In NDN, all data is signed by data producers and verified by the consumers, and the data name provides essential context for security. Centralizing the concept of security in the network's architecture will create an intractable problem. Certain parties will still want to impose their desire to be able to eavesdrop on the data. Therefore, there cannot be any real security in such centralized design for security. The…
UCLA, Cisco and more join forces to replace TCP/IP
41–50 of 86 posts
Re: UCLA, Cisco and more join forces to replace TCP/IP
#42Earlier quoted context omitted.
"Even IPv6 hasn't picked up" - this needs correction. http://6lab.cisco.com/stats/ https://www.google.com/intl/en/ipv6/statistics.html#tab=per-... http://www.worldipv6launch.org/measurements/ You can notice that 9% of the internet users in the US are IPv6-enabled. Germany is over 11%. Belgium is almost 30% (of course due to smaller population it's less in absolute host count). How many IPv6 users this is in millions,…
Yes, but considering that the intent of IPv6 is to replace IPv4, not just to work along with it, I would still say that IPv6 hasn't reached the critical mass. Things have started moving fast in the last 2 years, but IPv4 still carries 96% of the world's data. It's interesting that the adoption is 30% in Belgium and 11% in Germany, but in India, UK, Australia, China, Canada and many more countries, it's less than 1% (…
Also, another factor which will kick in as more and more folks get IPv6 is that maintaining both IPv4 and IPv6 is a bit of a pain.
Considering that you can pack the entire IPv4 internet into a single /96 IPv6 prefix (that's 4 billion times less than the address space available for a single subnet), getting your infra IPv6-only and frontending it with a stateless IPv4->IPv6 translator (or an SLB64 boxes) becomes a more and more interesting option.
More info on this: https://ripe64.ripe.net/presentations/67-20120417-RIPE64-The...
Another company which might be more familiar, moving in a similar direction: http://www.internetsociety.org/deploy360/resources/case-stud...
This is the content side. On the eyeball side, there are also wins to be made by simplifying the infrastructure by running IPv6-only, and running IPv4 atop that as a service.
See https://ripe67.ripe.net/presentations/131-ripe2-2.pdf for a good and public example of this being done.
These are the leaders, but they give the impression of what can and will be done by more and more folks.
Thus, it makes sense to start talking about when the IPv4 will be turned off. Some anecdata: http://www.networkworld.com/article/2168165/tech-primershen-...
And a couple more links with an economic/game theory angle on turning off IPv4:
https://www.nanog.org/sites/default/files/wed.general.howard...
www.asgard.org/images/pricing_v1.3.docx
So, indeed quite an interesting time ahead!
(Sorry for offtopic, BTW, given the thread was about the NDN :-)
Re: UCLA, Cisco and more join forces to replace TCP/IP
#43Umm.. how about let's NOT replace TCP/IP with anything because it's may be the only well-designed thing on the Internet that actually works? If you want an impossible super-hero project to work on, try replacing HTTP instead - at least you'd actually be solving a problem.
Whats wrong with HTTP? How would you improve it? Its a Text Transfer Protocol, you can even build applications with text only clients and servers. One only needs echo, bash and netcat to make a server and client.
> One only needs echo, bash and netcat to make a server and client.
Not as of HTTP/2.0. :(Re: UCLA, Cisco and more join forces to replace TCP/IP
#44In NDN, all data is signed by data producers and verified by the consumers, and the data name provides essential context for security. Centralizing the concept of security in the network's architecture will create an intractable problem. Certain parties will still want to impose their desire to be able to eavesdrop on the data. Therefore, there cannot be any real security in such centralized design for security. The…
In what way is SSL a "security joke"?
(and tons of others besides, plus crappy code in the most prevalent implementations used).
Re: UCLA, Cisco and more join forces to replace TCP/IP
#45There's already IEEE_802.1aq which is optimizing routing and allowing multiple parallel routing paths. https://en.wikipedia.org/wiki/IEEE_802.1aq Lecture well worth of watching: Frank Fitzek, Aalborg University: Network Coding for Future Communication and Storage Systems https://www.youtube.com/watch?v=qaJYWrYKVRo
Re: UCLA, Cisco and more join forces to replace TCP/IP
#46In NDN, all data is signed by data producers and verified by the consumers, and the data name provides essential context for security. Centralizing the concept of security in the network's architecture will create an intractable problem. Certain parties will still want to impose their desire to be able to eavesdrop on the data. Therefore, there cannot be any real security in such centralized design for security. The…
In what way is SSL a "security joke"?
Re: UCLA, Cisco and more join forces to replace TCP/IP
#47Earlier quoted context omitted.
In what way is SSL a "security joke"?
Since most servers were found to be vulverable to crazy simple attacks like that: http://en.wikipedia.org/wiki/Heartbleed or the Apple one: http://nakedsecurity.sophos.com/2014/02/24/anatomy-of-a-goto... (and tons of others besides, plus crappy code in the most prevalent implementations used).
Re: UCLA, Cisco and more join forces to replace TCP/IP
#48One of the earliest attempts to replace the the TCP/IP model (or rather the lower layers of the ISO-OSI model) was the Asynchronous Transfer Mode (ATM). Despite being a well-intentioned idea, it failed to see real world usage because of the complexity. Along the way many developments happened. People learned to live and work with IPv4. Even IPv6 hasn't picked up despite solving some important problems. So when it com…
"Even IPv6 hasn't picked up" - this needs correction. http://6lab.cisco.com/stats/ https://www.google.com/intl/en/ipv6/statistics.html#tab=per-... http://www.worldipv6launch.org/measurements/ You can notice that 9% of the internet users in the US are IPv6-enabled. Germany is over 11%. Belgium is almost 30% (of course due to smaller population it's less in absolute host count). How many IPv6 users this is in millions,…
Re: UCLA, Cisco and more join forces to replace TCP/IP
#49In practice, especially at large companies, it will certainly without a doubt degrade into workstation001, workstation002... workstation999 and then we're in effect back where we started from - using numbers.
This looks like a solution in search of a problem.
Re: UCLA, Cisco and more join forces to replace TCP/IP
#50Earlier quoted context omitted.
Let's take a look at the Internet itself. https://www.ietf.org/rfc/rfc791.txt is dated 1981. Figure 1 in http://www.census.gov/prod/2013pubs/p20-569.pdf shows that the first time they recorded was in 1997, at 18%. That's 16 years (actually a bit more because my understanding is rfc791 documents the running code), and still under 20% - so by the same metric, the Internet is a failure! Of course, then we can see the ta…
Yes, but I don't think comparing Internet adoption with IPv6 adoption is terribly valid. The first was a radically new technology and it took years for people to figure out how to best make use of it. IPv6 was supposed to be a purely technical improvement to deal with some deficiencies of IPv4, notably address space limitations. It should mostly concern only network and systems administrators and systems software dev…
I'm no network engineer, but as I understand it, to support IPv6, companies need to replace their switches. I think it's fair to say that there are literally millions of switches that need replacing. We are talking billions of dollars in total investments. I really don't see how it's surprising that this will take a while. Billions of dollars don't hang on trees, companies need to earn the money before they can spend it.
At the same time, because IPv6 is used less frequently, it is more expensive. The price of electronics is determined by volume: the more you produce the cheaper it gets. This means IPv6 has a price disadvantage to IPv4, which is especially noticeable in the early years (of ~0.1% adoption). A device that is produced at only 0.1% the volume of the most popular devices will be considerably more expensive.
This is, in part, why we see an exponential adoption curve: the more people who buy IPv6 equipment the cheaper it gets, and the cheaper it gets the more people buy it, this chain reaction helps to cause the exponential adoption rate.
I'm not saying everyone will end up using IPv6, although I think it is likely, but I'm saying it should be no surprise that replacing billions of dollars worth of network equipment takes time.