public inbox for netdev@vger.kernel.org 
 help / color / mirror / Atom feed
From: Fernando Gont <fernando@gont•com.ar>
To: Jan Engelhardt <jengelh@inai•de>
Cc: netdev <netdev@vger•kernel.org>
Subject: Re: VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts
Date: Wed, 28 Nov 2012 23:29:57 -0300	[thread overview]
Message-ID: <50B6C8A5.2090404@gont.com.ar> (raw)
In-Reply-To: <alpine.LNX.2.01.1211282203310.11510@nerf07.vanv.qr>

On 11/28/2012 06:37 PM, Jan Engelhardt wrote:
>> On 11/28/2012 05:06 PM, Jan Engelhardt wrote:
>>>> If the VPN is supposed to secure all traffic, and the VPN just fails to
>>>> support v6, then for me, it's questionable to have your traffic leak out
>>>> the VPN just because of that lack of IPv6 support.
>>>
>>> Well, what I am saying is that a server may not
>>> be conveying "all", but only "0.0.0.0/0"[0/0].
>>
>> In such scenarios, doing nothing about IPv6 would be an oversight/error,
> 
> Without additional input from the user, e.g. by means of a config 
> setting, the software itself cannot distinguish between an 
> oversight/error and a deliberate configuration.

Exactly. So fail on the safe side, and disable IPv6. Most users
forwarding all IPv4 traffic are meaning to secure all their traffic with
the VPN.

If you do nothing about v6, then it just takes a local attacker to
trigger v6 connectivity (or the user to connect to a dual-stacked
network) for the supposedly-secure traffic to go out in the clear.

Many people don't realize that v6 and v4, while being to different
protocols, are sticked together by means of the DNS. And the
aforementioned issue will come up as a surprise in most scenario.

Not to mention that nowadays, you will miss virtually nothing on the
Internet by having v6 off.

Thanks,
-- 
Fernando Gont
e-mail: fernando@gont•com.ar || fgont@si6networks•com
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1

  reply	other threads:[~2012-11-29  2:47 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-11-27 14:54 VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts Fernando Gont
2012-11-27 16:04 ` Eric Dumazet
2012-11-27 16:07   ` Fernando Gont
2012-11-27 16:22     ` Michal Kubeček
2012-11-27 16:10 ` Jan Engelhardt
2012-11-28 19:57   ` Fernando Gont
2012-11-28 20:06     ` Jan Engelhardt
2012-11-28 20:14       ` Fernando Gont
2012-11-28 21:37         ` Jan Engelhardt
2012-11-29  2:29           ` Fernando Gont [this message]
2012-11-29  3:15             ` Jan Engelhardt
2012-11-29  4:38               ` Fernando Gont

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=50B6C8A5.2090404@gont.com.ar \
    --to=fernando@gont$(echo .)com.ar \
    --cc=jengelh@inai$(echo .)de \
    --cc=netdev@vger$(echo .)kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox