IPv6 xmas display uses 75 Internet's worth of addresses
hackaday.com
hackaday.com
That was probably inevitable.
The last scrolling LED message I read was "Uncaught type error: Undefined is not a function."
Is one of you out there trying to fuzz this poor tree? :)
https://samsclass.info/ipv6/exhaustion.htm
I have two /29 of ipv6 and at current consumption rates they should last until the end of human civilization.
For reference of size, a /32 of ipv6 is what any ISP can get from Arin or ripe just for asking.
EDIT: My bad, I just checked today and there are positive changes - all my connections are now IPv6, mobile and fixed line. The IPv6 speed as opposing IPv4 one is very low though...
Another interesting things I noticed - pretty consistent ipv6 usage spikes on weekends.
Corporate filtered internet is typically v4-egress.
Someone think of something cool to do with that.
As an example things like port knocking can be carelessly translated into IP knocking. Doesn't make it any sneakier though, just less header.
The Right Way would be to make informed decisions per-port and per-protocol, but that's a nightmare to set up, and to maintain.
If you're trying to solve the problems of "How do we stop anyone on the internet sending packets to grandma's open ports?", then the answer is a packet filter. Thankfully, must sane consumer routers come with these.
“Mangling routing” to a single source IP requires state tracking of outbound sessions to know where to send inbound traffic. No outbound traffic, no session, no inbound traffic.
Firewalls are packet filters. Confusing routing and packet filtering doesn't help anybody solve any problems.
We're talking (I think) about how to mitigate threats from the public internet by dropping unwanted traffic with IPv6. The answer is a firewall (as it is with IPv4).
What would be the ipv6 equivalent? You can call it a donkey all you want.
Hardware that happens to be popular are often updated to a cheaper variant where the manufacturer rides on the fame and good reviews of the original version.
So you can't even do the research once and expect it to hold for future purchases/replacements.
usrusr explained it nicely. It will likely take years before anyone will realize that the firewall doesn't work at all. Whereas a similarly broken NAT router will be declared DOA.
Broken NAT:
iptables -t nat -A POSTROUTING -o outside0 -j MASQUERADE
iptables -P FORWARD ACCEPT
Google works fine, but when somebody sends the external interface of my router a packet with destination address 192.168.1.42 (as can often be done from any compromised router on the same cable segment), it gets forwarded to 192.168.1.42 on the internal network.NAT is not a firewall.
True, it will be called a "router" in consumer speak, but all consumer IPv6 routers should actually be firewalls.
NAT isn't doing that filtering, the stateful firewall is.. Every NAT device sold in a very long time has both features..
Some early DSL modems for example had only NAT, and they were horribly insecure.
NAT is not a firewall, and provides near zero security. And, in combination with a stateful firewall, it provides exactly zero additional security.
A NAT router without any kind of firewall functionality is incredibly unsafe too so even the cheapest ones have some of it these days.
Which follows that the cheapest IPv6 routers would also have a firewall and thus would not be inherently worse at protecting the internal network than a v4 router doing NAT would.
Add a stateful firewall with connection tracking, and that port is only open to the 1 server you tried to connect to.
The problem comes when your router receives a packet addressed to one of your local devices. Many people in this thread believe that if the router is NATing outbound connections, it'll drop this inbound packet, but that's not what happens -- the packet will actually be routed to whichever local device it was addressed to, just like any other packet would be.
This should be fairly obvious, because the only thing NAT does is change the apparent source address on outbound connections. It does nothing at all to inbound ones (and you can demonstrate this to yourself by setting up a test network in some VMs and NATing traffic between them with Linux and iptables).
(You can configure a NAT to do things to inbound connections using port forwarding rules and/or a DMZ, but those rules only apply to specific inbound connections. Connections not covered by those rules are treated as normal, and "as normal" for a router means normal routing.)
NAT isn't a firewall, because it doesn't drop connections. All it does is rewrite addresses on connections, not decide which connections can and can't be made.
Absolutely. It's trivial to demonstrate how utterly useless a router configured with NAT, with routing, but without a firewall is. (Useless in the context of a home CPE device for the average home internet subscriber..)
As a side note, yes, packets arriving towards your router with a destination address on your LAN will be forwarded by the router piece of your router.. the firewall piece would prevent this. This is independent of the use of/absence of NAT though..
But it's not trying to drop anything. You can set a default device to throw all incoming connections at.
And with a pure NAT you can't set any rules about what to allow or drop. It only acts like a firewall from one very narrow angle.
NAT on the other hand is not a fundamental requirement for a firewall.
NAT bolts onto a firewall, and it's the firewall that provides the security. Remove NAT, and you haven't lost anything in terms of security.
This is why firewalling is separate from NAT, and why NAT isn't a firewall. Yes, it's true that both NATing and firewalling rely on tracking state, and typically both NAT and firewalling are implemented together in the same software and hardware, but they're two separate behaviors and you can do one without doing the other.
What the GP is trying to tell you is that you're conflating sateful filtering with NAT. If you rip the address translation part out of a NAT implementation, you get a stateful firewall. You're probably better off with a purpose-designed stateful firewall, but ripping the NAT out of NAT works and is an obvious reduction in complexity.
Insisting that you lose packet filtering if you get rid of NAT is a straw man argument. Nobody is arguing for that. They just want to remove the address mangling portion of the cheap router while keeping the packet filtering.
Have a windows PC? Did you try access a network share that exists outside your network? Well, now the SMB port is open. Anyone on the internet can reach it. Hopefully your desktop has a stateful firewall to mitigate the hole in your router....
There's going to be hundreds of other examples.
NAT is nothing more than a lookup table of router IP+Port and internal IP+Port pairs.
(Well, PAT style NAT anyway... But that's what everyone here is talking about...)
Granted, this was a while ago.
At the end of the day, opening ports, any ports, is "dangerous".. A stateful firewall prevents much of the danger introduced by ports opened via NAT.
This isn't really 100% true though. Since IPv4 NAT was never standardized, many many variations exist in the wild and some can be exploited to send unsolicited traffic inside the network defeating the implicit "firewall" aspect of NAT.
NAT translates IPs. Firewalls allow or block traffic based on a policy. In some configurations (static NAT, port forwarding, etc. etc.), there's no firewall aspect to NAT at all. In others (PAT, what this discussion is mostly about), there's often an implicit firewall, but different implementations have widely variable behavior, and it basically should not be depended on as a firewall.
If you want to deny inbound unsolicited traffic, then you need a firewall.
Outbound allow Deny all
In any stateful firewall implementation. The only difference from IPv4 is the ruleset doesn't have the NAT statement.
Some will argue about what the exact firewall rules should be, but we can have that argument after we all agree to replace NAT with sateful firewalls.
I suppose this was meant to say "outbound allow all / (inbound) deny all".
Nitpick: please make sure ICMPv6 is allowed inbound though, else you'll get PMTU issues among other things.
It's also slightly more complicated than "outbound allow, inbound deny" because you want to accept reply packets to the outbound ones, using something like the iptables "-m state --state related,established" match.
On the in chain - allow ICMP, allow established/related, block otherwise. Open up any additional ports as needed, just the same as you used to do with port forwarding before.
All routers, even crappy consumer ones should have a basic stateful firewall on by default. Hopefully with sane default settings.
"IP over ping" is the street name that everyone is going to call it, or IPing for short.
also: TCPing and UDPing will replace TCP/IP and UDP/IP respectively.
IPing packets contain no data at all, but the data byte is encoded in the destination address
It is truly something that got me involved and learning networking to say the least and what a fun way to put it accross.
This one is like 10 times more dank.
They got a /48, and they got some inspiration. You too can get a /48 easily if you want to play! Even if you don't get a /48, you can do some messy play very easily.
My personal experience being messy: when I had to handle multiple containers on one actual computer, I had enough IPv4 addresses (like A.B.C.D) to give one per container, but just a single regular W:X:Y:Z/64 (the suggested minimum default for IPv6, like with SLAAC, while a /56 is often better even for a home network)
The provider wanted some insane amount of money for a decent IPv6 allocation while usually it's the opposite, and IPv4 is expansive but IPv6 is mostly free. I didn't want to use tunnelbroker to keep the latency low.
So I simply assigned W:X:Y:Z:A:B:C:D to each container -- because, why not? Yes it's wasteful, but it's easy to figure out which is which!
IPv6 make many creative things possible and simpler than what the equivalent IPv4 solution would be, simply because of space constraints.
After reading https://blog.donatas.net/blog/2018/12/14/geodns-ipv6-failove..., among my new year resolutions is setting up a CDN using IPv6. It's mostly to play with BGP.
It makes me curious. Did you apply any service-discovery mechanism in your IPv6-based container cluster? I wonder if IPv6 makes orchestration easier, tougher, or actually things just work transparently.
Full story: initially I wanted to do SLAAC with different subnets for the different physical computers.
To do that and use the MAC address of the containers in a "standard" way, I would have needed a larger subnet that what the provider even had for sale - but then everything would indeed have been much easier and automatic.
In case it's not clear, imagine having W:X:Y::/48 like the xmas tree example, then using Z to identify which physical computer the container is on: then A:B:C:D are automatically derived from the hardware address of the (here virtual) interface.
It's also very handy if you have multiple networks - say a wired and wireless setup: use a different value for each network on each site say Z=1 for your wired netword, Z=2 for your wireless, etc.
Then you can automatically populate AAAA records like computername.connection.site.yourdomain.com. Why is it cool? Then if you need to check connectivity or push updates or whatever, you can ping6 ceolaptop.wifi.nycoffice.yourdomain.com- but don't worry, that IPv6 address will not be leaked if you are using the privacy additions (lft=0 aka deprecation): this laptop will use a "throwaway" IPv6 access so it can't be tracked (well, at least the mac address part, but good luck finding the needle in a haystack!)
See https://en.wikipedia.org/wiki/IPv6_address#Stateless_address... : A 64-bit interface identifier is most commonly derived from its 48-bit MAC address. A MAC address 00-0C-29-0C-47-D5 is turned into a 64-bit EUI-64 by inserting FF-FE in the middle: 00-0C-29-FF-FE-0C-47-D5. When this EUI-64 is used to form an IPv6 address it is modified:[1] the meaning of the Universal/Local bit (the 7th most significant bit of the EUI-64, starting from 1) is inverted, so that a 1 now means Universal. To create an IPv6 address with the network prefix 2001:db8:1:2::/64 it yields the address 2001:db8:1:2:020c:29ff:fe0c:47d5 (with the Universal/Local bit, the second-least-significant bit of the underlined quartet, inverted to 1 in this case because the MAC address is universally unique).
(v6 also has a protocol, DHCPv6-PD, to manage prefix delegations automatically, whereas v4 requires manual config or some custom mechanism.)
You could argue that the difference between 2^32 and 2^128 is big enough to be considered a fundamental difference.
(Also: "lets".)
I can think of several approaches (all using a single PC for all the IPv6 addresses), but curious which they chose.
I imagine it works the same way now just with the added x y coordinates.
Edit: n/m, watching the video made more sense. That said, it wasn’t simply “adding the X Y coordinates”, the Christmas tree example didn’t use IPv6 or Ping, but I’m sure the process was likely similar.
tl;dr They use a Microtik firewall which uses an rsyslog forwarder with an Arduino to control the Christmas lights.
(I certainly understand the problems with ipv4, but ipv6 reveals far too much information in it's current state).
Let's say I'm a transit provider [like Google]. Right now, I see TLS traffic from your public IPv4 address to another public IPv4 address. I have no idea how many devices are behind those public IP addresses. I can maybe combine a few assumptions with my browser-based tracking, but it's difficult to identify you in apps I don't have control over.
Switch to IPv6, now I know exactly how many devices behind your firewall are talking and how many devices you're talking to.
Even better, I can combine this with a browser-based tracker and I can see what you're doing in apps I don't control. I first identify you with the browser and what IPv6 address you're using. Then as you use other apps that I can't spy on, I just have to look for your IPv6 address in my transit traffic to figure out what you're doing.
Or... just stop using google and use uBlock Origin to block all Google domains.
Ipv4 did not have this. Many users were allocated IPs temporarily from IP pool
So it was difficult to track inviduals devices as IP would change all time.
What information does IPv6 reveal?
Thinking something is unlimited is the fastest way to find out that it is.
There was an article about this recently on the German news site Heise: https://heise.de/-4196981
Translation: https://translate.google.com/translate?sl=auto&tl=en&js=y&pr...
> If you think this use of addresses seems wasteful, you needn’t worry. There are around 3.4×1038 IPv6 addresses, enough for 10^27 such displays.
So even an intentionally wasteful project has plenty of headroom for quite a while yet!
I'm a fulltime native of the web and yet I don't even know if I have ipv6.
I just typed 'do i have ipv6' into Google and the first page I landed on says "0/10 You appear to be able to browse the IPv4 Internet only.".
I doubt I am missing out on anything. I'm sure I would have noticed.
I also make a living from the web, yet I don't even know if my websites support ipv6.
Let me type 'test website for ipv6' into Google and see what happens ...
...ok here we go:
"No AAAA record. This website is not ready for IPv6."
I get that for all my websites.
Again, I would be very surprised if that has any impact. Somebody would surely have told me that my websites don't work for them. They are constantly in the press and on social media. Some users would surely mention it if they had problems accessing them.
Unfortunately, some ISPs only provide IPv4 support, so (almost) all websites have to support IPv4. And as all websites support IPv4 there is no insentive for ISPs to add IPv6 support. Repeat ad infinitum.
Ipv6 would make that easy for my isp, but they're still never going to do it.
Very excellent tunnel service too. I'm pretty sure it's gone down less than 8 times in that interval.
I bet you already support IPv6, you just need to configure the relevant DNS records. If not, you might want to consider a change of host, as there's no good reasons for them to not support it today, and you're probably better off with someone else then.
You may not need to know about it but it's already started to save your ass without you knowing.