Earlier quoted context omitted.
I want ipv6 as much as anyone, but we are not spending enough time preparing for NATs death. It's responsible for far more security than we as a collective would like to admit and there's a lot more we could be doing now to get ready.
That's a common misconception. NAT isn't a security feature but rather a feature of a stateful firewall, which is. There's no reason to remove the firewalls that are in place now when ipv6 happens.
Amazon owns more than $2B worth of IPv4 addresses
191–200 of 372 posts
Re: Amazon owns more than $2B worth of IPv4 addresses
#192Earlier quoted context omitted.
My startup offers a residential IP sharing model where users get paid to share their bandwidth: https://packetstream.io
This is the one of the best (if not the best) solution out there I tried so far, congratulations. I am very happy to see it is from fellow HNer.
Re: Amazon owns more than $2B worth of IPv4 addresses
#193Re: Amazon owns more than $2B worth of IPv4 addresses
#194How are we not out of IPv4 addresses already? Aren't there a billion phones out there? And probably the same number of PCs and god knows how many servers?
When i read the title, I first thought to myself that those 2 billion dollars will be pretty much worthless once everyone uses ipv6. But as soon as more ipv6 adresses are used (or CG-NAT), ipv4 adresses will become cheaper, so there seems to be a natural balance which will keep the state of "There are IPv4 adresses left" and "IPv4 adresses will run out sometime soon"
Re: Amazon owns more than $2B worth of IPv4 addresses
#195Earlier quoted context omitted.
That's a common misconception. NAT isn't a security feature but rather a feature of a stateful firewall, which is. There's no reason to remove the firewalls that are in place now when ipv6 happens.
If firewalls are even needed, a recent poll on an IPv6 professional forum ended with 50/50 split between opt-in and opt-out for IPv6 firewalls in routers of consumer ISPs...
Re: Amazon owns more than $2B worth of IPv4 addresses
#196Your ISP doesn’t want real IPv6. It’s bad for business.
I don't see why. Major consumer-grade French ISPs give IPv6 by default on FTTH installations and the router is configured accordingly (Orange, Free, SFR, Bouygues Telecom). Generally, you get a /64. Of course, when using IPv6 there is no NATting, each of your device has its own IPv6 address of the /64 range allocated to you.
Re: Amazon owns more than $2B worth of IPv4 addresses
#197Earlier quoted context omitted.
It has nothing to do with network admins. Everything the majority of customers care about in the US is available on IPv4 and sometimes ipv6. If v6 goes down for your customers, they probably won’t even notice. If you don’t have v4, you don’t have a business. It hasn’t even been that long that Amazon EC2 has had v6 support, which is where a huge chunk of the Internet is hosted. The network admins at ISPs are just prov…
First: Here in Australia no major ISPs provide a native IPv6 service, and if they do, they don't provide it to business. It's obscenely difficult to obtain IPv6 in Australia. None of the major telcos do it, you have to go down the list to like the 5th or 6th biggest ones before it becomes an "experimental option" for residential connections only. Second: Ever since IPv6 has been a thing, I've offered to customers the…
As such a customer, I’m worried that my ISP would eventually bait-and-switch me from routable IPv4 + optional IPv6 to CGNAT IPv4 + IPv6 when convenient to them. Sorry, but I’m not risking going behind a 1:n NAT layer that I don’t manage.
Re: Amazon owns more than $2B worth of IPv4 addresses
#198A small nitpick: They don't "own" these addresses, the regional internet registries (ARIN, RIPE, APNIC etc.) loan them to Amazon so they can use them, they could take them away again if AWS would do something that's against the RIRs' policies. We also have a single /22 block of addresses from RIPE (we were one of the last companies to get such a block in 2019), so far we haven't made use of it though as it's still a…
> o far we haven't made use of it though as it's still a bit tricky to find providers that will announce your addresses (without asking a hefty amount of money for it). Vultr can do so https://www.vultr.com/features/bgp/ for no additional cost.
Re: Amazon owns more than $2B worth of IPv4 addresses
#199Earlier quoted context omitted.
When's the last time you gave an IPv4 address over the phone? I've been in networking for 30 years, worked for multiple multinational ISPs, and the answer is basically never.
6 months ago. I let about 10 family and friends connect directly to my home server. My firewall blocks everything except for these 10 IP addresses. I did get tired of having them figure out their IP address so now I just tell them to access a dummy page page on my external VPS and I check the web server log to see their IP to add to my firewall config.
And also it seems like a lot to sacrifice in order to make something marginally more helpful about once or twice a year.
Also why would you say it over the phone? Would you not ask them to email or IM it? I can't count the number of times passwords and names have been misunderstood over the phone. Numbers? Basically always at least one number is misheard.
Re: Amazon owns more than $2B worth of IPv4 addresses
#200Earlier quoted context omitted.
But you still need an ipv4 address even if it’s only 10% of people who are ipv4 only.
Fewer and fewer people are able to get an IPv4 address - that's the main reason for IPv6 !
Some people are unable to get ipv6 from their cloud hosted servers outbound right now too. Even if they tried.