• 16 Posts
  • 2.58K Comments
Joined 1 year ago
cake
Cake day: June 23rd, 2023

help-circle











  • Governments are not anyone’s issue other than other governments. If your threat model is state actors, you’re SOL either way.

    Making it harder for everyone else is the goal, and to do that you need a swiss cheese model. Hopefully all the holes don’t line up between the layers to make it that much harder to get through. You aren’t plugging all the holes, but every layer you put on makes it a little bit harder.

    And NAT is not just simple to set up, it’s the intuitive base for the last 30 years of firewalls. I don’t see where you get a cost from it. As I said, separating network spaces with it comes naturally at this point. Maybe that’ll change, but I remember using routable IPV4 when it was it the norm, and moving to NAT made that all feel way more natural.