Live data from Hacker News

AWS to start charging for IPv4 usage, but critical services don't support IPv6

old.reddit.com

81–90 of 245 posts

Re: AWS to start charging for IPv4 usage, but critical services don't support IPv6

#82
post #71

Earlier quoted context omitted.

[flagged]

VoIP. Two peers, each behind a CG-NAT (or other symmetric NAT), depend on somebody running a relay in order to be able to communicate. This makes it very expensive (and sometimes risky, since unrestricted relays can be used for all kinds of nefarious things too) to deploy any new VoIP service. I'd call that "broken by NAT". > everything works right now. Yes, everything that works right now works right now, but that's…

Doesn't that present a privacy issue? One can _casually_ infer who you are talking to merely by examining network traffic.

Re: AWS to start charging for IPv4 usage, but critical services don't support IPv6

#83
post #63

Earlier quoted context omitted.

> So we can get rid of STUN/ICE/etc and make peer-to-peer easier. All you're left with is hole punching through your SPI firewall (no worse than today). Do you really think Roomba is going to let you run your Robot Vacuum without contacting, er permission, from their data center in Virginia?

Currently my roomba is behind a nat and still insists on contacting their main data centers. And if i turn off the internet to my nat the roomba will run but none of the advanced cell phone related features of the roomba will work, even though my cell phone is connected to the same wifi network in the same nat as the roomba. So this is completely unrelated. IP addressing schemes will not change the business methods o…

> IP addressing schemes will not change the business methods of large consumer device companies.

That's exactly the point; they market it as if it would make a plethora of new and innovative things happen but in reality they will allow none of it.

So, it's pointless to rush adoption.

Re: AWS to start charging for IPv4 usage, but critical services don't support IPv6

#84

Earlier quoted context omitted.

> ok, but why? Because NAT breaks a lot of services. > Is that going to change with ipv6? Yes. You no longer need NAT, so port negotiation is much easier (even when inbound is blocked) > Are you _really_ just going to allow random traffic into your network? Common misconception! Even without NAT, the router can have port/traffic policies. There's just no address translation happening. There's a lot of good stuff abou…

>> The biggest one is people seem to equate NAT = router/firewall. This is absolutely not the case, I dont think anyone equate that, but IPv6 proponents refuse to recognize that decades and decades, especially in home users, and SMB space, NAT was a layer of the security model, often times one of the biggest Right or wrong is irrelevant, that is/was the reality Just tossing IPv6 as a replacement for ipv4 with out fac…

Home router NAT "layer of security" is equivalent to closing all ports.

If an IPv6 home router closes all ports by default, then the same level of security is achieved.

Re: AWS to start charging for IPv4 usage, but critical services don't support IPv6

#85
post #67

[flagged]

> * "It's so hard to initiate a connection to something behind a ipv4 NAT firewall!! " > Is that going to change with ipv6? Yes, because stateful firewalls are much easier to consistently traverse than NAPTs. This alone is a huge advantage for P2P applications. Behind a (usually symmetric) CG-NAT, I have no way to directly connect to anybody else behind one without a relaying server (which are expensive and add needl…

> IPv6 is also doing nothing to combat pollution by microplastics and overfishing.

We disagree but I actually laughed at that.

Re: AWS to start charging for IPv4 usage, but critical services don't support IPv6

#86

Earlier quoted context omitted.

The existence of PASV mode and STUN/TURN is because the end-to-end addressibility of the IP protocol was broken with CGNAT. Furthermore, in populous countries like India, ISPs enforce extremely aggressive timeouts on IPv4 connections in order to keep the 5-tuples on the egress side of things manageable. Trying to make a request that takes 10 seconds to process (like a user requesting a report consisting of multiple S…

> The existence of PASV mode and STUN/TURN is because the end-to-end addressibility of the IP protocol was broken with CGNAT. But isn't all that still necessary as long as the typical user isn't going to be opening their firewall on those ports to arbitrary incoming connections? That's the whole point here.

STUN (or something similar) yes (since you'll need to coordinate outbound traffic which creates the appropriate inbound rules), TURN no (since STUN will always succeed with stateful but non-translating firewalls).

And STUN scales almost infinitely better than TURN.

Re: AWS to start charging for IPv4 usage, but critical services don't support IPv6

#87

Earlier quoted context omitted.

> ok, but why? Because NAT breaks a lot of services. > Is that going to change with ipv6? Yes. You no longer need NAT, so port negotiation is much easier (even when inbound is blocked) > Are you _really_ just going to allow random traffic into your network? Common misconception! Even without NAT, the router can have port/traffic policies. There's just no address translation happening. There's a lot of good stuff abou…

>> The biggest one is people seem to equate NAT = router/firewall. This is absolutely not the case, I dont think anyone equate that, but IPv6 proponents refuse to recognize that decades and decades, especially in home users, and SMB space, NAT was a layer of the security model, often times one of the biggest Right or wrong is irrelevant, that is/was the reality Just tossing IPv6 as a replacement for ipv4 with out fac…

> Just tossing IPv6 as a replacement for ipv4 with out factoring that in while simply screaming into the void "NAT IS NOT A FIREWALL" will be of little comfort to the elderly retiree that has their home computer ransomwared, or the small business that is put under due to a cyber attack because the ipv6 address was strait on the public internet

This is definitely what I'm seeing. IPv4 is really engrained in us - I actually had a really hard time conceptualizing how things worked until I forced myself to learn by deploying dual-stack and ipv6-only networks.

The major downside I see right now is that "addresses are harder to memorize," but there are solutions to that as well.

Re: AWS to start charging for IPv4 usage, but critical services don't support IPv6

#88
post #59

[flagged]

Here is something very simple, with no self flogging and no circus hoops. I do not want to pay for a number. There is no shortage of numbers. In fact there is an infinite amount of them. There are many things I am forced to pay for and their prices keep going up and up and more things get added every year. Well on this one I fight back. I do not wish to pay for the use of an arbitrary number just so my device can be…

Of all of the arguments, I personally find this one the weakest. As you're describing your IP address makes it no different than a phone number for your mobile.
Post reply on HN