Tech CEO sentenced to 5 years in IP address scheme
krebsonsecurity.com
krebsonsecurity.com
Have had to pull one out of the pump at the bottom. Best part is your clothes are trapped inside with a half load of water. Or you can chance it and hope it can drain a bit at a time over a dozen drain attempts with burning it out.
I suspect another small article of clothing led to a clog in the line (apartment building). Nothing like a whole washing machine load of water back flowing onto your floor.
Fancier machines have an access hole to open up the pump. Annoying models have 3 screws flush with the ground that are nearly impossible to remove without an “airbag” door entry tool. A couple $9 ones from aliexpress can lift my machine and the dryer on top.
Edit: maybe there wasn't actually spyware and it just injected extra banner ads in your browsing. I never looked into installing it myself.
A /16 subnet was routed to our fraternity house, licensed to house up to 22 people. 65,536 (minus broadcast, gateway, and network address) IPv4 addresses for 22 people. My roommate bought 1 GB of RAM (about $4k at the time) and a VMWare student license for his Linux desktop. He cut down Win95 to be able to run in 32 MB of RAM (including his COM scripting bot, Internet Explorer, and the AllAdvantage spyware). I seem to remember him configuring the VMs to run 16-bit color to save memory footprint. He scripted the Win95 boot process to read a CSV file off of NFS, remove the top line, and write the file back. The CSV file contained fake name, fake address, etc. The VM would register itself with AllAdvantage, with my roommate as the referrer, and then randomly click on links in Internet Explorer until hitting the payout limit, and then shut down the VM. A Perl script (remember the late 90s?) on the Linux host would re-launch a clean VM every time an old VM shut down, and keep the CSV populated with fake account details.
30 VMs were browsing 24x7 for ALlAdvantage. My roommate set up a caching proxy on his Linux box, so he didn't hose the house's T1 connection. 10% of the payout (the referral fees) over something like 4-5 months paid for the whole desktop. AllAdvantage never got returned cheques from the fake addresses because they never paid out. I think he ran his system for over a year before AllAdvantage went out of business, for a total of something like $12k in profit.
He ran his own DNS server that hopped randomly all over the /16 to reduce the probability of detection. He's pretty convinced AllAdvantage's fraud people noticed him as an extreme outlier. He suspects they ignored him because the data he was generating for them cost 1/11th as much as most of the other data they were selling to customers.
Edit: a quick search shows the AllAdvantage rate was maybe $0.40/hr. 10% of this was $0.04 x 30 VMs = $1.20/hr 24x7. 8766 hours/year works out to about $10,000 per year. $12k in profit, $4k in RAM, and $1k for the rest of the machine works out to a bit under 2 years of running the system, if the rest of my memory is roughly accurate.
A few years later, our school kept the /16 allocated to us, but only routed the first /24 to the house. I'm sure my roommate wasn't the only one to get up to shenanigans with so many IP addresses.
Edit: He also found some online casinos that didn't explicitly forbid bots and he set up some poker bots that would keep track of its winning percentages against all other players. He set up some monitoring/control software for his feature phone (or was it a PDA?) so he could watch his losses from class and shut it down if necessary.
He kept records of every card seen in every game his bots played. I asked on at least 3 occasions for access to that data, to check for (1) naive shuffling (2) using a linear congruential generator instead of cryptographic quality random numbers and (3) seeding with time instead of a true random seed. He told me at least 3 times that he would give me FTP access to card histories, but never did. A couple years later, a paper came out detailing a code review of the most common online poker software finding (1) naive shuffling (2) using a linear congruential generator (3) seeded using only the time the game started and (4) containing an off-by-one error in the naive shuffle. The off-by-one error might have prevented me from figuring it all out from the poker bot histories, but there's some alternate history where we made millions in online poker, fully within the published rules of the sites. (Unfortunately, the millions would have come entirely from other players, the online casinos not bearing any of the costs of the shoddy coding.)
He mused several times that it would be fun to create a cardboard box with one of those see-through windows for a shipping label... and two subtle slits allowing a continuous roll of various shipping addresses and an advancement mechanism to be hidden within the package. He'd use a battery and/or inertial energy harvesting weight to power a device to change the sipping address every 4 hours. He wanted to send such a package with tracking information and watch it ping-pong around the country until someone realized something was fishy with the package.
He eventually dropped out of school and was living off of his poker bots until (without health insurance) his appendix burst and he was forced to get a day job to pay off his medical debt.
I hope he gets elected to Congress someday (though he's not very political) just to make a great epilogue to a biographical film.
On a side note, I thought a naive shuffle with a well-seeded cryptographic-quality pseudorandom number generator was the most likely finding from his poker bot history archive. I thought the linear congruential generator and seeding with the current time were long shots. I was just hoping that the skewed distribution gave a measurable edge over bots and players that were playing under the assumption of a uniform distribution of cards.
Had I thought there was a reasonable probability of a popular poker site using a LCRNG seeded with the current time, I would have been much more persistent in my requests for the history data.
That and netzero. The wild west of the internet.
The only thing missing from your story was Napster
The actual criminal activity (fradulent affidavits, forged signatures) started in 2017.
Then we encountered these spammers were willing to forge BGP LOA stating that they could announce certain, defunct and unused blocks on BGP.
I left there in a hurry, but it seems like they got away with it for a while. It would've been pretty catastrophic if their upstream ISPs decided to cut them off because they were announcing blocks they should not have been.
Today RPKI means that machines can in effect authenticate the LOA, the same way your web server is able to prove it's itchyouch.example (or whatever) to a web browser, the real owners of 203.0.113.0/24 can prove to a machine they're the real deal and you aren't. Unfortunately there are still transit providers who don't do that, or have it set just to bring the discrepancy to the attention of a human.
This is likely true for much of the legacy space in the US, since ARIN requires you sign their registry agreement and actually pay fees to enable RPKI. It's not grandfathered.
How about creating an email address using a pseudonym?
Or does it have to involve money? If someone uses a fake name to order a sex toy delivered (out of embarrassment) is that wire fraud?
My understanding is that using an alias to commit a fraud is an aggravating factor, like it means you went out of your way to deliberately hide your crime. It'd be awfully hard to convince a court that you made an honest mistake if you lied about your identity during the process.
So if you are doing things purely for anonymity it's OK, but if you are registering many email addresses to overcome email service's per account free storage limit, or if you order sex toy delivery for new identity to get a first buyer's discount multiple times, then as I understand that could be a wire fraud.
In this day and age if you're committing fraud it's pretty hard for it not to be wire fraud given how everything is transmitted digitally. And penalties for wire fraud are extremely steep (up 20 years for each charge), and it automatically makes it a federal crime. So just don't...
https://www.youtube.com/watch?v=N5S74kKimFs
Jake (Andy Samberg) and Charles (Joe Lo Truglio) form an unlikely alliance with Jack Danger (Ed Helms), a nerdy lead investigator at the United States Postal Inspection Service, as they embark on a mission to crack the case to bring down a drug dealer.
https://en.m.wikipedia.org/wiki/United_States_Postal_Inspect...
But in all fairness, the distinctions are all pretty arbitrary, I'm sure people were laughing as much when the navy spun off their weather stuff and when the army spun off their flying stuff as they do now with the air force spinning off the space stuff.
It's a psychological thing as far as I have been told. As in, the smaller the "amount" or "area" of power you give someone to enforce / defend the fiercer they will do so.
I saw this live once. A tiny office building's front entrance security guard. Had a sign in/out list for visitors. He was o the stereotypical leaned back in his chair, far away from the heightened desk type guy. Our visitor wanted to sign out. He knew the procedure from other days. The list sat behind the counter but in plain view. Our guest thought nothing of it so as he mentioned he'd leave and just sign out he grabbed the list from behind the counter. You should have seen how fast the security guy got up from his chair and started shouting at the guy what the... he was thinking just grabbing that list! He pulled the list back out of our visitors hands and then we heard a littany of other stuff. Until he finally let him actually sign out
I guess one can make use of this in some cases :)
I've read of someone who worked at a bank who was told that after getting a counterfeit, looked them up in the phone book, and they dealt with it promptly.
[0]: https://about.usps.com/postal-bulletin/2019/pb22524/html/cov...
IANAL but to get 20 years they'd have to commit a massive fraud that ended in some serious damage like costing victims million of dollars with some other mitigating circumstances.
You mean aggravating circumstances.
[1] https://en.wikipedia.org/wiki/United_States_Federal_Sentenci...
The Belgian guy I was in with got raided by the police. His hard disks had been hidden behind a brick wall with only the cables visible. They didn't find the hard disks so he got away with it, and I never got arrested or charged.
Good times.
Anecdotal, second-hand story I remembered being told by a former colleague with some significant time working in the Postal service: state or city police pulled over a contracted semi truck carrying mail from one station to the other on suspicion of running un-taxed cigarette shipments from a reservation manufacturer. Because the semi was contracted by the postal service, they had the requisite security: tags, seals and the magical panic button in the cab of the tractor. The driver pushed the button when the state/city police broke the seal and started rummaging through parcels which summoned the inspectors, guns drawn to the scene. Apparently the Postal Inspectors arrested the -police- at that scene on breaking and entering mail facilities.
Some of the details pertaining to why the shipment was actually legal and the police didn't have cause/jurisdiction yadda yadda yadda I don't remember, but still a good story even if the telling of it by my former colleague was more engaging than I can recount.
As the story goes, one of the scientists there copped a warrant high grade enough for the Federal Marshals to come by and make an arrest. They were stopped at one of the gates into a more secure area, asked their business, and told that security would send out the person in question. The Marshals balked at this and demanded to be let in to make the arrest, lest the fugitive make good an escape somehow. After security asked for their requisite clearance, which the Marshals could not provide, it continued to escalate. Fingering their pistol butts, the Marshals insisted they were on lawful business and must be let in, while the guards with rifles replied that by all means the Marshals might make their entry but as armed intruders into a secure laboratory they would promptly get shot.
The pissing match took long enough that the fugitive was finally marched up to the gate and taken into custody before it could escalate further, at this point I believe the Marshals were on the phone with their higher ups trying to plead their case to be let in.
My coworker went to the local police, who wouldn’t do anything, but then his lawyer advised him to go to the postal inspector (he had mailed the check to the contractor.)
The contractor ended up getting five years in federal prison for mail fraud.
In terms of civil disputes between citizens from different member countries - well, we don't have any phone/internet/post police.
Not only do I have absolutely no idea how to get from here to there, I also assume the degree of simplification I desire — to the point that normal people know what's going on most of the time — is the legal equivalent of saying "Twitter doesn't need 6000 employees because Mark Zuckerberg wrote Facebook by himself in college" in a software engineering context, and wrong for much the same reasons.
And, oh boy, do we have many laws.
It is by design, to oppress the people.
I very much agree. And I live in the US.
77k fine for a net worth of $10-14 million from his businesses, and a 5 years sentence at a minimum security prison (with the likelihood of parole much earlier) is not a bad retirement plan.
Idk where the “postal inspectors are bad ass” meme comes from online, but from my sample size they’re just as useless as any other government org.
For some reason, the internet thinks they are a group of James Bond secret agents. In my experience dealing with them, they are TSA level, totally indifferent schlubby federal workers waiting for their pension to vest.
That to me is the definition of victimless.
I lost imaginary income that never would have actually existed doesn’t make you a victim.
This was your original comment.
The opposite is true here: a person received addresses at low costs reserved for people who don't have any addressing of their own, and then sold the addresses for millions of dollars to companies who already have a lot of addresses and would be ineligible for this.
They pretended to be dozens of new companies to do this. They filed false affidavits where they swore facts that were untrue.
Meanwhile companies actually eligible for ARIN's initial block policy had to wait indefinitely because this scalper had snatched up all the inventory. Were they not harmed?
Fraud basically means lying to someone to steal from them. Wire fraud means doing that using electronic communications.
Of course there can be bogus charges and you should vote to acquit on those, but wire fraud seems squarely in the set of things that should be illegal if we have laws at all.
While counterfeit stuff are sold by sellers in the marketplace that Amazon provides, that is not equivalent to Amazon being the one selling the stuff.
Substance over form.
I'm sorry, but as far as I'm concerned, Amazon is selling the item.
2. There is so much counterfeit stuff on Amazon that they should know about it, and should be held responsible since they do nothing about it. "Should have known" is sufficient for guilt in a court of law, when the thing is blatantly obvious.
The other crime was looking like a douche canoe for his profile pic - https://krebsonsecurity.com/wp-content/uploads/2019/08/amirg...
The lesson here is that if you have something to hide, and it looks like you're going to be dragged into civil court (especially Federal civil court,) you should rush to settle or beg for arbitration behind closed doors.
A few months later, he was indicted for hiding $2 billion of income from the IRS [2]. He died before trial took place anyway..
1- https://amp.smh.com.au/national/australian-barrister-denies-...
2- https://www.justice.gov/opa/pr/ceo-multibillion-dollar-softw...
> In general, the IRS will pay an award of at least 15 percent, but not more than 30 percent of the proceeds collected attributable to the information submitted by the whistleblower.
Looks like it was a successful Trump-like attempt to just delay things forever by filing dozens of motions; First mention of a competency hearing was in January 2020, they assigned experts, delayed the examination a bunch of times, appealed certain aspects of it, eventually in August 2020 the experts found him competent, which he then appealed again, and again and again -- after several more hearings and briefs where his lawyers lied about the expert testimony, it was nearly 15 months later that he was formerly found competent to stand trial in May 2021
Vista Partners evaded billions in taxes for almost two decades, it was investigated and exposed in 2018, IRS/DOJ filed charges in 2020, his partner pleaded guilty in late 2020, Brockman was charged in Jan 2021, found competent in May 2022 and then died in August 2022 a free man.
Sounds like a real scumbag.
Arbitration records aren’t protected from disclosure to law enforcement.
No. If I took you to arbitration and think you acted illegally, I can send the case documents to law enforcement. Most people don't do this, because it's a hassle. But if you pissed me off or were morally offensive, hell yes I'm doing it. After that, yes, they need to execute searches to follow up on the information.
Only if the terms of arbitration allow you to share said documents.
An NDA cannot stop you from reporting criminal conduct. You can be sued by the criminal for doing so, but this is America, you can be sued for anything by anyone. It doesn't mean that they'll win (And will look a hell of a lot like witness intimidation in their criminal trial.)
Makes you wonder if anyone has started an "AI-powered legal database miner as-a-service" for rent to zealous prosecutors.
(and don't make enemies of police either, as they can easily set you up/charge you)
You can lose a whole decade of your life in jail waiting for a trial that never comes.
Source: experience.
The delays were partially due to COVID then later he was able to get it caught up with SCOTUS review of criteria for denaturalization.
But geez his backstory is wild. Iranian born, escaped with parents to Dubai. Started his business in his bedroom at 16. Bought quite a rock for his sweetie back in 2012 (https://youtu.be/FhPiC7zC7wA). She divorced him after everything came undone. Apparently they have a lot of stuff in storage in London. Amazing what you can find in 15 minutes with google.
I did a crazy stunt proposal, but it wasn't douchey like this. And no photos or video were taken.
Golestan created 20 companies under false names. And wrote 1 check from each company. Which means 20 cases of (money) wire fraud.
What’s funny here is the chain of laws used to get to a prosecution. Apparently creating twenty companies under twenty false names was not illegal enough.
There's nothing beyond convention that would stop them from _also_ charging for creating companies under fictious names, for adding a wire fraud count for every e-mail he sent as one of the people, for not including their real address on any marketing e-mails they sent, etc etc.
The huge company that owned it went out of business, so he registered their domain name, and sent in an email to authorize the transfer.
Once you've got a hot class A network on your hands, but don't have 16,777,216 computers to use it, what can you possibly with it? How do you launder it?
It's not as if you can hide it in your garage, file the serial number off, repaint it, and put them all up for sale on the black market or ipBay individually!
Given that there are 24 bits for host identifiers, the total number of possible addresses in a Class A network is: 2^24 = 16,777,216
However, two addresses within that range are reserved: The "all zeros" host address is reserved as the network address, and the "all ones" host address is reserved as the broadcast address for the network. So count those out.
Therefore, the number of usable IP addresses in a Class A network is: 16,777,216 - 2 = 16,777,214
And at today's price of at least $15 a pop, 16,777,214 addresses × $15/address = $251,658,210
He ended up trading it under the table to a company that could use it, in exchange for the promise of free service for life.
If he had taken a defunct entity's /16 (class B), it could probably have been marketed more directly. Although, I'm assuming this was long enough ago that it might have been still quite possible to get a previously unused class B from ARIN.
If you want maximum efficiency, your hosts all have RFC1918 IPs and you route the public IP addresses to them. zero wastage, everything usable.
With today's switches, you could do much crazier things. Definitely not an /8 though.
Even back in the early days of the internet, non-government Class A blocks were few and far between. I doubt there was a form you could fill out and authorize a transfer to a random individual by merely having an e-mail address and a domain name.
Even if you could finagle a transfer by impersonating the company via e-mail, that would be a clear case of fraud and theft from the defunct company's assets. You couldn't actually expect to use or sell the block without anyone noticing.
> He ended up trading it under the table to a company that could use it, in exchange for the promise of free service for life.
If the story is true, what likely happened is that they coordinated the actual sale through proper channels and laughed at your friends' fraud, er, antics, choosing to give him a token gesture instead of actually buying anything from him.
I do know folks who have "defacto" control of legacy blocks belonging to defunct organizations. In fact, if you look hard enough, you can find entire ASNs full of them. Basically, IP squatters.
Is it supposed to present him in such a way (other than just me thinking that's odd)?
Yeah, that can't be it.
Searching his name instantly shows images with a mich more contemporary look, and somelooking 15+ years older than that of the article's image.
Furthermore the pic in the article lists his title as "Executive Director" and makes reference to his launch of a company in 2005.
I'm working on my second million $...
...I gave up on my first.
https://en.wikipedia.org/wiki/Network_Control_Protocol_(ARPA...
There's something to be said about a human readable IP address. Where you can't tell a person the address, you have to copy and paste. where you cant infer any information about the IP address just by looking at it. It adds unnecessary overhead to small packets, etc.
Are you forgetting that NAT exists? IPv4 is barely functional based on how many workarounds we've had to implement over the years
Honestly, all they had to do was add alpha characters. Just doing so would have gave us more IP addresses than we ever needed while keeping it human readable.
"Just adding characters" isn't a solution on its own. IPv4 is 32-bit addresses, IPv6 is 128-bit addresses. That's all there is to that.
Where do you propose they put these alpha characters?
It kind of is, yes.
But at this point I'll take what I can get. Just give it to me already.
https://en.wikipedia.org/wiki/Observable_universe estimates 10^53 kg in the observable universe.
10^53 kg / 2^128 = 10^14 kg per address, though I have no idea what fraction of the universe is sand.
In practice, the number of allocations is much smaller because IPv6 is effectively a 64 bit address space, with the second half reserved for edge networks.
> There's something to be said about a human readable IP address.
Is 2a01:4f8:1c1c:f6aa::1 really so unreadable, given that every device needs a different number?
I think just saving the endless discussions of "my Xbox only got nat type 2, how do I change it?" alone saves more lifetimes than are lost by c&p adresses (not to speak of the large infrastructure costs of maintaining gcnat at scale).
Conveniently, 2^13 = 8192 allows you to use most of the information available in four decimal digits. And 64 = 13•5 - 1 means that you get a roughly even division into five address tiers (with either the first or last one half the size). 4095.8191.8191.8191.8191 is a bit worse than 255.255.255.255 but not nearly as bad as ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff.
I don't type in many IPv6 addresses anymore, so this doesn't see much use anymore. It does make a great desk nicknack, though!
Should have just walked outside and asked some homeless people to be nominees
And plus he changed to a guilty plea and didn’t wait for the trial
That bolsters my opinion that a small clerical change would have nullified prosecutor’s zeal on the criminal side
Most of this kind of clerical stuff is simply making the exact same action legal by paying attention to the clerical structure
They pushed him into a plea deal though. They were likely to mash all the charges consecutively and he'd be looking at 100 years like Ross Ulbricht if he lost at trial. I know people who have played that game and lost.
What is the deal with the notarized affidavits, though? Each of those is a federal offense which carries 5 years on its own, IIRC.
So the sentence is for the "Scheme", not the "IP Address".
This is pretty unclear if you have only read the title.
Edit: There's also numerous cases ongoing for fraud relating to loans / purchases under these companies. One of the things he did was buy dormant LLCs around the US so they'd have logenvity making it easier to secure loans.
Source: Worked with a National Paper on the story back when it started.
What makes ARIN so special? I am going to bet for other RIRs this is pretty normal. AFRINIC IPv4 has a hassle to transfer, and ARIN and RIPE IPs is the target. That leaves APNIC and LACNIC.
I believe, APNIC allocated MASSIVE IP ranges to government research agencies and government educational institution which are slowly being traded and re-registered under ARIN and RIPE.
I bet you could get a really good price on them
> Prosecutors showed that each of those shell companies involved the production of notarized affidavits in the names of people who didn’t exist.
We need to think about the bigger picture and how this fits into rehabilitation.
We should definitely punish the fraud. But also look at rehabilitation.
In this case, we are taking someone that could under the right circumstance be a net positive for society and putting him in jail for 5 years where he will most probably come out as a destroyed human.
I will never understand how people desire for revenge negate the bigger picture.
It is more that people tend to be extremely selective about when they see that bigger picture.
There are lots of smart people rotting in prison who committed very similar crimes who never seem to elicit sympathy. Coincidentally, they tended not to be white collar strivers before being busted.
This is more evidence of the flaws of the (US, anyway) penal system that an argument against custodial sentences in general, no?
I get where you are coming from, but do you have practical alternatives? A slap on the wrist is probably overall a worse (global) outcome...
When you've created 20 shell companies, I think at this point you've gone beyond "messing up". Just like there's a difference between a crime-of-passion single murder and a serial killer.
Rehabilitation is another issue entirely. I really wish we had a system in place to make that happen, but we don't. Putting him away isn't about revenge at all, at least not to me.
Not punishing this is the same as allowing it.
It's not a stretch to believe that its better for society to keep people like this (a combination of high intelligence and low morals) in a place where they can't continue to perpetrate clever schemes.
Then the jail time is calculated based on the value of what was taken as a result of the fraud.
5 years seems fairly reasonable for a multi-million dollar scheme, involving multiple employees, explicitly designed to defraud.
The second link [2] is about the US.
[1] https://i.stuff.co.nz/national/crime/300878382/newsable-bill...
[1] https://www.ussc.gov/guidelines/2021-guidelines-manual/annot...
[2] https://www.ussc.gov/guidelines/2021-guidelines-manual/annot...
[3] https://www.ussc.gov/guidelines/2021-guidelines-manual/annot...
So execs need to consider that serious prison time is a possibility, or there will be no constraints on bad behavior.
>> "production of notarized affidavits in the names of people who didn’t exist"
> 5 years in jail seems a bit of an overreaction.
Multiple counts of fraud that would have netted $10M and did net a percentage of that? Breaking the notarization process? By a CEO of a tech company?
5 years seems about right, maybe even too lenient.
Also, it is 3 years in jail followed by 2 years of supervised release.
They should indeed make an example out of him.
They must limit IP address purchased on a per org / person basis?
$15-$25? when was that? Currently it's $40-$55 on ipv4.global.
He had to commit fraud, otherwise the business wouldn't work!
But on the flip side, we all know it is a bad idea to judge a book by its cover. How many times can we all recall doing this and feeling bad when our snap judgement was incorrect?
But look at the guy! What is it we are all picking up on in these comments. I am not the only one. Is there something about how he is positioning himself that warrants this? Or do we need to be more aware of our own biases?
Normal people don't dress or look like that. It's a choice, and he's using it to communicate and signal non-verbally who he is and what he values.
His clothing, accessory, and hair style choices make him appear like he's about to sell me a used car, or muscle me out of my own company.
The pose, the unbuttoned shirt, the hair, those are all conscious choices to communicate a sleazeball personality that probably plays great with his friend/colleague network.
If we were judging someone from a cultural context that's unfamiliar to us or based on irrelevant characteristics like race or gender that would be incorrect and likely biased. But in this case we're just clearly receiving the message he's trying to communicate with intentionality
This fellow decided to present himself as something like a cross between a pickup artist and a street magician, which seems like it was pretty on the money.
The rest is very much "oh, this person is now known as a criminal, let me find the most sinister looking photo of them possible."
It seems like the only argument for sticking with IPv4 is NAT, but I can't think of a technical reason we couldn't do NAT with IPv6?
Yeah, NAT acts as a defacto firewall, but you can just... use a real firewall.
You're right and that's what I love about NAT, IPv6 in contrast is a hacker/spy tracking digital superhighway right through my front door and straight into my devices.
Wrong. Try what I said. It was recent enough the results are reproducible.
> An ad company can no more track my individual computer inside my house than it could your computer inside yours.
Yes, they can and my testing showed me, they do:
https://johannaullrich.eu/assets/papers/ullrich2015_raid.pdf
Nope. What really happened is that an ad company might have started collecting information about your IPv6 prefix, precisely like they might store information about your IPv4 address. That's all the information they can reconstruct about the hosts inside your LAN.
The paper you linked showed that if a host uses the method for generating pseudorandom addresses described in RFC 4941 instead of using completely random one, and if the attacker has a complete history of your generated pseudorandom addresses, and if the attacker has successfully defeated MD5 on a practical time scale, then it's possible that they could guess your future pseudorandom address.
In practice, most OSes generate truly random addresses, and an advertiser doesn't have your complete history of generated addresses, and the advertiser wouldn't spend all those resources to track you specifically anyway. In other words, that 8 year old paper isn't relevant to the situation today.
I'm fairly confident that nobody is ever going to scan a single /64 of IPv6 addresses within our lifetimes.
In comparison, scanning the ENTIRE IPv4 internet on a single port can be done by anybody at all and it's going to take about 40 minutes.
Do the proponents of IPv6 also advocate for large ranges of IP rotations to deal with this?
Why? Keeps P2P like BitTorrent, soulseek, gnutella, and newer protocols crippled. And content creators don't want people consuming content other than through themselves.
And a NAT can also differentiate between "consumer household" and "business" - do you get a real IP or not?
It's also why companies like Comcast zero-rate their own content.
EDIT: for you -1'ers ; you DO realize that most mega-ISP-content companies want the push-style of the television back, right? And these companies will institute NAT, data caps, and "3 strikes" to boot people off.
(You can hack around this with keepalives, but it's just another PITA because of the original sin of breaking the end to end principle.)
Even if we were setting up a VPC from scratch, it would probably be ipv4 since it's what everyone knows how to easily do. There's a learning curve with deploying a ipv6 network and very little benefit when it's all behind a ipv6-enabled CDN.
Correct, NAT works fine with IPv6, there just aren't many reasons to use it.
One of the main uses for IPv4 NAT is extending a network without the operator's permission. On IPv6 that can usually be accomplished with ND Proxy.
Why would you want to use NAT with IPv6 though?
I imagine it being far simpler for the average person to adopt IPv6 without much research if all of their current firewall rules, including port forwards, work exactly the same as they did with IPv4. You may not need those port forwards without NATs, but do you trust the firewalls on your servers to disallow accessing other ports from outside your local network?
The only regime that is still "IPv4-by-default" is public facing servers, which (obviously) still need to present the old addresses for compatibility.
But that last 5% will still be around until we all die. There are just too many client devices out there that will never get an IPv6 update, and client devices tend to live much, much longer than you (or their designers!) think they should.
There's also a fair number of still popular libraries and frameworks that don't handle IPv6 well. Maybe not in their latest release, but in their more popular older ones.
We absolutely can do NAT with IPv6, but there's no reason why anyone should (aside from stateless NAT66 in case you get a dynamic prefix that changes every now and then, but that's about the only use case)
Besides, NAT gives ISPs insight into their users (number of devices, services running on devices, how much traffic each service uses, etc). So you can probably do regional pricing based on that and some other things.
I had a really weird problem where Youtube videos were unwatchably laggy on my home desktop PC. Gigabit hard-wired connection. Every other streaming site worked great, ditto every other device I owned. Even downloading the videos on the same device using yt-dlp worked great. After much tearing of hair, I noticed that in the network tab for attempting to watch Youtube, all of the requests for video data that were laggy were going to IPv6 addresses. So I turned off IPv6 at my network adapter and everything worked great after that. I guess Youtube and that PC and browser were the only things that supported v6, every other site, device, and Python dropped to v4 and worked fine.
I guess I could dig deeper into what really went wrong and try to fix it, but I feel like I've already spent enough time and headaches on it. The off switch is just easier.
Recently, I've created an interactive map of all IPv4 addresses, PTAL: https://reversedns.space/