAT is also not cheap and very complex from a architectural point of view. Vendors have been pushing it though, because implementing IPV6 only somehow is still a very, very scary thing for large ISP's to pull off. what should happen is it should be very easy to deploy ipv6/4 translation mechanisms in ipv4 only networks, this would allow easy interopability and make it easier for the large networks to push IPV6.
- rugby_poppeye 1mo agoNAT made distinction between PCs and servers too broad.
- TZubiri 1mo agoRelated comment from another thread https://news.ycombinator.com/item?id=49454785 https://news.ycombinator.com/item?id=49454785 > Even more ironic is that NAT got normalized as a security feature — “your devices are hidden!” — which is one of the things that made people resist the thing that would fix it. That tracks. I briefly looked into the Tailscale website and I thought maybe I was wrong, maybe it's not a NAT/ddns toolchain, maybe it's something more complex that I'm too dumb to understand. But if my thesis that it's NATware is right, it makes sense to market it as a security product, it fooled me for one, but it also passes as a quality product for an organization, and they feel they are getting a security product when they are actually signing the purchase request of a developer that is applying networking techniques they learned from managing a videogame server.
- wmf 1mo agoI'm having trouble decoding this but Tailscale is a VPN that can traverse NAT when necessary. Arguably Tailscale wouldn't be needed if NAT didn't exist but considering the timeline I'm not going to declare a conflict of interest.
- TZubiri 1mo agoYou are describing the product technically, but I find how it is used more important. Do you use it? What do you use it for? If empirically most users use it to host a server on a machine with firewalled IP, then that's more descriptive than its technical featureset as listed on the tin.
- wmf 1mo agoI don't think any of us could know how most users use it.
- parasyte 1mo agoi personally have used it * to provide access to my home network, as though i am on the home network, while outside of said network * to connect several locations to the same business network the first lets me provide locally hosted services without exposing them to the internet, by allowing members of the VPN ("tailnet" in their parlance) to connect to those services the second was very handy to move a few users from a company in the process of shutting down to their homes, so they could continue to work like they had in the company network once the actual internal company network was shut down.
- mittensc 1mo agoI remember times before NAT and SSL You could share things easily, sure, but anyone could get hacked pretty easily and very targetted. After NAT, sharing was still easy lots of 'piracy' apps, various messengers with NAT passthrough Both before and after you needed to be technical, you can't ask someone that doesnt know about computers to set up an FTP server, and if they did it would be a nightmare and they'd likely share their whole drive Same goes for anything else. Anyway, we'll get the whole non-nat with IPv6, let's see what that brings
- teekert 1mo agoIt brings the requirement for a firewall on every endpoint with a unique address. My Phone often has an ipv6 address (found out this holiday wen I couldn't resolve one of sites because of an orphan ipv6 entry nobody noticed), and has little problems. Perhaps there is also "firewalling" on the router and the phone can't even have incoming connections. Not sure. In any case, the phone seems to do fine.
- vbezhenar 1mo agoI'm still not convinced that IPv6 is a good thing. I think that we should have doubled down on sharing IP addresses. Both for consumbers (NAT) and for servers (NAT, TLS/HTTP reverse-proxying). It just solves all problems with IP address exhaustion. And the fact that consumers can't just directly connect to each other is a feature.
- Almondsetat 1mo agoP2P communication is also a feature, which an entire class of applications would love to make use of. Instead, we need to spawn (and PAY for) TURN and STUN servers
- mr8031 1mo agoipv6 is a window for every buttock. I don't see this as a good thing.
- platesmead 1mo agoWhen I want to debug reachability concerns, it's a shame that I can only use ping/traceroute between the non-NAT peers, and then have to SSH to my reverse proxy to do yet another ping to the backend. Similar for tcpdump. This is the cost to splitting your routing between layer 3 and 4. I'm now IPv6 everywhere, and so I get to just use ping. Much simpler. Further, protecting IPv6 services is simpler, because I can terminate (m)TLS on the backend. With a reverse proxy on another host, I have to have yet another means of securing the proxy-backend path. Yet more complexity! > And the fact that consumers can't just directly connect to each other is a feature. Consumers should be protected by firewalls. That's independent of routing.
- titularcomment 1mo agoReverse proxies work because they're not behind restrictive NATs, and having a few central servers that are not behind Symmetric NAT is a surefire way to establish an ISP-granted monopoly. Even if that somehow worked, this completely breaks P2P for consumers (which I think you intend) as well as torrenting without, again, a central NAT-punching TURN-like server. So yeah, address exhaustion is done but so is the Internet as we know it.
- 1mo ago
- elric 1mo agoCalling NAT the original sin is a serious exaggeration. Carrier Grade NAT (CGNAT) is a truly evil concept that restricts the freedoms of the CGNATed users. But regular NAT is fine as long as you can control it. "No one wanting to bother with port forwarding" is largely a matter of shitty UX on the home gateway side and laziness on the side of the operator. Same with UPnP. If anything, NAT has saved millions of wildly insecure devices running unpatched old Windows versions from getting pwned the second they connect to the open internet.
- NoMoreNicksLeft 1mo ago>If anything, NAT has saved millions of wildly insecure devices running unpatched old Windows versions from getting pwned the second they connect to the open internet. This might not be a good thing. Perhaps if there had been no protection for those odious operating systems, they'd have died the horrible deaths they earned decades ago. We should only want to protect things we intend to keep, after all, and none of us wanted to keep that garbage.
- mikewarot 1mo agoAll of the current OS choices are insecure by design. The all operate programs with the ambient authority of the user. While this was fine for the corporate world of AT&T in the 1970s, and the classroom in the 1980s, it's insane to use it in the era of ubiquitous persistent megabit Internet connectivity, and mobile code. I know of zero systems that can survive exposure to the raw Internet, unpatched and without administrative oversight, with uptimes of years.
- NoMoreNicksLeft 1mo ago>I know of zero systems that can survive exposure to the raw Internet Sure. And as long as nothing has to survive exposure to the raw Internet, no one will build anything that could survive it. Not sure why that's so difficult to understand. You seem to think that the protection is the reaction to dangerous operating systems, when it's the cause.
- 1mo ago
- arisudesu 1mo ago> Why you don’t have a FTP server May be due to US DoD holding large amounts of IPv4 for no reason
- deleted 1mo ago[deleted]
- g023 1mo agoI miss the old days of ICQ and just dragging a file onto the person you are sending your file and bam, done like dinner.
- wmf 1mo agoCan't every chat app do this now, including SMS/MMS?
- Uptrenda 1mo agoAuthor is right about everything. Also: IPv6 doesn't fix this, it just introduces a new problem. IPv6 machines end up with local firewalls + stateful firewalls on the router. That router doesn't let in inbound cons. There is a part of UPnP that lets you add "pin holes" (it works like you expect) -- but the drawbacks are its kind of obscure, poorly implemented, and not guaranteed to be enabled. The idea of router sounds simple and like it should implement some standard protocols. But in practice -- a lot of it is a mishmash of proprietary, ad hoc shitware. Something I never hear spoken about is the deep packet inspection filter component of the router firmware. It's a part of the router that decides on what traffic is allowed / not, and almost no company publishes this part. So you're not even in control of your own Internet traffic, tiny blobs of code written by some company get to decide if something is allowed or not. If that sounds sus AF and kind of a bad idea -- well, it is. You can always run 100% open software with open-wrt. But the thing is -- the Internet isn't just your part of it. It's a network of networks, and all those shitty routers, with all that shitty firmware, is deeply ingrained within the entire Internet. That's millions of devices that would need to be replaced to fix the issue.
- tsimionescu 1mo agoWhat consumer routers implement DPI in their default firmware? What type of traffic are you claiming they are dropping? I've never heard of a claim like this, so I'm really curious. Note that I'm not talking about the huge DPI market for corporate/state networks.
- GoblinSlayer 1mo agoMaybe it's about ALG.
- Pesthuf 1mo agoSending files to another would be easy if only the services that allow doing this - over WebRTC - didn’t sell out to sketchy advertisers constantly. I have to look up which service is still good to use every time.
- dboreham 1mo agoThat's because they're actually not "sending files to another". A hairpin service has to be provided for double NATed scenarios and a rendezvous service has to be provided for all cases. There's no magic about WebRTC that makes it actually p2p.
- CrimsonCape 1mo agoCheck out Bitbang: http://github.com/richlegrand/bitbang-cli http://github.com/richlegrand/bitbang-cli I've been using it and it certainly has the potential. I signed up for Cloudflare's TURN server which you use with bitbang and it gets you 1TB free data transfer per month.
- dboreham 1mo agoPeople have forgotten, or weren't alive, but NAT was created and deployed originally by users. The problem they were solving wasn't "how do we stop running out of addresses" but rather "how do we save money". That's because early ISPs had hit on the idea of charging more for more address space, as a way to differentiate between small and large customers. So you could buy a cheaper service with one IP and use NAT to get your whole organization online.
- Hizonner 1mo agoI was alive and don't think I've forgotten. What distinguished large from small users was the width of the pipe. Address space charging was never important as a revenue driver. There were some attempts to charge for address space to keep people from getting huge blocks they didn't use. The long term solution for that was, of course, supposed to be IPv6. If I wanted to blame large corporate "users" for NAT (which I actually do), I would blame their obnoxious intransigent refusal to upgrade to IPv6. That part wasn't the ISPs' idea, but it had nothing to do with the cost of address space and everything to do with shortighted laziness. They were, in fact, willing to pay for IPv4 space to avoid having to do anything.
- miki123211 1mo agoThe designers of the internet made one fundamental mistake, namely applying meatspace norms to cyberspace. In the "real world", you don't really need that much security. Your actual security comes from the fact that all the worst criminals are already locked up, most of the would-be criminals are afraid of being locked up, and if somebody does actually commit a crime, they will get locked up and won't be able to do it again for a good while. A lot of real-world security is about post-factum detection (think alarms, CCTV, panic buttons etc), because in the real world, detection and prevention are two sides of the same coin. This only works because if a real-world crime happens, the criminal by definition is in the same location as the victim, and law enforcement cares most about the community they serve. If the criminal is across the world, as is the case in cyberspace, even if it's a friendly country, it's often "not their problem". This means internet systems need actual security, and NAT provides exactly that. If not for NAT, we'd all need a firewall, and things would be almost if not exactly the same. In the real world, "leave things relatively open, because locks are mostly for keeping honest people honest" is a valid strategy. This strategy doesn't work on the internet.
- baron3dl 1mo agoI think about this frequently. IMO, geographic sparsity is the biggest difference. Every malcontent on the planet just can't reach my door, and the physical reality of movement through space means they can't reach my door, AND every other door on the planet, in the same way they can reach every IP, or practically every IP. There's probably a field of study with vocabulary and accompanying proofs of significant rigor that prove or disprove this. Maybe they'll stop by our little subthread and clear it up.
- api 1mo agoUhh... you can have a firewall without NAT, including one at the perimeter. This is a very common misunderstanding. NAT and firewalls are separate concepts. You can also have NAT with no meaningful firewall -- a port remapping NAT that allows anything through. Most IPv6 networks are firewalled but there's no NAT.
- tptacek 1mo ago
- solatic 1mo ago> There’s lots of things you can blame for killing the open Internet, but I think NAT was one of the earliest. Running a server used to be trivial: run an executable, tell people your address, done... It also trained everyone to think client‐server is natural. “My device talks to The Cloud which talks to other devices” feels normal, when that feeling originated as an artifact of address scarcity. A lot of this feels like a requiem for the days when the only people on the Internet were "high-computer-skill" type folks. Most people will gravitate to "user-friendly" solutions: Gmail and other managed email providers were popular because they didn't stop working when you shut down your computer to save electricity, when your server's hard drive crashed, when you upgraded your computer to something with a faster processor, more RAM, and a newer operating system. It was hard enough to educate laypeople about URLs and email addresses (AOL keywords, anyone?), let alone a combination of random numbers in an IP address, or convincing people to register domain names. Yes, NAT shoved fences into a network that was all about connecting everybody. But we'd still end up with server-client cloud architectures, even if we had started with IPv6 in the beginning. ISPs would have just sold highly restrictive firewalls as part of their home-install basic boxes, and we'd still have ended up with those fences.
- warkdarrior 1mo ago> Running a server used to be trivial: run an executable, tell people your address, done... This works, until you have more than one person accessing your server. Then you need to worry about accounts, credentials, data isolation, etc. And then if a couple of people connect to your server and start using it, you have to worry about staying online, staying updated, backing up the data. But other than that... yes, trivial. And just to be really explicit, you always have more than one person accessing your server, and most of the time they are unwanted users trying to break in.
- mxkdjdjdb 1mo agoI mean, no, you don't have to worry about all that stuff unless the business logic demands it. The OP is entirely correct for eg just serving a static file.
- 1mo ago
- exabrial 1mo agoI think its funny everyone thinks that ISPs, Device Manufacturers, and Cloud Providers are going to let your connect back directly to your "home" with IOT devices. Absolutely not. They can charge your $9.99/mo so you can connect their craptastic app to their craptastic cloud so you can "use their app from anywhere".
- Hizonner 1mo ago... and NAT was a big part of giving them the market power they now use to enforce that.
- exabrial 1mo agoI would say the lack of deploying service locator records in DNS was also a major contributor. We have trillions of ports/ip combinations available and we use waste bits by always using 443.
- cm2187 1mo agoNATs are also firewalls. I think people forget that before NATs, when you would install Windows, the minute you connected it to the internet, you had to rush to update it before a virus would infect it. The OS of the 90s weren't secure enough to be exposed to the WAN.
- talideon 1mo agoNATs are not firewalls. Any firewall-like functionality provided by NAT is entirely accidental and better provides by an actual NAT.
- icedchai 1mo agoThere are really two things here: 1) The typical "NAT" is a "PAT", which requires state for mapping traffic flow. An implementation is going to look very similar to a stateful firewall, by necessity, not accident. 2) The use of RFC-1918 addresses behind the router / NAT box provides some protection. If your address is not globally reachable, it's much harder to reach any hosts behind it. Yes, a poor implementation might allow direct routing from adjacent networks, like your ISP or neighbor. But that still isolates you from 99.99% of the internet.
- talideon 1mo agos/actual NAT/actual firewall/
- icedchai 1mo agoWindows wasn't secure enough. I ran Linux, *BSD, and Solaris systems for years without any firewalls, host or otherwise.
- thomastjeffery 1mo agoThe consequences are so much more significant than people seem to realize. Because of NAT, hierarchy (centralized servers) is the foundational design pattern of the internet, and anyone who wants any semblance of anarchy (decentralized networks) must use a workaround that is itself hierarchical and costly. We are all interconnected, but only a wealthy few can truly speak fist.
- kazen44 1mo agowhile i agree with your sentiment, i personally think that the foundational design pattern of the internet as a network is highly decentralized. once you get public IP space and the infrastructure required to talk BGP, making decentralized designs is actually quite easy. The issue that ipv4 exhausting and "solutions" around it like NAT are making it very hard for actual users (bussiness, people etc) to get access to public IP space without strings attached. IPv6 solves a lot of this, especially because IP space is so massive LIR's don't need to be so spare with giving out address space. The far larger issue we have is that applications are ingrained in a client server mindset, in which big incumbents want to have this architecture because it forces control from the server towards to client. And control usually also means having the data itself, which is where the real value lies.
- __MatrixMan__ 1mo agoI agree that assumptions on the application side are the bigger issue, but it's less about encouraging client/server architecture in general. It's often very helpful, even among peers, to drop into a mode where somebody is wearing the client hat and somebody else is wearing the server hat. The sin here is the hierarchy imposed by SSL and its infatuation with server names. Its says: these people are lords, they can wear the server hat. As for the peasants, your client hats are over there. If we catch a peasant wearing a server hat, the browsers will make them look like a criminal. Our applications have evolved accordingly.
- deleted 1mo ago[deleted]
- api 1mo agoReading the comments: Why do so many people still think NAT equals firewall when they're not directly related? I guess it's because they're normally packaged together for practical reasons. They're both packet handling functions often performed in the same place. But they are NOT the same and you can have either one without the other. Most IPv6 networks have firewalls, and it's possible to have NAT that liberally passes anything. I wonder how much this misconception has delayed V6 adoption? "But I'll be wide open without NAT!" No, you can have a firewall. Most IPv6 routers have stateful firewalls on by default.
- unethical_ban 1mo agoYou are correct. The reason NAT is seen as security on home networks is that, absent a firewall, it acts as a default deny to inbound traffic.
- tptacek 1mo agoIn other words, the reason NAT is seen as security is that it provides security (imperfectly, like almost everything else).
- unethical_ban 1mo agoIn such a way that it can partially break connectivity and in a way that fails to have users think about security explicitly, yes. Imperfectly.
- tptacek 1mo agoYes when has a security mechanism ever pissed off Unix-on-the-desktop nerds like us before.
- Dagger2 1mo agoNo, the reason is that people incorrectly believe it provides security. It doesn't actually do that.
- deleted 1mo ago[deleted]
- RustyRussell 1mo agoSorry. I implemented the current NAT system in Linux. In particular, avoiding port reservation in favor of squishing more connections into one IP address, as long as the remote address allowed us to differentiate. This, in turn, means incoming traffic from a different address is unroutable. You no longer have a public endpoint. This is "poor man's firewall", but erodes our ability to have a server the way we used to. I was a young engineer solving a specific problem, without considering the larger picture. It wasn't the only thing, but I feel it definitely moved the internet to a client/server infrastructure and a key equality was lost.
- gerdesj 1mo agoMate ... How many people are engineers, technicians, mildly interested, not fussed or call the internet "Facebook"? IPv4 without NAT was fucked at the design stage. To be fair: Who knew? I was asked by my employer a while back to investigate this new www thing that has hit the internet (in around 1994 or 5, it took a while to notice) and I said it was a bit crap and no better than WAIS and GOPHER. I was using telnet on a Windows 3.1 PC and telnetting madly via a VAX and a X.25 PAD and what I now know was close to magic! No one had any idea how things would turn out back then. I'm actually quite impressed how long IPv4 has managed to work and without NAT (which I do mildly despise, given 30 years messing with this stuff), it would be stuffed. Thank you for your work.
- alexpotato 1mo ago> no better than WAIS and GOPHER. I was using telnet on a Windows 3.1 PC I had a corporate internship in the late 1990s and they blocked external web access. They did, however, allow external Telnet access. This meant that whenever I had free time and/or was waiting for new projects, I would telnet back to my college server and use lynx to go read my favorite websites.
- Uptrenda 1mo agoWhat a comment, lmao. I'm aware of some of the work that you've done. You've had an impressive career, tbh.
- 1mo ago
- crote 1mo agoYeah, no. Working around NAT was trivial for the people who actually cared about it. I was adding port forwarding rules to my parents' router at age 12. Turns out exposing a poorly-configured Windows XP box to the wider interwebs is a Really Bad Idea - and for the same reason UPnP letting random unpatched shady P2P applications do the same is Very Much Not Good. Let's face it: consumer devices simply aren't secured well enough to let the entire internet poke around in them, and it was even worse a decade or two ago. Decentralization is pointless when it only results in people compromising their own machines, and the people with the skills to set up a 24/7 Linux server in a broom closet won't care about adding some NAT forwarding rules. Even without NAT, we would've definitely gotten home internet routers firewalled with a default-deny policy on all incoming connections. Exactly the same "manually configure a bypass, or use UPnP" dance blocking you from trivially running a web-available service on your machine, but with a firewall rule rather than a NAT port forward. It's of course a different story with CGNAT, but that only became a thing well after the internet was already centralized.
- deleted 1mo ago[deleted]
- sundancegh 1mo agoThe distinction between NTP as a protocol and the assumptions imposed by NAT is useful, especially when considering how much modern networking depends on intermediaries rather than direct connectivity.
- xvilka 1mo agoOne option to resolve current worrying trends is to invest in development of alternative network protocols/structure, Yggdrasil[1][2], for example. [1] https://yggdrasil-network.github.io/ https://yggdrasil-network.github.io/ [2] https://github.com/yggdrasil-network/yggdrasil-go https://github.com/yggdrasil-network/yggdrasil-go
- mintflow 1mo agoAs a engineering all my career life focused on networking, I am so depressed that IPv6 still not fully replaced IPv4 We have dozen of RFCs and vendors gears support IPv6 as well, but it just not finished
- RiverCrochet 1mo agoIt's fine. IPv4 addresses might get too expensive at some point, encouraging their deprecation. Or it's entirely possible having the option of IPv6 prevents IPv4 addresses from getting prohibitvely costly. Either way, IPv6 has its role.
- tptacek 1mo agoNAT wasn't so much normalized as a security feature as it was introduced as one. The flagship NAT product of the 1990s was the Cisco PIX, a firewall. It resulted from Cisco's acquisition of the company that originated NAT.
- icedchai 1mo agoYes, I remember the PIX! After my time at a few early ISPs, I briefly had a corporate networking job and a PIX was one of the first hardware firewalls I deployed.
- deleted 1mo ago[deleted]