Hacker News new | ask | show | jobs
by tenebrisalietum 2600 days ago
NAT is not a security layer. It's possible through techniques like STUN and such to discover and reach hosts behind a NAT.

CG-NAT is crippling because I want to receive incoming connections like anyone else who has a connection to the Internet should be able to. Router manufacturers can do better. The world does not have to consist solely of cloud-based middle-men who take full advantage of the fact that all your data has to pass through them, and that you have to trust them.

1 comments

What's somewhat ironic to this discussion is that some Linksys routers modify STUN responses, which breaks legitimate functionality if the router is used with dual-NAT or CG-NAT:

https://www.voip-info.org/stun

Both Linksys and CG-NAT need to be avoided.