

Assuming the risk of being naive… Why is checking the hash not enough?
Or didn’t I understand your problem?


Assuming the risk of being naive… Why is checking the hash not enough?
Or didn’t I understand your problem?


Don’t know what to say,
I maintain a double stack since 5 years and apart of some small nuisance I never had a real problem.
Ipv6 has been with us for more than 20 years, and It is true that to have that fine grain control in ipv6 you will need to go to a prosumer devices, but those are not that expensive and if you have a home lab you should check on them anyway…
Things are mature despite your bad experiences


Well…
Ipv6 is needed for peer to peer networks, easier for vpn and full mndgoru if you want to have a vps…
With it, you can avoid Cgnats and home Nats and usually it is faster and more reliable than ipv4.
So, see it for yourself…


The only thing I can tell is that it is totally worthless.
Because you can not have an uga ipv6, then obviously you will have an ula served via dhcpv6 with ipv4 local address (double stack).
And in this point you will realize that most computers implementation select which ip address to use following prio: ipv6 uga -> ipv4 -> ipv6 ula
So even if you do all the things right, your clients will not use it because ipv4 is there and you cannot deselect it because I assume you still want connectivity
Funny, right? :)
Got it, I thought it was a last segment attack (image substition) but now I see you are aiming to a fully supply chain attack.
And if you find an nswer to that, please let me know because this things have virtually not a solution that ticks all boxes