Live data from Hacker News

Tell HN: IPv6-only still pretty much unusable

news.ycombinator.com

521–530 of 649 posts

Re: Tell HN: IPv6-only still pretty much unusable

#521

Earlier quoted context omitted.

> How does this not see more abuse by bad actors? Because this tech goes unused in almost all cases. Also doesn't work if your DNS client is secure against tampering (i.e. uses DNSSEC) without more configuration. To make this work, you need to intercept and modify the victim's DNS traffic or reconfigure the victim's DNS server somehow. With that amount of control, IPv6 or IPv4 no longer matter; you apparently have fu…

Ugh, I was under really looking forward to trying out NAT64 one day. Potential complications with DNSSEC never occurred to me. Thanks for the reality check.

Luckily (or sadly) many clients still don't do any actual DNSSEC validation instead relying on the outdated mechanism of validating the records on the DNS server and flagging them as secure.

You can keep the level of protection most people get from their DNS servers by doing the same; validating DNSSEC before NAT64 before rewriting them and disabling additional validation on the clients if enabled.

This does require trust in the connection between your devices and your server, but if you were planning on altering the DNS records automatically anyway, this shouldn't be too much of an issue.

Another thing to keep in mind is that some (headless) browsers will switch to DoH automatically depending on your network configuration. To fix this, you can run a DoH server next to the NAT64 server quite easily and configure your devices to use that, or disable DoH entirely. As far as I know only Firefox is enabling DoH in some privacy unfriendly countries, so you'll probably be fine if you forget, but this is something to check if your browser starts having weird issues.

TL;DR it'll probably still work

Re: Tell HN: IPv6-only still pretty much unusable

#522
post #3

Hetzner should provide free CGNAT IPv4 Addresses (IPv4 Gateway) for IPv6-Only VMs

A whole lot of ISPs are doing CGNAT for IPv4 now, mostly in Asia. Starlink does it. It's mostly OK but has a lot of drawbacks, particularly IP-based geolocation. (Starlink does not support IPv6 although they seem to be rolling it out this month.)

No post body was provided.

Re: Tell HN: IPv6-only still pretty much unusable

#523
post #382

Earlier quoted context omitted.

Is it enabled by default on customer equipment?

On their leased hardware, it is enabled from what I've seen. And if you are running your own modem and router, you will get IPv6 if you configure your setup to request it (via DHCP). They will even give you a /60 if your DHCP client asks for it.

Weak, here in Sweden I get a /56 from my ISP. You'll run out of IP addresses long before I do!

Re: Tell HN: IPv6-only still pretty much unusable

#524

Earlier quoted context omitted.

> I would switch to that "IPv4+" system if it existed.. I am willing to use latest software/standards to future-proof my setup, but duplicating all the work is too much for me. And exactly how would you accomplish this switch to a larger address space? Please explain the steps exactly how they would be done. Because IPv4 has 32 bits of address. Anything after IPv4 needed >32 bits of address. How exactly do you fit in…

It's like no protocol has ever been extended or revised. Ever. Let's pretend there isn't an Options and Padding section in the IP header: "Options and Padding - A field that varies in length from 0 to a multiple of 32-bits. If the option values are not a multiple of 32-bits, 0s are added or padded to ensure this field contains a multiple of 32 bits." Wow, like I CANNOT think of how that would be used to add more bits…

Lets call the ip4 the area code and serve the Rick Astley video if no further bits are provided.

Re: Tell HN: IPv6-only still pretty much unusable

#525
post #367

Earlier quoted context omitted.

They took much more on with IPv6 than IPv4 replacement. The spec goes much deeper than IPv4 did, replacing ARP, DHCP, etc. It's a product of its time, including a lot of over-engineering by committee. Many of the problems they tried to address didn't pan out to be real issues. You can read the RFCs and compare. IPv4 w/ more bits is a lot more simple. Yes, older network gear wouldn't deal with it well, but that's not…

No kidding - they got rid of dhcp and more but it’s a nightmare getting networks to work with just ipv6 concepts- everything from provisioning phones (dhcp options to push config / NetBoot stuff) and more. Layer in privacy extensions, renumbering on uplink wan flapping (slow too - the failover is pathetic compared to NAT wan failover) - icmp traffic differences - firewalls need to be much more careful with ipv6 and r…

128 bits was probably picked to give 64 for "MAC address-based locals" and then the reasonable thing is to have 64 more bits on the other side, if you only had 32 you're just IPv4 with more steps.

Re: Tell HN: IPv6-only still pretty much unusable

#526
post #432

Earlier quoted context omitted.

> most of you are probably using ipv6 through your mobile carrier and don’t even know it! My mobile carrier provides dual stack (with NAT in the IPv4 side). So no problem with any kind of site. Are there operators who provide IPv6 only? Haven't really read up on that topic, but I guess that requires NAT64 because the average user needs to reach IPv4-only sites. Does that generally work well? If yes, why can the poste…

T-Mobile has been IPv6-only for a while. I guess you can't use NAT64 at Hetzner because Hetzner doesn't provide it.

Why would Hetzner need to provide it? If you have several IPv6-only nodes you can rune one NAT64 node yourself. Of course that would work only if you save enough on IPv4 to pay for the extra node. And not if you are heavily network-bound.

There are also free NAT64 solutions, but of course you can't base anything but a random hobby project on something free. Maybe there are also commercial solutions, but IPv4 might still be too cheap to make that really interesting.

Actually the AskHN talks mostly about client cases. Those still seem "easy". Offering more than one service on let's say port 443 would require a full application level gateway / forward-proxy.

Re: Tell HN: IPv6-only still pretty much unusable

#527

Earlier quoted context omitted.

> All mobile clients are behind CG-NAT. Demonstrably false. T-Mobile US mobile clients are IPv6-only and connect via IPv6 to IPv6 sites: * https://www.youtube.com/watch?v=d6oBCYHzrTA * https://www.youtube.com/watch?v=nNMNglk_CvE NAT is only used to connect to IPv4-only hosts via DNS64 (with or without 464XLAT). As of 2022Q2, T-Mobile US has 110 million customers: * https://www.statista.com/statistics/219577/total-cus…

Even my smalltime telco in Australia uses ipv6.

My fiber-based residential ISP here in Japan uses IPv6, and from what I can tell, they're all like that here.

Re: Tell HN: IPv6-only still pretty much unusable

#528

All ipv6 shortcomings discussion aside; What I think is the more vital problem to focus on is that the governments clearly don't want us mere mortals to expose our own servers running on our own hardware to the outside world (most often justifying that with "it's for your own security" mantra, for we're all deemed too dumb to figure that out for ourselves). ISP-imposed ipv4 double NAT (imposed on ISPs by the governme…

I think US cloud companies got a huge boost when ISPs in the US handicapped users with NAT and asymmetric download speeds. You basically are forced to use a middle-man to serve to the internet.

With IPV6, anyone anywhere can be a host again and p2p applications have a chance to be competitive with Cloud SaaS offerings.

Re: Tell HN: IPv6-only still pretty much unusable

#529
post #519

Hey all... unquietwiki from r/ipv6; been lead-mod there for a while now (though the rest of the folks are really amazing on the mod-side). IPv6 has saved my bacon more times in the past 15 years, than IPv4 has fought with me. No clashing of IPv4 ranges. No fighting with NAT. Ability to easily have concurrent networks, for different purposes. Ability to assign multiple network addresses. Internally, it "just works" on…

> And lastly... a lot of IT guys still don't care for IPv6; as those biases show up in these & on Reddit; so that perpetuates the cycle You know the 3rd and 7th largest networks on the internet still can't reach each other over IPv6, right? It is super awesome that it "just works" for you, but recognize you might just not have the perspective of one of the people who has to make it "just work" for you.

>You know the 3rd and 7th largest networks on the internet still can't reach each other over IPv6

Who is responsible? Which networks are those?

Re: Tell HN: IPv6-only still pretty much unusable

#530

I have to say I’m super disappointed in the ignorance and negativity in the comments on this thread. Ignorance of both the difficulties inherent in upgrading a fixed size wire protocol designed for a research network fifty years ago, and the widespread adoption of ipv6 for real customer deployments. Heck most of you are probably using ipv6 through your mobile carrier and don’t even know it!

You're essentially blaming the victim. The ISPs still haven't adopted it after 25 years. ISPs are a massive monopoly in the USA. IPV6 can't be adopted by software until a sufficient number of the backbone works. I've heard that "the backbone is all working for ipv6". Um, is comcast? Wasn't last time I had comcast. If the ISP monopolies aren't 100% ipv6 (and you see lots of comments here that ipv6 support in ISPs is s…

45% of users are on IPv6. Clearly almost half of ISPs have adopted it, probably more than half of consumer ISPs.
Post reply on HN