[135041] in North American Network Operators' Group
Re: Is NAT can provide some kind of protection?
daemon@ATHENA.MIT.EDU (Marshall Eubanks)
Sat Jan 15 09:32:05 2011
From: Marshall Eubanks <tme@americafree.tv>
In-Reply-To: <4D31ACE5.2090205@consolejunkie.net>
Date: Sat, 15 Jan 2011 09:31:17 -0500
To: Leen Besselink <leen@consolejunkie.net>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Jan 15, 2011, at 9:19 AM, Leen Besselink wrote:
> On 01/15/2011 03:01 PM, Joel Jaeggli wrote:
>> On 1/15/11 1:24 PM, Leen Besselink wrote:
>>=20
>>> I'm a full supported for getting rid of NAT when deploying IPv6, but
>>> have to say the alternative is not all that great either.
>>>=20
>>> Because what do people want, they want privacy, so they use the
>>> IPv6 privacy extensions. Which are enabled by default on Windows
>>> when IPv6 is used on XP, Vista and 7.
>> There aren't enough hosts on most subnets that privacy extensions
>> actually buy you that much. sort of like have a bunch of hosts behind =
a
>> single ip, a bunch of hosts behind a single /64 aren't really insured
>> much in the way of privacy, facebook is going to know that it's you.
>>=20
>=20
> Now this gets a bit a offtopic, but:
>=20
> If you already have a Facebook account, any site you visit which has
> "Facebook Connect" on it usually points directly at facebook.com for
> downloading the 'Facebook connect' image so the Facebook-cookies have
> already been sent to Facebook.
That assumes that you use the same browser for Facebook as for other =
uses. I recommend not
doing that, but to dedicate a browser for Facebook only, precisely =
because=20
Facebook plays these sorts of games and is such a security hole.=20
Regards
Marshall=20
>=20
> Why would Facebook care about your IP-address ?
>=20
>>> And now you have no idea who had that IPv6-address at some point
>>> in time. The solution to that problem is ? I guess the only solution =
is to
>>> have the IPv6 equivalant of arpwatch to log the MAC-addresses/IPv6-
>>> address combinations ?
>>>=20
>>> Or is their an other solution I'm missing.
>>>=20
>>>=20
>=20
>=20
>=20