logoalt Hacker News

bb88today at 4:34 AM0 repliesview on HN

You're talking IPv4 here, not IPv6. A 24 bit network has 254 addresses in IPv4. A 64bit subnet in IPv6 has 2^64.

If you can scan 1M ipv6's in a second, you can maybe scan 1 subnet in 584,942 years.

So if you're a firewall, and you notice scanning from a particular ip or network, it's easy enough to block them.

Also if you are scanning IPv4, you're not scanning addresses behind the NAT'd routers -- which is also effectively a form of obfuscation. So I would argue it's not the entire internet.