Live data from Hacker News

IPv6 may already be irrelevant – but so is moving off IPv4

theregister.com

41–50 of 54 posts

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#41
post #20

Earlier quoted context omitted.

Did you miss the part about CG-NAT? Once your ISP runs out of their IP4 addresses and puts you behind a CG-NAT, you can punch all the holes you like; nothing is going to get to you. At least not without doing fancy stuff like using an externally-hosted VPN to shuttle connections to you.

People seem to have misconceptions about CGNAT. Of course you can punch holes there. CGNATs can be asked for port forwarding using PCP, unless your ISP disabled that.

I've yet to see a single ISP (I live in the US) that even allows customers to host services. If you look in the TOS for services like Comcast, AT&T, T-Mobile, etc, you'll see a part about hosting services being forbidden. And that's even for normal IP4 addresses that aren't behind CG-NAT. Now, they probably don't look too hard unless you give them reason (I hosted various things over a Comcast connection for a decade) but the rule is in there.

Perhaps it's different for a mom & pop ISP, but I don't see the big ones configuring anything that makes it easier to do what they already don't want you doing anyway. They see the inability to forward ports as a feature, not a bug.

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#42
post #41

Earlier quoted context omitted.

People seem to have misconceptions about CGNAT. Of course you can punch holes there. CGNATs can be asked for port forwarding using PCP, unless your ISP disabled that.

I've yet to see a single ISP (I live in the US) that even allows customers to host services. If you look in the TOS for services like Comcast, AT&T, T-Mobile, etc, you'll see a part about hosting services being forbidden. And that's even for normal IP4 addresses that aren't behind CG-NAT. Now, they probably don't look too hard unless you give them reason (I hosted various things over a Comcast connection for a decade…

I'm not in US, but in EU. Here, T-Mobile or Orange do not have a problem with incoming traffic, and they know that people have security cameras, doorbells, or NAS devices in their homes that they want access from outside.

So even if you expose your Home Assistant web to the wide web, no ISP is going to have a problem with that and won't interpret it as hosting services. What they really want is that you don't run a bandwidth intensive services on a consumer connection, which is going to be overbooked somewhere in their infra, causing service degradation to other users.

And for example Orange does provide PCP for their CGNAT.

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#43
post #8

I mean its an opinion. The argument is somewhat thin "CDNs use DNS so it doesn't matter what the IP is" I mean yes, that true, but it should have always been true. Dishing out raw IPs is bad anyway, it limits your flexibility (yes yes anycast exists, but if you're big enough to setup any cast, I bet you're using ipv6 internally already) Ipv6 is here, and will slowly grow as time goes on. There will be growing pains,…

> 10.0.0.0/8 runs out pretty quick 16,777,216 containers, wow.

So, if you have a sane ipv4 network, where everything is dhcp, and nothing apart from a few key things are statically assigned, then yeah _technically_ you can have 16million addresses all at once.

But, subnets need to be located next to each other physically, otherwise performance suffers. subnets have affinity.

but once you have subnets, you then start loosing packing efficiency.

for example, in the batshit world of K8s, you give each node its own /24 to dish out. Not only cant that limit the number of containers you can host, it also is really inefficient. (eating 256k addresses)

More over, it also means that you need to reuse addresses. in a large cluster of say 1000 nodes, each hosting 40 containers, starting/stopping anything up to 30 containers a second isn't unreasonable. Its not inconceivable that you'll end up trying to connect to a stale address (either because its not propagated yet, or your brand of service discovery isn't that fast). This can cause hilarious transitory errors.

but if you could assign an IP per container, and have enough space to not re-use that address for at least a few hours then that goes away. so instead of getting weird fuzzing errors(or misc 404/401), you get a connection timed out.

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#44
IPv6 and Python 3 are case studies in How to Not Upgrade Something.

They basically created entirely different products that provided a marginal immediate benefit to the users and then said "upgrade whenever you get around to it". They are both now in the 2nd decade of their upgrade cycle.

PowerPC->Intel, Xbox/PlayStation emulation, x86 32-bit>64-bit, and Java are all technologies that had successful upgrade strategies that were centered around replacing the original product rather than indefinitely providing an alternative.

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#45

The resistance to switch to ipv6, or the comfort with the ipv4-born address exhaustion remedies, only helps an internet of consumers, not an internet of peers that create and share. If you are behind NAT or CG-NAT, you can only consume, not create. You can't host a server, expose a port. You are at the mercy of the big fish.

99.99% of people who create and share things via the internet do so via centralized social media providers, and that would continue to be true if the whole world were magically IPv6-only. I think it’d be nice to self-host things to, but it’s inaccurate and even a bit insulting to claim that the millions of people creating content on the internet today don’t exist.

And then there are people like myself who host publicly-available internet services from my home internet service that's absolutely behind CGNAT. That makes things a bit more hassle to get working, but it's certainly possible.

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#46
post #44

IPv6 and Python 3 are case studies in How to Not Upgrade Something. They basically created entirely different products that provided a marginal immediate benefit to the users and then said "upgrade whenever you get around to it". They are both now in the 2nd decade of their upgrade cycle. PowerPC->Intel, Xbox/PlayStation emulation, x86 32-bit>64-bit, and Java are all technologies that had successful upgrade strategie…

I think this describes very well what's happened.

I haven't moved my systems to IPv6, and have no current plans to do so, because it's a pretty major change (meaning a ton of hassle) that brings me no benefits that I care about.

If/when IPv6 becomes mandatory to connect to the internet, I'll go to the trouble of shifting my systems.

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#47

Earlier quoted context omitted.

Are you sure about this? It’s in the rfc from like 1998 that ISPs should allow customers to sla for larger prefixes. I don’t know a single US isp that doesn’t allow at least a 56. IPv6 is pointless and still a security risk but I’m guessing you’re misconfiguring something.

Yup, Liberty Global (also known as UPC) in Europe. Assigning only /64 & no DHCP-PD. There's not much to misconfigure, since in IPv6 you have to use their router and they are pushing the config. And since you have only /64, you cannot put another router behind theirs.

Which of course goes against what RIPE is saying:

> The following sections explain why /48 and /56 are the recommended prefix assignment sizes for end customers.

* https://www.ripe.net/publications/docs/ripe-690/#4-2--prefix...

And it's not like it's a new policy:

> RIPE-690 outlines best current operational practices for the assignment of IPv6 prefixes (i.e. a block of IPv6 addresses) for end-users, as making wrong choices when designing an IPv6 network will eventually have negative implications for deployment and require further effort such as renumbering when the network is already in operation. In particular, assigning IPv6 prefixes longer than /56 to residential customers is strongly discouraged, with /48 recommended for business customers. This will allow plenty of space for future expansion and sub-netting without the need for renumbering, whilst persistent prefixes (i.e. static) should be highly preferred for simplicity, stability and cost reasons.

* https://www.internetsociety.org/blog/2017/10/ipv6-prefix-ass...

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#48
post #44

IPv6 and Python 3 are case studies in How to Not Upgrade Something. They basically created entirely different products that provided a marginal immediate benefit to the users and then said "upgrade whenever you get around to it". They are both now in the 2nd decade of their upgrade cycle. PowerPC->Intel, Xbox/PlayStation emulation, x86 32-bit>64-bit, and Java are all technologies that had successful upgrade strategie…

> IPv6 and Python 3 are case studies in How to Not Upgrade Something.

There was no other way to do it with IPv6: IPv4 has 32-bits of address space and >32 was needed for more addresses. That 32-bits is hard-coded in data structures, APIs, and even DNS formats (e.g., A records).

So regardless of anything else related to IPv6 (ARP vs ND), you would have still needed to release a bunch of code that had to be installed on every router, L3 switch, firewall, DNS server, and end device.

It was also recognized that, given the size of the Internet even in the 1990s, that a flag day like was done for the NCP->IP transition would not be possible:

      We believe that it is not possible to have a "flag-day" form of
      transition in which all hosts and routers must change over at
      once. The size, complexity, and distributed administration of the
      Internet make such a cutover impossible.
* https://datatracker.ietf.org/doc/html/rfc1726#section-5.5

So you were always going to have to have a 'rolling upgrade' to get a larger address space. You were always going to have translation systems.

It was also recognized that the 'legacy' may never go away:

      Furthermore, we note that, in all probability, there will be IPv4
      hosts on the Internet effectively forever.  IPng must provide
      mechanisms to allow these hosts to communicate, even after IPng
      has become the dominant network layer protocol in the Internet.
* Ibid

Re: IPv6 may already be irrelevant – but so is moving off IPv4

#49

Earlier quoted context omitted.

99.99% of people who create and share things via the internet do so via centralized social media providers, and that would continue to be true if the whole world were magically IPv6-only. I think it’d be nice to self-host things to, but it’s inaccurate and even a bit insulting to claim that the millions of people creating content on the internet today don’t exist.

> I think it’d be nice to self-host things to, but it’s inaccurate and even a bit insulting to claim that the millions of people creating content on the internet today don’t exist. It's not just about self-hosting, but peer-to-peer clients as well. When Skype originally came out it was P2P, but because of NAT they created (ran?) "super-nodes" that could do things like STUN/TURN/ICE. Wouldn't it be nice to be able to…

I agree! I was just taking issue with the overly broad claim that being behind NAT only lets you consume, not create.
Post reply on HN