Live data from Hacker News

The IPv6 Transition

potaroo.net

131–140 of 433 posts

Re: The IPv6 Transition

#131
post #54

Earlier quoted context omitted.

I can route to v4 endpoints on my v6-only network just fine. Shrugs

They aren’t compatible. There is a device in the middle doing a translation for you. That’s like saying HTTP can talk to FTP servers as long as there is an HTTP to FTP proxy. The only thing that makes them seem compatible is there is a well formed address space in v6 that clients send v4 requests to. But it’s still v6 and a 64 proxy needs to have an actual IPv4 address to translate the source to before sending it via…

> They aren’t compatible. There is a device in the middle doing a translation for you.

The same could be said of the awful mess we have currently with IPv4 NAT almost everywhere on the current IPv4 network (and CG-NAT as well).

Re: The IPv6 Transition

#132

Earlier quoted context omitted.

India is also around 75%. Both of them cover quite a bit of humanity. The regions where growth is going to happen don't own a lot of blocks so they will focus on IPv6.

Vietnam (pop. 98M) has mandated moving to IPv6, with goals for migration between 2025 and 2030: * https://www.theregister.com/2024/10/14/vietnam_digital_infra...

Meanwhile in Australia I called my ISP to enable IPv6 and they asked me to justify why I needed it.

Because "it's the Internet" and has been a standard since the year 2000 doesn't seem to be sufficient reason to bother...

Re: The IPv6 Transition

#133
post #120
post #90

People posting have mentioned that IPv4 is working for what they use the internet for. But of course it is. When NATs has been required for your whole life, how could the internet have built features that needed p2p routing? Just convince businesses to build something that requires special router configuration? And still wouldn’t work on phones or with ISPs that require CG NAT? You got what worked out of the box. You…

Why do people assume IPv6 means "easy p2p"? Even if NAT will be gone one day, the stateful firewalls won't. Every every home router would still ship with "deny all incoming" by default, and every corporate network would have the same setting as well. Same as IPv4, IPv6 serving would still need registration with border device, either manual by user, or via UPnP-equivalent.

"everything gets a global IP, no more NAT headaches" was one of marketing talking points for IPv6. Not necessarily the case nor welcomed by everyone, but that was the intent.

Re: The IPv6 Transition

#134

These charts that show IPv6 adoption really don't mean shit. The thing is: every single device out there isn't being used directly by a human bean (and a real hero.) They include things like sensors, smart lights, fridges, washing machines, a huge huge number of mobile devices, company networks, ... apparently even tooth brushes? Look at another sector and the story is ((quite horrible.)) I'm talking a regular fixed…

Strange, every router I've used in the last 10+ years has done IPv6 fine. Even the RSP/ISP supplied gear I've used at friends/family houses are all fine with IPv6. Where I live all fixed line RSP/ISPs (except for one) has IPv6 enabled and on request will sell RSP-supported routers with IPv6 enabled out of the box. I personally don't use RSP-supplied gear but I've used Ubiquiti, Microtik, Netgear, etc routers and they all work just fine with sane IPv6 defaults. I really have not come across a single case of a bad IPv6 routers -- even among RSP-supplied equipment.

Re: The IPv6 Transition

#135

Earlier quoted context omitted.

> in fact, having a public address is actually a security and privacy risk. I strongly disagree with this. Privacy (not that it's a big deal imo) is well handled by the temporary address extension, and security is not an issue if you run a firewall. And you should be running a firewall even if you use v4, because NAT is not an acceptable security measure.

Whilst I agree with you, I rather depressingly suspect a lot of people equate NAT with “security”.

Only CG-NAT provides any semblance of "privacy" from the perspective of the outside world, but is a hideous technology that shouldn't exist.

Normal NAT as seen with home internet routers provides zero privacy, because you still have a predictable public IP.

People also think that IPv4+NAT provides security, but IPv4 is such a tiny address space that all public IPs are scanned daily by various malicious bots. Meanwhile IPv6 is so enormous that unless you register your address in some public way, you're completely invisible to port-scanning bots by default!

Re: The IPv6 Transition

#136
post #98
post #62

Earlier quoted context omitted.

Serious, competent network engineers are not created in vacuum from platonic ideals and TCP fragments. They're home hobbyists who grew up hating ipv6, and won't magically learn it overnight when their previous networking guy quits and they get handed the keys to the server cage

These people are neither competent nor serious. In the real world, people who design and operate large networks are the very same people who staffed the working groups who designed IPv6. It's their design.

A key aspect of IPv6 is that the address space is big enough that 'carving it up' for subnets is dramatically simpler even at the largest scales. You don't need to be frugal with network sizes, and you don't need central coordination to avoid conflicts. This is huge!

E.g.: If I want to deploy a cloud VPC (or vNET), then I have to go find "the guy with the spreadsheet" and peel off a tiny(!) private IPv4 address space. If he's away from his desk or on holidays, my 1-minute automation script will now take 1-10 working days until he's back and responding to requests. With IPv6 this just disappears as a bottleneck.

Re: The IPv6 Transition

#137

One of my biggest issue is: how do you even detect exfil when ICMP is mandatory in IPv6 for the other protocols to even just work? IPv6 looks so Rube-Goldbergy to my eyes that if I squint just a little tiny bit and put a very thin thinfoil hat on, I could nearly swear this complexity is there by design. For example so backdoors allowing exfil through ICMP are impossible to detect. IPv6 is chatty. So chatty. There are…

ICMP is required for IPv4 to work correctly, too. It's often completely blocked by cargo culting net admins who then wonder why their things fail that ICMP would have fixed.

Re: The IPv6 Transition

#138
post #120
post #90

People posting have mentioned that IPv4 is working for what they use the internet for. But of course it is. When NATs has been required for your whole life, how could the internet have built features that needed p2p routing? Just convince businesses to build something that requires special router configuration? And still wouldn’t work on phones or with ISPs that require CG NAT? You got what worked out of the box. You…

Why do people assume IPv6 means "easy p2p"? Even if NAT will be gone one day, the stateful firewalls won't. Every every home router would still ship with "deny all incoming" by default, and every corporate network would have the same setting as well. Same as IPv4, IPv6 serving would still need registration with border device, either manual by user, or via UPnP-equivalent.

UDP hole punching works when you don't have symmetric NAT. So e.g. voice and video calls don't need a proxy and can be higher quality. You only need a third party to locate/signal your peer.

Re: The IPv6 Transition

#139
For my entire life, the networking nerds have been shaming us for not using IPv6. Back when I had a NeoPet in middle school, IPv6 was was "just around the corner." I'm now raising my own children and still listening to the same IPv6 talking points.

Every company I've ever worked for has completely disabled IPv6 on the corporate network. My own ISP still doesn't offer it. Disabling it is often the quickest fix for a variety of networking issues.

At some point we must admit failure. There is no conspiracy to limit IPv6 adoption. If the technology was truly useful, you'd see far more in our profession advocate for it.

Re: The IPv6 Transition

#140

If the US had the same IPv4 scarcity as the rest of the world (specifically, if major US ISPs were using CGNAT), the IPv6 transition would be happening much faster.

That's probably true for consumers. For large, global corporations, IPv6 is a million miles away. I've worked with several, and they all have poorly managed kit, vulnerabilities everywhere, poor documentation/diagrams, poor performance, millions of firewall rules, tons of vendors to connect with, outsourced wireless vendors, remote access solutions that are a byzantine security mess, ... IPv6 is suicidal for most large organizations beyond ok we can speak IPv6 for a small part of the infrastructure. Add to this the recent deluge of VPNs everywhere (probably due to WireGuard) and container networking, IPv6 would be a recipe for disaster. Security is difficult in this scenario, in part due to the people implementing this stuff don't have a good handle on what they are doing.
Post reply on HN