Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Those of us who were supporting Windows machines in the ‘00s remember when 100% of Windows machines not behind NAT were pwned in minutes, while those with NAT were fine indefinitely. Should a firewall have been doing that job? Yes. Were firewalls doing that job, in practice? No, NAT did, and it was very, very effective.

I have… concerns about removing NAT from everyone’s house now that IOT is a thing. Could it be done safely? Yes. Will it? Signs point to no.



Have you looked at what's actually getting deployed? It's mostly no NAT and firewalls, so the signs actually seem to be pointing to "yes".

Even without a firewall, a /64 is an extremely large amount of space. It's nearly impossible to find active hosts by port scanning, compared to v4 where it's trivial to scan the entire address space. We won't end up in the same situation we were in on v4 back when nobody used firewalls, and that's not just because our networks mostly have firewalls these days.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: