Live data from Hacker News

AWS adds an extra 5.5M IPv4 addresses

github.com

181–190 of 283 posts

Re: AWS adds an extra 5.5M IPv4 addresses

#181

Earlier quoted context omitted.

Problem with CGNAT is the costs involved in bookkeeping for law enforcement. Where an IPv4 solution for your clients only needs change-logging on IPbinding-to-client level, the CG-NAT requires you as an ISP to log every outgoing IPv4/port combination with timestamp to client mapping. Which requires A LOT more storage and much more expensive equipment. Going rate per IPv4 is up to $40 nowadays, selling of your v4 bloc…

I'm finding more and more that I go to some random website, and get a message about an IP ban. That or a 401 error with no context. If cgnat keeps scaling, these ip Limiters need to phase out.

> I'm finding more and more that I go to some random website, and get a message about an IP ban. That or a 401 error with no context.

The association between IP and user/endpoint is changing, especially with the advent of Apple’s Private Relay, other privacy-protecting proxies, and increased CGNAT.

Website & hosting providers will have to adapt, but right now we’re certainly in a transition state.

Re: AWS adds an extra 5.5M IPv4 addresses

#182

Earlier quoted context omitted.

My company owns a /16 and everybody gets an static address for each device, so I currently "own" two global IPv4 addresses. But everything is firewalled to hell and we need to connect through a proxy, so what's the point?

I own a /24, personally. It was registered in the early 90’s. I have it routed to my home network.

Out of curiosity, how much does it cost for you to run this? Not that I'm willing to pay $10k for my own /24, but I find this super interesting.

I just installed a new FTTH ISP at home and learned the hard way what CG-NAT is, after years of having my own public IP with my previous ISP.

Re: AWS adds an extra 5.5M IPv4 addresses

#183
post #178

Earlier quoted context omitted.

Can IPv4 even be defined as private property if it is nothing more than a few DDN numbers? I could make a Internet 2 that's totally isolated and restart the whole IP allocation process all over again.

Given there is such a thing as intellectual property, where someone literally owns an idea, I'd say owning an address isn't far-fetched at all.

IP only exists because of copyright law, and it would be tricky to apply copyright to an IP if it is not a creative work.

Re: AWS adds an extra 5.5M IPv4 addresses

#184

Earlier quoted context omitted.

Problem with CGNAT is the costs involved in bookkeeping for law enforcement. Where an IPv4 solution for your clients only needs change-logging on IPbinding-to-client level, the CG-NAT requires you as an ISP to log every outgoing IPv4/port combination with timestamp to client mapping. Which requires A LOT more storage and much more expensive equipment. Going rate per IPv4 is up to $40 nowadays, selling of your v4 bloc…

> Where an IPv4 solution for your clients only needs change-logging on IPbinding-to-client level, the CG-NAT requires you as an ISP to log every outgoing IPv4/port combination with timestamp to client mapping. Why does each individual connection have to get a port from the global allocator, rather than any of the pooling or hierarchical techniques that high performance memory allocators use?

The allocators already use pooling, but there are only so many source ports to choose from.

Re: AWS adds an extra 5.5M IPv4 addresses

#185
post #139

Earlier quoted context omitted.

That organization did not own those addresses. In the most generous interpretation of the situation, they were administrative custodians to the good usage of those addresses. Reselling them to a for-profit company was definitely not what was intended by anyone and directly contradicts their mission as custodians. Those addresses were that of the global radioamateur community and no one else's. That's why i made a com…

They very much did own them, you need to look at the history of ampr.org, who sits on the board and “who” applied for the /8. These did not belong to amateur radio, TAPR, the ARRL or anyone but this organization.

Looks like the answer you're suggesting is Dr. Hank Magnuski[0]? He seems like an important and impressive fellow, but I'm not sure how that addresses the idea of ownership here.

Most likely we have different understandings of how ownership/stewardship of ipv4 addresses works. My take is "I don't know how it works", but I think the people further up thread believe it's not about ownership, but merely the right to administer on the understanding that it's done for the public good, or something like that.

If you have a concise resource that summarizes how it works that would likely do more to convince us than telling us to research ampr.org.

[0] https://www.ampr.org/faq/

Re: AWS adds an extra 5.5M IPv4 addresses

#186
post #176

Earlier quoted context omitted.

There would be penalties for that, maybe even legal ones. How easy it is to steal does not really factor in whether it's a critical resource.

Can it be defined as property? I could make a Internet The Second using isolated networks and advertise whatever I wanted. It's not like digital movies and music where it's defined as property under copyright law because it's a creative work.

Isolated? Sure.

This is the same as saying no one can own a Disney character because anyone can draw it at home. Or no one owns songs because you can freely transmit them between devices you own.

People still own those things in most jurisdictions around the world.

Re: AWS adds an extra 5.5M IPv4 addresses

#187
post #186

Earlier quoted context omitted.

Can it be defined as property? I could make a Internet The Second using isolated networks and advertise whatever I wanted. It's not like digital movies and music where it's defined as property under copyright law because it's a creative work.

Isolated? Sure. This is the same as saying no one can own a Disney character because anyone can draw it at home. Or no one owns songs because you can freely transmit them between devices you own. People still own those things in most jurisdictions around the world.

The thing with Disney is that those characters were created by someone in a creative pursuit. IP addresses, on the other hand, are simply pointers to some location, and so it's an unknown if they can be covered under IP law. Digital copies of media only count as property because of that IP law, or they would be worthless because they can be copied infinitely.

Re: AWS adds an extra 5.5M IPv4 addresses

#188
post #2

low whistle I imagine they paid a pretty penny for those /12s. A thought comes to me: If IPv6 adoption continues to drag along, and AWS/Azure/GCP continue to expand their IP blocks like this, how quickly are we in danger of the cloud providers effectively being the Internet?

[deleted]

Re: AWS adds an extra 5.5M IPv4 addresses

#189
post #139

Earlier quoted context omitted.

That organization did not own those addresses. In the most generous interpretation of the situation, they were administrative custodians to the good usage of those addresses. Reselling them to a for-profit company was definitely not what was intended by anyone and directly contradicts their mission as custodians. Those addresses were that of the global radioamateur community and no one else's. That's why i made a com…

They very much did own them, you need to look at the history of ampr.org, who sits on the board and “who” applied for the /8. These did not belong to amateur radio, TAPR, the ARRL or anyone but this organization.

So, take my words with a grain of salt because i'm not a member of those communities. From reading the previous thread on HN (which i linked in my parent comment), even the people who think the sale is a good thing agree that it was a rather shady deal where it wasn't very clear that a single entity should feel entitled to "own" this IP range.

If you have links with more information going one way or another, historical internet politics is always something i have time for reading, and i think i'm not the only one around here! :)

Re: AWS adds an extra 5.5M IPv4 addresses

#190
post #171

Earlier quoted context omitted.

I've said it for years too. It's not JUST because they're long - years ago (and maybe even today?) there's still some hardware issues with keeping large sets of addresses for routing (I'm not an expert on this - I seem to remember reading about this years ago - larger ISPs not being able to keep all their routing rules in memory because of IPv6 address sizes - maybe I'm WAY off). But, yes, generally, you're right. It…

In designing ZeroTier I put a ton of effort into creating a secure P2P layer with addresses that are only 40 bits long. This effort continues with new solutions being worked on to maintain security while allowing more openness and federation. It would have been much easier to use long addresses that are long hashes of keys. Having only 40 bits means we need two layers of defense in depth to prevent intentional collis…

ZeroTier has a flat address space governed by a single algorithm. The Internet is a loose hierarchy of independently-managed networks. These problems have quite different addressing requirements.

Analogy: ZeroTier is to https://plus.codes/ as IPv6 is to mailing addresses. A mailing address is pretty long, but you can use its structure to route the mail efficiently.

Post reply on HN