[OpenWrt-Devel] IPv6 firewall and Port Control Protocol (Was: Barrier Breaker 14.07-rc1)

Sebastian Moeller moeller0 at gmx.de
Fri Jul 18 03:44:40 EDT 2014

Hi Karl,

On July 17, 2014 11:40:52 PM CEST, Karl P <karlp at tweak.net.au> wrote:
>On 07/17/2014 08:26 PM, Sebastian Moeller wrote:
>>        I argue that people unable to change the router settings are
>better of with all unsolicited inbound traffic disabled.
>I've tried to avoid weighing in on this, but I'd argue that you're
>wrong :) 
>Making sure that people can _never_ have services in the future, just
>they never had them in the past is a terrible way to live.

    It seems I was not clear enough: what I meant is: if one can not be added to expose a host IP and port range in one's router than maybe one does not really need the inbound connection to begin with. All that "people" in my statement need to do is google how to open the ports, not exactly rocket science, is it? People incompetent enough to not being able to open the ports on the router are unlikely to keep all their devices perfectly safe and updated (as if that is enough, given zero-day exploits, but I digress). Really, I do wonder how easy we want to make an attacker's job here ;)

Best Regards

