Live data from Hacker News

Who is squatting IPv4 addresses?

blog.benjojo.co.uk

141–150 of 208 posts

Re: Who is squatting IPv4 addresses?

#141
post #140

Earlier quoted context omitted.

The acquisition's IPs might not conflict with IBMs, but surely they conflict with those of the other acquisitions? Is there any benefit after the first acquisition?

My point is that if every company uses real IPs then you can merge networks with no conflicts. 10/8 is fine for home use but not for enterprise networks.

In a word where any medium sized company could just get a /20 network and any enterprise could get a /8 I would agree, but with IPv4 we live in a world where the vast majority of companies don't have anything but 10/8 (and a couple of IPs for public facing stuff).

The only real options besides 10/8 are to have been big at the advent of the internet (like IBM or Apple) or misappropriate one of those IP blocks in the hope it never becomes publicly routable.

Re: Who is squatting IPv4 addresses?

#142
post #123

Earlier quoted context omitted.

It's not relevant whether or not it's accessible from the internet. And that 9/8 allocation predates RFC1918 by at least four years.

I'm curious what you mean by this. RFC1918 is just an update for earlier RFCs that go back farther in time, like RFC1597. And IBM people are credited on the relevant RFCs. IBM is basically hoarding a bunch of addresses where there's no technical reason to. I get that they aren't required to do anything about it, but it does seem topically relevant.

IBM owns Softlayer. They may have a legitimate need for that many addresses. :)

Re: Who is squatting IPv4 addresses?

#143
post #54

Interesting work, but IMHO anything that extends the life of IPv4 does active harm. I'd prefer if these addresses stay out of the pool so scarcity increases and forces people to upgrade. IPv4 is fundamentally too small, period. There are already more people and computers on Earth than possible IPv4 addresses even if it were perfectly optimally used. It leads us further down a path in which everything is behind increa…

The total population I don't find to be a very strong argument, because all that matters is the population of people who desire to communicate with my service. If people not able to communicate with my service also don't want to communicate with my service and I don't see a need for them to communicate with my service, why do we both need the same protocols? Something I have observed is that sites that tend to attrac…

As for point one: I'm not talking about client/server access to services. I'm talking about the capacity for endpoints to talk to each other. IPv4 would be fine if we want a fully centralized computing infrastructure where everything is only a thin client, but that's a future with zero privacy or personal freedom.

I don't think there's anything special about IPv4 in terms of DDOS mitigation. What you're probably seeing is an artifact of focus and investment. IPv4 is still the lowest common denominator standard. Virtually everyone can talk to an IPv4 endpoint. As a result the DDOS protection services still mostly use IPv4 endpoints because it reduces the amount of attack surface they have to protect. If they were dual-stack they would have to deal with BGP black holing on what amounts to two BGP networks instead of just one.

DDOS is something that desperately needs a more comprehensive solution, but it's a hard problem to solve. Right now the solution is for DDOS protection services to run bastions with enough bandwidth to absorb attacks, but that's a solution that constricts innovation tremendously. I feel like a permanent solution would require cryptography to be designed into the entire network so that you could do things like rate limit packets to your host for people who didn't present a certificate. That would require a deep redesign of the entire network though, and that's not going to happen.

Re: Who is squatting IPv4 addresses?

#144

Earlier quoted context omitted.

I'd rather the ISP pushed for IPv6.

We are at least at the ISP I work for. That is a major project for us this year, but any network engineer can tell you that deploying IPv6 is not straight forward at the ISP level. Getting everyone together on how to have some standard form of addressing from different entities is the toughest lift. Get Juniper, Cisco, and Arista on the phone and you will get three different ways on how to deploy it. You don't want t…

Interesting. What are the big differences if you're allowed to talk about it? I have no doubt that the IPv6 rollout is difficult, I helped move some simply cloud stuff to IPv6 and even that had a few issues. I'm much happier without the heavy layers of NAT though.

Re: Who is squatting IPv4 addresses?

#145

I don't understand why was the next version of IP not just identical to IPv4 but with more bits in address space? Were they trying to do too many things at once in the 90's?

I think D.J.Bernstein has the same question -- and has for 20 years now :^)

https://cr.yp.to/djbdns/ipv6mess.html

Re: Who is squatting IPv4 addresses?

#149

I don't understand why was the next version of IP not just identical to IPv4 but with more bits in address space? Were they trying to do too many things at once in the 90's?

I think D.J.Bernstein has the same question -- and has for 20 years now :^) https://cr.yp.to/djbdns/ipv6mess.html

This has been addressed hundreds of times but I guess DJB doesn't care. He just lit the fuse and walked away.

Re: Who is squatting IPv4 addresses?

#150
post #143

Earlier quoted context omitted.

The total population I don't find to be a very strong argument, because all that matters is the population of people who desire to communicate with my service. If people not able to communicate with my service also don't want to communicate with my service and I don't see a need for them to communicate with my service, why do we both need the same protocols? Something I have observed is that sites that tend to attrac…

As for point one: I'm not talking about client/server access to services. I'm talking about the capacity for endpoints to talk to each other. IPv4 would be fine if we want a fully centralized computing infrastructure where everything is only a thin client, but that's a future with zero privacy or personal freedom. I don't think there's anything special about IPv4 in terms of DDOS mitigation. What you're probably seei…

I'm not clear that IPv4 doesn't offer at least one measure of reduction against a DDoS, and that's just one time hits every second from 1 quadrillion unique IPv6 addresses. You simply can't have that level of problem in IPv4. However, I have never been on the inside of a DDoS attack, so I don't speak from experience on this.

In regards to mitigation, what we are talking about is an exclusive network with central controllers in the form of ICANN. Every packet has digital footprints, so what ICANN could do is permit IP address blocks to be seized and transferred when it is demonstrated the owners are consistently using the network for purposes of doing harm, even when it is through negligence. This would work its way through the service level agreements between various ISPs. As in the rest of the business world, you cannot just dump your garbage onto someone's property without eventually being forced to pay for it.

Post reply on HN