HN user

bcook

1,139 karma

:)

Posts2
Comments620
View on HN
Google Pixel 9 Pro 2 years ago

I paid $1000 cash for my Samsung Galaxy S10+ and the 5½+ years with it have been flawless.

I was very hesitant to spend $1000 on my first smartphone but if it can easily last 5 years, I'm impressed.

Even now, I can't think of a reason to upgrade aside from wanting a new, shiny gadget.

The telephone companies seem to actively push for you to get rid of your land line. My monthly bill recently dropped $75 ($50 for local-only phone service + fees like 911), when I canceled my land line.

My 100mbit VDSL2 bonded internet line is $75, so it was a very noticeable monthly decrease. My ISP/Telco is Windstream in the eastern USA.

As someone who has carried a pocket knife for most of my life, I very rarely think of the knife as a weapon. When I was younger, me and my friends would throw knives at trees. Sometimes we would throw hatchets at trees. It's fun and very satisfying to finally stick the knife/hatchet.

Violence was never in my thoughts.

NAT Types 3 years ago

The scenerio I commonly see is a dual-stack (IPv4 & IPv6) router blocking all unsolicited incoming IPv4 packets (because of NAT), while all IPv6 LAN hosts will unintentionally be globally accessible through the internet.

This is why I worry about more IPv6 deployment. Too many people are ignorantly relying on IPv4 NAT as a layer of protection.

NAT Types 3 years ago

And by the way, nobody, noone forbade you from having explicit firewall rules denying anything from anywhere, not explicitly allowed. Just like it is done in a proper IPv4 configuration.

Sure, in a perfect world, migrating to IPv6 should be safe, but the default configuration on many ISP-supplied routers has no firewalling beyond what NAT offers.

NAT Types 3 years ago

I worry about the loss of the implicit firewall that NAT offers.

Network security audits of dual-stack networks far too often show practically no open ports on IPv4, because of NAT, while IPv6 exposes everything. The security through obscurity of the practically unscannable IPv6 address space is not a firewall.

Take a close look at how that question isn't answered.

I think that's the joke. I prefer this non-answer over a long-winded bullshit answer that ultimately means nothing.

In case you're unaware, "goatse" doesn't have anything to do with goats or animals or anything good.

Don't Google it.

Because of colons. Colons separate the different sections of an ipv6 address but HTTP URLs also use colons for the port, so the ipv6 IP must be encompassed in brackets to differentiate between IP and port.

I was much more confused by your post than I should've been because I overlooked that ">" is how HackerNews prefixes quoted text.

I vastly prefer blogs and githubs that aren't mainstream. Like BIOS/UEFI security blogs or the very useful kefctl github with 40 stars (CLI control of my Kef LS50W).

I left Facebook over a decade ago because doing things "to be talked about" felt awful. Focusing on sharing information to help others, rather than to stroke my ego, is much more rewarding.