Emily! :Blobhaj_Witch_Broom: on Nostr: npub10cq07…a6nm3 Haelwenn /элвэн/ :triskell: correct, altho if you’re going ...
npub10cq07ulfyc7y2l8rczk9s36g8j65tq3m6xk9us8hr3ua4ktfmaqq9a6nm3 (npub10cq…6nm3) Haelwenn /элвэн/ :triskell: (npub1ysu…2jyl) correct, altho if you’re going that far you might as well net.ipv6.conf.<iface>.accept_ra=0 and set your IPs directly
blocking RAs would be equivalent to making a dhcp client which gets very angry and doesn’t accept an IP unless it’s from that specific subnet of france (because “otherwise it’s just sparkling packet spoofing”). sounds cool until you realize that DHCP{,v6} and RAs were meant for autoconfig, not security, and manually deploying rules like those for all your clients kinda invalidates the concept
blocking RAs would be equivalent to making a dhcp client which gets very angry and doesn’t accept an IP unless it’s from that specific subnet of france (because “otherwise it’s just sparkling packet spoofing”). sounds cool until you realize that DHCP{,v6} and RAs were meant for autoconfig, not security, and manually deploying rules like those for all your clients kinda invalidates the concept