-
sagaracharya
Exactly the same issue I see
-
sagaracharya
An IPv6 address space has 1 ip for each grain of sand on earth
-
sagaracharya
In such a case, how can one make sure that in public space, bot attacks won't happen?
-
sagaracharya
If I have a blacklisting kind of logic where I ban IPs, it can grow till my server finds it impossible to manage the list of IPs.
-
jonas’
generally, with IPv6, you ban entire subnets. /64 is commonly assigned to a single "user", customer or tenant.
-
radovan
IP blocking is usually a nice to have, you should still have actual tactful security behind it
-
jonas’
so you'd start with /64, and if you find adjacent networks to also be problematic, you gradually escalate the prefix length
-
jonas’
(keeping the whois information in mind to not go beyond ISP boundaries)
-
sagaracharya
Even with such a subset assigned, how many IPs are we talking about?
-
sagaracharya
Even after banning it, the resultant search set is very high, right?
-
sagaracharya
> so you'd start with /64, and if you find adjacent networks to also be problematic, you gradually escalate the prefix length But wouldn't this even ban unrelated computersm
-
sagaracharya
computers?
-
sagaracharya
So say, my neighbour has [a,b] IPs. I have [b,c] My neighbour engages in bot attacks but I don't. Even I will be banned in that case!
-
jonas’
yes.
-
jonas’
it's not perfect, same can happen with IPv4 with carrier grade NAT though
-
jonas’
that's the issue with IP bans
-
jonas’
IPv6 just makes it more explicit and workaroundable really (you could add exceptions if users complain)✎ -
jonas’
IPv6 just makes it more explicit and workaroundable really (you could add exceptions if users complain, can't add exceptions for individual users behind CGN) ✏
-
sagaracharya
4,29,49,67,296 values are extremely manageable on a program. One can easily ban and prioritize individuals
-
sagaracharya
If one can fix IPv6 addresses, then one can whitelist
-
sagaracharya
My ISP, Jio, keeps a stable IPv6 but if I switch off the router and switch it on again, the address changes
-
Menel
I've daily new ips by default.. That's the thing with ips... It is only a small part of your strategy.
-
sagaracharya
Menel: v6 or v4?
-
Menel
Both
-
Quinn64
Same here, that's why I have my TTL set to 1min and crontab updating the IP every minute
-
TheCoffeMaker
Mine changes only when router is more than a minute offline and it's only v4
-
sagaracharya
1 person was mentioning how they have privacy because they are in an IPv4 network
-
sagaracharya
It is a very interesting argument! Extremely true!
-
radovan
Cgnat doesn't give you privacy
-
MSavoritias (fae,ve)
yeah that sounds misinformed
-
sagaracharya
? Come on, when a bunch of devices use a single IP, one wouldn'y be able to differentiate one packet from another that well!
-
sagaracharya
That's privacy
-
sagaracharya
What are your views on gopher and gemini?
-
sagaracharya
Do you think they're needed?
-
sagaracharya
Above 2 questions are directed to everyone
-
Licaon_Kter
Still offtopic...
-
radovan
sagaracharya, please join this chat if you want to continue these diatribes: xmpp:conversations-offtopic-reloaded@conference.trashserver.net?join