top | item 41920935

(no title)

apearson | 1 year ago

You’re going to have to explain that one.

I don’t see how CGNAT does anything but allow easier access to attacks (using private ip space outside of the local network)

discuss

order

coretx|1 year ago

All the details can be found in the EUROPOL publications begging for it to be banned.

zamadatix|1 year ago

IIRC there was some hullabaloo made with RIPE in ~2017. Half of it was "go to IPv6 and it isn't a problem" and the other half was "or also log the source ports so we can complete the identification through CG-NAT".

It's nearly 8 years later, we haven't moved to IPv6, and they stopped making noise so I'm left to assume they either got more source port logging or found some other method?

apearson|1 year ago

Ah, allows hiding behind a massively shared single address with less traceability.