Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
151.
▲
by
Dagger2
7mo ago
We already did it decades ago, with 6to4. The extra address space is under 2002:<v4 address>::/48.
152.
▲
by
Dagger2
7mo ago
But like the similar proposals, it fails to avoid a dual-stack scenario. Note that going from v4 to v6 also doesn't mean changing all your routes and addresses; you just enable it and everything still works. Network components can get
153.
▲
by
Dagger2
7mo ago
It might get hidden by disabling v6, but not fixed. And if your DNS server fails to reply to an AAAA lookup over v4, that's 100% not a v6 problem.
154.
▲
by
Dagger2
7mo ago
If you disable the NIC, the problem goes away 100% of the time. Don't blame v6 for problems with your network.
155.
▲
by
Dagger2
7mo ago
v4 doesn't even manage one IP per person. It's fundamentally completely insufficient in a world with personal computing devices. Even if you declared every single IP in v4 to be wasted and demanded we repurposed them all, it would
156.
▲
by
Dagger2
7mo ago
Sure there is: use single-stack v6 with NAT64. What you're describing there is just an approach to store NAT state inside every packet instead of on the router. I'm not sure that's even an improvement on v4, but in any case i
157.
▲
by
Dagger2
7mo ago
Two 6to4 networks will communicate directly between each other without using a relay, so it will still work for that. Although you ought to be able to use native v6 these days. If you can't deploy v6 (whether native or 6to4) on the rem
158.
▲
by
Dagger2
7mo ago
If your DNS server isn't replying to requests, your DNS server is broken. That has nothing to do with v6.
159.
▲
by
Dagger2
7mo ago
Plenty of people are switching v4 off. Facebook run basically all of their datacenters without v4. T-Mobile USA use only v6 on their network. Thread only supports v6 in the first place There are plenty of other places doing the same thing,
160.
▲
by
Dagger2
7mo ago
You will certainly need to update applications, because they won't be able to connect to v6 addresses otherwise. 464xlat only helps you connect to v4 addresses. It just means that updating _all_ of your applications is no longer a prer
161.
▲
by
Dagger2
7mo ago
It does exist though. The OS part is 464xlat and the router part is NAT64. You can try the second part out by setting your DNS server to one of the ones listed on https://nat64.net/ , which will work with hostnames. To get I
162.
▲
by
Dagger2
7mo ago
They *are* making progress on it: https://aws.amazon.com/new/?ams%23article-feed%23pattern-dat... They seem to have been averaging about two services per week for the past year. But they have a lot of services...
163.
▲
by
Dagger2
8mo ago
There's also the question of whether we should be tracking percentage or number of users -- there's about 3 billion v6 users at the moment based on Google's stats, but 12 years ago there were only 3 billion Internet users in
164.
▲
by
Dagger2
8mo ago
Except not really. You can't assign v6 addresses to people, because IPs are picked ephemerally by devices based on the IP range of the network they're attached to. You need a separate protocol (like HIP or LISP) on top to map the
165.
▲
by
Dagger2
8mo ago
It's possible to do NAT without firewalling in netfilter. I gave the rules for it in this comment: https://news.ycombinator.com/item?id=46709150 -- you literally only need the first one for NAT. Inserting it will make
166.
▲
by
Dagger2
8mo ago
You can't get a packet from a random store wifi network to your home network when your home network is using 192.168.* (barring something like routing headers, which most routers wouldn't process). You said that yourself in the fi
167.
▲
by
Dagger2
8mo ago
No, it might belong to the router. If it does then the connection goes to the router, but if it's set to a LAN machine's IP then the packet gets routed to the LAN machine. You aren't in control of the contents of inbound pa
168.
▲
by
Dagger2
8mo ago
There's no inherent ACL in NAT, and adding one would just demonstrate that ACLs can block packets, which we already knew. > What you’re describing would happen if NAT were completely disabled. You’re just describing an open router Y
169.
▲
by
Dagger2
8mo ago
Source address selection is usually left to the kernel, so that part should be okay. It'll pick a GUA source for a GUA destination unless you've changed the labels with `ip addrlabel`.
170.
▲
by
Dagger2
8mo ago
I could do it if it was using a routable v4 address too, and I can do it with either RFC1918 or ULA as well (which are both routable, just not over the Internet) if I can get close enough to send the relevant packets. NAT provides no protec
171.
▲
by
Dagger2
8mo ago
Neither of them prevent inbound connections, on their own or together. I don't really think that "inbound connections work fine and you're basically just praying that the people that can do them simply won't" counts
172.
▲
by
Dagger2
9mo ago
They connect to whatever IP is specified in the packet's "destination IP" header field. It's exactly the same behavior as if there was no NAT going on.
173.
▲
by
Dagger2
9mo ago
The same problem applies to masquerading. Routers are happy to route packets they receive, and NAT (in whatever form) isn't the tool you use to drop those packets.
174.
▲
by
Dagger2
9mo ago
Well no, it's purely a property of the fact that the packet is addressed to the router. If the packet is addressed to a machine on the LAN, neither RPF or NAT will protect you from it. "The Internet won't route to private IPs
175.
▲
by
Dagger2
9mo ago
And in this common configuration, NAT does nothing to prevent inbound connections.
176.
▲
by
Dagger2
9mo ago
The point is that NAT offers no security, so it doesn't make sense to be skeptical about the security of a network just because it doesn't have NAT. The only way to be confident is to have a firewall, and you can do that on v6 jus
177.
▲
by
Dagger2
9mo ago
We haven't forgotten that, but we're also aware that non-IT people can't run NAT either. They can plug in a box that already has NAT configured though, and if they can manage that then they can also plug in a box that already
178.
▲
by
Dagger2
9mo ago
You could turn NAT off completely and still no-one on the Internet could reach your 192.168.0.7. There's no security perimeter coming from NAT here. > And the NAT router won't send a packet that arrives with its public IP as ds
179.
▲
by
Dagger2
9mo ago
I'm not. You literally can do this, provided there's no firewall. All you need to do is send the router a packet that's already addressed to a LAN machine, and in it goes. "NAT won't translate the packet" doesn
180.
▲
by
Dagger2
9mo ago
RPF wouldn't help, because the reverse route for 192.168.80.26 is going to be the LAN interface, not the WAN interface. You need a firewall.
More ›