Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

IPv6



On Mar 31, 2011, at 10:20 PM, Rich Braun wrote:
> 
> IPv4 NAT makes such verification more or less impossible at the upstream ISP
> side. That's one thing I like about the status quo.

This is a myth.  It's quite possible and sometimes trivially easy for an ISP to determine if a customer has multiple devices behind NAT and to count how many are being used.  A simple method is to look at the time stamps on every packet.  Every OS has a known time stamp increment method.  If you watch how the time stamps change then you can identify the operating system.  If you see more than one OS then chances are that the customer has more than one running system behind NAT.  Related, no two system clocks are precisely in sync, not even with NTP.  If you see time stamps shift forward and backward in time then you have identified multiple nodes behind the NAT bridge.  There are other ways; these just happen to be two of the easiest ones.

Remember when I wrote that NAT provides zero security?  It really, really does provide zero security.  None whatsoever.  If you think it does then think again.

--Rich P.







BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org