Hacker News new | past | comments | ask | show | jobs | submit login

Mr. cube00, for a static website it's a toss-up (you should activate it anyway if you're able to!).

The problem is that (for example) for forums etc., 40-bit addresses (the best-approximation considering that only a slice was allocated and /64 is treated as a single network connection) adds a whole lot of problems when it comes to combating spam etc. 8 bits sounds like nothing to you but you multiplied their problem 256 times. In shorter words, it's not always economical to turn the proverbial switch on. For Google, they can rely on their AIs but for small forums? That's just (unfortunately) an additional attack surface on something that they want to be gone.




How do you make sure that the single IPv4 address you are blocking is not used for CGNAT? When you don't care about collateral damage you could as well block IPv6 /40 or /48s. Currently this is maybe not a problem yet because most people don't have CGNAT addresses but the problem will become bigger.


Hotmail sometimes blocks not only my IPv4 address, but the entire subnet. We already have collateral damage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: