Live data from Hacker News

I spent a week without IPv4 to understand IPv6 transition mechanisms

apalrd.net

401–410 of 511 posts

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#401

Earlier quoted context omitted.

I have multiple computers in the house, mostly not logged in to Google. YouTube recommendations spill between devices all the time - like, if I watch a video on one device, I’ll see the same video recommended on another. Or if my partner watches something, YouTube will recommend it to me. They’re obviously doing recommendations based on IP address. (And this is purely over ipv4).

> They’re obviously doing recommendations based on IP address. (And this is purely over ipv4). I have IPv6 at home and connect to Youtube over IPv6 (that's generally the default behaviour on macOS and many other OSes). I reboot my DSL modem-router every night and get a new IPv4 address and new IPv6 prefix every day. Now: I live in Ontario, and my ISP is based in Ontario, but they serve clients in Quebec. Every so oft…

I live just outside London and have been wondering why I’ve been getting ads from More4 for Wales and Cardiff.

Iechyd Da!

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#402
post #261

Earlier quoted context omitted.

Your ISP, "mapping your network" means being able to take data that was previously an amalgam of a household and reliably split it into the individual members and devices for better targeting.

Unless you're part of the tiny percent of people who run their own router, your ISP can just monitor what goes through your ISP-provided router.

With the home router+wifi market estimated to be USD 2070.43 million in 2022, I wouldn't say it's a tiny percentage of people, just people you know.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#403

Earlier quoted context omitted.

There is no downside to everything to be globally routable. It's completely orthogonal to firewalling. What is the risk you're picturing here? I'm really curious. Features like RFC4941/8981 mean nobody can infer anything about your network from the source addresses they see making requests out if it. If you want to use link-local V6 addresses and NAT to a global one, you can do that. But IMHO that's sacrificing one o…

> There is no downside to everything to be globally routable. Yes there is. I sure as fuck don't want random people from the Internet to know how many devices and what kind populate my home LAN.

If an adversary knowing your IP address scheme it’s so bad to you, you’re not doing it right.

Security through obsecurity is not security.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#404
post #402

Earlier quoted context omitted.

Unless you're part of the tiny percent of people who run their own router, your ISP can just monitor what goes through your ISP-provided router.

With the home router+wifi market estimated to be USD 2070.43 million in 2022, I wouldn't say it's a tiny percentage of people, just people you know.

1. Where does this stat come from?

2. You can't say anything about the percentage with just the absolute market value. At the very least you need something else to compare it too.

Please, be serious.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#405
post #64

I've given a try to IPv6 in a company with few tens on servers in a 2 DCs, an office + additional location, 3 ISPs in total. For me the real challenge is not just different way to write an IP address or doing NAT. The challenge is that IPv6 changes a lot of unexpected things: - Our ISPs support IPv6 but routing quality is way worse than IPv4 including occasional inability to connect to some networks or greater latenc…

> You have to be careful with site-to-site VPN since even your internal services like database are now globally addressable. You really need proper firewall rules / routing policies to not leak unencrypted packets over internet. Uhmm I might be wrong here, but can’t you just not assign global IPv6s then? Keep your local network on ULAs ( https://en.wikipedia.org/wiki/Unique_local_address ) for network-internal routin…

Sure, you can. But on advantage of IPv6 is you addresses are globally unique. If you ever need to connect two networks that were created independently (like different companies), unique addresses, even local are very helpful.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#406

Earlier quoted context omitted.

The problem is that IPv4 is not forward-compatible and therefore there cannot be a protocol that is entirely interoperable. There can only be ones that are somewhat interoperable. And IPv6 has plenty of mechanisms that make things interoperable (NAT64, embedding ipv4 addresses in ipv6, etc.).

What we need is a pure 4 network to be able to talk to a 6 network - that's what it means to be interoperable. Going 6 to 4 is obviously required or otherwise 6 would be a useless protocol to begin with. Anycast routing plus tunnelling is one way to achieve 4 to 6. But the "ngtrans" team didn't accept this a transition plan, nor did they provide an official transition plan for migrating 4 to 6. Basically 6 has been a…

I think this discussion is 20 years too late, the only reasonable way forward is IPv6 or bust. We're reached the end of the IPv4 space and the pressure is mounting; any imaginable backwards-compatible technology would have to run for many years in a limited mode where it's basically just a better way to do NAT traversal and only then, when most endpoints are compatible, you would get to see the address-space relief benefits.

Another nail in the coffin of a graceful upgrade from IPv4 is the widespread filtering of IP options in the backbone, the only practical way I know you could craft an extended IPv4 packet that is still routable by the legacy infrastructure while forwarding and maintaining all the extra header data required for routing in the IPng realms. This was not necessarily true in the early 90s, and many hardware generations would have had the ability to fix it.

So I somewhat disagree with the GP that IPv4 was not forward compatible: it included a mechanism for just that in the form of IP options that seemed like a good idea in 1983, but which proved technically inappropriate for the future needs of the internet. So you can't really fault IETF for wanting to break away from that and earnestly thinking people would just upgrade.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#407

Earlier quoted context omitted.

> There is no downside to everything to be globally routable. Yes there is. I sure as fuck don't want random people from the Internet to know how many devices and what kind populate my home LAN.

If an adversary knowing your IP address scheme it’s so bad to you, you’re not doing it right. Security through obsecurity is not security.

I wonder if whoever coined that phrase knew that it would be used so often in contexts where people want both obscurity and security based on their own respective merits.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#408

Earlier quoted context omitted.

Doesn't it let you put it in bridge mode (i.e. modem only)?

ISP uses DS-Lite: ipv6 is native, ipv4 is 4-in-6/CG-NAT. When I switch to bridge mode, it loses ipv6 connectivity, so sadly, that's not an option if ipv6 is the goal.

I see. Or rather, I don't quite. :D

I'm not very familiar with DS-Lite. My ISP also uses CG-NAT but I get my connection details over DHCP - both native v6 with /56 PD and the v4 CG-NAT 100.x.x.x IP. That means I connect my OpenWRT router directly to the ISP's plug in the flat.

You said v6 is native for you, but if you put the modem in bridge mode you lose v6 connectivity. Why is that so? Shouldn't you lose v4 instead, which relies on tunneling?

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#409

Earlier quoted context omitted.

you identify device each day, identity is X, daughter of Y on iPad. Once identified via data broker all its traffic is identifiable including torrents for example and porn websites, etc (say X goes to facebook with new address it now has real name) Once identity is known for address X you know its traffic for the day, including past traffic for the day. once address changes you do the whole identification again. All…

Nobody bothers to do this kind of tracking because web browsers leak 100x more information by default anyway. The “I don’t care if they track my household but it’s critical that Daddy’s activity not get disambiguated from my dealing daughter” is just not a valid reason to abandon the benefits of IPv6. Please stop with this line of argument. If you’re really desperate to ensure that the ads shown to your daughter are…

> because web browsers leak 100x more information by default anyway.

I don’t quite feel convinced yet by this argument.

For example, one essential difference is that while it’s true that my web browser does have those leaks, I can be reasonably sure that it’s only leaking to specific hosts, i.e. the one I’m visiting and its embedded resources.

Tracking on the IP source address level, however, would be a whole other thing: that means that whoever happens to see the byte stream can now track who is visiting what. That includes, for example, my ISP, all large Internet exchanges, and anyone tapping into those.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#410
post #38

Earlier quoted context omitted.

Here's an easy one for you: if you have a gigabit connection, most home routers can barely handle the load of NAT. That's why gamers push for IPv6. It's mentioned in the article but few people realize how inefficient NAT can be at gigabit and more. My ISP router could do max 800 mbps, which isn't so bad, but it degraded when we were multiple people using the link. With IPv6 it's much less of a problem, we can easily…

> if you have a gigabit connection Rare in the US. Hell, we don't even have a 1Gb connection at work.

The consumer links are usually oversubscribed. In Prague, you can easily get 1Gbps if you're near fibre. However, office-quality link will cost you 10x more for the same nominal speed.
Post reply on HN