As IPv6 Launches, It’s Time to Worry About Security

執筆者
eweekdev
eweekdev
Published: Jun 6, 2012
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

By: Robert Lemos

Providers, large Web content providers and home router makers teamed together on Wednesday to launch their services on the next-generation Internet Protocol version 6, or IPv6.

The effort, known as IPv6 World Launch Day, should change little for enterprise users and consumers, but IT groups at companies should take notice. Like any technology transition, the change to IPv6 can cause problems, including issues that can affect companies’ security. Security researchers and some attackers have already started looking at IPv6 security and most enterprise security teams will be behind the curve, said John Spence, vice president of IP services for consulting firm Nephos6.

“One of the significant risks is that the hacker community is ahead-on exploiting V6-of the security professionals who are securing V6,” he said. “So there is a temporary advantage [for the] attacker, because of the V6 transition that, hopefully, will get corrected.”

On Wednesday, Facebook, Google, Microsoft’s Bing and Yahoo all permanently enabled their presence on the IPv6 Internet. In addition, at least 65 Internet providers have committed to transitioning at least 1 percent of their subscribers to IPv6. Large home router manufacturers have also made IPv6 the default communications protocol for their hardware.

The Internet Society claimed that this new support for the protocol meant that adoption is taking off.

“IPv6 is not just a ‘nice to have’; it is ready for business today and will very soon be a ‘must have,'” Leslie Daigle, chief Internet Technology officer for the Internet Society, said in a statement on June 6.

Yet companies thinking of moving their infrastructure to IPv6 should beware of two major issues, said Nephos6’s Spence.

Companies need to be mindful of the gap between their IT teams’ knowledge of IPv4 and their lack of expertise with IPv6. The technology and corporate IT staff will not be ready to completely handle IPv6, and that could leave security lacking, he said. Companies should do their research and only deploy IPv6 technology when their staff is properly trained and the security software and appliances on which they rely are mature enough to provide protection similar to the level on IPv4.

Advertisement

“It is important not to deploy V6 in advanced of having the security tools at V6 at parity of the security tools for V4,” he said.

Also, companies should beware of networking hardware and computing systems that are configured to be IPv6-friendly. In many cases, routers and operating systems will attempt to connect to any IPv6 devices first-a user-friendly situation for consumers, but a potential pitfall for enterprises. Many companies may have systems that have created inadvertent tunnels to the IPv6 Internet, effectively a backdoor that could be exploited by hackers, Spence said.

Making devices easy to set up on home networks “is probably a good thing in an unmanaged environment,” he said. “But you don’t want PCs in the enterprise to build back doors to the IPv6 Internet [just] because they’re trying to be helpful.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。