Re: [BEHAVE] Perils of structured host identifiers
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BEHAVE] Perils of structured host identifiers



On 6 jul 2009, at 21:26, marcelo bagnulo braun wrote:

Maybe this can be addressed by having the Pref64 i.e. the prefix used to make representations of IPv4 addresses in the IPv4 address space to be shorter than 32 bits. This would allow to have the Pref64+ IPv4 address shorter than 64 bits and we can still embed crypto info in the last 64 bits as done with CGAs

Why would the NAT64 need CGA IIDs in the bottom 64 bits of IPv6 addresses that represent IPv4 addresses?

CGAs are only useful when they're assigned to a host, not in the address space of protocol A that represents the address space of protocol B.

The concerns about privacy can be mitigated by using algorithms that scramble the bits of the IPv4 address around.

Sorry, but the idea that privacy should apply to NAT64 is stupid.

If you want privacy, set up an IPsec tunnel to the NAT64. Or get an ISP that you trust enough to let them see the destination addresses in your packets.

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.