Hacker Newsnew | past | comments | ask | show | jobs | submit | xl-brain's commentslogin

It appears to be trained on Eric Weinstein quotes.


The tension here is the difference between theory and reality. In reality, IPv4 NAT is the only thing protecting most users in their homes. If you force IPv6 on this same population, you have to give them an equivalent posture by default.

This is kind of like writing an argument that motorcycles are not unsafe because they lack 4 wheels. This is true, but if you put my grandmother on one and ask her to drive across town, she would not survive it.


No, the reality is that every modern network device running NAT for a user device network is also already a fully stateful firewall, because the software required to do one is virtually identical to the other.

You can't buy a home router with NAT and no firewall, and no home routers ship that don't also have a default deny rule on that firewall. The same is true for SOHO routers and effectively every consumer network gateway device you might buy.

You literally have to go well out of your way to find a network device capable of NAT that can't function as a stateful firewall, and when you find it, it's likely to be carrier-grade. In other words, not intended to be capable of any security at all. The amount of NAT processing it's intended to handle will challenge the hardware enough as it is.


Nope, I agree with the findings here:

https://arxiv.org/abs/2509.04792?


NAT isn't protecting them. Not being on the public internet at all is protecting them.

NAT is then unprotecting them a little by letting them punch out again. It's super easy for routers to implement this behaviour by default if your LAN is publicly addressable, and removes a whole class of exploits caused by applications making NAT hacks.


This is splitting hairs. The point stands that PAT is the de facto firewall for most soho users.


Not in the context of claiming NAT offers protection.

An ipv6 lan with default ingress deny is more secure than ipv4+nat


I think you missing my point. My point is not that IPv6 cannot be secured, it is that the author's take is controversial because people are skeptical about whether networks ARE being secured when NAT is not present. This skepticism is backed up by the research paper that I quoted and real world experience. IPv6 is deployed in many places incorrectly and without the good defaults. IPv4 NAPT in residential networks acts as a last line of defense because most users have been incapable of turning it off.

I suppose I will distill my thought into the assertion that the author should have prefixed his title with "In capable hands,"...


The point is that NAT offers no security, so it doesn't make sense to be skeptical about the security of a network just because it doesn't have NAT.

The only way to be confident is to have a firewall, and you can do that on v6 just as well as you already do on v4.


France with >85% IPv6 adoption mostly made of grandmothers driving a motorcycles across the town manually delivering packets like in their youth.


https://arxiv.org/abs/2509.04792?

"Collectively, our results show that NAT has indeed acted as the de facto firewall of the Internet, and the v4-to-v6 transition of residential networks is opening up new devices to attack."


ISP hosting a virtual machine you remote desktop into from internal network as the only way to access the external internet can also work as a "de facto firewall".

But the best de facto firewall is a proper firewall.


I don't disagree with your comment that the best de facto firewall is a proper firewall. I think you are reacting against the idea that I am saying IPv6 is less secure than IPv4. I am not saying that.

The point of my original post is that the author's take is controversial because people are skeptical about whether networks ARE being secured when NAPT is not present.

They are right to be skeptical, in my opinion, because the rollout of IPv6 has been bungled over and over again. That is not a problem with IPv6, its a problem with the adoption of IPv6.


This is entirely untrue. Every shitty router shipped by ISPs this side of the doctom bubble has a stateful firewall enabled by default. NAT is distinctly not the only thing protecting most home users. Not to mention every OS I know of shipping with its own firewall enabled with default deny on inbound.


You are stuck on the theory of what is protecting this population. In practice, less than 1% of these users can or will turn NAT off.

Can you imagine how great things would work out with a public IP on all your nana's computers, NAT turned off, protected by the prowess of her Arris gateway's stateful firewall?


Telstra, one of Australia's massive telcos who are the "go to" telco for nannas who don't know anything about this internet thingy, have IPv6 enabled by default on their CPE routers. Without NAT. With a stateful firewall. Works perfectly fine for their millions of customers.


It would work out just fine, because NAT was never providing any actual security to your nana. It was only ever the firewall which made her secure, not NAT.


With NAT turned on nana's computer is still protected by the same Arris gateway.


That's not the case at all. You could disable their NAT and they wouldn't lose any protection whatsoever.


Yes, it is the case. In the real world, there are malfunctioning ALGs, permissive defaults, and connectionless protocols that are poorly tracked by these sloppy, underpowered "SPI" devices.


It's not, because in the real world NAT only affects your outbound connections. That means that turning it off only changes the behavior of outbound connections, not inbound ones.

Any inbound connection that would have worked before you turned it off will still work afterwards, and any that wouldn't have worked before will still not work afterwards.


Think about what 99% of SOHO users have: PAT (Nat Overload). This NAT impacts the way a connection is established in BOTH directions. Inbound connection attempts from the Internet to the NAT public IP address of the SOHO router can go no further than the router. We are talking what 99% of users have installed.

Maybe this is the reason for some of the disagreement. I am focusing on what is installed at 99% of user installations (PAT). I would agree with the comments that a 1-to-1 NAT offers no EXTRA security.


That's the type of NAT I've been talking about the entire time. It doesn't do anything to inbound connections unless you explicitly tell it to.

Connections to the router's IP address go to the router, but you need to consider what happens to connections that go to IP addresses on the network behind the router too.


The micro center in my neighborhood has hundreds of 5090s in stock. I'm not sure its as hard as it used to be.


As well as any human beings could, they knew what lay behind the cold, clicking, flashing face -- miles and miles of face -- of that giant computer. They had at least a vague notion of the general plan of relays and circuits that had long since grown past the point where any single human could possibly have a firm grasp of the whole.

--The last question by Isaac Asimov


I wish they called it llamarama...


I would bet at least one person at Meta wanted to call it Llamapalooza.

In any case, I'm excited!



That way attendees could be called Llamarama Dingdongs.


I think the claim in the title is a little overstated. Every few months, there is a claim that it has been solved, only to conclude that more work needs to be done. The remember the last time it was solved:

https://www.the-tls.co.uk/articles/public/voynich-manuscript...


So, I guess they are saying you can brick a Tesla roadster.

Just to add to the PR observations, I like how they have a few positive comments, but it is actually impossible to make comments on the post.


This notion that the URL bar is too complicated is just plain poppycock.

I have a feeling most of the folk pushing for this have a vested interest in search. Maybe they are just overly eager UX people trying desperately to put a fingerprint on something.


This honestly feels like another case of Gnome 3, where a group of inexperienced "UX" people want to make a big splash and change things and take away features as part of their "grand vision". If you disagree, you are wrong. If you have alternate suggestions, you will be ignored.

I think it fundamentally arises from the perception they are developing the interface for some kind of idealized idiot/user that doesnt exist. As is usual, software written for "other people" misses the point and just generally sucks.


See also: Chrome removing the "Go" button.


> trying desperately to put a fingerprint on something

[touches tip of index finger to his nose]


I couldn't tell who was interviewing who.


Yeah weird way of conducting an interview, though follow the link for his name and it says "CEO & Co-founder of SiteAdvisor (acquired by McAfee)".


Apparently it was an "outtake." This also confused me.


I only hope there's a small chance that shareholders can reject the acquisition.


I don't know the schedule, but Intel will likely be rather committed by the next shareholder's meeting. And this is not entirely and clearly insane enough to e.g. muster the failed effort to keep HP HP a while ago.

Robin Harris is a great analyst with a sense of history and he shows all that in this column. I sure looks like it'd just going to be a repeat of those two last failures, especially since there's not (much of) a hardware component (as far as we know) in this cunning plan.

I suppose it's good for Intel that they're swimming in so much cash the don't need this to make or modify another fab line or three, but still....


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: