Live data from Hacker News

Why IPv6 is so complicated

github.com

511–519 of 519 posts

Re: Why IPv6 is so complicated

#511

Earlier quoted context omitted.

> Nobody asked for that. I mean thats not true. SLAAC is great for public/untrusted networks where you just let the clients figure that shit out. the only thing thats a bummer is not being able to map DNS records to addresses, which is kinda the point, for privacy.

this is still kind of possible, by doing neighbour discovery and querying the host for its hostname with mdns. In my opinion, this automatic mapping of DNS names to addresess is not part of the IP protocol, and shouldn't be.

> ...mdns

"use MDNS for name resolution" works until your machine is reattached to your LAN and your MDNS server thinks your hostname is "in use" and sticks a "-N" at the end of it to "avoid hostname collisions". Though, it might just be Avahi that has this particular bit of brain damage... I haven't paid attention to the behavior of the Macs that I've been obligated to use over the years.

Few people are more sad about this behavior than I am.

Re: Why IPv6 is so complicated

#512

Earlier quoted context omitted.

Opening a dual stack ipv4 and ipv6 does allow the service to accept both ipv4 and ipv6 connections. But I do not think that is what zadikian is getting at? It does not address the network level identity and reachability. There is no default, globally routable mapping where owning a ipv4 automatically gives you an equivalent identity in ipv6 that others can reach without translation infrastructure. The transition mech…

I’m not clear on who is supposed to do the translating that isn’t doing it today, or why the mapped IPv4 addresses don’t qualify. Virtually all ISPs either give you an IPv4 address or do the translation for you, and the software you write doesn’t have to care exactly how it’s set up for the most part (there’s some subtlety about stuff like MTUs, but if you’re just doing unencapsulated TCP it usually doesn’t matter).…

You wrote "I don't understand what is missing"

ipv6 was standardized in 1995 6to4 was standardized in 2001

6to4 is not used in any meaningful way today.

What was missing was ipv6 should have had 6to4 (but better) in it, in 1995.

Now, I could go on about what is wrong with 6to4, but every new topic is just another surface area for ipv6 proponents to launch another question (I sometimes suspect in bad faith).

Re: Why IPv6 is so complicated

#513

Earlier quoted context omitted.

Don’t need dual stack, just one updated. Further addresses would have stayed readable and there wouldn’t be two bindings per adapter etc. When typing addresses first byte is optional and defaults to zero. Problem solved. I saw this strategy work well with Brazilian phone numbers. Partial rollout is not a problem to me at home but multiple address gibberish is.

A node having 198.51.100.42 and 7.198.51.100.42 (or 198.51.100.42.7) is dual-stack: one address is for the IPv4 protocol and other is for the IPv7 the protocol. You need different DNS records for IPv7 and new API calls. You need Happy Eyeballs so that if 7.198.51.100.42 fails your application falls back to 198.51.100.42. It's the exact same situation.

There’s not two there’s one, the longer. There will be old equipment that can’t handle the new but would have been mostly replaced over time, perhaps a deadline. Like phone numbers or hdtv.

Now think a better name is IPv4+.

Re: Why IPv6 is so complicated

#514

Earlier quoted context omitted.

A node having 198.51.100.42 and 7.198.51.100.42 (or 198.51.100.42.7) is dual-stack: one address is for the IPv4 protocol and other is for the IPv7 the protocol. You need different DNS records for IPv7 and new API calls. You need Happy Eyeballs so that if 7.198.51.100.42 fails your application falls back to 198.51.100.42. It's the exact same situation.

There’s not two there’s one, the longer. There will be old equipment that can’t handle the new but would have been mostly replaced over time, perhaps a deadline. Like phone numbers or hdtv. Now think a better name is IPv4+.

Sounds identical to IPv6, but with only one new byte instead of 12 new bytes.

Re: Why IPv6 is so complicated

#515

Earlier quoted context omitted.

Y’know I see you in every thread about IPv6 and you have this terrible habit of completely ignoring the actual point someone is trying to make and bogging straight down into the minutiae of some technical detail instead. I will stipulate that it’s possible to configure a network so that clients don’t set up their own addresses and use only DHCP. I will stipulate that I fucked up the configuration the last time I trie…

> ...you have this terrible habit of completely ignoring the actual point someone is trying to make and bogging straight down into the minutiae of some technical detail instead. ... [w]ould you maybe get past that and look at my actual point, which is that multiple addresses is the expected and default behavior of IPv6... Here's your comment's [0] second paragraph: I think this is the biggest change with IPv6: that a…

See here you go again. I'm not doubling down on anything.

My claim goes like this. Tell me where you disagree.

1. In a typical IPv6 setup you have more than one address. You even had to exclude android from the discussion just to bring up a scenario where this isn't true.

> Yes, I'm very aware that Android doesn't support anything that DHCPv6 provides other than getting an entire damn prefix delegated. For the duration of this discussion, let's ignore Android.

Yeah so as long as we ignore the largest operating system in the world by number of devices, yeah you totally are making a great point here.

2. In such a setup, things like IP-based access control become impossible (no, I'm not going to just pretend android doesn't exist, sorry), reverse DNS lookups become irrelevant, etc.

3. Yes, it is possible to configure a network such that these things are not the case, but that is not a typical IPv6 setup. There are a lot of reasons this setup is not typical, there are a lot of SHOULD lines in various IEEE specs that talk about this. Hell, even if you get your network configured perfectly, it's not going to stop a random machine from deciding to use its link-local address when talking to somemachine.local (which happens all the damned time in my network.)

It's like if someone came in and critiqued that /64 is way too huge of a subnet size in IPv6, and you responded with "yeah but you can change it and run a /96 network!" Which while technically true is also not how literally fucking anybody does IPv6 at all.

Now I wait while you attack the above with dumb fucking nitpicks about technicalities while totally fucking ignoring the point I was trying to make. Go ahead, you've done it in these threads for years.

Re: Why IPv6 is so complicated

#516

Earlier quoted context omitted.

> ...you have this terrible habit of completely ignoring the actual point someone is trying to make and bogging straight down into the minutiae of some technical detail instead. ... [w]ould you maybe get past that and look at my actual point, which is that multiple addresses is the expected and default behavior of IPv6... Here's your comment's [0] second paragraph: I think this is the biggest change with IPv6: that a…

See here you go again. I'm not doubling down on anything. My claim goes like this. Tell me where you disagree. 1. In a typical IPv6 setup you have more than one address. You even had to exclude android from the discussion just to bring up a scenario where this isn't true. > Yes, I'm very aware that Android doesn't support anything that DHCPv6 provides other than getting an entire damn prefix delegated. For the durati…

Hon, you really need to step away from the keyboard and seek yourself some headpats, or other such comforting entertainment. I expect that -like most people- once you're able to find a way to regularly and reliably enhance your calm, you'll be better able to take critique and acknowledge when parts of your argument are substandard.

Best of luck to you.

Re: Why IPv6 is so complicated

#517

Earlier quoted context omitted.

There’s not two there’s one, the longer. There will be old equipment that can’t handle the new but would have been mostly replaced over time, perhaps a deadline. Like phone numbers or hdtv. Now think a better name is IPv4+.

Sounds identical to IPv6, but with only one new byte instead of 12 new bytes.

As mentioned three times now, the addresses would be readable, and there would not be two stacks. Much less complexity. So no, not identical.

Re: Why IPv6 is so complicated

#518
post #243

Earlier quoted context omitted.

> The original comment also doesn't state they are issues just that they are differences. My point is that, in most cases, these aren’t differences , since IPv4 does the same thing as IPv6. Therefore, the claim that IPv6 “ has some quirks that make it harder to digest [than IPv4]” is incorrect. > Interfaces do not have link local addresses if they have a DHCP or statically configured address I could be wrong, but I s…

> What? I have never seen this. What? Never? Is extremely common. I just checked both my Mac and Windows desktops and they both show a link local gateway. It makes me question whether you've used IPv6 all that much.

Every single machine I use, both at home and at work, has IPv6. Exactly none of them use a link-local address as the gateway address.

Re: Why IPv6 is so complicated

#519

Earlier quoted context omitted.

NAT is a crutch to circumvent the problem of "there are not enough addresses for each device". I _assume_ you are referring to a default deny inbound firewall (so that devices are not reachable from the outside), but these are very different, completely orthogonal concerns (and independent of the IP version in use).

Everyone I've talked to with this opinion are typically mobile devs thinking about cell phones. Ipv6 works great there, but NATs are often used in corporate networks for isolation and in particular obfuscation. You can't tell what's behind a NAT by inspecting traffic coming from inside it like you can with no NAT networks. Some of the networks I administrate are contractually obligated to be so isolated.

I am not a mobile dev :D

I am aware that NAT is often used in corporate networks, but it does not automatically make any more sense there - the isolation is achieved by the firewall, not by NAT.

NAT (address or port translation) and a firewall (allowing traffic from/to those addresses or ports) are orthogonal concepts.

You can do NAT on IPv6, if you so desire.

It _should_ make no difference whether any adversary knows "what's behind a NAT", because it is your firewalls job to block any unwanted traffic.

Relying on "nobody knows what is inside our network so it can't be attacked" is not a viable strategy.

Post reply on HN