Live data from Hacker News

Tell HN: IPv6-only still pretty much unusable

news.ycombinator.com

101–110 of 649 posts

Re: Tell HN: IPv6-only still pretty much unusable

#101
In Norway, it's required[0] for all public sectors to have IPv6. We are not there yet, but I believe the push will only increase with time.

Especially all new internal networks must be IPv6, and IPv4 is optional.

[0]: https://lovdata.no/dokument/SF/forskrift/2013-04-05-959?q=ip... (Sorry that it's in Norwegian.)

Re: Tell HN: IPv6-only still pretty much unusable

#103
post #70

Earlier quoted context omitted.

> anyone who thinks "ipv6mess" is still relevant in 2022, doesn't understand the problem space it describes. It was relevant then -and it is relevant now- because there are good lessons in how to migrate from thing A to thing B, even if some of the then-missing necessary bits are in place now. Still, it's almost certainly the case that DJB's rant had no real effect, and that the necessary steps were bound to be taken…

I'm not sure it was ever relevant. All it does is describe the problem, which was already well-known at the time by the people working on v6. It doesn't give a fix for it. It doesn't give a fix because no fix is possible. Because the problem comes from the design of v4, not from v6. For some reason djb wasn't able to get his head around that, and people have been pointing to that damn page as if it's some big gotcha…

If it describes problems we're still struggling with, it's still relevant.

Re: Tell HN: IPv6-only still pretty much unusable

#104

To use GitHub on an IPv6-only Hetzner instance, you'll need to use a NAT64 gateway. There's a list of public ones here: https://nat64.xyz/ This can just go into your /etc/hosts: 2a01:4f8:c2c:123f:64::140.82.121.3 github.com www.github.com

That’s what I ended up doing, but it’s a major turn-off to learn this by trial and error, after setup scripts fail with seemingly unrelated messages.

Re: Tell HN: IPv6-only still pretty much unusable

#105
post #5
post #4

The biggest problem remains cloud and CDN companies with poor to nonexistent IPv6 support. Most ISPs, especially on mobile, have it now or are adding it very soon. I've wondered whether some might be dragging their feet because they see an advantage in IP address scarcity to sell cloud gateways, CDNs, and other middle box type services. But the most likely explanation remains that not enough customers are asking for…

> Most ISPs, especially on mobile, have it now or are adding it very soon. Except Charter/Spectrum in the US.

https://www.spectrum.net/support/internet/ipv6-faq:

> IPv6 is available today with an IPv6 capable modem in the majority of Spectrum’s footprint.

Very curious what "majority of Spectrum’s footprint" means in this context.

Re: Tell HN: IPv6-only still pretty much unusable

#106
IPv6 is a case study in the second sytem effect [1]. Realizing you need to make breaking changes and it being rare that you get to do so you decide to make all the changes.

The truth is IPv4 only had 2 real problems:

1. Lack of address space due to 32 bit addresses; and

2. Lack of a solution for roaming since your IP address is a core part of connection identity (between the source and destination address and port).

IPv6 managed to only solve one of these problems and it did so in a way that removed functionality. Yes there are more addresses but now address blocks are non-portable. I guess 25 years ago they thought that routing protocols like BGP4 were considered a problem and decided to remove that with hierarchical address spaces and massively expanded those address spaces to do it.

Somehow ports were also considered a problem so we got /64 addresses. Part of the motivation for this was to use (mostly) unique MAC addresses (48 bits) as your identifier and that fits in 64 bits. Of course this became a massive PII leak and a tracker's dream so it never happened but we're still stuck with /64 blocks that we absoultely do not need.

It's an object lesson in solving actual problems and not solving imagined problems.

[1]: https://en.wikipedia.org/wiki/Second-system_effect

Re: Tell HN: IPv6-only still pretty much unusable

#107
post #104

To use GitHub on an IPv6-only Hetzner instance, you'll need to use a NAT64 gateway. There's a list of public ones here: https://nat64.xyz/ This can just go into your /etc/hosts: 2a01:4f8:c2c:123f:64::140.82.121.3 github.com www.github.com

That’s what I ended up doing, but it’s a major turn-off to learn this by trial and error, after setup scripts fail with seemingly unrelated messages.

Yeah, if any Hetzner reps are reading this thread, it would be great to put up a support page talking about NAT64, and link to it from the dashboard when creating IPv6-only instances.

Re: Tell HN: IPv6-only still pretty much unusable

#108
post #32

IPv6 has been one of the biggest failures in the last couple of decades. And I don't mean adoption, I mean the standard itself. If IPv6 were IPv4 with more octets, then we would all have been using it for like a decade. Yes, I understand it would still require some breaking changes, but it would have been a million times easier to upgrade, as it would be a kind of superset of IPv4 (1.2.3.4 can be referred as 0.0.0.0.…

It’s the firewall rules that always creep me out. The nice thing about NAT is open ports on your internal network are hidden to the outside world by default. You have to think about which ports you want the NAT gateway to forward. With IPv6 the entire network is reachable outside by default. Granted I assume you can probably create a default DENY rule for inbound traffic and selectively open ports up as exceptions. R…

No.... Absolutely no...

NAT is absolutely not in any way a substitute for an actual firewall, despite the side effect of 'blocking' ports.

And how is "You have to think about which ports you want the NAT gateway to forward." any different from thinking about firewall rules?

And most consumer CPE devices (i.e. 'router' etc) are perfectly capable of running a firewall, and often do.

And any firewall that doesn't drop inbound traffic by default is not really much use at all.

And lastly, if you want you can still do NAT66 if you really must, or IPv6 network prefix translation, which is a slightly improved version.

Re: Tell HN: IPv6-only still pretty much unusable

#109
post #94
post #45

Earlier quoted context omitted.

So how do you do DNS then? Not sure if this is a good source but it had some history to recap, and it doesn't look pretty... https://www.reddit.com/r/networking/comments/ajb2ec/comment/... [...] To be honest because of this hot mess if you want to reliably support any possible client you'll need to do both DHCPv6 and RDNSS for DNS information. [...]

The SLAAC should not change after the host has generated it during installation / first connection, as long as you don't reinstall the OS etc. It's basically no problem. Even better: I can set my own ::/64 so personal servers at home can be ::d3ad:b33f and accessible from outside without NAT. It's beautiful. Firewall configuration is not hard either these days is it?

So I have to manually configure every device to be able to use internet?

Every friends phone that wants to connect to my wifi needs manual setup?

That is a problem. To which the solution is IPv4?

Re: Tell HN: IPv6-only still pretty much unusable

#110

I was thinking about ipv6 the other day. I concluded in my head that adoption was just around 5-10%. Luckily I went to verify that with statistics. https://www.google.com/intl/en/ipv6/statistics.html While price of ipv4 addresses are increasing, the world has slowly been adopting ipv6. From the graph above, I'd say we cross over 50% in about 2-3 years time. At some point the "dash" to adopt ipv6 starts, and brave fol…

> At some point the "dash" to adopt ipv6 starts, and brave folks will drop support for ipv4.

I wouldn't be sure about that. I don't see any "dash" to support v6 in our future, when the option to just keep working around issues with v4 is so much easier and cheaper in the moment. Really, what does anyone have to gain by switching to v6?

Post reply on HN