Live data from Hacker News

A brief history of IPv4 address space exhaustion

blogs.igalia.com

21–30 of 89 posts

Re: A brief history of IPv4 address space exhaustion

#21
post #5

I now receive a block of IPv6 from Comcast. I allow the router to assign them to devices on the network, but I admit that I am somewhat worried that my local PC is no longer isolated from the Internet by a private IP.

I think whilst it's nice to have that barrier, it's prevention rather than cure anyway. There's no substitute for secure devices :)

what's more secure than a device you cannot possibly reach?

I'll take an insecure device isolated at the bottom of the ocean in a titanium block over a probably-secure device that is publicly addressable any day.

Re: A brief history of IPv4 address space exhaustion

#23
post #5

I now receive a block of IPv6 from Comcast. I allow the router to assign them to devices on the network, but I admit that I am somewhat worried that my local PC is no longer isolated from the Internet by a private IP.

I think whilst it's nice to have that barrier, it's prevention rather than cure anyway. There's no substitute for secure devices :)

Which devices are secure?

Re: A brief history of IPv4 address space exhaustion

#25

Earlier quoted context omitted.

I don't think that perception is accurate. Google's IPv6 tracker shows continual progress: https://www.google.com/intl/en/ipv6/statistics.html (with the expected bumps around weekends and holidays) It's not a fast process, but I don't see any evidence it is stalled.

How much progress is simply due to mobile? Not a bad thing, but legacy ISPs seem to be updating at a glacial pace.

Comcast is one of the leaders in this space in the US. They are nearing 100% deployment and their X1 platform is supposed to run IPv6 only internally (SetTop Boxes to their content source).

Verizon on the other hand hasn't done shit.

Re: A brief history of IPv4 address space exhaustion

#26
I find DJB's take on this interesting: https://cr.yp.to/djbdns/ipv6mess.html

EDIT: Dan has many excellent points, but I'd like to quote my favorite:

The IPv6 designers made a fundamental conceptual mistake: they designed the IPv6 address space as an alternative to the IPv4 address space, rather than an extension to the IPv4 address space.

Indeed, what were they thinking!

It's certainly an undeniable fact that IPv6 adoption has been a disaster, taking much longer than hoped for. Frankly, I expect to see IPv4 coexist with IPv6 for the next hundred years - not ideal.

Re: A brief history of IPv4 address space exhaustion

#27

I now receive a block of IPv6 from Comcast. I allow the router to assign them to devices on the network, but I admit that I am somewhat worried that my local PC is no longer isolated from the Internet by a private IP.

Be sure that you are really isolated if relying on it for protection. Its only as secure as the least secure node inside the bubble, and there can be quite a dangerous in large networks like in a company or campus. It would not surprise me if a number of WannaCry victims was behind nat and got infected by a machine on the same local network.

Re: A brief history of IPv4 address space exhaustion

#28
post #5

Earlier quoted context omitted.

I think whilst it's nice to have that barrier, it's prevention rather than cure anyway. There's no substitute for secure devices :)

what's more secure than a device you cannot possibly reach? I'll take an insecure device isolated at the bottom of the ocean in a titanium block over a probably-secure device that is publicly addressable any day.

Your appliance 'router' can (and probably does) run a firewall to give you that kind of control. NAT never really gave you that.

Re: A brief history of IPv4 address space exhaustion

#29
post #5

Earlier quoted context omitted.

I think whilst it's nice to have that barrier, it's prevention rather than cure anyway. There's no substitute for secure devices :)

Which devices are secure?

Certainly not the 'router' running your NAT.
Post reply on HN