Live data from Hacker News

Amazon owns more than $2B worth of IPv4 addresses

dangoldin.com

351–360 of 372 posts

Re: Amazon owns more than $2B worth of IPv4 addresses

#351

Earlier quoted context omitted.

> Your 50/50 example is hugely biased, first it's on a Telco discussion forum so that clearly selects for technical users, then it's on ipv6 which is going to further select for technical people. As you can see I'm aware of that, they are also aware of that, and the discussion is not so much about themselves (since they know how to configure a firewall or even to install their own router), but about what your "averag…

If only average grandma's were just limited to grandma's. I don't know a single person who isn't a gamer or IT person that can properly use a firewall as they exist now.

The overwhelming majority of users doesn't bother in changing any settings, as can be seen from the dramatic changes in IPv6 adoption when an ISP goes from opt-in IPv6 to forced IPv6.

Re: Amazon owns more than $2B worth of IPv4 addresses

#352

Earlier quoted context omitted.

Do you ever configure, type or have to share MAC addresses? Probably not. On the other hand, most devs / technical staff type IPs into the browser and terminal daily.

> On the other hand, most devs / technical staff type IPs into the browser and terminal daily. No they don’t. Configure a DNS server and type these in once. Any time I see IP addresses passed around it’s a sign of broken infrastructure. (It also means you aren’t using tls or you’re training people to accept cert errors)

> No they don’t

Oh yes they do.

> Any time I see IP addresses passed around it’s a sign of broken infrastructure

Nope.

> It also means you aren’t using tls or you’re training people to accept cert errors

So, let me get this straight. You have a server that's behind CloudFlare, and you're claiming we should use DNS and TLS to SSH into it?

Re: Amazon owns more than $2B worth of IPv4 addresses

#353

Earlier quoted context omitted.

> On the other hand, most devs / technical staff type IPs into the browser and terminal daily. No they don’t. Configure a DNS server and type these in once. Any time I see IP addresses passed around it’s a sign of broken infrastructure. (It also means you aren’t using tls or you’re training people to accept cert errors)

> No they don’t Oh yes they do. > Any time I see IP addresses passed around it’s a sign of broken infrastructure Nope. > It also means you aren’t using tls or you’re training people to accept cert errors So, let me get this straight. You have a server that's behind CloudFlare, and you're claiming we should use DNS and TLS to SSH into it?

IPs should be passed to the DNS server, yes.

Every server/VM I control (~200) has a DNS entry. Every active IP has a reverse (PTR) entry.

I have a monitoring task to check for missing DNS entries, as it usually suggests a problem (i.e. we've deployed or undeployed something incompletely).

Re: Amazon owns more than $2B worth of IPv4 addresses

#354

Earlier quoted context omitted.

> On the other hand, most devs / technical staff type IPs into the browser and terminal daily. No they don’t. Configure a DNS server and type these in once. Any time I see IP addresses passed around it’s a sign of broken infrastructure. (It also means you aren’t using tls or you’re training people to accept cert errors)

> No they don’t Oh yes they do. > Any time I see IP addresses passed around it’s a sign of broken infrastructure Nope. > It also means you aren’t using tls or you’re training people to accept cert errors So, let me get this straight. You have a server that's behind CloudFlare, and you're claiming we should use DNS and TLS to SSH into it?

I think you’re confused a bit, so let’s split apart the use cases to be clear why IPs are bad in both cases.

You said devs and technical staff were typing IPs into their browsers. Presumably this means the address bar, which breaks TLS.

SSH derives a big chunk of security from key caching. If you’re using IPs you now can’t have an IP change without triggering key warnings on the SSH clients for a new key at a minimum or (worst case) a breach.

Re: Amazon owns more than $2B worth of IPv4 addresses

#355

Earlier quoted context omitted.

The smallest routable IPv4 network on the Internet is a /24, which is 256 addresses. Regional Internet Registries won't assign you smaller than a /24, but individual ISPs might. Even if you have an assignment, maintaining it requires payment of annual fees to your RIR, unless you're a lucky "legacy" address holder from before the RIRs were formed.

I own a /24 from the early 90's, registered before ARIN and the other RIRs existed. It is considered a legacy block and I've never signed the legacy registration agreement, so no fees for me! I do have it routed to my home network over a "business broadband" connection.

Jealous! I pay ARIN hundreds of dollars a year in RSA fees.

As a legacy address holder, how do you feel about RPKI?

Re: Amazon owns more than $2B worth of IPv4 addresses

#356

Earlier quoted context omitted.

I own a /24 from the early 90's, registered before ARIN and the other RIRs existed. It is considered a legacy block and I've never signed the legacy registration agreement, so no fees for me! I do have it routed to my home network over a "business broadband" connection.

Jealous! I pay ARIN hundreds of dollars a year in RSA fees. As a legacy address holder, how do you feel about RPKI?

I use my network mostly for experimentation and it is unlikely to be a target for hijack. If I were a commercial enterprise I would want RPKI for the future. Currently it seems mostly irrelevant in a practical sense, due to the small number of ASes actually validating.

Re: Amazon owns more than $2B worth of IPv4 addresses

#357

Earlier quoted context omitted.

Industry leaders like NordVPN and ExpressVPN may engage in P2P routing (to use residential IPs especially) to unblock services like Netflix and Disney+ [1]. HolaVPN unapologetically does this too [2]. All of this is discounting the new-age dVPNs like Orchid (not quite the Tor replacement that was promised? [3]) and Mysterium [4]. [1] https://news.ycombinator.com/item?id=21664692 [2] https://news.ycombinator.com/item?…

How does residential IPs actual work?

You filter by block's AS. It's not always 100% correct, but with enough people you can collect your own list of most common VPS / hosting companies.

Re: Amazon owns more than $2B worth of IPv4 addresses

#358
post #210

Earlier quoted context omitted.

I mean, I don’t have any moral problems with it. But any time you’ve got one entity opening a bunch of LLCs, I think it qualifies as sketchy.

Or good business sense, maybe? If you're in real estate and own a bunch of properties, you're going to have an LLC for each property, and maybe even one LLC for each state that owns the other ones. You could easily end up with a dozen LLCs for Maybe there's some similar avenue here.

Is there a non-sketchy reason why having multitudes of LLCs makes good business sense?

AFAIU, typical reason is to compartmentalize liabilities, but aren't you doing something sketchy if you have reasons to compartmentalize?

Re: Amazon owns more than $2B worth of IPv4 addresses

#359
post #207
post #117

Earlier quoted context omitted.

man I'd have just stuck with it for 20k a month damn, good luck getting a salary that high working for some company.

Come on man everyone here works for a FAANG making $600k/yr plus stock, don't you know that?

fucking apparently, I don't even know why I bother sometimes.

Re: Amazon owns more than $2B worth of IPv4 addresses

#360

Earlier quoted context omitted.

Did you register a ASN?

Not yet. Getting an ASN number is independent of getting LIR status.

More hosts are willing to be a upstream for your ASN than announce your IP block on their ASN.
Post reply on HN