Worth Reading: NatJack
The passage argues that NAT should not be treated as a security feature, noting that NatJack documents multiple real attacks against common NAT implementations and mocking predictable dismissals that such issues are merely theoretical.
MAIN POINTS
- NAT security claims are criticized as a sign of poor design choices.
- NatJack documents several attacks against typical NAT implementations.
- The author expects defenders to dismiss the attacks as theoretical.
- A “remote host cannot reply” argument is compared to outdated security denial.
TAKEAWAYS
- NAT provides address translation, not meaningful security guarantees.
- Documented attacks weaken the case for relying on NAT as protection.
- Security debates often repeat old, unconvincing objections.
- Practical evidence matters more than theoretical comfort in network design.