Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In other words, the reason NAT is seen as security is that it provides security (imperfectly, like almost everything else).


No, the reason is that people incorrectly believe it provides security.

It doesn't actually do that.


I know that's an article of faith among networking people but it's not actually true.

It is true. NAT only changes the source address used for outbound connections, it doesn't deny inbound ones.

You don't need to take that on faith either -- you can just test it.


Go ahead, make an inbound connection to my dev laptop. I'll even give you the IP address: it's 192.168.8.21.

Get me onto the network that's on the WAN interface of your router, disable the firewall on it, and I will.

How do you want to go about doing this? Although, 100% of the time people have asked me to do this they chicken out at actually doing it, so I suppose you will too. You might prefer to test with some network namespaces instead.


In such a way that it can partially break connectivity and in a way that fails to have users think about security explicitly, yes. Imperfectly.


Yes when has a security mechanism ever pissed off Unix-on-the-desktop nerds like us before.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: