Re: IPv6 supported?

"G.W. Haywood" <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
Hi there,

On Wed, 8 Jul 2015, Administrator wrote:

> It would be very useful if IPCop acknowledged the existence of IPv6.
> Without that, there seem to be security risks ...

It is not clear to me that acknowledging (or otherwise) the existence
of IPV6 has any real bearing on security risks.  From one of my /64s I
can assign to my toaster more IPV6 IPs than exist in the entire IPV4
address space.  But it's still just a toaster.  Incidentally NAT does
not generally figure in IPV6 networks, so the whole world, if it is in
the slightest bit interested, can talk to my toaster and can know that
it's my toaster that it's talking to.  Does the whole world care if I
have my toast very lightly done?  Do I care if the world knows or not?
Can a miscreant burn my toast?  The whole house?  Is it security risk?

> IPCop has VPNs "out of the box."  Do they protect against these
> information leakage issues?

Your questions are vague.  You need to be more precise with this kind
of thing.  A VPN is essentially something which joins two private nets
in a private (for some meaning of 'private') way using a channel which
can be intercepted by third parties.  The third party can tell when a
packet passes through the channel.  That is information leakage of a
kind, in that the third party can tell that the VPN is in use.  So a
burglar might infer from the week-long absence of traffic that you're
on holiday and it's a good time to burgle your flat.  Security risk?
People have had their homes burgled because they'd forgotten to cancel
the daily milk delivery.

If it should happen that the VPN client and server negotiate an
encryption key to use for the session, then the third party can
probably carry out what is called a 'man in the middle' attack, by
impersonating the client to the server and the server to the client.
When I use a VPN I would normally pre-share a private key using other
secure means to transfer the key.  The man-in-the-middle attack is
much more difficult in that situation.  I would not say that it is
impossible.  I am only using VPNs to join private networks and to keep
secure the traffic between them - I am not particularly interested in
hiding the existence of any of the traffic between the sites, nor in
hiding the identity nor the 'public Internet browsing habits', nor
even the electronic mail of the users on those networks which I have
joined; and I am not generally working in countries with oppressive or
criminal regimes although many people in such countries routinely
attack (routinely unsuccessfully) the systems which I operate.

> Can anyone with more understanding of these things comment?

As I said, your questions are vague.  More than what? :)

-- 

73,
Ged.

------------------------------------------------------------------------------
Don't Limit Your Business. Reach for the Cloud.
GigeNET's Cloud Solutions provide you with the tools and support that
you need to offload your IT needs and focus on growing your business.
Configured For All Businesses. Start Your Cloud Today.
https://www.gigenetcloud.com/
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.