logoalt Hacker News

montecarl • today at 4:16 PM • 4 replies • view on HN

This reminds me of when I used to do IT work for small businesses in college. One printing company I worked for, had about 100 computers on their network, and was using public ipv4 addresses, that they did not own, on their internal network. I forget what range they were using now. But imagine seeing a DHCP server handing out addresses like 142.250.110.1/16 on a LAN and the public ip being something totally different.

It was funny, because when I brought it up to them, it was hard to articulate why it was a problem and I couldn't convince them it was worth the effort of trying to fix. They never ran into a specific issue due to this while I was there but it felt so gross.


Replies

masfuerte • today at 4:30 PM

The problem is that they wouldn't be able to talk to any internet service that legitimately used those addresses. Whether that was likely to be a problem very much depends on whose addresses they were.

irusensei • today at 4:28 PM

When I was working with Linux based kiosks and PoS systems I had a good share of issues with the Microsoft MVP signature use of .local on their forests. Back then their training material recommended .local for Active Directory services.

Brian_K_White • today at 4:40 PM

It's always hard because when you contrive possible examples of how it goes wrong, every single example sounds contrived because of course they are contrived.

Sure one day your printer might start spewing random json code meant for some microservice of the rightful IP owner.

Sure the IP's might be owned by the Air Force and one day they might start getting traffic from your pos ipad that they decide looks like an attempt to attack one of their internal secret networks...

Sure one day traffic meant to go to your printer ends up flooding and dossing a windmill controller, preventing the rightful operators from turning it the right direction during bad weather and causing $25M damage...

And of course the real failures are more like, only people from the Maldives can't send email to your email server, a failure with no impact.

deno • today at 4:29 PM

There's a good reason to do this if you can't be certain what reserved subnets are used in a given network and you absolutely need a static ip for some reason.

At least that's the conclusion I've arrived at at some point, but I don't remember what was the exact use case anymore.

However there are still several global IPv4 ranges that are not local reserved ranges but are effectively reserved and you could use them if you really want to without any issues.