Live data from Hacker News

Google Hits 50% IPv6

blog.apnic.net

241–250 of 496 posts

Re: Google Hits 50% IPv6

#241
post #20

Meanwhile T-Mobile/Odido in the Netherlands is still not supporting IPv6 despite promising to have been working on it for years. Ubiquity gateways also seem to not support it sadly. It would be awesome if they supported something like Hurricane Electric’s tunneling.

> Meanwhile T-Mobile/Odido in the Netherlands is still not supporting IPv6 despite promising to have been working on it for years.

While T-Mobile US has been IPv6-only since ~2018:

* https://www.youtube.com/watch?v=d6oBCYHzrTA

Re: Google Hits 50% IPv6

#242

Earlier quoted context omitted.

Why one byte? Is that enough bytes? An extra 4 bits each for source and destination? Maxing out at 2^36 addresses? That seems uncomfortably small safety margin.

I was saying adding a byte to the address so its a 40 bit address which would be two bytes to the header. Obviously it would still have the same issue where hardware and software would be incompatible and would need to be replaced but the same concepts that worked in IPv4 would work in my fake protocol instead of IPv6 where the network needs to be redesigned from the ground up. Also IPv6 addresses are ugly

How sure are you that 40 bits is a good number of bits? What's your justification? It takes over 30 years to deploy new bits, so you have to be really sure before you start that effort.

Re: Google Hits 50% IPv6

#243

Earlier quoted context omitted.

> a better web experience than IPv4 That's already the case. IPv6 is often faster because most ISPs these days use cgnat for IPv4.

I have yet to see any ISP use CGNAT here in Sweden. It seems to be a highly regional problem for some reason. Both on mobile and on broadband I get publicly routable IPv4.

Wow a publicly routable IPv4 address on a mobile phone? Wouldn't that drain the battery a lot? Or is there some kind of carrier-level firewall still?

Re: Google Hits 50% IPv6

#244
post #151

Earlier quoted context omitted.

The corporate world tend to be easy to do, just put a gateway to IPv6 on their zScaler (or similar) exit points and done. However, that is not really needed as they are "only" consuming a few IPs around the world (for that purpose). No one in the corporate world wants to go back to the days of Public IPs on all devices. Internally the enterprises have no reason to switch as it just complicates their setups.

I wouldn’t want a public ip for all the devices and computers on my home network either. Seems like a huge security risk.

> I wouldn’t want a public ip for all the devices and computers on my home network either. Seems like a huge security risk.

The real security risk is thinking that just because you have an internal RFC 1918 address space your security has improved.

It's been a decade+ since a firewall being considered a castle/moat of security being best practice. Any IT person that thinks that if they see a device with an 10/8 (or 172.16/12 or 192.168/16) IP and think you're safe you should be fired: it's lazy thinking.

At least if you had a GUA address it would force you to pay more attention to the rest of your security controls. Just recently a co-worker retired some systems that were accessible to the outside via DNAT—but forget to clean up the firewall rules. So he then—for some fucking stupid reason—decided to re-use those same IPs, even though we had so many fucking other IPs available, and one of the boxes got compromised because it happened to have a simple, guessable password on the initial image install.

Re: Google Hits 50% IPv6

#245

Literally all we had to do was add a byte to IPv4 and we'd be done but noooo we need to overengineer the next protocol and make it as painful as possible to adopt.

this keeps coming up, if you add a byte to ipv4 you still have a transition problem. 5 byte machines can't talk to 4 byte machines. pretty much the only thing that solves is people not liking the :: syntax. the only other change is auto configuration, which...kind of doesn't matter? is that really causing problems?

Re: Google Hits 50% IPv6

#246
post #86

Earlier quoted context omitted.

The point of local networks of a minimum size of 64 bit isn't only to have MAC-based addresses (48 bit would have been enough for that, fwiw), but in general to support non-coordinated/probabilistic self-assignment schemes with negligible collision probability. Picking a random local address (which is very important for privacy, as you've mentioned) is much easier if you don't have to do an elaborate dance of listen,…

The best thing about SLAAC is that it forces your ISP to give you at least 64 bits. Otherwise you know Comcast would only give out a /128 and charge you for more, so you'd use NAT at home just like IPv4.

Unfortunately SLAAC doesn't force upstream to provide a /64 universally.

Some ISPs are reportedly giving out a /128, and SLAAC works adequately with a router performing IPv6 NAT, so those ISPs don't see a problem.

Mobile phone as WiFi access point is another common way people access the net nowadays. I've occasionally seen permanent installations, with a phone taped to a window. I've never seen a mobile phone AP offer IPv6 to clients, but if they do they have to use SLAAC-compatible IPv6 NAT in that situation.

Re: Google Hits 50% IPv6

#247
FTA:

>Individual economies such as India, Viet Nam, and Saudi Arabia exhibit adoption curves that differ markedly from the global average. As the APNIC Labs data shows, this global trend does not necessarily reflect the experience of individual economies.

>APNIC’s own measurement records a 42% worldwide IPv6 capability (Figure 2). That’s a substantial difference, which also needs clarifying."

The nuance is that IPv6 is growing faster in developing countries with poorer economies. I'm guessing this is because building modern IPv6 network from scratch is cheaper & more efficient than acquiring scarce and expensive IPv4 addresses. This is a major advantage for newer providers in growing economies.

So while the Google is showing it at 50%, APNIC's weighted global measurement shows it at 42%.

Re: Google Hits 50% IPv6

#248

Earlier quoted context omitted.

I was saying adding a byte to the address so its a 40 bit address which would be two bytes to the header. Obviously it would still have the same issue where hardware and software would be incompatible and would need to be replaced but the same concepts that worked in IPv4 would work in my fake protocol instead of IPv6 where the network needs to be redesigned from the ground up. Also IPv6 addresses are ugly

How sure are you that 40 bits is a good number of bits? What's your justification? It takes over 30 years to deploy new bits, so you have to be really sure before you start that effort.

> It takes over 30 years

Only because it is overengineered. Parents pragmatic protocol would have been adopted faster

Re: Google Hits 50% IPv6

#249

Earlier quoted context omitted.

I wouldn’t want a public ip for all the devices and computers on my home network either. Seems like a huge security risk.

> I wouldn’t want a public ip for all the devices and computers on my home network either. Seems like a huge security risk. The real security risk is thinking that just because you have an internal RFC 1918 address space your security has improved. It's been a decade+ since a firewall being considered a castle/moat of security being best practice. Any IT person that thinks that if they see a device with an 10/8 (or 1…

Home networks are usually, nearly always, not run by anyone who is capable of “paying attention to the rest of their security controls”

Re: Google Hits 50% IPv6

#250

Earlier quoted context omitted.

> It was also predicted that the address exhaustion problem would be averted, in fact that was the purpose of v6. It failed to deliver. It was averted: how do you think we got several billion smartphones connected to the Internet? Do you think that would have been practicable without IPv6? Comcast—not even mobile—had to move to IPv6 on their landline ISP business because they ran out of IPv4 addresses for TR-069: the…

NAT / CGNAT has been doing the heavy lifting extending the life of the Internet; ipv6 has done jack shit. If v6 was useful and actually averted v4 exhaustion we'd all be accessing v6 sites/addresses at this point. Put another way, we can drop v6 completely and the Internet will still work. Obviously wouldn't work the other way around. As for telco addressing handsets, they could use any addressing scheme to be honest…

> NAT / CGNAT has been doing the heavy lifting extending the life of the Internet; ipv6 has done jack shit. If v6 was useful and actually averted v4 exhausted we'd all be accessing v6 sites/addresses at this point.

This is factually difficult to support. (Sent from my iPad which doesn’t have an ipv4 address… to hacker news which has an ipv6 address)

Post reply on HN