22 ms·
Is there hope for IPv6?
- Proven 8y agoI always disable IPv6 at home and computers I administer. IPv6: for machines (IoT) IPv4: for humans
- philjohn 8y agoif it doesnt do ipv6 it's broken
- donatj 8y agoI think that is an overstatement. A car is not broken because it does not drive on rail, you can get you to the same places. There is currently very little you cannot do without IPv6.
- philjohn 8y agoIt's a well known quote. There are ways to solve the IPv6 problem - and ISPs in Europe have successfully rolled out both major variants, Dual Stack (Native IPv4 and v6 running alongside each other) or DSLite (Native IPv6 throughout the network, CGNat at the edge for tunnelled IPv4 traffic). Liberty Global have opted for DSLite, the last major network of theirs will go live this year (Virgin Cable), BT and Sky (the two biggest xDSL providers) have been live for over a year at this point with Dual Stack.
- geofft 8y agoThe article says the exact opposite: if it doesn't do IPv4 (either on its own, or via reliance on a NAT somewhere) it's broken.
- dpark 8y agoIPv4 is for machines. IP addresses were never intended for humans, which is why domain names exist.
- Pxtl 8y agoExcept that setting up domain names for devices in your network is out of reach for most humans, while IP addresses are trivial. My cheap router that I have to reboot nightly lets me bind an ipv4 address to every device on the network so I have known address for everything. There is no comparable functionality for a domain name, or a subdomain or whatever. If my ISP offered free dyndns (and there was a well-adopted global standard for the service), and I could assign subdomains for each of my devices, then I could have real names for everything. However, no consumer-level router supports that.
- rleigh 8y agoMost common routers and systems will automatically register and resolve names automatically on the local network. Plus there's zeroconf on top of that. You don't need to manually edit bind zone files for your local network unless you really want to.
- Pxtl 8y agoI have literally never ever seen a cheap consumer router that did anything "automatically" successfully other than run DHCP and provide access from the LAN to the WAN.
- rleigh 8y agoThe last two I've used over the last decade have automatically done this. Every machine requesting a DHCP lease is assigned "$host.lan" in the DNS service on the router, where "lan" is a default but configurable domain name. But even if you don't have this, then zeroconf/avahi/equivalent should be giving you "$host.local".
- mdaniel 8y ago> If my ISP offered free dyndns I am about 80% certain that in the time it took you to write this comment you could have bought a domain name, used the registrar's web-gui to input your now static IP addresses, and had a perfectly functioning DNS setup for your home. Or, if the free DDNS is the most important to you, OpenWRT appears to natively support quite an extensive list: https://openwrt.org/docs/guide-user/services/ddns/client https://openwrt.org/docs/guide-user/services/ddns/client
- notbestcomment 8y agoIETF: Makes a non-backward compatible change Internet: Doesn't adopt it Everyone: Pikachuface.png
- kevinoid 8y agoThese are some interesting insights into the economic incentives on the deployment side. I'm looking forward to reading the report. It is also interesting to consider the incentives (or lack thereof) for IPv6 peering. The fact that HE and Cogent haven't resolved their peering dispute from 2009 suggests to me that there is insufficient incentive (particularly from their customers) to do so, even when there are obvious practical effects. (I can't reach openstreetmap.org via an HE IPv6 tunnel even now.) Perhaps the technical effectiveness of Happy Eyeballs and other backwards-compatibility mechanisms necessarily reduces incentives for improving IPv6?
- csears 8y agoWhat if we started charging a small but slowly increasing annual fee for each IPv4 address? And with the proceeds ICANN starts buying back IPv4 blocks and permanently retiring them.
- geofft 8y agoThis article is largely about IPv6 in internal networks, not IPv6 in the internet as a whole - as they say, "No one uses IPv6 only. All public network operators, and nearly all private ones, must offer full compatibility with all other network operators and as many end points and applications as possible." Their three choices are about remaining on IPv4 only, running dual-stack IPv4 and IPv6, and using a translation layer to run IPv6-only internally and convert to IPv4 at the border. All of them involve public IPv4 addressing, and the assumption is that the internet will forever be IPv4. So this means two things. The first is that the desire to move to IPv6 on the part of the article's authors has nothing to do with public IPv4 address space exhaustion, it's based on other alleged inherent benefits of IPv6. The second is that IPv4 NAT already solves the exhaustion problem - you're either doing NAT to IPv4 or NAT to IPv6 (using your favorite 6preposition4 encoding/tunneling scheme), but as far as the public internet is concerned, it looks like you're doing plain old IPv4 NAT.
- orev 8y agoThat might actually have the opposite effect of what is desired. Whoever is charging and benefiting from the fee would then have an incentive to maintain the status quo of IPv4 and continue collecting the fees. We’re already seeing this now as people are selling IPv4 addresses. Scarcity + demand creates market opportunities.
- coding123 8y agoCouldn't they can mandate, that no customer must be charged MORE than the global fee, and violations instantly lose their ipv4 addresses (or rather replaced with v6)? I don't know who the ultimate benefactor would be - would it be ICANN?
- 8y ago
- sverige 8y ago> "Given that fundamental constraint, there are only three basic choices for network operators: ... 3. Run native IPv6 among compatible parts of their own network with some kind of tunneling or translation (i.e., converter technologies in economics) at the boundaries to make it compatible with IPv4 Among these viable alternatives, we show that dual stack will never get us across the finish line; it is not economical. It is the third category that shows promise for some growing networks." So, basically a more complex version of NAT is what they're proposing for the "transition" from IPv4 to 6. Am I the only one who remembers that IPv6 was supposed to eliminate NAT?
- geofft 8y agoYeah, it's fascinating here that they've gone from "NAT is bad and we won't let you implement NAT, we need an internet on a single flat 128-bit address space" to "The internet will be IPv4 forever and you should implement IPv6 internally and run NAT, because we like it better than running IPv4 NAT which is what you've done for years and works great".
- Dagger2 8y agoThat's not what the article is saying. They're saying that you still need to provide access to legacy v4-only hosts on the internet somehow, and you either do that via v4 (i.e. dual stack) or by some transition technology of which NAT64 is just one possible option. Nobody is suggesting to not talk native v6 to the internet too, they're just suggesting to not cut your users off from v4-only services.
- geofft 8y agoIf all your connections are potentially NATted (i.e., any DNS lookup might only return an IPv4 record), what's the advantage? You still have to build applications that are capable of dealing with NATs / non-end-to-end connections. You just also have to maintain IPv6 infrastructure. That seems strictly worse than staying on IPv4 NAT. (If you're talking to specific parties that you know have working IPv6, it's less work to run a site-to-site VPN than to both maintain working IPv6.) The only world in which IPv6 is worthwhile is one in which we can turn off access to legacy v4 hosts and stop having public IPv4 addresses. At this point, it seems like there is no hope of doing so in the current Internet. Perhaps in a few hundred years the Internet itself will be dead and IPv4 will die with it, but not before then.
- krkoch 8y agoWe tried setting up automatic DNS records on dhcpv6 and slaac on our company lan, and we just weren't able (opnsense). We have ipv6 working, but it still doesn't "feel finished".
- qwerty456127 8y agoPerhaps I just misunderstand IPv6 but I prefer IPv4 with NAT and temporarily leased public router address for privacy and security reasons. AFAIK IPv6 means every device gets assigned a stable unique address everybody can identify and reach it by. And I have never seen a SOHO WiFi router that would support IPv6 anyway (perhaps latest fancy expensive ones do).
- pixl97 8y agoWindows uses ipv6 temporary addresses by default. NAT isnt security, and lot of implementations are faulty, so dont depend on it for security.
- geofft 8y agoNAT absolutely is security. It prevents naming a resource that an attacker shouldn't have access to, which is the fundamental principle behind many successful security schemes: capability models, containers / virtualization, MMUs, etc. Sure, there are implementation flaws (as there have been in other such schemes), and sure, just clicking a NAT button and walking away doesn't get you security any more than just clicking a capability or virtualize or MMU button gets you security. But it's a powerful and solid building block, and the Internet is a better and safer place because of widespread use of NAT.
- Dagger2 8y agoIt doesn't actually do that though. If you give a machine an IP of X, and then you turn on NAT on the upstream router so that its outbound connections appear to come from Y instead, the machine is still called X. NAT won't prevent someone from sending a packet to X, and it won't cause the router to somehow drop the packet when it sees it either. That stuff is handled by firewalls, not by NAT.
- geofft 8y agoOn Linux at least, NAT isn't handled by routing, it's handled by a separate layer (the firewall layer, in fact). I think that's the obvious way of implementing NAT: you're not routing at all. On the public side you're not accepting any packets not addressed to you. On the private side you're converting all packets, so you're not doing normal packet forwarding. When packets arrive on the public side, you have to translate addresses sent to the router to convert Y to X, so you might as well drop packets that aren't sent to a valid target. I'd expect you have to go out of your way to get NAT "wrong," possibly by trying to stuff the functionality on top of actual routing. Home routers generally don't need to do actual routing ever (and if they do, they're in a non-NAT mode) so it would be surprising for them to get this wrong.
- geofft 8y agoThis article completely fails to mention that IPv6 is not just an extension of the address space but a whole different worldview about how to run a network: - IPv6-to-IPv6 NAT has only been accepted very recently and very begrudgingly. Whatever your views are on NAT, the fact is that lots of people have network designs that rely on it, and if you want them to stop, you're now asking them to couple two major transitions, which is a significant economic cost. (Option 3 in this article is IPv6-to-IPv4 NAT, assuming that the public internet will indefinitely be IPv4; it's noteworthy that none of their options ever envision the public internet becoming IPv6.) - IPv6 recommends the use of its own scheme, SLAAC, for address assignment, with DHCPv6 being also very recent and poorly implemented - for instance, Android has no DHCPv6 support and plans to never implement it https://code.google.com/p/android/issues/detail?id=32621 https://code.google.com/p/android/issues/detail?id=32621 . There's also a "stateless DHCPv6" for communicating DNS servers but using SLAAC for addressing; without it, SLAAC expects you to use a scheme called RDNSS to communicate your DNS servers, which is also not 100% supported. So you now need to spend engineering time supporting all of these options because some devices only support one and some only support the other, and you need to come up with network designs that work with both SLAAC (which has strong opinions on how you use /64s) and DHCPv6 (which doesn't). - IPv6 doesn't use ARP, on the grounds that it's a layering violation, a separate layer-3 protocol that runs directly on top of Ethernet but talks about IP addresses. Instead, IPv6 has a clever scheme for using multicast to transfer the information that ARP would convey, by having machines join multicast groups based on their MAC address. This works very, very poorly with networks that aren't designed to support significant multicast load - for instance an attempted deployment of IPv6 caused packet storms in the MIT Computer Science and AI Lab's network for about a week because their switches were falling back from multicast to broadcast: https://blog.bimajority.org/2014/09/05/the-network-nightmare-that-ate-my-week/ https://blog.bimajority.org/2014/09/05/the-network-nightmare... So a working IPv6 deployment involves upgrading all of your hardware to hardware that has good support for multicast, which is also a significant economic cost. - Various protocols like Teredo and ISATAP attempt to set up tunneled IPv6 routing in preference to IPv4 routing, making it hard to do a staged deployment, especially if you have BYOD on your network. For bonus points, because they're tunneled, you get different and possibly worse routes over IPv6, making debugging harder. So that's a cost in additional L1 and L2 support. If someone had come up with an IPv7 that's just "We extended IPv4 to 128-bit addresses and we left ARP and DHCP and NAT and everything alone," people would have switched to it already. But the powers that be are drowning in the second-system effect and nobody wants all the features they added.
- hn_throwaway_99 8y agoI hope (but am skeptical) that folks look at the overall failure of ipv6 from a deployment perspective to understand the root causes of why it failed (some may think "failure" is too strong a word, but I remember v6 being "just around the corner" in 2000, yet in 2019 I'm still connecting to a GCP database with v4). Coming up with a solution that looks like a huge technological advancement, with no real respect for the motivations or incentives of those who'll need to implement and use it, is a fairly common occurrence in tech and something engineers should be trained to guard against.
- Dylan16807 8y agoWhat does a system that does take those incentives into account look like?
- geofft 8y agoLoose coupling and no second system effect. IPv6 should have been extended address space and extended address space only, in a manner backwards-compatible with IPv4. You think ARP is broken? Great, implement a fixed version of ARP for both IPv4 and IPv6, meanwhile we'll spec IPv6 to use ARP. Don't design IPv6 to use your new thing called NDP that layers completely differently. You think everyone using NAT is wrong? Great, go convince them. Don't tell those people "I don't care what you think, I'm right, and you better agree with me in order to deploy the new thing." They're going to - entirely justifiably - not deploy your new thing.
- AnIdiotOnTheNet 8y ago> Don't tell those people "I don't care what you think, I'm right, and you better agree with me in order to deploy the new thing." They're going to - entirely justifiably - not deploy your new thing. Pay attention developers. This attitude is all too common in our industry.
- protomyth 8y agoPay attention to the system admins, because someone has to deploy and use the new code everyday.
- the_mitsuhiko 8y agoThe weird thing is that on some countries IPv4 only turned effectively into the premium offering. This is for instance the case in Austria where you generally have the option of ipv4 or ipv6 with dslite or worse only. All new contracts are ipv6 and the only way to get to ipv4 is via customer support. However right now ipv4 gives you the better experience.
- deleted 8y ago[deleted]
- vnw 8y agoI don't believe it's weird, in fact, I think it's natural. IPv4 is better (because every single machine and server has IPv4 connectivity, unlike IPv6) and available addresses are getting scarce. Therefore, IPv4 access with no CG-NAT is turning into a "premium" service.
- joeseeder 8y agoYup, now you have to go out of your way to not support it. Literary, every modern ISP, hosting or Cloud provides it. Every Operating System, be it server or client or router, supports IPv6.
- geofft 8y agoWhat does "support" mean? Everyone having an IPv6 stack with no routing between them isn't "support". For instance, do you support RDNSS or DHCPv6? How big are your multicast tables?
- yjftsjthsd-h 8y ago> Literary, every modern ISP This is either factually incorrect, or else you're using a definition of "modern" that excludes a substantial portion of real world isps.
- mrweasel 8y agoIt in fact excludes most ISPs in many countries.
- zzzcpan 8y agoTo be precise this excludes 75% of all autonomous systems in the world, which is at least 75% of all ISPs plus those that connect to 25% of IPv6 capable autonomous systems, but still don't use IPv6. So we are talking like 80% of all ISPs in the world.
- joeseeder 8y agoevery ipv4 only isp is legacy, not modern basically they are the edissons of electricity boom era when AC was becoming the new standard for power transfer
- ben0x539 8y agoNot the truely Scottish ISPs. :>
- vjeux 8y agoFacebook publishes some stats about worldwide ipv6 usage that they observe: facebook.com/ipv6
- rawoke083600 8y agohow about ipv5 and we just add an extra .255 ? Im sure our kids wilk figure out a better solution... ?
- SlowRobotAhead 8y agoYou joke, but I’m pretty sure ipv6 suffered by removing the familiar octets system in favor of something most people can’t understand.
- apple4ever 8y agoAbsolutely. Its so much easier to read 10.59.271.49 than 2001:ACE3:26CF:0192:6A42:18A3:018F2:3752.
- rawoke083600 8y agoabsolutely ! I can shout an ipv4 address across the office... i cant easily do it with ipv6 :/
- CydeWeys 8y agoAssuming you're not joking, the nice thing about IPv4 is that it uses 32 bits, so you can store addresses in an unsigned int and use memory efficiently. Just adding one octet takes you up to 40 bits, which has alignment issues. You may as well go up to 64 bits (half of IPv6), which could be represented as 16 hex characters, e.g. 06A4.6E1B.12C9.95C8. That way you're kicking the can much farther down the road too.
- paulddraper 8y agoI always wish IPv6 had done example this -- use 64 bits. The address space is still enormous: a couple billion for every currently living person (yes, I know allocating isn't 100% efficient, but even at 0.001% efficiency, that's still tens of thousands per capita). And, the address could fit in a common word size, and be significantly more readable. As is, IPv6's one-address-per-atom-on-Earth is unnecessary, the addresses are horrendous to read, and the collapsing colon stuff is just obnoxious.
- magila 8y agoWhat we really need is a killer app that requires end-to-end connectivity. Users have little reason to care about IPv6 right now because the existing ecosystem of services has evolved around the constraints of NAT. As IPv6 deployment expands hopefully we will reach a point where some great new application becomes economically viable. My biggest fear is such an application not emerging quickly enough. Without an imperative from users for end-to-end connectivity there's a risk that IPv6 networks which somehow break it become entrenched. If that happens we are back to the old chicken-and-egg situation: Users don't care because there's no app and there's no app because the network is broken and operators don't care.
- lisper 8y ago> What we really need is a killer app that requires end-to-end connectivity. That seems unlikely to emerge. Anything you can do with end-to-end connectivity you can do with a server in the middle forwarding packets. Servers are cheap and reliable, so there's very little incentive to get rid of them.
- keypress 8y agoI still like the idea of a peer to peer web, with something like hosting in your own browser. This could be a great alternative fallback network with distributed DNS. Most phones are capable. Energy, speed and security are concerns, but in cracking them you'd probably make the web a better place.
- lisper 8y agoI like that idea too. A lot of geeks like that idea. But ordinary people couldn't care less. All they care about is that their latest instagram photo gets a lot of likes. They neither know nor care what goes on under the hood. Unfortunately, that ignorance and apathy is what drives the market.
- keypress 8y agoI can't really comment about what other's care about and use the web for. I've never met anyone that even uses Instagram!
- krylon 8y agoI have been getting native IPv6 from my ISP for nearly six years now. It is not quite as cool as it could be, because I get assigned a new prefix every 24 hours, but still, IPv6 is there, and it "just works". When I connect to machines on my home network in any way involving avahi/zeroconf, the machines talk to each other via IPv6 by default. At work, it's a different story. I have drifted from a sysadmin/helpdesk role into a programmer position, so that is no longer my concern. When it was, however, there was little incentive to use IPv6 - everything worked and continues to work just fine with IPv4, and sometimes there were even some rather esoteric problems with Windows' "Network Location Awareness" when IPv6 was enabled.
- mrweasel 8y ago>I have been getting native IPv6 from my ISP for nearly six years now. Meanwhile Danish ISPs refuse to implement IPv6 because: There's no demand. That completely missing the point and their responsibility in my opinion. There's never going to be any significant IPv6 demand from private users. At work however we have customers that have started to request IPv6 only devices and networks, because there's no need for IPv4 specifically, and in some ways IPv6 is just easier (for example there's no need to do NAT). For IPv6 to be successful the ISPs need to role it out, regardless of demand. The issue isn't necessarily at the consumer end, but the ISPs are part of the Internet and they need to help develop it, regardless of profitability in the next fiscal year.
- vetinari 8y agoElsewhere, the ISPs are doing the IPv6 rollout in the worst possible way imaginable: DS-Lite with no PCP for AFTR (i.e. no way to have incoming IPv4), and allocating only /64 subnet, where their CPE is mandatory in router mode, no way to switch it to bridge mode (thus losing control of your own gateway. I'm talking about you, UPC/Liberty Global). For just consuming the web, it is fine. For switching from public IPv4, is is insufficient.
- pas 8y agoNAT traversal (hole punching) works for CGN well, doesn't it? sure you need a coordinator/RP between to CGNed users, but that is not really an issue as far as I know.
- vermontdevil 8y agoMy university (100k students) is transitioning to ipv6. But it’s a long term roll out. I have both static ipv4 and ipv6 for my work station. They tell me the ipv4 will go away in near future.
- ah- 8y agoFunny how it's posted on www.internetgovernance.org, which doesn't support ipv6.
- deleted 8y ago[deleted]
- dghughes 8y agoI like IPv6 it can actually be easier to set up stuff instead of using IPv4 for example OSPF. But I find IPv6 is not as intuitive as IPv4 just looking at an address in IPv4 vs IPv6. You can create new networks for IPv4 pretty easily just by eyeball but not IPv6. At least I can't.
- apple4ever 8y agoIt can be done (using each :XXXX: block as a network instead of splitting it up), but its definitely not quite as easy to eyeball.
- Dagger2 8y agoIt's quite a bit easier to eyeball than v4, because it's much easier to make sure that your network falls on a character boundary (multiple of 4 bits out of 128) than it is to make it fall on an octet boundary (multiple of 8 bits out of 32). If you find v6 harder than it's just down to a lack of practice.
- zamadatix 8y agoIt's pretty easy in v6 if you follow the best practice of making client subnets /64s. Say you were assigned a bog standard /48 then you would have the patternxxxx:xxxx:xxxx:yyyy::z where: x represents your fixed routing prefix y represents your subnet instance (0000-FFFF, 2^16 subnets) :: represents the expansion of "0000:"s z represents the client identifier. For a relatively normal /56 or /60 home user assignment via PD from an ISP you simply lose 2 or 3 "y"s respectively. In both your client netmasks are always /64 and your gateways should always be fixed:subnet::1.
- Dylan16807 8y agoReally? I find it significantly easier. In IPv4 you might get allocated 250.250.16.0/22, and then you have to calculate in your head where exactly that begins and ends, and carefully divvy it up into partitions of different sizes. In IPv6 you get a /56 or /48 and you know that two or four digits are wildcards. No binary math is needed, and all subnets can be the same size of /64
- Animats 8y agoIs this US-centric or worldwide? In particular, does it include China?
- zamadatix 8y agohttps://www.google.com/intl/en/ipv6/statistics.html#tab=per-country-ipv6-adoption https://www.google.com/intl/en/ipv6/statistics.html#tab=per-... https://www.facebook.com/ipv6/?tab=ipv6_country https://www.facebook.com/ipv6/?tab=ipv6_country US isn't doing so bad thanks to it's mobile networks being early v6 adopters.
- 7e 8y agoThis chart: https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html ... reports a steadily increasing adoption rate for IPv6. Is that rate somehow too slow? It currently stands at 25% of Google users.
- AnIdiotOnTheNet 8y agoConsidering that ipv6 has been around for more than 20 years?
- k__ 8y agoGermany has a good rate. My cable provider uses IPv6. But yes. When I did an internship in 2001 my co-workers told me that I had to learn IPv6 because it will replace v4 in the next years, hehe.
- owenversteeg 8y agoHuh! I looked closer at the graph and wondered why the line was so fat. If you zoom in, a clear trend appears: far higher IPv6 usage on weekends. About 25% more people using IPv6 on weekends than weekdays. (IPv6 is 21% of the total on weekdays vs 26% on weekends.) I'm surprised there's such a big gulf.
- vertex-four 8y agoA lot of home users have had IPv6 “silently” enabled, while many corporate networks have never implemented it, or only implemented it for a small portion of services that need it.
- gweinberg 8y agoLet's just skip to IPv7.
- Pxtl 8y agoImho IPV6 failed because of a failure to make DNS usable to non-specialists. If every device on every network could be assigned a domain name, then we'd never have to know what underlying addressing scheme exists. My ISP has a name. I have an account with them. Every device on my network has a name. There's no good reason I don't have Device.accountName.pub.ispName.tld Bound to the phone I'm writing this on right now. But because that doesn't exist, users are still used to screwing with MAC and IP addresses just to set up port forwarding and all that other nonsense. And so we have to care about IP addresses. And so we're stuck on ipv4.
- zamadatix 8y ago99% of users couldn't tell you what an IP address or port is let alone manually configure MACs and IPs into their router so I don't think that has anything to do with adoption of v6. To the vast majority of users they type a name in the URL bar and that's their full interaction with what they'd think of as "internet addresses". Those administering the systems users connect to have always handled DNS just fine so I don't see why they wouldn't be able to know that the address got a bit longer.
- iagovar 8y agov6 adresses are hard to memorize tho
- Dagger2 8y agoNot really? I don't think you can reasonably argue that: 2001:db8:4242:1::2 is much harder to remember than: 203.0.113.42+192.168.1.2 In fact it's substantially fewer characters. Okay, obviously you can pick v6 addresses such that they're long and hard to memorize, but I'd argue that if you do that and also refuse to use DNS for them then you've lost your right to complain about how long and hard to memorize they are.
- sliken 8y ago39% of Google's traffic is IPv6, clearly there's no hope.
- geofft 8y agoOnly if the end state is that the public internet will be dual-stack IPv4/IPv6 forever and everyone will need some form of IPv4 connectivity, either a real IPv4 address or NAT to one (from either private IPv4 or private IPv6). Is that the world we want? Have we solved the address space exhaustion problem if that's the route we take?
- BenjiWiebe 8y agoIf 95% was dual stack, we could start getting rid of ipv4.
- ec109685 8y agoNo it’s not: https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html
- sliken 8y agoSorry, it's 39% in the USA., other countries vary. Just click on "per country IPv6 adoption" at that url.
- AndrewKemendo 8y agoThe argument seems pretty straightforward and is a classic collective action problem: v4 isn't expensive enough (in all cost measurements) to justify switching to v6. Once that flips, when there aren't any more v4 addresses then everyone will move there. It sounds like the costs of v6 are so high that we basically need complete saturation of the v4 IP ranges, and then a market that trades IPs at a higher friction/cost rate than than implementing v6.
- xvilka 8y agoIPv6 is already a success in mobile and IoT, and in countries that matter in economical sense. The rest will follow automatically because they have no choice. More worrying issues are BGP and SS7 reliance in global networks, and there are no viable alternatives on the horizon.
- pas 8y agoCould you expand on these problems? Why is SS7 an issue? (Aren't telcos moving to IP based platforms? Device registration on towers can work on whatever protocol the device supports the base station encapsualtes/proxy-es/processes that further, and the telco can use whatever routing it wants internally - eg iBGP. Or even some fancy OpenFlow based control plane.) And of course the issues with BGP seem even more interesting, if you could detail those too ot'd be great.
- xvilka 8y agoThe SS7 protocol stack is soaked with security problems, but also because it doesn't represent the modern nature of traffic. Of course, telecoms moving to IP cores and such, but SS7 still widely used mostly because of the interoperability and roaming. Positive Security recently made a summary report of the current status of the problem[1]. BGP main problem is the inherent trust to users and servers, thus allowing malicious actors or even some errors to do weird things with network traffic. See this[2] Black Hat talk quickly summarizing them. [1] https://www.ptsecurity.com/ww-en/analytics/ss7-vulnerability-2018/ https://www.ptsecurity.com/ww-en/analytics/ss7-vulnerability... [2] https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-co...
- pas 8y agoThanks for the reply, links, and details! Regarding BGP, it seems that the basic protocol and implementations are okay. ("No implementation allowed BGP OPENs with the wrong AS or from non-configured peer to reach BGP ESTABLISHED state—as a result, TCP spoofing is required to inject data", and when you can spoof TCP between routers ... it's probably too late anyway. In a peering scenario between ASes people either use a direct cable, a separate VLAN or other direct "transport", in a IXP the IXP operates a big switching fabric and the peers exchange traffic over that, but the BGP sessions use fixed IPs and basically they are fixed to switch ports, and even if currently not every IXP monitors the spoofing/abuse of those, it is easy and they should be doing so. Sure, the reality is always bleaker, but that's security. Maybe next-next-next gen will have crypto built in so far down the stack that without a shared secret no packets will flow. But then humans will just put the PSK on a bright sticker, or will continue to use "chang3me" for decades.) The problems I heard with it is that Tier1 providers just can't really filter the routes they get from downstreams, as they'd have to know which Tier2 handles which prefixes for which clients and so on. Though I'm not convinced they are putting much effort into it, as it's easier to just plug in big Cisco boxes and set up peering with your core and your downstream customers and call it a day. (And setting up is always messy already, so it's sort of understandable that there are no easy and custom solutions for somehow verifying announcements from whatever databases.)
- spullara 8y agoThere is no hope. Without backwards compatibility with IPv4 addresses we will always have IPv4. The specification was a complete failure.
- Dagger2 8y agov6 has dual stack, Teredo, 6to4, 6rd, 6over4, ISATAP, 6in4/4in6, NAT64/DNS64, 464xlat, DS-lite, MAP-T/E, 4rd, LW4over6... it has pretty much every possible backwards compatibility method that can work with v4. You could make a reasonable argument that it has too many of them, even. Where did you get the idea that it didn't have backwards compatibility?
- spullara 8y agoIt doesn't have any backwards compatibility. You can't turn off IPv4 and just have IPv6 and still use IPv4 addresses. If it had it, you wouldn't need all those hacks.
- Dagger2 8y agoYes you can. Those "hacks" are how you do it. I mean, you can call them hacks, but at the end of the day v4 uses a fixed-width 32 bit address field and has no mechanism to extend it in a way that's compatible with other v4 hosts. All you can do is hack around that. There's nothing that v6 could possibly do to avoid it, because the flaw is in the design of v4 and not in the design of v6.
- ctime 8y agoI'm curious on how the non-contiguous ipv6 [1] usage will eventually affect the use of the TCAM in vendor hardware. It seems that most TCAM being developed today will never be able to store anywhere near the unfathomably large amount of possible address prefixes being carved - and of course the prefixes are only are going to get more and more fragmented. Right now the typically default behavior for switches/routers that encounter the exhaustion is to summarize prefixes with a shortened prefix and (possibly) punt the evaluation to the general purpose CPU (example here[1]) - which suffice it to say, introduces a host of security concerns. This means, as a security engineer, in situations where complex/large ACLs exist, I need to be aware of and control how IPv6 TCAM exhaustion failure modes work and plan that eventually my hardware TCAM may be exhausted and fail in a spectacularly bad way. Or, I just ignore IPv6 almost entirely and just don't have the problem (cleverheadtap.jpg) [1] https://www.iana.org/assignments/ipv6-unicast-address-assignments/ipv6-unicast-address-assignments.xhtml https://www.iana.org/assignments/ipv6-unicast-address-assign... [2] https://community.cisco.com/t5/switching/tcam-utilization-issue/td-p/2904935 https://community.cisco.com/t5/switching/tcam-utilization-is...
- jerkstate 8y agoI have a theory that announcements will be part of what you pay for in the future, like you pay for ports and bandwidth today.
- amaccuish 8y agoCan anyone explain to me. So right now for v4, we have NAT, and several ways to get a port open and pointed at us. With v6, every device has its own public address, like how the internet was intended. And as sensible network admins, we should have a default deny incoming firewall policy for v6 traffic. But surely that will prevent these "end-to-end" apps from working, and now they don't even have protocols like UPnP to bypass the firewall and request ports to be opened?
- pseudalopex 8y agoSensible network admins will open ports for specific services. Also, UPnP, NAT-PMP, and PCP support IPv6.
- bartwe 8y agoAs a gamedeveloper it hasn't been particularly easy or clear how to make connections between users over v6, it is enough of a mess with v4 tbh
- Ericson2314 8y agoMaybe we need to tax IPv4 addresses. Once again, markets suck at dealing with scarce resources. Tax externalities or ditch capitalism, you choose society!
- lkdjjdjjjdskjd 8y agoI really want to enable ipv6 on my web site, but then I heard horror stories about connections failing if not all routers between the client and the server have ipv6 enabled. Apparently at least for a while, browsers would not try the same request again via ipv4, so the site would simply be unreachable. Perhaps browsers have become smarter about that, but it really makes me wary about enabling ipv6. I have no immediate benefit besides "doing the right thing", and some possible downsides.
- capitol_ 8y agoYes, browsers have become smarter about that. You can test it by enabling ipv6 and then drop all ipv6 packets with ip6tables, that has the same effect as if some middlebox dropped them.
- a2dictator 8y agoWe should have really gone with an ""IPv5"", because IPv6 tries to boil the ocean. We do not need that many ip addresses and now we will rarely be able to recall specific IPv6 addresses like IPv4 addresses.
- seanlinmt 8y ago“No one uses IPv6 only." I had a go using only IPv6 recently. What surprised me was the site that broke it for me. Github.com.
- mikeytown2 8y agoIf a major player like GitHub doesn't support ipv6 then ??? Also a lot of vps providers do ipv6 incorrectly so some form; vultr seems to be the only one I've found that does it well.
- hkt 8y agoI've been saying it for years: IPv4+ would be fine. Just add more bits to addresses (maybe twice as many octets) and dual stack that instead.
- amsaleka 8y agoNice blog..! I really loved reading through this article. Thanks for sharing such a amazing post with us and keep blogging... <a href="https://www.credosystemz.com/training-in-chennai/react-js-training/">Best https://www.credosystemz.com/training-in-chennai/react-js-tr... React js training near me</a> | <a href="https://www.credosystemz.com/training-in-chennai/react-js-training/">React https://www.credosystemz.com/training-in-chennai/react-js-tr... js training online</a>
- Bombthecat 8y agoThe main problem is :it is too easy to ignore. You can build around all of the limitations of ipv4. Which makes ipv6 useless / not needed in the first place.
- lurkinghere 8y agoIPv6 is so 90s. Put a pink lens and design a global network where are good people. Netizens as were called. Give an IPv6 with last digits of the MAC address is unacceptable today. Unique IP per device maybe dangerous. Today tracking exists and is smart, some organizations are logging bittorrent activity. People buys VPN, right? Really I love shared IPv4 at my University (although they have a /16). Maybe there are thousands of devices behind. Google Ads becomes crazy. I only want privacy.
- dennisgorelik 8y agoA couple of months ago voted for IPv4 by paying $1/month for every IPv4 IP address on my new server. 128 IP addresses total. That is well over $1k/year voting power. The reason for that purchase is that IPv4 addresses represent internet reputation while crawling websites. I am not interested in getting IPv6 at all. How much did you pay for IPv6?
- sliken 8y agoComcast gives regular home users 2^68 of them.
- HankB99 8y agoRequire that porn sites use only IPV6 addresses. Or provide some free benefit to people who access those sites using IPV6. I'm pretty sure adoption will surge. It worked for VHS.