Live data from Hacker News

Tell HN: Hacker News now supports IPv6

news.ycombinator.com

361–370 of 396 posts

Re: Tell HN: Hacker News now supports IPv6

#361
post #329

Earlier quoted context omitted.

Sounds like adding yet another potentially exploitable service listening on every host? Swell! Seriously, I have yet to see a good tutorial how to herd IPv6 LAN with reliable local DNS, as is usual with IPv4. Everything is just handwaved away "nah, zero configuration". The reluctance to adopt it could stem from that.

Dude, it actually is zero configuration lol. My devices assign themselves an IPv6 via SLAAC, and they are reachable from other devices via devicename.local. Macs and iPhones have relied on mDNS for years. Windows supports it. Android supports it since 2022. Linux has avahi. If people could look a little further than the tip of their nose, they’d realize how much easier it’ll be to explain to people to just type in al…

..until another Alice joins the network with her iphone. There are plenty of valid reasons to manage names centrally and configure addresses explicitly, but no I'm supposedly a dinosaur that is supposed to get extinct finally :(

Re: Tell HN: Hacker News now supports IPv6

#362
post #191
post #140

Earlier quoted context omitted.

ARIN recently handed out a /16 allocation to Capital One. That is one 65,025th of all of IPv6. A reasonable sized /32 allocation would have allowed for giving every ATM they operate worldwide its own globally routable /48.

>ARIN recently handed out a /16 allocation to Capital One. That is one 65,025th of all of IPv6. A reasonable sized /32 allocation [...] The more one digs, the more egregious it seems. If the NETIFY webpage is accurate, it shows that Capital One already had "/32" and "/36" blocks, and yet they also got "/16" : https://www.netify.ai/resources/networks/capital-one And if I'm reading the ARIN fees correctly, it only cost…

> And if I'm reading the ARIN fees correctly, it only costs $4000 annually for a "/16" allocation:

For better or worse, you're not; that's for IPv4 /16. For IPv6 /16, it'd be the X-Large service category, so $16,000/year.

Re: Tell HN: Hacker News now supports IPv6

#363
post #316
post #150

Earlier quoted context omitted.

IMHO it means that they are not fully IPv6 compliant. Corporate networks often have DHCPv6 rather than just SLAAC.

They are fully compliant, SLAAC is part of the standard whereas DHCPv6 is an optional extra. DHCPv6 also does not work without RA. DHCPv6 just assigns an address, a routable prefix, dns servers etc, it does not assign a subnet or any routes, you need route advertisements for that.

Seen like this, you can also argue that DHCP is an optional extra for IPv4, but it almost essential in most networks. Sure, IPv4 has no SLAAC that can be a valid alternative, but still, given that SLAAC doesn't solve every use case...

Re: Tell HN: Hacker News now supports IPv6

#364

Earlier quoted context omitted.

I have deployed personal servers that are IPv6 only that's at least a handful of v4 addresses saved / v6 addresses used

That's great, let me know when you can use the Internet without any IPv4 addresses involved (including upstream).

https://google.com/ https://news.ycombinator.com/ https://www.netflix.com/ https://www.espn.com/

Not sure what you mean you can't use the Internet without IPv4. Yes some sites won't work but some sites don't work with https but that doesn't mean you can't use https on the internet

Re: Tell HN: Hacker News now supports IPv6

#365

Earlier quoted context omitted.

URLs use : to separate the IP and port. There needs to be some way to disambiguate that from the colons in the address.

But if a URL has more than one colon, can't you assume is an IPv6 address?

You can't tell if there's a port or not, e.g. http://2001:db8::1:8080/. Is that 2001:db8::1 or 2001:db8::1:8080?

Re: Tell HN: Hacker News now supports IPv6

#366

Earlier quoted context omitted.

That's great, let me know when you can use the Internet without any IPv4 addresses involved (including upstream).

https://google.com/ https://news.ycombinator.com/ https://www.netflix.com/ https://www.espn.com/ Not sure what you mean you can't use the Internet without IPv4. Yes some sites won't work but some sites don't work with https but that doesn't mean you can't use https on the internet

All those sites you mention work with IPv4 just fine. When you shut off IPv4 in favour of IPv6 you shut off access to probably 70% of the Internet. Let's see what happens when you don't enable IPv6? Oh nothing... that's right, the Internet will remain working just fine. There's very little incentive to support IPv6 when all that is required to connect to the Internet is IPv4. Which comes to the fundamental issue with the deployment and transition with IPv6, it will always remain a second class citizen until we no longer need to rely on IPv4.

Re: Tell HN: Hacker News now supports IPv6

#367
post #352
post #337

Earlier quoted context omitted.

Moving away from the cloud is the trend. Moving between AWS and GCP will probably stay stable.

Do you have a source for that claim?

In this thread I'm being a source. Anyone asks you, you can point to this thread

Re: Tell HN: Hacker News now supports IPv6

#368

Earlier quoted context omitted.

I've been looking into keeping my network IPv4 in an IPv6 world, and it looks like there are a lot of sharp corners and kinks that make that problematic. In any case, considerations like that are part of why I'm putting off any serious effort or decisions until it's required.

The reason it's problematic is the same reason we need a new protocol in the first place: because the old one isn't enough. You've spent longer talking about not deploying v6 than you would have done deploying it. I said this before, but I suggest you sit down and turn v6 on for your network -- and *just* that, don't start gaming out how to disable v4 or deal with devices that don't support v6 or anything else, *just…

> You've spent longer talking about not deploying v6 than you would have done deploying it.

I guarantee that I haven't.

> I suggest you sit down and turn v6 on for your network

I did this a long while ago. I apologize for giving the impression that I haven't. But actually using IPv6 in any serious way takes more than just turning it on. It requires reconfiguring a nontrivial number of machines/devices, figuring out how to accommodate the many machines/devices that aren't able to use IPv6, and so forth.

Now, I will admit that I'm still learning IPv6 stuff and as a result there are likely things that I'm overthinking. But responses like yours don't move that ball forward any. You're just scolding people for not being experts.

Re: Tell HN: Hacker News now supports IPv6

#369

Earlier quoted context omitted.

Which is?

Literally the one job it had, to prevent address depletion on the Internet. Just to be clear, we're talking about the Internet here, and not some IPv6 island.

I don't get you. We are running dual stack for the time being, and indeed we cannot solve address depletion this way, but that doesn't mean we are doing it forever.

At some point -- maybe when 60%, 70%, or 80%, or 90% of the Internet is running on IPv6 -- Internet services at a large scale will begin to deem IPv4 as a liability, and drop IPv4 support along with the addresses they are holding.

I am not talking about a distant future either. We already have IPv6-only servers up and running, mine included, and we haven't even reached the 50% milestone. In a way, the existence of IPv6-only servers meant that IPv6 is _already_ preventing IPv4 address depletion, because those servers would otherwise have to compete for IPv4 addresses with the other servers too.

Furthermore, I find "I hate IPv6 because it hasn't eliminated IPv4" a really weird opinion (it's not exactly what you said, but it is how I interpret your first few comments combined) because it's sort of recursive: hate IPv6 -> continues to use IPv4 -> IPv6 is unable to eliminate IPv4 -> hate IPv6??? Perhaps you can elaborate on it further, but I don't think it will be agreeable either way.

Re: Tell HN: Hacker News now supports IPv6

#370
post #226

Earlier quoted context omitted.

> there is no nat w/o a "firewall" Actually, there is! People normally don't notice because NAT is usually co-located with a stateful firewall (since both need connection tracking to work, unless it's the rarer 1:1 NAT). But you can run NAT with firewall disabled, and in that case, it's possible in some cases for a device on the outside to access a device on the inside. For instance, suppose a NAT router with 192.168…

true, un-statefull nat's exist but their usefullness is limited

The post you replied to was talking about stateful NAT. Stateful NAT doesn't firewall either. If you do what they described, you'll be able to connect in just fine unless there's a separate firewall blocking it.
Post reply on HN