Live data from Hacker News

By installing NAT, MIT stifles innovation

blog.achernya.com

91–100 of 188 posts

Re: By installing NAT, MIT stifles innovation

#91
post #77

Earlier quoted context omitted.

AWS does support ipv6 everywhere; the problem is that many consumers do not (I can't access ipv6 on my current provider w/o doing work on my side, for example) and so the need for public ipv4 is going to continue for years. I would be really happy to have only ipv6 addresses in my VPC, as that would make connecting up multiple VPCs much easier since I know their ip space won't overlap.

That's new. Last time I tried to get an IPv6 address for an EC2 instance it was either impossible or you had to set up this complicated virtual network thing depending on where your EC2 instance was physically hosted.

AWS will give each VPC a /56, and each subnet a /64

https://aws.amazon.com/blogs/aws/new-ipv6-support-for-ec2-in...

Again, the thing I would like to see is being able to either peer only ipv6 for VPCs, or have a VPC that is ipv6 only. That to me will greatly increase flexibility and simplicity if I'm ok with an ipv6-only deployment

Re: By installing NAT, MIT stifles innovation

#92
post #62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

I am almost positive I saw IPv6 in the release notes for the latest Google Wifi app update, am I crazy?

Re: By installing NAT, MIT stifles innovation

#93

I moved to student housing in Sweden in 2004 when they had aging network infrastructure (all 100 MBit but that also applied to the shared links to the housing areas[0]), and by the next year they just ditched the school-sponsored network and moved to making students pay for third party internet (distribution to rooms was still Ethernet-based but now with a citywide fiber backhaul run by the municipal power company sh…

It's not about what innovate service a university can provide: it is about what kind of innovation the university can help empower its students to make.

Re: By installing NAT, MIT stifles innovation

#94
post #48
post #35

Earlier quoted context omitted.

> MIT is just moving to IPv6. The "just" is incorrect. There are four bullets on the slide: DHCP, IPV6, private IPV4/NAT, and firewall. From the diagram it looks to me like even if you move to IPV6 (which, as others have noted, MIT has not yet rolled out, so at this point you can't), you will still be behind the firewall, so setting up a service visible to the Internet will still be more difficult than it used to be.

The post isn't objecting to the firewall, though. I totally understand the need for a campus-wide firewall. The MIT network is a juicy target for botnets, and individual students are not good enough at running security on their own computers. The old approach to IP assignment was that you needed to get your IP approved and made routable by IS&T anyway, and if they detected botnet activity on your computer, they'd man…

Independent living communities controlled this process using an automated registration system. In my living group I was elected to the position democratically, attended a training seminar, and passed down the knowledge to my successor. I hope they continue to give the students the same autonomy.

But I have my doubts. http://pilot2021.com/index.html

Re: By installing NAT, MIT stifles innovation

#95
post #62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

> Forcing people to use anything is never a good way to promote innovation.

Of course it is. That's how innovation happens. They are focused on overcoming a constraint of the system they operate within. In this case, it will be to get around the limitations of the private IPv4 network, or to make the upcoming IPv6 network easier and more appealing to use.

Most innovations are to overcome some sort of limitation, whether that is with a man-made system or just the laws of nature as we currently understand them. Unbounded innovation hardly ever occurs and usually results in some shitty mobile game.

Now that's not to say MIT IS&T isn't behaving extraordinarily shitty here. But this won't stifle innovation, just refocus it. Whether that's towards a more worthy goal is certainly up for debate.

Re: By installing NAT, MIT stifles innovation

#96
post #70

Earlier quoted context omitted.

But that would just be ridiculous, considering that experimenting with Tor relays is like a favorite student passtime...

And hosting websites is? I don't see the average student doing that either. I do, but then I also hosted hidden services, relays and exit nodes...

Well, an average student isn't going to do anything interesting. The MIT I know works to enable its most resourceful and enterprising students, and is not satisfied with just enabling "being average".

Re: By installing NAT, MIT stifles innovation

#97
post #62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

When MIT rolled out IPv4, the world wasn't ready for it either.

Re: By installing NAT, MIT stifles innovation

#98

I wonder if any of this is related to the new NIST Standards[1], which have to be followed by research labs who receive government funding. I could see MIT, already having to retrofit a lot of their research networks, also changing around the network architecture in other places aswell. [1]: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP...

Nah, NAT doesn't provide the security; firewalling does. Besides, what kind of controlled unclassified information could possibly be residing on dormitory networks?

Sorry, but NAT provides practical security for all but the most pedantic use cases.

I'm terrified of IPv6 for this exact reason - it assumes every device will have direct access to the Internet. As we've seen with security cameras and other IoT devices, they just aren't designed to protect themselves and are easily hackable, so making them accessible to the wider Internet is crazy. Firewall options for IPv6 for most home routers are limited at best at the moment... I for one am quite happy to have all my local devices happily running behind an IPv4 NAT (in addition to a firewall), knowing they can't be targeted directly without some sort of concerted effort.

Re: By installing NAT, MIT stifles innovation

#99

Earlier quoted context omitted.

It has nothing to do with amounts of addresses, and everything to do with making dividing stuff up for routing easier. A large ISP entity like comcast or AT&T can now have say a single /16 or /24 allocation and pretty much no matter how much they subdivide up their regional routing, routing to AT&T can easily be coalesced and summarized , and every end customer can still get a /64 till pretty much the end of time.

I totally understand why Comcast, AT&T, Verizon and other service providers would want /16s. They are continent wide providers with millions of customs (millions of sites). I'm trying to grok why MIT went for a /24 instead of a /32. Because they could?

Because they are replacing their /8. They want to make sure they are never constrained.

Re: By installing NAT, MIT stifles innovation

#100
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

Moving IPv4 to NAT and moving to IPv6 seems orthogonal.

Not if you're selling your IPv4.
Post reply on HN