3 ms·
I remember times before NAT and SSL You could share things easily, sure, but anyone could get hacked pretty easily and very targetted. After NAT, sharing was
by mittensc 1mo ago
I remember times before NAT and SSL
You could share things easily, sure, but anyone could get hacked pretty easily and very targetted.
After NAT, sharing was still easy lots of 'piracy' apps, various messengers with NAT passthrough
Both before and after you needed to be technical, you can't ask someone that doesnt know about computers to set up an FTP server, and if they did it would be a nightmare and they'd likely share their whole drive
Same goes for anything else.
Anyway, we'll get the whole non-nat with IPv6, let's see what that brings
- teekert 1mo agoIt brings the requirement for a firewall on every endpoint with a unique address. My Phone often has an ipv6 address (found out this holiday wen I couldn't resolve one of sites because of an orphan ipv6 entry nobody noticed), and has little problems. Perhaps there is also "firewalling" on the router and the phone can't even have incoming connections. Not sure. In any case, the phone seems to do fine.
- mittensc 1mo ago> Not sure. In any case, the phone seems to do fine. That's mostly because a phone is very locked down, can you run an accessible ftp server on your phone? It's also not windows
- c0balt 1mo agoFor android, the answer is yes (without rooting being required).
- iggldiggl 1mo ago> without rooting being required If you want to use the standard port, that's only true as of very recently, though, see https://issuetracker.google.com/issues/218578943#comment17 https://issuetracker.google.com/issues/218578943#comment17
- jasomill 1mo agoAlso on iOS, though I've only done this over Wi-Fi, and have no idea whether telcos expose open ports to the (IPv6) Internet.
- kijin 1mo agoPhone OSs tend to pay a lot more attention to security than the crap they put on consumer-grade routers, "smart" TVs and cheap webcams. I would invest in a proper firewall for the entire home before opening up anything to the world, IPv6 or not.
- gatio 1mo ago> Perhaps there is also "firewalling" on the router and the phone can't even have incoming connections. Not sure. Correct. Every home wifi router worth its salt will firewall incoming connections by default, whether v4 or v6. It's then possible (unless it's some shitty ISP-provided locked down device) to add specific allow rules, or allow all for a particular client. egress is typically wide open, although sometimes they lock down particular protocols by default (eg. smtp, bittorrent)
- anamexis 1mo agoThere's no home wifi router for an address assigned by the cell carrier.
- deleted 1mo ago[deleted]
- eru 1mo ago> Anyway, we'll get the whole non-nat with IPv6, let's see what that brings I'll believe it when I see it. So far it doesn't look like IPv6 will win anytime soon.
- lstodd 1mo agoWell, any 3G or later mobile backbone is SIP+SCTP over IPv6. So in many ways it won already
- eru 1mo agoWeird, I used to remember that going to test-ipv6.com on my mobile (on 4G and 5G) used to fail all the tests. But today it passes. Well, good to know!
- hdgvhicv 1mo agoMy phone, on 4g, is not IPv6 At home it can be if I connect t to my ip6 ssid, but there’s a stateful firewall which may as well nat.
- lstodd 1mo agoWhat your phone shows to app land is entirely different thing. I'm talking about the backbone.
- silon42 1mo agoI absolutely plan to NAT my home, I don't see a good reason to do otherwise. I don't see a reason why my machine addresses should change over time... then again, most shouldn't have direct internet access anyway, a http proxy on firewall should be enough.
- vel0city 1mo ago> I don't see a reason why my machine addresses should change over time You can still use fixed addresses locally if you want, its not like IPv6 is forcing you to use the prefix assigned if you just want to communicate locally over never-changing addresses. You can have your computers be fd01::1, fd01::2, fd01::3, etc, and talk to everything on their local addresses when wanting to stay local. And then when they want to talk on the public internet they can just use whatever public addresses like 2600:1700:53c2:2573:4c:c001:dead:beef based on whatever prefix your ISP gives you. Its not like your devices have to only have a single IP address.
- api 1mo agoFirewalls, both at the perimeter and locally, was what patched over this. NAT had nothing to do with it. You can have firewalls with no NAT just fine. You can also have NAT with no firewall. NAT is not about security and never was. It's about stretching the IPv4 supply and allowing each endpoint to just get one precious V4 IP.