Hacker News new | ask | show | jobs
by mitchs 1206 days ago
The big issue with v6 is you don't know what every ISP is doing with their IP space. The current RIPE recommendation is to delegate somewhere between a /48 to a /56 to every customer. Some ISPs might only delegate a 64, and perhaps typical home wifi setup may only use a single /64. For data aggregation maybe the error is ok, but I've wondered about what IP banning/filtering looks like for v6. Assume everyone gets a /64 and most cats will have 256 lives, and sometimes 16384. Assume everyone has anything larger than a 64, and you may block 255+ other people with the intended target.
2 comments

IP based bans have long been obsolete imo. These days a combination of google captcha tracking and phone number verification is mostly used. A few things like IRC and 4chan still do IP bans which is painfully obvious when you notice you are randomly banned depending on what CG-NAT handed you at the time.
Start by banning /64's, but if you see a lot of nearby bans in some ASN, mark that one for bigger bans. Easy-peasy-ish.