securecomputing.net.au’s post on IPv6 security
Secure Computing Magazine states that IPv6 presents a clear and present danger to the security of many operating systems. As true as this blanked statement is, it also lacks the necessary qualification of the real problems that lie in having a loose definition of perimeters and trust models. I tried to correct or leave a comment for them on their site but it appears they have some server-side issues with their comments plug-in.
My comments were to state that for one thing, they didn’t get the maths around IPv6 address sizing correct, likely because their HTML skills didn’t allow for using exponents. The number of addresses in IPv6 is 2^128 or 3.4 * 10^38.
Additionally, the discussion around IPv6 enabled OS causing issues does not describe the fact that most IPv6 enabled computers do not automatically tunnel with Teredo or 6in4 or 6to4, instead they get link local addresses on their ethernet links. Yes, Apple Airport Extreme will also allow for 6to4 mode and then assign global scoped addresses to IPv6 clients, but this is not truly default behavior. As IPv6 is a direction that we need to go, the more hurdles and security propaganda that is positioned to scare us away from using the technology, the harder and longer it will be to take the path to co-existence with IPv4.
Originally published on truman.net. See the archived copy.