Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
Dagger2
6mo ago
Blame the WHATWG for that. They're the reason that v6 addresses in URLs are such a mess. http://[fe90::6329:c59:ad67:4b52%8]:8081/ should work, but doesn't because they refuse to allow a % there. (This is really d
62.
▲
by
Dagger2
6mo ago
You would also need something like O(N²) routing update messages to keep those tables updated, instead of the current... I'm guessing it grows more like O(log N) in the number of hosts. So everyone would need vast amounts of CPU and ba
63.
▲
by
Dagger2
6mo ago
Or frequently, considered and accepted. 6to4 is a popular one to reinvent.
64.
▲
by
Dagger2
6mo ago
AAAA records have lower priority than A records if you don't have a v6 address assigned on your system. (Link-locals don't count for this). You would only see a timeout to an AAAA record if the connection attempt to the A record a
65.
▲
by
Dagger2
6mo ago
Are you talking about reaching the devices from inside the network, or outside? If inside then you don't need NAT66 and ULA, you just need ULA. Use both ULA and the ISP GUAs on the network, and do your internal connections over ULA. If
66.
▲
by
Dagger2
6mo ago
None of that has anything to do with what you said in the post I replied to. "Add an extra octet to v4 addresses" has hard technical barriers to deal with if you want it to work, regardless of what the world looks like or what you
67.
▲
by
Dagger2
6mo ago
You don't need any tricks like that. Regular new connections will work.
68.
▲
by
Dagger2
6mo ago
That might well have been a more immediately pressing issue, but they did know that v4 was going to be too small and that they still needed to work on v6. I might be saying something obvious here, but address space exhaustion and size of th
69.
▲
by
Dagger2
6mo ago
It's just normal routing. If you send packets to a router, it'll route them. More concretely, they can run the equivalent of `ip route add 192.168.1.0/24 via <your WAN IP>` on a machine that's connected to your WAN
70.
▲
by
Dagger2
6mo ago
It will let them in without a port forward in place. The port forward just rewrites the IP on an incoming connection, nothing more.
71.
▲
by
Dagger2
6mo ago
Our world. It was a good design in our world. I don't think v6 is the absolute pinnacle of protocol design, but whenever anybody says it's bad and tries to come up with a better alternative, they end up coming up with something eq
72.
▲
by
Dagger2
6mo ago
Enabled and actively using it to connect to servers that have v6. Though yes, this is tracking by session rather than by packet or byte.
73.
▲
by
Dagger2
6mo ago
> NAT66 implies using fd00::/8 No it doesn't. Use the GUA from your primary ISP.
74.
▲
by
Dagger2
6mo ago
NAT is state tracking with a trick, but not firewalling. It doesn't block connections, so it's not a firewall.
75.
▲
by
Dagger2
6mo ago
See RFC 2766.
76.
▲
by
Dagger2
6mo ago
Country would be far too coarse to be useful. I suspect it's more likely to be at the AS level, or /32 or somewhere around there. I have a /48. The amount of "we have detected unusual activity from your network" mes
77.
▲
by
Dagger2
6mo ago
It's honestly not that hard. Tell your router to reject new inbound connections from the WAN interface, and you're done. You have to do the exact same thing to make sure inbound connections aren't possible on v4 (even with NA
78.
▲
by
Dagger2
6mo ago
Even a correctly-configured NAT will let connections in from outside, and a lot of people don't understand this. Personally I'd count "your security thing doesn't actually do the thing it's supposed to do" as b
79.
▲
by
Dagger2
6mo ago
If you can't enforce a flag day then that's all you're left with, isn't it? Other than maybe hacking into people's networks, upgrading them and then somehow preventing them from undoing your work.
80.
▲
by
Dagger2
6mo ago
Big parts of it are copied straight from v6's approach, so it's kind of inevitable that at least those parts would be workable -- because they're workable in v6. But of course, you might as well just use v6 at that point.
81.
▲
by
Dagger2
6mo ago
At this point, the people who would be worried about this ought to know that temporary addresses are a thing, and that they prevent workstation N from having a single fixed IP for its outbound connections that it could be identified with.
82.
▲
by
Dagger2
6mo ago
NAT64 is a subset of a different thing that existed since 2000 though, when v6 was ~5 years old and before most OSs even had support for it.
83.
▲
by
Dagger2
6mo ago
Nope, it doesn't. The security model is based on your firewalls and routing, not on NAT. NAT just gets in the way and makes it harder to understand what's going on. For example, on a normal home network, if you don't have a f
84.
▲
by
Dagger2
6mo ago
Honestly, it sounds more like your network is fragile rather than robust. A robust network would be able to handle the IPs changing, rather than needing them permanently set to some specific value.
85.
▲
by
Dagger2
6mo ago
It's the illusion of a firewall too. NAT changes the apparent destination address of a connection, it doesn't filter them. If a connection arrives with the destination address already set to one of your machines, NAT won't pr
86.
▲
by
Dagger2
6mo ago
SEND secures NDP by putting a public key into those 64 bits, and also having big sparse networks renders network scanning rather useless at finding vulnerable hosts, so there are reasons to make subnets /64 other than SLAAC. Also we ca
87.
▲
by
Dagger2
6mo ago
That's because the problems he's describing come from v4 rather than v6, and v4 hasn't changed in a long time.
88.
▲
by
Dagger2
6mo ago
Uh, no it didn't? Routing table size is still something of a problem, especially as v4 continues to fragment more and more, but also the main driver was insufficient IP addresses in v4 and that problem hasn't even slightly gone aw
89.
▲
by
Dagger2
6mo ago
You're at the very beginning, baby steps stage of inventing IPv6 there. You aren't the first person to come up with the idea of adding extra bits to IP addresses to make them longer. The problem isn't finding somewhere to sta
90.
▲
by
Dagger2
6mo ago
Well, other than the transition plans that it has and still has. The exact same plans that the other options like TUBA had. If you ignore those then sure, it didn't have a plan.
More ›