Live data from Hacker News

By installing NAT, MIT stifles innovation

blog.achernya.com

101–110 of 188 posts

Re: By installing NAT, MIT stifles innovation

#101
post #62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

If your access point wont pass IPv6 traffic - you should consider another AP vendor. I have plenty of older network gear that cannot do IPv6 - but it passes the traffic along un-molested.

Re: By installing NAT, MIT stifles innovation

#102
post #69

Earlier quoted context omitted.

Many years ago in a past life, I worked on the network security team at the University of Chicago. We had a similar policy (and they may still for all I know) of just being able to requisition publicly routable IPs and run whatever you wanted on them with no default firewall rules applied at the border. Not for nothing did we call this a "target rich environment". For all of the cool things I got to do (troubleshoot…

> behind NAT/firewalls These are two separate things. There is no security difference between "route port 80 of one of our public IPs through to my NATted address" and "open port 80 for my public address". The public addresses are easier to administrate, troubleshoot, log, etc.

I agree. I meant the / to indicate that either one or a combination would have been helpful in different ways, but I certainly could have phrased it better.

Re: By installing NAT, MIT stifles innovation

#103

Wow - 2603:4000::/24. That's the largest block of IPv6 addresses I'm aware of being handed out to a single entity. Normally, ISPs get a /32, from which, they hand out /48s to their customer. And, with pretty much zero paper work, and ISP can get a second /32 (usually adjacent with their first /32 so they can summarize as a /31). So - an ISP might get 2001:1868::/32 and then hand off 2001:1868:0209::/48 to a customer.…

It has nothing to do with amounts of addresses, and everything to do with making dividing stuff up for routing easier. A large ISP entity like comcast or AT&T can now have say a single /16 or /24 allocation and pretty much no matter how much they subdivide up their regional routing, routing to AT&T can easily be coalesced and summarized , and every end customer can still get a /64 till pretty much the end of time.

Sometimes I wonder if we'll have an IPv6 shortage eventually. There aren't all that many /16 networks to go around.

Re: By installing NAT, MIT stifles innovation

#104

My college didn't have internet campus wise, you had access to a limited, firewalled internet "protected" by Fortinet so i can't feel empathy for the MIT alumni since you can perfectly work without those tools.

Sorry that your college doesn't see Internet access the same way MIT does. But don't you think that by making its campus network more unnecessarily restrictive, MIT is setting a bad example?

Re: By installing NAT, MIT stifles innovation

#105
post #62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

> Forcing people to use anything is never a good way to promote innovation.

Yes it is. Your previous paragraph shows exactly why. If left alone people will happily just use what alread works.

Re: By installing NAT, MIT stifles innovation

#107
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

Moving IPv4 to NAT and moving to IPv6 seems orthogonal.

Why do you say that? They're converging with the way the rest of the world* does things.

*Consumer, and Enterprises in the US

Re: By installing NAT, MIT stifles innovation

#108

Wow - 2603:4000::/24. That's the largest block of IPv6 addresses I'm aware of being handed out to a single entity. Normally, ISPs get a /32, from which, they hand out /48s to their customer. And, with pretty much zero paper work, and ISP can get a second /32 (usually adjacent with their first /32 so they can summarize as a /31). So - an ISP might get 2001:1868::/32 and then hand off 2001:1868:0209::/48 to a customer.…

It has nothing to do with amounts of addresses, and everything to do with making dividing stuff up for routing easier. A large ISP entity like comcast or AT&T can now have say a single /16 or /24 allocation and pretty much no matter how much they subdivide up their regional routing, routing to AT&T can easily be coalesced and summarized , and every end customer can still get a /64 till pretty much the end of time.

So what happens when we run out of /16 to give out?

Re: By installing NAT, MIT stifles innovation

#109
post #97
post #62

Earlier quoted context omitted.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

When MIT rolled out IPv4, the world wasn't ready for it either.

"Rolled out" is different from "forced to use".

If I come up with a super-awesome computer vision algorithm and want to run a server in my dorm room to demo it, being forced to use IPv6-only when the school has enough IPv4 addresses is a stupid annoyance and will only reduce the number of people that can reach the website. Running on AWS or other IaaS service isn't an option for many students without much cash.

Re: By installing NAT, MIT stifles innovation

#110
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

Yes, yes, it’s been three months since the provost triumphantly announced that IPv6 will finally be coming to the campus network, and communication about IPv6 on campus goes back much longer than that, but we have yet to see it in a single building (beyond the buildings where students have set up their own tunnels, and who knows if those will even work with the new network). Meanwhile, the NAT was deployed in twelve buildings with same-day notice and no prior communication, leaving some student groups with unreachable servers. If this had anything to do with pushing innovation, don’t you think the priorities and communication pattern would have been a bit different?
Post reply on HN