There are some problems with IPv6, but these are not it. All ISP customer routers I've seen blocks inbound IPv6 by default when IPv6 is enabled. Most devices these days randomize their interface identifier part of the address either periodically or hashing the prefix + some local secret + eui (or some other stable identifier). This way the MAC/EUI/"serial" is not encoded into the address, and also does not stay the same when moving to other networks. The way IPv6 SLAAC *used to* address using the MAC/EUI was madness. That design was from before the internet became a privacy nightmare and has fallen out of favor (well more or less.) Neighbor Discovery is similar to ARP in IPv4 and has many of the same security problems. It is also just local to your network segment so doesnt really matter in the grand scheme of things. If you absolutely must secure it, the mechanisms to do so is very similar in IPv4 and IPv6 - quite complicated for both - and not suitable for a home-type environment. The localization of prefixes is total, and utter ???. That is not how the space is allocated at all. I cant even. However: there will still be geoip databases - like with IPv4 - and chunks of addresses tends to be used in one area - like with IPv4. fe80:: addresses are local to your LAN (a single network segment - it's in the name - link-local), not internal to ISP. Although they do often control your router and could theoretically reach them - just like your internal addresses with IPv4. I probably forgot several things, but I'm not watching this one more time. One actual IPv6 privacy issue is: when a VPN provider does not support IPv6 properly, or at least account for it, it will leak left and right if IPv6 is available on the network. VPN providers needs to to better.
@WyzerDev4 жыл бұрын
NAT require RAM and CPU on Modem/Router, IPv6 is more efficient, may by 40% less lantency, don't recalculate CRC on each jump/router as IPv4. IPv6 Allow direct comunication for IoT ... or VoIP calls, without a server recording our call ;-). Many ISP today need use CGNAT (Carrier Grade NAT) for IPv4, it's NAT over NAT, then one public IP is Shared by 8, 16, or to many client, and all devices on his homes, this not allow open ports or a VPN Server. IPv6 have too many address ... a hacker need to many years to found your IPv6 address ... avoid use "::1", "::2" ... on static address for that. EUI-64 may be obsolete on near future, and replaced by a new formula to use the same address for a prefix. For a different prefix will assign another persistent address.
@robbraxmantech4 жыл бұрын
The other problem is that the IPV6 Prefix is even more specific with location identification in a more precise way than IPV4. Maybe great for networking infrastructure but very bad for privacy
@Ultrajamz4 жыл бұрын
Luis de la Barra my ping testing to local sites showed ipv6 had MORE latency also... I’m sure it depends on the site and my isp
@m0wao6904 жыл бұрын
I'm using IPv6 since 2003 and can't really agree with this video in many ways. Sure you have to have the right equipment and settings to be secure but that's for everything connected to the Internet. And since when is NAT secure? Probably never heard of SlipStream NAT... Anyway everyone it's pleasure
@tmoney39963 жыл бұрын
Check out proton vpn. They have features to stop ipv6 leaking on its vpn service
@paulshankster3 жыл бұрын
OK, let's talk about device fingerprinting: The auto assigned IPv6 address that uses the MAC address (7th bit flipped) begins with FE80 and is NOT routable - much like the 192 / 172 / 10 prefixes on IPv4. It is only used on the local network. On the other hand, smart phones on cellular data connections almost always use public IPv6 addresses (like 2001) yet are still secure. The problems you mention are problems of implementation not protocol. Any potential problem with IPv6 is also a potential problem with IPv4. However, IPv6 actually solves several problems which required work arounds on IPv4.
@nd-costa3 ай бұрын
Wrong! Routers assign at least 3 IPs, one of which is for the internal network, link-local type, and is not routable as you said, but the other two are always global and dynamic. Worse still, these IPs are not behind a NAT, meaning that your device is on the street, is open, and any port will be accessible from OUTSIDE the internet. One of these two global IPs will be marked as non-expirable (forever), it is like a fixed IP; the other global IP will be expiring for a period of time, usually 24 hours or a little more. The problem is that those damn cell phones never allow you to disable IPv6, which would be ideal for these type of devices. A real disaster waiting to happen.
@James_Knott3 жыл бұрын
It sounds like someone isn't competent or is trying to push a product that doesn't support IPv6. Devices that are IPv4 only are not affected by having IPv6 available. IPv4 hasn't been adequate for many years, due to the address shortage. As a result, many people are stuck behind carrier grade NAT, which means they cannot access their own network from elsewhere. Also, NAT breaks some protocols. This is why it's necessary to use STUN for VoIP and some games. It also breaks IPSec Authentication Headers, which reduces security. As for the "automatic firewall", firewalls by default block everything and you have to open what you need. As for each device having a routeable address, yes that is true. However, with SLAAC, you get one consistent address, which you'd use for incoming connections and random number based "privacy" addresses, which change every day, for outgoing. Further, you have at least a /64 prefix, which contains 2^64 addresses, which means that port scanning, a common attack with IPv4, is simply not feasible with IPv6. As for an ISP knowing who's doing something they shouldn't, while they may not be able to tie an address to a specific device, they can tie a prefix to a customer, just as they would with the single IPv4 address. Also, the MAC address is only used if enabled in the consistent address. Very often a random number is used, even for the consistent address. The MAC is never used in the privacy addresses. Further, even with IPv4, your general location is still more or less available. Certainly your ISP is identified. In short, this video is based largely on ignorance.
@robbraxmantech3 жыл бұрын
You understand only what you understand.
@James_Knott3 жыл бұрын
@@robbraxmantech Given I have been working with IPv6 for 11 years and am also a CCNA, I know quite a lot, enough to know there were significant errors in your presentation. For example, you said your MAC address would be revealed. Well, that's only true if you configure your system so that the address is based on the MAC and you do not use privacy addresses. Privacy addresses, used for outgoing connections, are based on random numbers that change every day. No trace of the MAC there. Even the consistent address, which you'd use for servers etc, so you can use DNS with them, can be either MAC based or random number, your choice. That is just one serious error of many. If you don't understand this, then you don't understand the security risks. I suggest you read up on SLAAC and privacy addresses to understand this point.
@yegfreethinker17 күн бұрын
My God how dumb are you dude how many bits are guids/uuids by the way and how many bits is an IPv6 address? do the math
@revravenli3 жыл бұрын
There are so many misconceptions about IPv6 (and networking in general) in this video for someone who supposedly builds router software. Even the cheapest consumer grade routers (regardless of whether they have IPv6 enabled) have a built in firewall to block incoming connections. NAT is not responsible for this functionality in a home router. NAT is NOT firewalling! NAT64 is a transition technology meant for ISPs and enterprises (those with publicly accessibly resources) to migrate to IPv6 while continuing to support IPv4. In essence NAT64 translates a publicly routable IPv6 address to a public IPv4 and vice-versa. It is not meant to translate Private IPs to a Public IP as you are implying. There is no reasonable use case to implement it on a consumer router. Man-in-the-middle attacks are possible are just as possible on IPv4 as on IPv6. One of the many solutions is encryption. IPv6 unlike IPv4 natively supports IPSec to mitigate this risk. There are several issues with IPv6 as it is today and I really enjoy your videos but I think you missed the ball on this one.
@tamask2 жыл бұрын
"Even the cheapest consumer grade routers (...) have a built-in firewall to block incoming connections" This is simply not true. I'm not sure the router my ISP gave me has one. I have not seen it, there are no settings for it, and it's not in the documentation. With IPv6, all your devices just get a direct, public IP address, and you are out there in plain sight, exposed to any potential threats. There is no router, no firewall, nothing. (Apart from the software firewalls which may or may not have security vulnerabilities.) If someone did this just 5-10 years ago with IPv4, it was very bad practice, and potentially dangerous. And now, all of a sudden, this is the norm with IPv6. IPv4 NAT is not a firewall, but it surely acts like one! It won't let anything in, unless you specifically set up a port-forward rule for it. Yes, the same thing can be done with IPv6, without NAT, but the crappy router your ISP gives you won't do it. They'll rather save costs.
@revravenli2 жыл бұрын
@@tamask What is the make of the router your ISP gave you?
@tamask2 жыл бұрын
@@revravenli Kaon CG3000
@whothefoxcares4 жыл бұрын
didn't Obama say *"If you like your IPv4, you can keep it?"*
@lb46602 жыл бұрын
😂 no that was health insurance
@nuncaleite4 жыл бұрын
No joke: I changed providers recently and got a dual IP (v4 and v6) configuration. When I checked the DNS for the ipv6 I couldn't believe my eyes: they were using a HUAWEI dns server! And there was no option to turn it off or change the dns (there were options for the ipv4 though). Fortunately I managed to access it another way and turn it off, but my jaw is still dropped. I am nowhere near China for it to use a chinese DNS, and they're installing it as standard config for all users.
@robbraxmantech4 жыл бұрын
Get my BraxRouter and it will route the DNS away
@briangreen77974 жыл бұрын
Thank you Rob, I find your talks very informative. My ISP provider told me I had to change my IPv4 router for an IPv6 router or loose my cable Internet service. They said that they would give me a replacement router, but when it arrived I found that it was not a router but a hub! So I searched on the Internet and found that there was an Mobile Use Only option. I made connection via fast ethernet cable to a Draytek Vigor 2860ac router that allow me to use IPv4 and IPv6 as well as specifying 2.4G or 5G and Dos protection, and power levels ... I also found on my android phone that there were other frequencies other than my selected ones which were also transmitting. I had to go back into the set up system and turn them off. Which reminds me, I had better go and check that my settings haven't been changed. For window, I find Sphinx is excellent. I am looking for a secure Linux OS. Would you use Alpine Linux?
@robbraxmantech4 жыл бұрын
If my ISP gave me that ultimatum I'd say zuck you to them. Or have them pay for a security appliance in between
@briangreen77974 жыл бұрын
@@robbraxmantech It was Virginmedia operated by Google.
@briangreen77974 жыл бұрын
@Max Raider I thought that too, but after watching many programmes of 'Eli the Computer Guy' on Utube, I realised what I had received was a Hub or that it didn't have the functionality of my previous router or the Draytek router I subsequently purchased.
@MadCowMusic4 жыл бұрын
I've been pretty sketched out ever since I read the wiki description of ipv6; says it's used to 'identify and locate computers'....
@robbraxmantech4 жыл бұрын
The way IPV6 is assigned will point the address to specific neighborhoods. Instantly. IPv4 is more vague and requires a database of locations through wifi-triangulation to pinpoint.
@mjducharme2 жыл бұрын
@@robbraxmantech Not true. Both require the database. The way IPv6 is assigned will NOT point to specific neighborhoods. It is assigned the same way as IPv4.
@Alex74ch3 жыл бұрын
Rob brings complex tech to normies who have no idea how zucked they are. In other words, he is a saint like citizen who we need 👏🏻
@James_Knott3 жыл бұрын
He brought a load of nonsense and he clearly does not understand how IPv6 is used. I don't know what his qualifications are, but I'm a CCNA and have been working with IPv6 for about 11 years.
@robinhammond44463 жыл бұрын
@@James_Knott Agreed. Also earned a CCNA and worked with v6 for more years than I care. As a Bayesian if this person claimed the sky were blue, I'd decrease my believe that it were.
@RobertBelcher4 жыл бұрын
This was one of the most important videos I've watched all year about security. Fantastic job.
@robbraxmantech4 жыл бұрын
Glad it was helpful!
@johndrexmond81384 жыл бұрын
Please make a quick video on how to set up a basic router for defense! Can't wait to hear about other hidden threats you're discovering
@TheJackiMonster4 жыл бұрын
There are actually things you gain from IPv6. First of all you can remove the whole NAT garbage from many routers and use proper firewalls instead. IPv4 introduced for many applications this whole crap of NAT traversal, hole-punching and pricing IPv4 addresses and sub-nets completely unnecessary. The only reason IPv4 stayed so long was compatibility to old systems and devices. Disabling IPv6 now is only a temporary solution... all related problems have to be solved differently in long term. What me bugs the most is that the IPv4 actually had very neat features like multicast groups you could have used for decentralized streaming, podcasting or messaging. This would have reduced traffic, latency and server cost. But they turned this service down in favor of more addresses because of the lack of address space. So IPv6 brings this feature back hopefully for everyone.
@robbraxmantech4 жыл бұрын
btw don't be so certain that enterprise firewalls are good to go with IPV6. Checkpoint firewalls just block all IPV6 extension headers since it doesn't know how to handle them. A lot is unknown. And will you install a NAT64 firewall in your house then? If the average person knew how to do that then there is no issue
@TheJackiMonster4 жыл бұрын
@@robbraxmantech I don't want to use enterprise wirewalls. There are open source firewalls, I would use. It shouldn't be difficult to close all incoming connections by default. I also think it is in any case important to make sure your devices don't have any open ports for incoming connections. So a firewall should be installed or all services closed anyway. Otherwise you are still vulnerable in other peoples networks or open ones. The most privacy concerns of IPv6 could actually be work-arounded by generating a static address with urandom. The range of IPv6 would allow something like that.
@magneticshrimp74294 жыл бұрын
@@robbraxmantech NAT64 is not a firewall thing. All it does is translating between IPv6-only devices to IPv4 services. IPv6 firewall is simply firewalling.
@m0wao6904 жыл бұрын
@@TheJackiMonster Indeed you can build your own like OPNsense for example
@petevenuti73552 жыл бұрын
come on, really?!?, that makes you sound like someone who's mom still balances their checkbook and does their laundry cuz they just don't want to learn how themselves.. (I really hope that's not true). Seriously though, I know setting up nat traversal can be a pain, but at least it forces one to learn something so you can make it work. Learning how helps put you in some control and gives understanding of what's going on. Would you really want all your devices publicly addressable like putting everything in the DMZ of your old ipv4 router? I can't imagine anyone would want to be committed to an institution just because they don't feel like taking care of themselves any more then I could conceive of giving a stranger maid power of attorney to clean up my life. In the same vein, why would anyone want their ISP automatically configurating all their personal devices inside their own network for them? and if you are curious, I was that geek that was totally against plug and Play devices when they came out and I miss setting jumpers. at least back then windows didn't have to report back to Microsoft to tell me how I want to set up my own computer.
@Tru-dp9yt4 жыл бұрын
Thanks for your very expert and incisive analysis which has become so indespensible!
@josephinebell46823 жыл бұрын
Thanks for looking out for us!
@darrenlomax12833 жыл бұрын
Rob, if all routers are set to use dhcp, and a typical IP address is 192.168.1.1/2/3/4/5 etc couldn't someone fire a packet through a nat firewall by guessing a PC is using Skype for example and get a malicious packet into a network? Or is the nat firewall more sophisticated than that?
@Andrew-jh2bn3 жыл бұрын
Yes, you are right. The way this is actually done is a little more technical: samy.pl/slipstream/ This video is full of misinformation. Just because your network is behind nat doesn't mean it is somehow more secure. Rob seems to think that ipv6 just leaves your network completely open to the internet, but this isn't true. Firewalls are still used and extremely important, no matter which ip version you are using. Nat simply allows you to use more devices on the same address, it's not some magic security tool.
@darrenlomax12833 жыл бұрын
Steve Gibson of GRC.com said a similar thing to rob a few years ago regarding nat and ipv6 so I don't consider this video to be full of misinfo. The industry has moved on a bit.
@Andrew-jh2bn3 жыл бұрын
@@darrenlomax1283 there definitely are are security and privacy concerns associated with ipv6, but what Rob brings up in this video really misses the mark. This video does a much better job of going over the pros and cons: kzbin.info/www/bejne/iZPKk3iul9pkoc0 Funnily enough it was actually Rob that posted a link to this video, so I don't know how he got it so wrong.
@buddyadams47814 жыл бұрын
Partial solution? For ISP modem/router combo: turn off wifi, connect to Nighthawk router by cat5, use that wifi?
@personanongratis4 жыл бұрын
I give up,every step we take is being "recorded", I'm going to become a lonely monk!
@Techie-ks9nh4 жыл бұрын
Every day that goes by we find out that we're screwed over 20 different ways than the day before I know we still have ways to mitigated but it gets damn depressing I just don't brother watching each video immediately until I get money to by the needed hardware to do half of these things
@locutusofborg71224 жыл бұрын
@Timi - Timi, I was feeling the same way earlier today too. I think we all are going to feel thay way from time to time, but we must not give up the fight! I say this to encourage you, myself, and everyone else. Listen, we all are not a Rob Braxman, so we just have to take baby steps, educating ourselves a little at a time by good, knowledgeable people like Rob --- and knowing we all will be discouraged at times. Eventually, as we learn, we'll become more and more savvy until we reach a point where we finally can feel competent --- and have a confidence --- at what we've accomplished; knowing, feeling, and realizing just how far we have come --- which will catapult us onward in the fight!
@cloudsinthesky674 жыл бұрын
@@locutusofborg7122 Like George Floyd, they have a foothold on your necks especially if you're an active targeted individual. Only way to change this is to make it a 'political issue' but espionage benefits them, they want all the power kept on your necks to make you feel powerless, so how to make change: kzbin.info/www/bejne/kGfPd6KkoraHe7c
@robbraxmantech4 жыл бұрын
They exist but don't get used much (I2P). Maybe awareness will spark a change
@davesmith19294 жыл бұрын
Great videos, but I think you are overstating the privacy risks of IPv6, and falling for a few misconceptions here: 1. FE80 "link local" addresses are equivalent to non-routeable IPv4 addresses (like 192.168.0.1). They're local only and NOT routed to your ISP's network*. 2. EUI-64 (where IPv6 addresses are based on a device's MAC address) is NOT used in the example you give (around 16m20s+). Any EUI-64 address can be identified as it has __FF:FE__ in the middle: networklessons.com/ipv6/ipv6-eui-64-explained The RFC4941 from 2007, "Privacy Extensions for SLAAC in IPv6", means that the MAC address is no longer used to generate devices' IPv6 addresses. Even my cheapo, years-old ISP router doesn't use EUI-64. Wikipedia: en.wikipedia.org/wiki/IPv6#Stateless_address_autoconfiguration_(SLAAC) RFC4941: tools.ietf.org/html/rfc4941 3. The location identifiers of IPv6 are pretty much the same as in IPv4. A public IPv4 address will reveal which ISP you use, and which subnet of that ISP you are connected to (which can narrow-down a more accurate location). How is IPv6 any different? --- * - One "feature" that exposes your local network to the ISP is TR-069. ISPs use this on their routers to remotely update the firmware, but can also see all the devices and IP addresses (IPv4 and IPv6) on your local network. en.wikipedia.org/wiki/TR-069
@vatevor3 жыл бұрын
I'm honestly quite clueless but I only configured IPv6 because my ISP modem router combo and personal router are causing double NAT. Somehow, enabling IPv6 solved double NAT issues for me.
@nd-costa3 ай бұрын
The problem with disabling IPv6 is that websites are switching to IPv6 and disabling IPv4. Eventually, it will no longer be possible to access any website via IPv4. There is no turning back from this trend and it is necessary to create a way to protect ourselves with IPv6.
@James_Knott3 жыл бұрын
BTW, you forgot to mention Unique Local Addresses, which are the IPv6 equivalent of IPv4 RFC1918 addresses and can be used for local networks.
@danilamiroshnichenko20353 жыл бұрын
NAT is not a Firewall. What’s a shame
@jmonlive20 күн бұрын
11:20 Only a perk maybe, but not security filtering/inspecting.
@Hecurles-sz1jz Жыл бұрын
So I have a question? My ipv6 and ipv4 change randomly and sometimes they go out out randomly as well. This happens when I'm on a VPN on my cell phone and when I'm off a VPN. The vpn takes the ipv6 away but the ipv4 still changes randomly. Sometimes 3hrs sometimes 1hr, 4 min. I'm curious to why it does this? Then my ipv6 changes and sometimes my ipv4 will remain the same. And sometimes they change at the same time.
@gordonfreeman87962 жыл бұрын
I don't know much about ipv6 but these are the things immediately concerned me. Thanks for this video. Literally nobody talks about it.
@audrunasgruslys92434 ай бұрын
I said a lot of truths, especially about fingerprinting, but getting rid of NAT does not immediately imply getting rid of a firewall.
@chazfaz35954 жыл бұрын
Thanks Rob! Where do we go if we need answers to questions we have about your products, that arn't provided in the description?
@robbraxmantech4 жыл бұрын
Talk on Brax.me and ask
@chazfaz35954 жыл бұрын
@@robbraxmantech Thanks. At the end of the video you mentioned that you do live stream Q&A at 8 pm pacific time. Where is that hosted?
@MadCowMusic4 жыл бұрын
@@chazfaz3595 Fridays, right here on KZbin.
@chazfaz35954 жыл бұрын
@@MadCowMusic Sweet
@christopherhoy5924 жыл бұрын
@@MadCowMusic sometimes simulcasted on Periscope and posted to Ibry.com
@kali_yuga41404 жыл бұрын
I found an option in the KDE wifi settings under the tab "IPv6" then Privacy, where you can set it to generate a "public" or "temporary" address. Not exactly sure what that does, but it probably does something so I guess I'll turn that on.
@frederikholfeld8684 жыл бұрын
as i understand it, the part that would normally be filled with your hardware address / mac address is then substituted by a randomly generated one. that random address is apparently also discarded and regenerated every day or so, in order that you're less traceable over time, hence temporary address.
@kali_yuga41404 жыл бұрын
@@frederikholfeld868 so it's a good thing then..
@Wayne-Jones3 жыл бұрын
I’m glad I watched your video, I was thinking of setting up IPv6 tomorrow, I’ve always used my own router but using my isp’s modem.
@romana28164 жыл бұрын
I'm learning so much from you. Really appreciate your time and effort. When I build my house, I will take all the necessary steps to protect my privacy.
@lucasmzreal2 жыл бұрын
no.
@Protikugen3 жыл бұрын
THANKS ROB FOR ALL THIS INFORMATION, THIS HELPS A LOT SPECIALLY THOSE LIKE ME I AM NOT SO EXPECT SO ALL THIS INFORMATION HELPS ME OUT.
@johng.49594 жыл бұрын
It's getting to the point where I'm ready to abandon the internet completely. What a dystopian future we all have waiting for us.
@yegfreethinker2 жыл бұрын
Hear hear brother
@danielbuenrostro4 жыл бұрын
Thanks for the info, Rob.
@nancypagan47903 жыл бұрын
Thank you Mr. Braxman.
@michaelm12 жыл бұрын
Tell me how an attacker can pinpoint a particular IPv6 of your home computer. There are hackers continuously scanning IPv4 addresses for vulnerabilities, because going through 4 billion possibilities is easy. With IPv6, a hacker randomly stumbling upon your IPv6 address is an effective impossibility. The odds are truly astronomical. Actually, IPv6 is much better this way. And privacy extensions make things even better.
@paaao4 жыл бұрын
So much wrong with this video, I'm not sure where to begin.
@muskrat73124 жыл бұрын
Ipv6 is not as horrible as some think. You dont need stateless autoconfig if you dont want although most will use it by default. True, v6 is not the greatest design but it is just another addressing scheme. NAT is security through obscurity and is not a real security control. The biggest privacy issue is the mac address can be known through stateless autoconfig but there are solutions to prevent that through ipv6 extensions.
@robbraxmantech4 жыл бұрын
The issue is that it is premature for ISP's to be defaulting to IPV6 when the average household has no NAT64 appliance to protect the network. Suddenly separate firewalls are needed (but not before with IPV4).
@muskrat73124 жыл бұрын
@@robbraxmantech I worked at an ISP and the deployments have been delayed for years. NAT is not a security boundary. It is true that it would be nice for customers to have more knowledge and ensure their firewalls/routers have full dual-stack capabilities and ensure they can hide their private MAC IDs but since most people are not technical this is the consequence.
@magneticshrimp74294 жыл бұрын
@@robbraxmantech The average consumer router and even ISP provided ones filters incoming IPv6. Are you confusing NAT64 with NAT66 to hide addressing details?
@WyzerDev4 жыл бұрын
@@robbraxmantech NAT64 is a protocol for IPv6 only host to reach IPv4 only hosts. It's not needed on Dual-Stack and don't protect your network
@WyzerDev4 жыл бұрын
@@magneticshrimp7429 NAT66 don't have RFC up to now. A "Prefix Translation" (NPTv6) option is under discussion, maybe it will not be approved, although it will be very useful
@robinhammond44463 жыл бұрын
Many avenues of attack can also be found focusing on IPv4. Or USB ports. Or Bluetooth. Or your web browser.
@russellm75303 жыл бұрын
I was checking out my Spectrum internet account and it showed each device that's been connected to my WiFi and supposedly I can block any of them from the website. But watching this video made me realize that Yes, not only do they have your router or home internet address but each device hooked to it. I also started checking out Google account settings too and see they have each device I've logged on with also. I think I'd seen somewhere on my Spectrum account that the router is ipv6. So if I had just an ipv4 modem/router then would all these devices not be known to Spectrum? How about Google? Thank you Rob and God bless you and your family.
@robbraxmantech3 жыл бұрын
Yes exactly that is my point. And you won't believe the negative comments like I don't know what I'm talking about
@saywhat91582 жыл бұрын
@@robbraxmantech So many people [even so called techy people] do not understand the difference between security and privacy especially as seen in so many comments here that “NAT’ing is not a firewall”. No shit but it was a privacy layer and served as a gatekeeper which should not have been necessarily excluded from use in IPv6.
@yuriireshetylo2454 Жыл бұрын
Google or any other website still can identify your devices just by reading the user agent even when IPv4 is in use. User agent can be spoofed as well as the IPv6 MAC portion of address. My android phone spoof the MAC "fingerprint" portion of the address by default. Non an issue at all
@robinhammond44463 жыл бұрын
NAT 64 IS NOT A FIREWALL.
@BobJones-dq9mx4 жыл бұрын
What an excellent tutorial! What are your thoughts about TAILS?
@dave24-73 Жыл бұрын
From what I can gather IPV6 offers point to point so outside devices can access internal without NAT (could be wrong here), but this equally means you have made a Hackers job easier and you are broadcasting your devices. So it appears IPV6 has a lot of security issues. Many man in the middle attacks take advantage of an IPv6 exploit, so I’d say turn IPv6 off if you don’t need it.
@efrongoedel90423 жыл бұрын
Is ipv6 good on a apn for phone im having trouble with my data when I go to my house it completely turns off I lose data and sometimes when I go out side I have to either put it in airplane mode and then put it back to normal to get data again can u please help me with my apn for metro pcs
@michaelschult94354 жыл бұрын
Incredible amount of Information you are sharing, Thank you for all these Efforts
@robbraxmantech4 жыл бұрын
My pleasure!
@HelplessHawk4 жыл бұрын
Very interesting and enlightening article, thanks. I’ve read that a growing number of websites are blocking “non ipv6” address. Is this correct and if so is there anyway round this?
@robbraxmantech4 жыл бұрын
IPv6 is not generally used yet. It is mostly used inside the ISP's network.
@autumnloving4204 жыл бұрын
Thanks for the info. I had to go into the modem/router settings to turn off ip6 :)
@tesses503 жыл бұрын
my problem is that I have a double nat my router and a LiteBeam 5AC Gen2 so the LiteBeam 5AC Gen2 (its out at the end of the driveway) can't be replaced due to thats how I get my satelite internet I guess I could request my ISP to turn the litebeam into bridge mode or dmz my router
@meslevres4 жыл бұрын
This video feeds wrong information. NAT is neither a security feature nor a prerequisite for firewall. So stop feeding misinformation. IPv6 is the future.
@mysnackr4 жыл бұрын
Regarding security from outside attacks: So you're saying if you're using one of these Spectrum modem/routers the ISP will give a public-facing IP address to each device in the home? How is that possible when the greater internet is running IPv4.. each device in your home would need its own internet IPv4 address to be reachable from the outside. there would be no other way the Spectrum router would know how to route incoming connections without using port forwarding, just like a standard router would do. Unless I"m missing something here?
@robbraxmantech4 жыл бұрын
Yes did you not watch the video????? We are talking about IPV6!
@chakrameditation66773 жыл бұрын
I need this answered, please. Can't you change your public IPV6 address anytime you wish?
@robbraxmantech3 жыл бұрын
absolutely not. An IPV6 is localized and many times will use the mac address of your device.
@chakrameditation66773 жыл бұрын
@@robbraxmantech Thank you for replying Rob, but I'm shocked out of 340 undecillion, You cannot change your address? So if you're playing online gaming and someone DDOS's your connection, There's not a way to get back online with IPV6?
@revravenli3 жыл бұрын
@@chakrameditation6677 You can CERTAINLY change your IPv6 address!!! In fact, your home router can do this for you depending on how SLACC is configured. The smallest subnet you can be assigned by your ISP in IPv6 is a /64. That is 18,446,744,073,709,551,616 possible IP addresses just for your home network. ALL PC operating systems beyond Windows XP no longer use the mac address of your device during IPv6 address auto-configuration. Instead the last 48-bits of your IPv6 address are randomized. I cannot understand why Rob chooses to ignore this fact yet it has been pointed out to him so many times in the comments. Regarding localization, even IPv4 addresses are localized. Everyone already knows which ISP you are connected to just by looking at your public IPv4 address. So in short, if you get DDOSed, you can manually change your devices IPv6 address if you want.
@benpracht26554 жыл бұрын
I have ATT Fios, and was told I.absolutely have to use their modem and router. The only thing I was able to do was put my router between theirs and my devices and configure it as bridge mode. Please help me keep Fios, but ditch their equipment. Also, is my setup insecure? Thx
@robbraxmantech4 жыл бұрын
Sometimes that's the only way. Put a router it between with NAT. But maybe a wired module would work better. BraxRouter does that and also VPN's the trunk
@saho94474 жыл бұрын
Doesn't it not matter whether or not ipv6 is exposed or not, since it changes regularly?
@chakrameditation66773 жыл бұрын
I am wondering the same thing..... Does it change?
@NightHawk18702 жыл бұрын
What about turning on IVP6 an android TV?
@DanWahrenberger3 жыл бұрын
Lots of well intentioned but misinformed information here based on out of date thought processes. The biggest one is is that NAT IS NOT A FIREWALL and shouldn't be used as such. NAT creates many issues with the advanced networking tasks many home users are trying to accomplish. For example NAT can interfere with the end to end communication needed for Video Conferencing or even just trying to run more than one gaming console simultaneously. Given that many ISP's are implementing CG-NAT (Carrier Grade NAT) and not giving a true routable IPv4 address NOW is the time to be embracing IPv6 in the home environment.
@robbraxmantech3 жыл бұрын
Sorry. We will agree to disagree.
@traderflorstock94974 жыл бұрын
Hi Rob. I use a modem/router combo. I can get into firewall settings and see ipv6 and firewall setting low- med - high. Should I implement those settings or turn them off completely since the modem router is it’s own firewall?
@robbraxmantech4 жыл бұрын
Just turn off IPV6
@volodumurkalunyak46512 жыл бұрын
@@robbraxmantech WRONG. You do NOT just turn ipv6 off
@Lesterandsons4 жыл бұрын
Will I have to put my edge router behind my isp modem/router ?
@robbraxmantech4 жыл бұрын
Or just dump the ISP router. Keep it simple. Saves you money too
@wildmanjeff424 жыл бұрын
Thanks for the video !
@efrongoedel90423 жыл бұрын
And I also have wifi and I use spectrum I really don't like it cause of hackers trying to get my identity or information so I would like more information on my phone service apn setting to get the most out of my phone thank u n great video
@locutusofborg71224 жыл бұрын
@Rob Braxman Tech - Exceptional vid! When you're at the top of your game, it's hard to out-do yourself---but you did on this one!
@robbraxmantech4 жыл бұрын
Much appreciated!
@Ultrajamz4 жыл бұрын
Rob Braxman Tech one thing I think is a “solution” if the ISP mandates ipv6, you can still buy your own router and put all your devices behind that router, and disable ipv6 on that router.
@frederikholfeld8684 жыл бұрын
as far as i'm aware the mac address part of the address is using a randomly generated address by default, at least on linux and windows, instead of the mac. does anybody know if rob is right on it not being this way?
@robbraxmantech4 жыл бұрын
By default, machines use SLAAC which is based on MacAddress. It can be reconfigured though specifically how by device is not clear. However, this is the least part of your problems. The IPV6 PREFIX alone is enough to spot your location pretty closely since it is a more accurate location assignment than IPV4
@frederikholfeld8684 жыл бұрын
@@robbraxmantech it seems to me that my pc running manjaro linux uses some random address generation. /etc/dhcpcd.conf at least has the "slaac private" option enabled: # Generate SLAAC address using the Hardware Address of the interface #slaac hwaddr # OR generate Stable Private IPv6 Addresses based from the DUID slaac private this leads me to believe that it wouldn't use my mac-address for ipv6 addresses. however, our old router doesn't seem to support ipv6, so it doesn't matter in my case either way. but the fact that the vendor specific part of your address exposes so much information about you already is certainly cause for concern. some orwellian shit we got us in :O
@definitely-not-daniel Жыл бұрын
IPv6 is like trying to protect a house with 1 door vs with 7 doors. Now instead of worrying with one you need to awry with 7. And who wants that 😭😭
@MattInIllinois3 жыл бұрын
Always good info thanks! I was about to switch to IPV6 to be like one of the cool kids but thankfully I saw this first.
@willsmith66393 жыл бұрын
Hi Rob, thanks for educating and informing us!
@user-r1g5i3 жыл бұрын
We are running out of 4B IPv4 addresses because Java always has been running on 3B devices 🙃
I'm in Canada ISP default routers are combo modem and router in my province. Since day 1, I had the ipv6 disabled, only ipv4 enabled at all time. Nonetheless, doesn't help against APTs. Difficult to find justa modem standalone that will work with the ISP with the appropriate matching mbps to set up the Brax router, I've looked at several sites. Therefore, haven't properly set up mine. Any suggestions?
@robbraxmantech4 жыл бұрын
For home use just a standard Wifi router will be fine. Just don't do port forwarding
@volodumurkalunyak46512 жыл бұрын
@@robbraxmantech There is nouthingh wrong with port forwarding. Why should one avoid using that?
@technerd9655 Жыл бұрын
Regardless of IPv4/IPv6 and any potential security and privacy issues, you should always use your own router and put your modem in Bridge mode (or use PPPoE passthrough if on DSL or Bell Fibre with PPpoE and no true bridge mode). The ISP provided gateway devices, although far better than the ones provided in the past) are not great devices, don't handle wifi congestion well, don't handle more than handful of devices well, create privacy concerns with the ISP being able to see and control every aspect of your home network. Your home network is not their responsibility, neither is wifi. They have no business seeing into and controlling your network and every device on it. Your home network, including the wifif, is completely independent of your internet service, but never it's on the same device remotely managed by the ISP, you are at their mercy, they control firmware updates, they control what configuration settings are exposed in the modem/router's webUI, they control what config settings are exposed in their app and cloud portal. They limit what you can do. Due to terrible marketing (from a technical perspective) most people conflate wifi and internet service as they same thing, it's not. Wifi is a value add. If budget allows, get a Ubiquiti UniFi system, otherwise I like the TP-Link hybrid powerline mesh wifi systems (current model in the US is Deco PX50, unfortunately not sold in Canada), these use wifi and powerline networking for backhaul allowing you to place these in more optimum locations for better coverage in your home.
@SomeDumbRandomUser4 жыл бұрын
Yes, NAT isnt important anymore ... But in Germany we will definetely still have Firewall-Routers using NAT. Isn't the IANA-Location based IP Adresses already in use with IPv4? My IP pinpoints me to my region and isp in germany already.
@robbraxmantech4 жыл бұрын
IPV6 points very precisely, not like a general IPV4 location of the ISP. Combined with 5G Beamforming we are truly zucked.
@doublej40774 жыл бұрын
Yes I wish you would give steps on setting a router up , or some links to some good vids on it ! I am no guru in this stuff and appreciate your information . I am glad you are discussing not only phones but computer security. Big brother & criminals are always ahead of the power curve on us it seems like all the time .
@anielrivera79774 жыл бұрын
yes i notied that too ,i have a hidden router .com router which is also a vpn router and google was still monitoring me on ivpn6 so i had ipvanish to couter that ,so i have both vpns on software and hardware
@MadCowMusic4 жыл бұрын
I really want to know who's walking around with 4 billion+ or even just 3.7 billion machines on their local network and worried about running out of ipv4 addresses...
@maynnemillares4 жыл бұрын
Seems like you are not aware of private and public IP addressing. The part that already ran out was the routable public-IP. ISPs are cycling their limited public IPv4 supply by using carrier-grade NAT. Carrier-grade NAT is bad if you are hosting server services.
@robbraxmantech4 жыл бұрын
Max you are a breath of fresh air... thank you for lending your expertise. I wou;dn't have the reading time quote an RFC!
@locutusofborg71224 жыл бұрын
I was upgraded to a new ATT modem recently, for free, so the first thing I did was go into the router and untick the radio button for IPv6. Since ATT buys only barebones modems/routers for the consumer market, and has them flashed with their proprietary firmware, there is no extra per-month cost for renting or buying the device; at least that is my case where I live in the US.
@christopherhoy5924 жыл бұрын
Ask AT&T - you might find that if you have your own Wifi Routers, you'll be charged about $10. less each month.
@finnk12893 жыл бұрын
People think a higher number is better with anything.
@charliecharliecharliecharl85542 жыл бұрын
Hackers using IPv6 to attack my devices
@Hecurles-sz1jz Жыл бұрын
Explain
@charliecharliecharliecharl8554 Жыл бұрын
Hackers gained access to my pc and used teredo tunneling using IPv6 protocol and lanman workstation on win 7 ,my pc was constantly sending multicast IP out over my network 224.0 using different services to send these packets used peerblock to see all IPS and TCP view for checking services and port numbers I deleted IPv6 protocols from my registry ,I don't have a network of pcs over a network just a router and pc and tablet
@presentcent14732 жыл бұрын
Someone hacked me and I'm sure they unencrypted my ipv6 to gain access to my electronics and I got NO help from anyone in government I reached out to other hackers at one point and got no help there either.... I'm still looking for help to this day.
@presentcent14732 жыл бұрын
I can see the word unencrypted on my network on my laptop and on my tower so they definitely took advantage of this info maybe even the same video to hack me who knows.
@yegfreethinker17 күн бұрын
for computer illiterate an IPv6 address is a tattoo mustache elimination place in poland. You don't want that. Great thing about IP before is that it reuses name so many times around the world that it's almost impossible to identify an end user definitively. It's safeguards your anonymity. IPv6 is essentially a universally unique ID which is not good privacy wise
@Durkhead4 жыл бұрын
Doesn't ur isp have its own firewall software on the modem router they provide?
@vivekjindal5784 жыл бұрын
in android you can go to APN settings and change setting to obtain ipv4 only. secondly, add iptables rules to drop all ipv6 traffic.
@vivekjindal5784 жыл бұрын
additionally, using sysfs you can disable ipv6 from network interfaces.
@whothefoxcares4 жыл бұрын
Why not limit corporations to 254 public IP addresses?
@MrRefael334 жыл бұрын
Thanks, great video 👍 I didn't have a clue about it.
@omgMBP2 жыл бұрын
there's a lot of misinformation here...
@BobJones-dq9mx4 жыл бұрын
How do I access your EU market?
@robinhammond44463 жыл бұрын
Today I learnt the fact that things are made up of two parts if you split them in half. That is all.
@robinhammond44463 жыл бұрын
LINK-LOCAL addresses, which start fe80: do not traverse routers. I have no idea what the "LOCAL LINK" your shouting about is.
@plenus73924 ай бұрын
I have my router as a VPN gateway and tunnel for my LAN just because having a big fat target pointing directly at my phone that is routeable over the web? No thank you
@humbertoabrego67754 жыл бұрын
We created nat to extend the life of ipv4
@robbraxmantech4 жыл бұрын
Max I did not know about that semantic distinction. Thank you.
@junialter4 жыл бұрын
This is piled up with misinformation. Don't listen to this guy. Read a book or watch legitimate videos about IPv6.
@robbraxmantech4 жыл бұрын
Why don't you watch serious discussions on KZbin about the flaws of IPV6 instead of reading your zucking book?
@robbraxmantech4 жыл бұрын
Yes watch this. kzbin.info/www/bejne/iZPKk3iul9pkoc0 And go make your videos about IPV6. I make videos about privacy
@DamjanDimitrioski4 жыл бұрын
I am excited when I click IpV6 disable on each wifi connection :).
@Bigdog-pf9kn3 жыл бұрын
Great job! I subbed!
@fyodorx54283 жыл бұрын
I recently tried to configure port forwarding on a router to one of my devices, and was surprised that the router only had an IPv6 address. I can confirm that MAC addresses were used to generate the IPv6 addresses of local devices. However, I actually couldn't make the device/port available from the outside Internet (v6). The firewall blocks all traffic by default, and it probably was buggy, I couldn't enable it at all -- I created an ALLOW ALL rule and it didn't even work. The most I could achieve was that traceroute6 could reach the device, but even ping6 didn't work, not even talking of TCP (I actually needed the port available over IPv4, so I just played with it, but didn't bring this up with ISP support)
@robbraxmantech3 жыл бұрын
IPV6 doesn't need port forwarding. IPV6 is direct device access
@fyodorx54283 жыл бұрын
@@robbraxmantech Right, but I need to support IPv4 clients.
@alexj01014 жыл бұрын
Another fantastic video. Great work, very concise!
@robbraxmantech4 жыл бұрын
Go back to your system admin job.
@ikomwrestling30884 жыл бұрын
NAT is not a firewall. Please don't confusing people with this misleading information.
@maynnemillares4 жыл бұрын
Yes, the video uploader is embarassing. Any practicing system administrator knows that NAT =/= to firewall. NAT is only a life-support system to extend the life of IPV4.
@robbraxmantech4 жыл бұрын
If you're some system admin, why don't you believe what you want to believe and I'll hack your network. Then let's see who believes what
@robbraxmantech4 жыл бұрын
Why don't you watch videos like these and listen well kzbin.info/www/bejne/iZPKk3iul9pkoc0
@robbraxmantech4 жыл бұрын
This is so basic it's not even worth responding. NAT makes non-routable IP addresses. So in essence it acts as a firewall! Now obviously it is not a commercial firewall with other features like Checkpoint but in a home Network it is the first line of defense firewall! Then in theory every device has it's own firewall. Don't spread disinformation!
@maynnemillares4 жыл бұрын
@@robbraxmantech Go ahead, feel free to hack me right now. I do not run Windows btw, so goodluck with that.
@patrickdee73654 жыл бұрын
Fantastic video very well explained
@robbraxmantech4 жыл бұрын
Glad you liked it
@S13Pauly3 жыл бұрын
Thank you. Just saved me a big risk. Top explanation. Was going to set up for gaming. After your video I don't think it will make a difference. Thank you again.
@zachsandvik18674 жыл бұрын
Very good Rob! 🤓
@nd-costa3 ай бұрын
Even though it is a serious privacy issue, there is nothing you can do about it. I don't think it is a good idea to disable it because IPv4 will be killed, and there is no going back. If you can't implement a way to make IPv6 secure, this workaround won't do much good.
@PlanetFrosty4 жыл бұрын
Excellent review!
@robbraxmantech4 жыл бұрын
Thank you kindly!
@ebreckpo65634 жыл бұрын
Thank you Rob, for clarifying this bag of worms called IPv6! I still have a modem from my ISP as I refused to have one of those crappy all in one devices they rolled out to other customers with are configured as dual stack. My modem was recently "upgraded" to dual stack without any comment. As my basic router had performance problems I finally updated my router with a Pfsense box where I disabled the IPv6 stack. Not only is this "under the hood" implementation a serious thread regarding privacy (that unfortunately we do not have anymore) but even more concerning it is a major security threat. Perhaps not the data that is available from a simple citizens computer but your computer can be used without your knowledge for infiltrating other computers. The current implementation of IPv6 will just facilitate these threats. With IOT getting more popularized this is calling for a major disaster. In the last 1 1/2 year I never heard so much companies in my country affected by hacking, data breaches, etc. These are the ones hitting the news, not speaking of the others hiding... I thought we learned about what happened 10+ years ago in one of the Baltic states . That state had to literally unplug their routers going to international sites because they were bombarded from all over the world. All banking, government,... facilities were down for several weeks. They even tried to kill the power plants but fortunately these were older platforms adapted to digital and they still had "manual controls" . I am getting more and more concerned about the computer infrastructures from my country as most people have a blind faith into the security implementations of these platforms. I still remember the quote from one of our teachers " security is a matter of time" . Most systems have no manual override because to expensive.... When I look through the log files of my Pfsense router I am surprised regarding all the port scans that happens on my router external IP address, some are targeted to the common ports, others are random ports. These addresses originate from countries like Iran, Russia, China, Bulgaria,... to mention the top 4.