Live data from Hacker News

Is there hope for IPv6?

internetgovernance.org

331–340 of 399 posts

Re: Is there hope for IPv6?

#331
post #281
post #236

Earlier quoted context omitted.

It is easy enough to criticize the IETF and the wider IPv6 community for the mistakes they made. But as far as I know, nobody came up with a credible protocol that is fully backward compatible with IPv4. So, you can ask the IETF to come up with a magically protocol that has longer addresses and is still backward compatible with IPv4. But they are only human. So that kind of magic is not going to happen.

Wouldn’t a predefined mask for IPv6 addresses do exactly that? The last 32 bytes of the address could easily be an IPv4 address I should think.

Nope, because:

- you would need to restrict yourself to an extremely tiny fraction of the v6 space that's the same size as the v4 space

- you couldn't use any IPs that correspond to in-use v4 IPs because they would overlap

- you couldn't use any IPs that correspond to unusable v4 IPs, for the same reasons you can't use them in v4

- you'd have to talk a protocol that looks the same as v4 on the wire, because otherwise v4 hosts won't be able to handle it

You know what we call that? We call it IPv4.

Re: Is there hope for IPv6?

#332
post #310

I hope (but am skeptical) that folks look at the overall failure of ipv6 from a deployment perspective to understand the root causes of why it failed (some may think "failure" is too strong a word, but I remember v6 being "just around the corner" in 2000, yet in 2019 I'm still connecting to a GCP database with v4). Coming up with a solution that looks like a huge technological advancement, with no real respect for th…

It was a monumental mistake to make IPv6 incompatible with IPv4.

What do you mean "incompatible"? You can run both of them at the same time, they work on the same links, in the same OS stacks, with the same programs, and you can talk between them or tunnel over them with a variety of transition mechanisms (dual stack, Teredo, 6to4, 6rd, 6over4, ISATAP, 6in4/4in6, NAT64/DNS64, 464xlat, DS-lite, MAP-T/E, 4rd, LW4over6, ...).

They're about as compatible as they can possibly be, given the design of v4.

Re: Is there hope for IPv6?

#333
post #214

Earlier quoted context omitted.

Elsewhere, the ISPs are doing the IPv6 rollout in the worst possible way imaginable: DS-Lite with no PCP for AFTR (i.e. no way to have incoming IPv4), and allocating only /64 subnet, where their CPE is mandatory in router mode, no way to switch it to bridge mode (thus losing control of your own gateway. I'm talking about you, UPC/Liberty Global). For just consuming the web, it is fine. For switching from public IPv4,…

NAT traversal (hole punching) works for CGN well, doesn't it? sure you need a coordinator/RP between to CGNed users, but that is not really an issue as far as I know.

This will not help you if you have something like an IP camera that you want to access from outside your home, since the address will change frequently.

The only good thing about UPC/Liberty global's implementation of DS lite (now "Ziggo" where I live) is that they will switch it back to IPv4 with a single phone call to the help desk. I can live without IPv6, I cannot live without being able to reach my home server and IoT things.

Re: Is there hope for IPv6?

#334

Earlier quoted context omitted.

Isn't it? I thought we were talking about NAT, not about RFC1918. Even NAT in combination with RFC1918 doesn't give you security. The use of RFC1918 would certainly limit the set of people that could connect to your LAN machines, but it would be hard to call the result secure since anybody sharing your upstream L2 network, plus your ISP and anyone who can trick, force or coerce them into cooperating could still acces…

> call the result secure since anybody sharing your upstream L2 network, plus your ISP and anyone who can trick, force or coerce them into cooperating could still access your network Ok, so the L2 thing isn't unheard of, but otherwise these are relatively unrealistic scenarios to be concerned about, don't you think?

I guess, but the fact remains that using RFC1918 is still both more effort and less secure than just using a firewall is, and that NAT doesn't help the situation.

Do you really want the security of your network to rely on your ISP always doing the right thing for you?

Re: Is there hope for IPv6?

#335
post #271

Earlier quoted context omitted.

That would normally be called CGNAT. Yes, that does change things somewhat... except what's actually going to happen is that people will record the port number and the time as well as the IP, and the ISP is going to record every single connection you make in a big database, and then bill you for the privilege of doing it. Law enforcement will still be able to identify you, now your ISP has a record of everything you'…

As far as I know, several court cases in Germany have confirmed[1] that the mapping of dynamically assigned IP to customer identity may only be stored for 7 days. I imagine the same upper bound, or an even tighter one, applies to the records you are talking about. [1] https://www.e-recht24.de/news/datenschutz/10387-datenschutz-... (in German)

Around here I'd expect something more like a 7 year minimum to be more likely...

Limiting the timeframe does improve the costs and the privacy impact, but the ISP will still need to build and run all of the logging infrastructure, and the end result is that you'll still be identifiable.

Re: Is there hope for IPv6?

#336

Earlier quoted context omitted.

> Literary, every modern ISP This is either factually incorrect, or else you're using a definition of "modern" that excludes a substantial portion of real world isps.

It in fact excludes most ISPs in many countries.

yup, modern is a qualification meaning that they support current internet standards, not only legacy

as per internet standards/rfc’s IPv4 is a legacy protocol, so every ISP limiting it’s customers to only this veraion is not considered modern

Re: Is there hope for IPv6?

#337

Earlier quoted context omitted.

I use copy and paste for both IPv4 and IPv6 addresses. I understand where you are coming from by adding a few more bytes to the address scheme but one of the things IPv6 was designed for was massive address aggregation which means really short routing tables. Your 192.192.168.168.0.0 (say) scheme does not go far enough. Also, your scheme needs to be efficient in the world of bits and bytes and I don't think it is. Yo…

The recommendation is to assign a /56 to end users from an ISP. That would give you plenty of subnets to work with. /56 == 256 /64s Each /64 == 18,446,744,073,709,551,616 addresses

Sadly, plenty of ISPs use DS-Lite with a single /64 issued.

(I'm looking at you UPC/Virgin Media/Liberty Global)

Re: Is there hope for IPv6?

#338
post #78

Earlier quoted context omitted.

It in fact excludes most ISPs in many countries.

To be precise this excludes 75% of all autonomous systems in the world, which is at least 75% of all ISPs plus those that connect to 25% of IPv6 capable autonomous systems, but still don't use IPv6. So we are talking like 80% of all ISPs in the world.

every ipv4 only isp is legacy, not modern

basically they are the edissons of electricity boom era when AC was becoming the new standard for power transfer

Re: Is there hope for IPv6?

#339
Nice blog..! I really loved reading through this article. Thanks for sharing such a amazing post with us and keep blogging... Best" rel="nofollow">https://www.credosystemz.com/training-in-chennai/react-js-tr... React js training near me | React" rel="nofollow">https://www.credosystemz.com/training-in-chennai/react-js-tr... js training online

Re: Is there hope for IPv6?

#340
post #319

Earlier quoted context omitted.

Depends on your skill set. If you're ok with *nix, then PowerDNS is pretty simple to work with: https://github.com/PowerDNS/pdns It's also fairly complete, used in production by some pretty big ISPs. For a light weight approach instead, Dnsmasq is good: http://www.thekelleys.org.uk/dnsmasq/doc.html It's what most home routers (and lots of other stuff) embed. :)

Ok, fair enough. It’s fairly simple to set up. It’s just a bit of a pain to maintain if the only thing you care about is connecting to server nr 192.168.0.x I could certainly do it, but there’s 5 services in my house I’d care to connect to, and remembering 1-5 is just as easy as giving them all names. The marginal gains are very low.

Oh, I very much agree. For very small local networks in a flat address space, manually remembering stuff works ok.

Personally I tend to throw the more stable IP addresses in /etc/hosts, as that's simple too. :)

Post reply on HN