Live data from Hacker News

The world in which IPv6 was a good design (2017)

apenwarr.ca

211–220 of 318 posts

Re: The world in which IPv6 was a good design (2017)

#211

I have said for the last decade or so whenever IPV6 comes up on HN that IPV6 was way too big of an address space for anything but having some sort of unique identifier in there to support an online digital ID. Like some space for a hash of a biometric or something in the lower 64 bits.

About a decade ago I worked on a project for secure networks where machines would encode identity information into the lower 64 bits of an IPv6 network and security devices could use that to enforce policy based on your identity, not your machine.

The most interested customer, the government, had the problem of having way too much IPv4 space and little incentive to upgrade so it never went anywhere. Even after the government mandates to switch to IPv6, which mostly just ended up with loads of IPv4 only government websites behind Cloudflare gateways.

Re: The world in which IPv6 was a good design (2017)

#212
post #99

Earlier quoted context omitted.

It has one huge advantage: larger address space. (Which we could have had with a minor tweak of IPv4 instead.)

The larger address space is only an advantage if we don't need a v4 address. The situation "I need a v4 address" is not worse than the situation "I need a v4 address and a v6 address".

Not exactly. There's some pretty snazzy interoperability tech out their. (I.e. 4-6-4 XLAT) that let's clients get v4 addresses when they need them, which means if there's a big chuck on devices on both ends that support v6 you don't need as many v4 address.

This kinda a problem for motivating people to move to v6 because as implementations of v6 grow there's going to be less and less pressure on the v4 address space.

Re: The world in which IPv6 was a good design (2017)

#213
post #89

Earlier quoted context omitted.

I'm worried about the long tail. IPv6 won't actually be useful until more or less everything supports v6; as long as there are enough clients which don't support v6 servers need v4, and as long as there are enough servers which don't support v6 clients need v4. And until we can start disabling v4, v6 gives no advantage and only causes significant added complexity. I'm worried that the time when we can start removing…

It has one huge advantage: larger address space. (Which we could have had with a minor tweak of IPv4 instead.)

We could, but it would have broken compatibility with v4 just as thoroughly as v6 did and so would have had the exact same deployment difficulties v6 has.

In fact v6 mostly _is_ a minor tweak to v4; most parts of it are lifted directly from v4 but with a longer address.

Re: The world in which IPv6 was a good design (2017)

#214

Earlier quoted context omitted.

Because it comes with all of the drawbacks of IPv6 but also ditches some of the advantages. You still need to update every router and application. Network admins still need to learn something new. The two protocols still don't interoperate. If you're going to go through all of that trouble why only do a half measure. IPv6 is supposed to be the final version of IP.

> The two protocols still don't interoperate. On the contrary, they would, the behavior's and quicks would be the same. And if we define, say, that if the last four components are zero, then the addr is the same as normal IPv4 address, then you could deploy the whole thing without having anybody assigning new addresses. NAT's/configs/etc could keep working. The big problem with IPv6 is that everything has to be doubl…

The devil is in the details. All applications that use the Socket interface (which is almost everything that talks on the network) still needs to be rewritten. Firewall rules still need to support longer addresses, even if you do keep the old ones--it is basically the same situation we are in now, only the line between the networks is fuzzy and there is more confusion. You still end up with two sets of configurations for everything.

Re: The world in which IPv6 was a good design (2017)

#215

Earlier quoted context omitted.

I think you’ll find the real transition to be a lot quicker than that. All it takes is one of the big companies drawing a line in the sand because they’re unable to buy enough IP addresses, so they finally take a stand. Just like when YouTube nailed the lid into the coffin of ie6.

I doubt a big company would draw the line in the sand. But I could see an upstart (think TikTok) not having up enough IP addresses and just giving a crappy, slow proxied experience over IPv4, but having it be native, zippy and good over IPv6. Suddenly you have teens begging their parents to switch ISPs.

I think you'll be surprised. As soon as most large and medium businesses support IPv6 we'll start to see people dropping v4, likely within the next 5-10 years. When only a tiny % of your potential customer base is dependent on v4 you start to weight the cost of staying dual stack or just going pure v6

Re: The world in which IPv6 was a good design (2017)

#216
post #123

Earlier quoted context omitted.

I doubt a big company would draw the line in the sand. But I could see an upstart (think TikTok) not having up enough IP addresses and just giving a crappy, slow proxied experience over IPv4, but having it be native, zippy and good over IPv6. Suddenly you have teens begging their parents to switch ISPs.

That comes with a major assumption that switching ISPs is an option. Most people get to choose between their cable company, or a fleet of ill-trained pigeons

Actually most people (in the US) get a choice between the cable company, the LEC, and a 5g carrier, and maybe even StarLink.

Re: The world in which IPv6 was a good design (2017)

#217
post #123

Earlier quoted context omitted.

That comes with a major assumption that switching ISPs is an option. Most people get to choose between their cable company, or a fleet of ill-trained pigeons

As an example, the options where I am right now (thankfully temporary) are: - $55/mo. 3 Mbps DSL - $80/mo. 300 Mbps cable (or even more expensive, faster cable) - $120/mo. 100+ Mbps (if you're lucky) Starlink - A few other heavily restricted, very expensive satellite options (e.g. HughesNet), to which the aforementioned fleet of ill-trained carrier pigeons might be preferable Only one of those is practical and (mostl…

Did you look at doing 5g home Internet? There's great coverage in lots of areas.

Re: The world in which IPv6 was a good design (2017)

#218

IPv6's biggest problem remains not that it's badly designed (at least not nowadays, there were problems but they were solved ten years ago) but that millions of network engineers never bothered to look deeper into IPv6 than "I don't get it, this feels off". You can't make a backwards compatible "IPv4 with more bits" like people dream of. L2 routers and middleboxes would still need to be replaced, software would still…

The user/customer is always right. If the people who would use IPv6 don't like it and don't want it, if they think it's bad, then it's bad. When forest rangers observe hikers repeatedly deviating from the official trail at certain spots, the ranger understands this to mean the trail is wrong, and he re-designs it to accommodate the hikers. The forest ranger is able to do this because he understands what the trail is…

I really like this – thank you for writing it! A related (but not quite the same, I think) idea is that people should not have to bend to technology; technology should bend to people.

It can be difficult to design for people, though. People tend to over- or underestimate the frequency and severity of rare events, are susceptible to the normalization of deviance, and due to their finite nature, fail to consider wider or longer-term implications of their decisions. Going along with the analogy: forest rangers also have a duty to protect the forest (and in fact, I think this ought to take precedent over accommodating hikers) and they also want to guide hikers away from dangerous terrain or wildlife that underprepared hikers may be tempted to visit.

I think the core idea here is "design around the way users actually behave, not the way they ought to behave".

Re: The world in which IPv6 was a good design (2017)

#219
post #71

Earlier quoted context omitted.

I gave a couple of talks promoting IPv6 in 1999 and I'm happy that I finally have it at home as a residential customer. (I didn't until this year.) I'm also working on a project to reclaim some IPv4 address space, which people often object to on the grounds that people should "just use IPv6". So I have to defend the legitimacy of the demand for IPv4 address space. In connection with this issue, I recently ran some DN…

> The over 99.9% of sites that still have an A record have it for a very good reason A records work on v4 and v6, so they'll probably stick around for a while. Perhaps they'll end up being concentrated around 4-to-6 forwarding NAT-as-a-service companies, but they're the fallback mechanism. I don't think anyone is advocating for dropping A all together unless you're really trying to pinch pennies. > I'd love to see so…

A records do not allow IPv6 connections

Re: The world in which IPv6 was a good design (2017)

#220
One thing that isn't discussed very often but is IMHO one of the bigger roadblocks for IPv6 deployment is the Berkley Socket Interface. The API that loads of code is built upon to do internet communication.

The problem is that the API is too low level, or more specifically there is no high level API for it. Ideally it would have a function that looks like:

    int sockfd = connect_to(hostname, port, SOCK_STREAM, options_bitfield);
This would allow the stack to work out the details on its own and automatically use IPv6 if available. Or whatever future protocols can provide you a STREAM socket. The old interface could also be available for people who need to do low level stuff, but most of the time this would be sufficient.
Post reply on HN