Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Since most IPv6 routers I have seen have default firewall rules similar to NAT (allow outgoing, and incoming only if part of a valid session), STUN servers would probably still be required, wouldn't they?


Not to my knowledge. With IPv6 you know each other's public address, and can thus "hole punch" directly. The problem with NAT is you don't even know the IP address you're attempting to establish a connection to.


You are right, I forgot about this. Though, as always, you need to obtain your peer's IP trough a side channel (also the case without firewall), if your firewall isn't too picky about answering to blocked requests, and doesn't meddle with source ports, punching a hole should be quite straightforward (one side just has to co-ordinate with the other to pretend the firewall didn't block the first incoming packet, right?).


Yeah; and this is why IPv6 is a bit evil and CGNAT+PMP (not that any clients are smart enough to do PMP correctly, which is stupid; and sadly not enough Internet is behind true CGNAT) is epic: you lose nothing (due to the explicit port mapping control) and get what amounts to free anonymity (unlike IPv6, which tattoos an identifier on you as if that's a feature).


Well, what you say is true to some extent, but there are some privacy extensions... And I don't think you should rely on having an obfuscated/shared IP for anonymity. There are better tools for this, like Tor, I2P, Freenet, etc.

IPv6 was designed back in the 90s, where we had much less concerns about tracking, privacy and anonymity. But IPv4 is even more ancient, and, make no mistake, CGNAT is not designed to make you more anonymous, so you could be fooled by a false sense of security.

Maybe we need to sell IPv6 as a way to track users to boost its adoption? And develop those privacy-conscious networks on top of it? Regardless, IPv4 and NAT are not consumer-friendly when it comes to self-hosting and p2p, so as long as these are the norm, software silos will be at an advantage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: