Live data from Hacker News

Tell HN: Hacker News now supports IPv6

news.ycombinator.com

321–330 of 396 posts

Re: Tell HN: Hacker News now supports IPv6

#321
post #125

Earlier quoted context omitted.

That's a very interesting case, as UDP is very reliant on MTU. If the IPv6 headers take out more space from the ethernet frame, that leaves less space for the UDP payload. Which means that a UDP payload which was at the limit for IPv4 on the typical MTU needs to be fragmented into two IPv6 packets, which will likely increase latency quite significantly. However, this will depend on each specific game, if they are usi…

If you try "ping" and "ping6" towards a multi-protocol host, you see both send 64 bytes each, so while v6 source and destination addresses take up lots of extra space, the v6 IP packets have less of the "this part could be useful for tcp" which means icmp pings can be of the same size, even though the two addresses eat up lots more bytes. Not sure if the same goes for game UDP packets, but the optional header stuff i…

There is nothing in the IPv4 header that is only useful for TCP, especially not in the parts removed from IPv6. Overall the IPv6 header gets rid of the 4 bytes of fields used for fragmentation, and 2 bytes used for the checksum. Fragmentation was never used for TCP in any sane implementation (as TCP can do fragmentation at the TCP layer), and the checksum were fully redundant for TCP. For UDP, the checksum used to be optional, but is now required. So, for an optimized implementation, the checksum removal isn't even a win for UDP, as it has just moved from the IP layer to the UDP layer.

So, we have added 24 bytes to the header because of the address difference, and removed 4 bytes from other places.

Now again, there are many differences between IPv4 and v6 that are much more relevant to latency than this extra header overhead. But it is a real overhead, there is no extra scope for payload. Your observation with ping is just wrong (most likely both versions are just padding the packets up to 64 bytes by default).

Re: Tell HN: Hacker News now supports IPv6

#322
post #283

I often wish that there had been a way to politically make 240/4 and 0/8 commonly available. But in part I drove those projects to annoy the IPv6 crowd into action.

I think the IPv6 crowd is already decently in action, hence vast swaths of the internet and mobile network already migrated (some on the mobile even without dual stack). What's needed for more IPv6 adoption is continued annoyance felt by the IPv4 crowd to want to bother migrating to any other long term solution. That's required a lot more time than most probably expected but it has been happening, IPv4 has become more and more difficult to use. Throwing in things like "Look IPv4 crowd, there are ways to extend IPv4 for some more years again without the pain of going to multi-layered NAT" is about the exact opposite of the kind of call to action needed.

Either way though, the inherent value in the technology is what has to drive the adoption and the value is already there it's just a matter of IPv4's value still holding well enough for now. As such I don't inherently mind 0/8 being available on Linux these days and wouldn't inherently mind 240/4 either but a completely separate set of "yes, you can configure that address but the problem is with getting between there and here not accepting it" is a bit disappointing for just another short term response to the problem.

Unrelated but kickass work on packet scheduling btw.

Re: Tell HN: Hacker News now supports IPv6

#323
Well, this exactly explains why HN's site has become so unreliable for me.

As soon as this post appeared, I began receiving timeouts. 90% of the time, the front page won't load, the host won't respond.

I have no troubles with any other IPv4 or IPv6 sites. My home network has been running IPv6 for about 8 years, since my ISP enabled it and I worked out some good router settings.

I routinely verify that all 3 of my devices are preferring IPv6. These timeouts are not occurring on my Android 11 phone, only on my Chromebook for now. Windows 10 Pro, not tested.

Re: Tell HN: Hacker News now supports IPv6

#324
post #182

I am so surprised by the hate for IPv6 in this thread. I have been deploying IPv6 for more than ten years and it really improve many situations (beside larger addresses). I have to admit, there is a learning curve. But I want to encourage everybody involved in configuring computers to learn. Also I want to rent about Cisco not using /64 for link local by default, thus being incompatible with BSD systems. Link local m…

> I have to admit, there is a learning curve. But I want to encourage everybody involved in configuring computers to learn. This is probably most of it. My gripe is that there is essentially no realistic end to ipv4 in sight. So we as an industry carry the debt of securing, managing and troubleshooting parallel v4 and v6 networks for decades. If ipv4 had an EOL it'd make the transition so much better

Nobody is in a position to EOL v4. We'd need a planetary government for that, and we don't have one. It would be nice, but we have to work with what we've got and not what we wish we had.

I run my desktop with no v4, so it's clearly possible to push handling for v4 out of your network. You could outsource it to somebody else even, for example by using one of the DNS servers listed on https://nat64.net/.

Re: Tell HN: Hacker News now supports IPv6

#325
post #31

As someone who grew up on IPv4, i will miss it, but the leap to 340 undecillion unique addresses is exciting in many ways so i think i can learn to live with this transition. If we ever need more than that, i can't even imagine what that future would look like.

The last time I looked into this (which was a few years ago), ISPs were allocating blocks containing billions of IPv6 addresses to anyone who paid a nominal sum. So that vast address space might not last as long as it would seem...

The space currently assigned to globally routable addresses is 1/8th of the v6 address space. Over 50% of the addressable space is currently reserved.

The numbers are frankly mind-bending. Even if we we make a complete pigs ear of assigning billions of IPs to billions of networks in the current /3, we have space for more than one do-over.

But I do believe there's a higher chance the next /3 will be assigned to Mars.

Re: Tell HN: Hacker News now supports IPv6

#326

Earlier quoted context omitted.

> I have to admit, there is a learning curve. But I want to encourage everybody involved in configuring computers to learn. This is probably most of it. My gripe is that there is essentially no realistic end to ipv4 in sight. So we as an industry carry the debt of securing, managing and troubleshooting parallel v4 and v6 networks for decades. If ipv4 had an EOL it'd make the transition so much better

Nobody is in a position to EOL v4. We'd need a planetary government for that, and we don't have one. It would be nice, but we have to work with what we've got and not what we wish we had. I run my desktop with no v4, so it's clearly possible to push handling for v4 out of your network. You could outsource it to somebody else even, for example by using one of the DNS servers listed on https://nat64.net/ .

We can EOL things insecure ciphers and old operating systems without much issue without a planetary government.

The migration strategy for ipv4->ipv6 was just so horribly conceived that we'll be running both in parallel for decades.

TBH I think it would have been better if ipv6 was named something else entirely. Running TCP and UDP in parallel doesn't raise any flags, but running two versions of the same protocol in parallel is strange.

Re: Tell HN: Hacker News now supports IPv6

#327

Earlier quoted context omitted.

That sure sounds like a lot. But "billions" is less than a /64. Try "sextillions" (/56) or "septillions" (/48). Of course, when the denominator is "undecillions", it becomes clear that this is actually a non-issue.

I'm sure people said exactly this about IPv4 back in the days.

So the funny thing is .. they didn't. They really didn't.

The original numbering plan for IP was that each network number became a /8. Which is how we miraculously ended up with 10/8, because network 10 was ARPANET itself, so 'flag day' left 10/8 vacant.

But back to the point at hand. IP itself is RFC 791, September 1981, nice and famous. The addition of classful networking because 255 network numbers wasn't going to last long, was RFC 790.

The first workaround for IP exhaustion was published before IP. It's been a Known Issue since day negative-one.

Re: Tell HN: Hacker News now supports IPv6

#328

Earlier quoted context omitted.

IPv6 will rid us from the abomination of domestic NAT. IPv6 will, finally, enabled the real internet: all p2p protocols will start to work seamlessly. I am thinking a super simple no-dns IP (audio|video) phone protocol listening only on tcp 1 port, new bittorrent like protocol for live streaming, etc. Since IPv6 has been almost everywhere in my country for years: enjoying ssh session everywhere (ipv6 mobile internet)…

Those of us who were supporting Windows machines in the ‘00s remember when 100% of Windows machines not behind NAT were pwned in minutes, while those with NAT were fine indefinitely. Should a firewall have been doing that job? Yes. Were firewalls doing that job, in practice? No, NAT did, and it was very, very effective. I have… concerns about removing NAT from everyone’s house now that IOT is a thing. Could it be don…

Have you looked at what's actually getting deployed? It's mostly no NAT and firewalls, so the signs actually seem to be pointing to "yes".

Even without a firewall, a /64 is an extremely large amount of space. It's nearly impossible to find active hosts by port scanning, compared to v4 where it's trivial to scan the entire address space. We won't end up in the same situation we were in on v4 back when nobody used firewalls, and that's not just because our networks mostly have firewalls these days.

Re: Tell HN: Hacker News now supports IPv6

#329
post #303
post #285

Earlier quoted context omitted.

Solved you say? So how do I set up DNS for LAN hosts that under IPv4 would have static private addresses? Under IPv6, you run into problems long before DNS - trying to assign static addresses as DHCPv6 is an afterthought, also whole setup has to be robust somehow when the whole network prefix changes.

Sounds like a good use for Multicast DNS?

Sounds like adding yet another potentially exploitable service listening on every host? Swell!

Seriously, I have yet to see a good tutorial how to herd IPv6 LAN with reliable local DNS, as is usual with IPv4. Everything is just handwaved away "nah, zero configuration". The reluctance to adopt it could stem from that.

Post reply on HN