Slashdot Mirror


User: j+h+woodyatt

j+h+woodyatt's activity in the archive.

Stories
0
Comments
312
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 312

  1. Re:Sigh - what the heck ... on Routers Pose Biggest Security Threat To Home Networks · · Score: 1

    They're wrong.

    Misfeatures of UPnP: A) only for IPv4/NAT gateways; B) proprietary specification; C) defined as profile of SOAP over UDP (so very wide attack surface); D) allows every client to make 3rd-party port maps by default (so very insecure by design).

    Corrections in PCP A) works for IPv4/NAT and IPv6 gateways (NAT and w/o NAT); B) open IETF specification; C) defined as simple binary protocol (so very narrow attack surface); D) disallows 3rd-party port maps unless optional extension implemented (so less insecure by design).

    You need something that does this if you have a firewall (whether there is NAT or not). If you have an IPv6 gateway, then see RFC 6092 section 3.4 Passive Listeners for an explanation. That RFC is referenced by CableLabs and BBF specs, so it is what you should expect to see in most provider-provisioned home gateways in the near future.

    Seriously, PCP is what you need to use for this. Does this suck? Maybe. Depends on whether you think having firewalls everywhere denying all inbound traffic to passive listeners by default is a good idea. If you think that's a good idea, then PCP doesn't suck. Deal with it.

  2. Re:Sigh - what the heck ... on Routers Pose Biggest Security Threat To Home Networks · · Score: 1

    > So how do you propose that my game on a machine on NAT arranges to receive UDP through the firewall? I'm supposed to manually configure firewall rules for each game? And then change them all if my IP changes?

    Ladies and gentlemen, I give you Port Control Protocol [RFC 6887].

  3. Re:Why I buy apple airports on Routers Pose Biggest Security Threat To Home Networks · · Score: 1

    Another feature of the AirPort home gateway product line is that it doesn't have any UPnP support, which is the attack surface that has been proven to be so difficult to secure. It also doesn't have an embedded web server for administration and configuration, using instead a proprietary Apple protocol between the firmware and the AirPort Utility rich client program that runs on OS X, iOS and Windows. The attack surface on the AirPort home gateway is really small compared to other products.

    Too bad Apple will probably never make another one.

  4. Re:IP6 addresses are a pain on Worldwide IPv6 Adoption: Where Do We Stand Today? · · Score: 1

    fc00:/7 are *not* private addresses. They are globally scoped, but non-globally routable.

  5. I Saw What You Did There on Sale of IPv4 Addresses Hindering IPv6 Adoption · · Score: 1

    Headline on the original article: What to Do About the Scarcity of IPv4 Addresses
    Headline on the Slashdot post: Sale of IPv4 Addresses Hindering IPv6 Adoption

    Well-played.

  6. Re:A dangerous situation on Last Bastion For Climate Dissenters Crumbling · · Score: 1

    > First I will not say which "side" I am on as that is unimportant as my total climate knowledge is based on grumbling about weather.

    Yet, that's the very first thing you did: tell us which "side" you are on. Well played.

  7. Re:Obvious on Conservatives' Trust In Science Has Fallen Dramatically Since Mid-1970s · · Score: 1

    Yes, but it's only a very superficial one. Scratch the surface just a bit, and you'll find the same reactionary impulse driving both of them.

  8. Concurrent Multi-path and Multi-streaming on Ask Internet Visionary and Pioneer Vint Cerf · · Score: 1

    TCP port 443 is the new waist of the Internet, and it doesn't look like that's going to change with the transition to IPv6 either. Should we just forget about concurrent multi-path and multi-streaming at the transport layer and do it all at the application layer? Or do you think there might still be room for fixing these problems at the transport layer?

  9. Re:Functional languages and RDBMS? on OCaml For the Masses · · Score: 1

    Ssh. You'll wake the baby.

  10. Sigh on Rob "CmdrTaco" Malda Resigns From Slashdot · · Score: 1

    We are old.

  11. Re:Yes, it's coming on Most Enterprises Plan To Be On IPv6 By 2013 · · Score: 1

    We're talking about an attack that only currently originates from a user population representing less than 0.3% of the Internet user population. If you're under attack over IPv6, then just pull the plug. Seriously, I get that you need to keep your family jewels in a bank vault. You can probably keep the rhinestones under the bed and save on the safe deposit fees.

  12. Re:Yes, it's coming on Most Enterprises Plan To Be On IPv6 By 2013 · · Score: 1

    Turns out for external facing web services, you don't need any of that. You just rack up an IPv6 load-balanced proxy and point it at your existing IPv4 servers. The trick is making sure you don't shoot yourself by implementing a stupid per-source address limit and kill your site over IPv6 because all the IPv4 source addresses are the for the proxy array.

  13. Re:Beside the point on IPv6-only Hosting Won't Make Sense For Years · · Score: 1

    Most of the IPv4 stuff that ISPs are already using today was either never designed for the NAT444 subscriber model, or if it was, then it's badly broken and not as well engineered as the comparatively older and better designed IPv6 stuff. This is especially apparent when you're looking at service providers with more than 16 million subscribers, who need to number subscribers in multiple separate address realms. This is the main problem cited to me by operators who have rejected NAT444 in favor of IPv6 DS/DS-lite.

    For evidence, I don't have much to point out except the fact that every major ISP in the United States and Europe, and many in Asia as well, having looked at the operational considerations associated with the NAT444 and IPv6 DS/DS-lite alternatives, now seems to have concluded that the latter is superior to the former. Admittedly, I have nothing but anecdotes to relay if you want help explaining their observed behavior.

    As for making GoldenShield workalikes, yes Virginia— that's a piece of cake with IPv6. Easier, actually, because you have only a single address realm to manage.

  14. Re:IPv6 Article Mandate on IPv6-only Hosting Won't Make Sense For Years · · Score: 1

    I play comment Bingo with them.

  15. Re:Beside the point on IPv6-only Hosting Won't Make Sense For Years · · Score: 1

    All of those things can be accomplished at lower cost and with higher scalability and manageability with IPv6. There are some reasonable arguments for deploying NAT444 instead of IPv6 DS or DS-lite, but none of them have anything to do with tightening your grip on what your user community is doing with your network.

  16. Re:IPv6 day using IPv4 addresses? on World IPv6 Day On June 8 · · Score: 1

    > and I believe similar functionality is also in Safari.

    Wrong.

  17. Re:Non Networking Guy Question... on IPv6 Traffic Volumes Are Low, But Nobody Knows How Low · · Score: 1

    Um... because we'd all rather write 2001:db8:0:a::101 instead of 32.1.13.184.0.0.0.10.0.0.0.0.0.0.1.1? Especially since, for anyone with much experience in IPv6 at all, we can look at the former and see the special documentation prefix 2001:db8::/32 at a glance, then see that the subnet identifier is "0:a" and the host identifier is "101" and we're good. That dot delimited version doesn't look so good next to that, does it?

  18. Re:Ignorance is bliss and nobody has made me switc on IPv6 Traffic Volumes Are Low, But Nobody Knows How Low · · Score: 1

    You should expect that avoiding IPv6 will mean paying extra in the not too distant future.

  19. Re:Non Networking Guy Question... on IPv6 Traffic Volumes Are Low, But Nobody Knows How Low · · Score: 1

    If your computer only knows how to send packets to 4-octet IP addresses, how does it communicate with other computers that have the new longer addresses you're proposing?

  20. Re:I'm using it on IPv6 Traffic Volumes Are Low, But Nobody Knows How Low · · Score: 1

    > The last thing I want is every device in my home having a globally addressable IP address.

    But you're totally okay with them having globally routed private realm IPv4 addresses. Good to know.

  21. Re:Trouble with Tribble on Apple Discusses iOS Privacy Issues Before Congress · · Score: 1

    Hell, your wireless provider has almost certainly set up a special backdoor for them to get this information about anyone they want without even having to write a letter or speak to a human being. It's a pain in the ass to read and respond to all those letters. It's a pain in the ass to have to write them. Everyone is happier when the cops just log into the LE portal and take whatever data they want.

    Everyone loves cops, and everybody wants to help them fight crime and stuff! You love the cops, don't you? Of course, you do. Now, shut up and go back to whining about the fact your location services cache got backed up in the clear to your personal computer.

  22. Re:Think of the users on Apple: "We must Have Comprehensive Location Data" · · Score: 1

    Which would be relevant if the UDID of the device were being sent to the global database. Gee, I wonder what the letter says about that. I wonder what identifiers competing devices with location services send. I wonder if anybody actually cares about trivial details like that.

  23. Re:Do Mobiles really need IPv4? on Asia Runs Out of IPv4 Addresses · · Score: 1

    Overly clever client-server application programmers using the client private IP address as a unique client identifier, formatting them on the wire with inet_ntop, and the server failing when it can't parse them. Stupidity like that.

  24. Re:Do Mobiles really need IPv4? on Asia Runs Out of IPv4 Addresses · · Score: 1

    You're probably going to be surprised when you find out how many web applications fail comically, when their clients come from IPv6-only hosts through a NAT64+DNS64 gateway, because stupid web coders think clients have to have an IPv4 address to communicate with their server.

    It's a non-trivial number. A lot of them are proprietary enterprise applications. My employers have a raft of them. People are beginning to notice that IPv6 transition isn't something can ignore for much longer.

  25. Re:Prevents Tivoization on Apple Remove Samba From OS X 10.7 Because of GPLv3 · · Score: 1

    There is a code-signing facility in Mac OS X.

    It's optional for 3rd-party applications, but many of the system components make use of it. If people want to run Samba on Mac OS X, there is this thing called MacPorts where you can find its port of Samba, plus lots and lots and lots of other GPLv3 software, and none of it requires an Apple code signature to run.

    That may or may not be what you want. Choose wisely.