Live data from Hacker News

India is almost 80% IPv6

apnic.net

101–110 of 126 posts

Re: India is almost 80% IPv6

#101

I personally can’t find a reason to switch over on my home network. I understand why v6 is necessary for the internet but I can’t reconcile it with my home network. I tried a few times migrating over and it’s just an insane amount of work for essentially nothing… all the firewall rules, containers to subdomain mappings, all the wifi clients would get a completely new numbering scheme. And it changes when you change I…

Here's the dumb naive question of the day: Why didn't "ipv6" simply get implemented as: "Well, our ipv4 addresses of 4x8bit, well, we'll just switch those to 4x64bit or whatever." Then it becomes like a gradual y2k migration. Old servers could be addressed by the new ones, and if the old ones didn't want to address the new ones, well, that was their problem. You didn't need new infra, addresses, etc, you simply upgra…

This is actually one of the most interesting parts of the Urbit project IMO -- their addressing scheme has 8, 16, 32, 64, 128 address support. The addresses are displayed in memorable terms that fit into an astromoical-styled system.

A /8, an example being "~rel" (one syllable names based out of a bank of 256 memorable 3-letter syllables)-- these are galaxies and are extremely rare (128 galaxies total). Then you have /16 stars which are like "~tabrel", combining two of these syllables -- their are 64,000 stars. And then finally, you have /32 planets like "~sampel-tabrel", which are 4b illion and enough to be valuable and stop spam, but are somewhat disposable kind of like a phone number.

Each one of those planets can spawn billions of /64 moons (sampel-tabrel^dambel-gabnel) which can be used for IoT or family members.This naming scheme draws a good delineation has both human understandable names and memorable addresses you can use for a lifetime -- as well as tremendous scalability to support routing between trillions of addresses.

https://urbit.org/blog/value-of-address-space-pt2

Re: India is almost 80% IPv6

#102
post #89

Earlier quoted context omitted.

The comment you're replying to is referring to Homeland. If all you have is an ISP-issued device, then you don't need to worry about it, just use the defaults. Also, I doubt ISPs will ever change their home routers to default to IPv6 because of the complexity it'll add to customer support with no extra benefits.

What is Homeland? I explicitly disable IPv6 because I don't trust the firewall, specially on an auto-updating device.

Is there a specific reason you trust your router for IPv4 but not for IPv6 traffic? IPv6 privacy extensions should be enabled by default on most devices. So even in the unlikely case of a device being exposed, someone has to know the temporary IPv6 address and then try to access it while it is still in use. This device would also have to run a vulnerable service on some port that the attacker has to know. All in all, I think that this is a pretty unlikely scenario.

Re: India is almost 80% IPv6

#103
post #65

Earlier quoted context omitted.

There is no need to move your whole private network over to IPv6, although it might provide a good learning opportunity. You could start with enabling IPv6 for your nginx reverse proxy and make it listen on its IPv6 address. IPv6 has subnets too and firewalling is still possible, only NAT isn't needed anymore (which is good). Edit: Reading your post again it sounds like you have mental model of either IPv4 or IPv6, w…

Yes it confuses me very much. If I were to get an ipv4 and and ipv6 to the internet but my internal network stays ipv4, then the ipv6 networking would never get used anyway and I might as well disable it, correct? Now if I also let internal devices get both a v4 and a v6, they essentially all become directly exposed to the internet through v6 don’t they? That’s the part that really confuses me. And if they aren’t pub…

> If I were to get an ipv4 and and ipv6 to the internet but my internal network stays ipv4, then the ipv6 networking would never get used anyway and I might as well disable it, correct?

If you enable IPv6 on your router it will likely advertise an IPv6 prefix on your internal network, which in turn will lead to your clients getting IPv6 addresses - unless you disable IPv6 on their interfaces. Clients will then make use of IPv6 to connect to any service that has an IPv6 address, as they prioritize IPv6 higher than IPv4.

> Now if I also let internal devices get both a v4 and a v6, they essentially all become directly exposed to the internet through v6 don’t they? That’s the part that really confuses me.

They won't become directly exposed - the router's firewall should block incoming IPv6 traffic by default. This is the case for my router and should also be the case for others. To be 100% sure you could do a quick check and try to ping your device from the internet using its IPv6 address. You will likely see a message saying: "Destination unreachable: Administratively prohibited" or get a timeout.

> And if they aren’t publicly accessible from the internet then I’m back to v4 NAT where I was all along which kinda makes v6 pointless doesn’t it?

You can open ports in the router's firewall for IPv6 addresses. However, the main advantage for you would be that your clients can access public IPv6 addresses - which they currently can't. This might not be a big deal yet, but as IPv6 slowly gains some traction it will be noticeable in the future. Some hosters already charge extra for IPv4 addresses.

Re: India is almost 80% IPv6

#104
post #47
post #34

Earlier quoted context omitted.

Forcing micro USB and now USB-C on electronic devices has been one of the best ideas by the EU overall. Remember using ten different charging cables? Gone, due to a helpful piece of regulation by the government.

Have you tried Nintendo Switch's USB-C charging? It is non-standard.

It’s not, that was debunked.

Re: India is almost 80% IPv6

#105
post #102
post #89

Earlier quoted context omitted.

What is Homeland? I explicitly disable IPv6 because I don't trust the firewall, specially on an auto-updating device.

Is there a specific reason you trust your router for IPv4 but not for IPv6 traffic? IPv6 privacy extensions should be enabled by default on most devices. So even in the unlikely case of a device being exposed, someone has to know the temporary IPv6 address and then try to access it while it is still in use. This device would also have to run a vulnerable service on some port that the attacker has to know. All in all,…

"Most devices", "should be, "unlikely case", "pretty unlikely". That's my impression too, and none of those are good enough. I have many internet connected devices (appliances) and really don't want to worry about someone remotely accessing them. Behind the NAT it just isn't possible.

Re: India is almost 80% IPv6

#106

Earlier quoted context omitted.

Here's the dumb naive question of the day: Why didn't "ipv6" simply get implemented as: "Well, our ipv4 addresses of 4x8bit, well, we'll just switch those to 4x64bit or whatever." Then it becomes like a gradual y2k migration. Old servers could be addressed by the new ones, and if the old ones didn't want to address the new ones, well, that was their problem. You didn't need new infra, addresses, etc, you simply upgra…

> Why didn't the original group simply expand the size of the numbers in the address quads? Almost all fields in IP header have fixed size - so it doesn't really matter that you just change address size - it is already a new and incompatible protocol. And adoption of IPv6 wasn’t so slow due to its design or any technical properties. Simply no one wanted to do additional work as long as supporting only IPv4 worked fin…

But IPV6 always had an "Internet2" vibe to it between dual stacks, different syntax/separator, hostility towards NAT firewalls. Like they wanted to be completely separate and force everyone to move to them. And this is back in the day when another stack meant another hunk of infrastructure, probably new switches, etc, not just a bunch of VMs allocated via API in IaaS.

As in they didn't even seem to consider that maybe you adapt the existing IPV4 code to some form that can handle both protocols. It seemed like they wanted to force total software rewrites and hardware purchases all over the stack.

I mean look, one if-then to identify the packet type is not that bad. Or simply have the ipv4 as the first part and the wrapped packet has another 128-256 addressing bytes.

Re: India is almost 80% IPv6

#107
post #105
post #102

Earlier quoted context omitted.

Is there a specific reason you trust your router for IPv4 but not for IPv6 traffic? IPv6 privacy extensions should be enabled by default on most devices. So even in the unlikely case of a device being exposed, someone has to know the temporary IPv6 address and then try to access it while it is still in use. This device would also have to run a vulnerable service on some port that the attacker has to know. All in all,…

"Most devices", "should be, "unlikely case", "pretty unlikely". That's my impression too, and none of those are good enough. I have many internet connected devices (appliances) and really don't want to worry about someone remotely accessing them. Behind the NAT it just isn't possible.

> Behind the NAT it just isn't possible.

It could be with UPnP, which as a security conscious person you likely have disabled. Do you trust it staying disabled or none of your many devices trying to use it to poke holes in the NAT?

Even if you have to use your ISPs modem/router device, it might have a bridge mode where it just becomes a modem, enabling you to use your own router. It might be worth checking this option if you didn't already.

Re: India is almost 80% IPv6

#108
post #37

Earlier quoted context omitted.

If you're talking about the RIPE region, then; - Can I request a /48 or larger IPv6 prefix from my sponsor LIR -> Yes. Something bigger than a /48 might be hard, but /48 shouldn't be any problems. - Can such IPv6 prefix be further distributed to customers? -> No. A IPv6 PI assignment can only be used by yourself and your own infrastructure and not assigned to customers[0]. Other RIRs will have the information on thei…

Thank you. Just to make things clear, customer from section 7 also equals end user? That is, if I were given for example a /48 from a sponsor LIR then I am forbidden to divide that and delegate resulting prefixes via DHCP/PPPOE to end user CPEs to whom I want to simply provide dual stack internet access?

Yes that's exactly whats not allowed for PI space. But you can get a PA subnet from your sponsoring LIR and use that for your end users.

Re: India is almost 80% IPv6

#109
post #34

Earlier quoted context omitted.

Because generally it would be a bad idea for the government to force certain technologies upon the private sector, even if in this case it might be fine.

Forcing micro USB and now USB-C on electronic devices has been one of the best ideas by the EU overall. Remember using ten different charging cables? Gone, due to a helpful piece of regulation by the government.

Except for Apple, all phone makers managed to agree to the USB-C standard without any government regulation.

What you're referring to is a very recent law (months old) that will take effect in 2024.

And it could limit future newer ports that are technologically superior (like lightning was when the standard was micro USB)

Re: India is almost 80% IPv6

#110
post #65

Earlier quoted context omitted.

There is no need to move your whole private network over to IPv6, although it might provide a good learning opportunity. You could start with enabling IPv6 for your nginx reverse proxy and make it listen on its IPv6 address. IPv6 has subnets too and firewalling is still possible, only NAT isn't needed anymore (which is good). Edit: Reading your post again it sounds like you have mental model of either IPv4 or IPv6, w…

Yes it confuses me very much. If I were to get an ipv4 and and ipv6 to the internet but my internal network stays ipv4, then the ipv6 networking would never get used anyway and I might as well disable it, correct? Now if I also let internal devices get both a v4 and a v6, they essentially all become directly exposed to the internet through v6 don’t they? That’s the part that really confuses me. And if they aren’t pub…

>they essentially all become directly exposed to the internet through v6 don’t they?

Most consumer routers have a stateful firewall [0] for IPv6 that basically behaves like NAT. But it's less of a problem than on IPv4 anyway. It's possible to scan the whole IPv4 Internet in less than 5 minutes. [1] And this is done constantly by many people. The IPv6 address space is way to big to do this and you have to harvest addresses. [2] It's always a good idea to have a firewall but unlike IPv4 you don't get port and vulnerability scans seconds after you expose a host to the internet.

>which kinda makes v6 pointless doesn’t it?

IPv6 is mostly useful for ISPs. There are just not enough IPv4 addresses for everyone.

[0] https://en.wikipedia.org/wiki/Stateful_firewall [1] https://en.wikipedia.org/wiki/ZMap_(software) [2] https://isc.sans.edu/diary/Targeted+IPv6+Scans+Using+pool.nt...

Post reply on HN