4 ms·
The problem with IPv6 is that it's a fundamentally flawed design. Which looks easier to input / dictate over the phone / write down somewhere? 220.12.30.01 or 2
by i_like_to_post 6y ago
The problem with IPv6 is that it's a fundamentally flawed design. Which looks easier to input / dictate over the phone / write down somewhere? 220.12.30.01 or 2001:cdba:0000:0000:0000:0000:3257:9652?
- bawolff 6y agoThe DNS name sounds easier to say over the phone...
- kortilla 6y agoUse DNS, that’s what it’s there for. MAC addresses aren’t referred to as fundamentally flawed and they are approximately the same length as the shorted version of the address you posted.
- mindslight 6y agoForget DNS. Use an overlay with content routing. Hierarchies suck. It's extremely hyperbolic to call an ugly syntax a bad "design". But IMO it would have been much nicer if they just reused '.' as in IPv4. ':' seemingly came out of their pie in the sky desire to replace MACs. Speaking of MACs, every time every time I see some cheap trash gizmo come with its own MAC I'm surprised there isn't address space pressure. I guess that's due to having 16 more bits as well as being non-aggregable.
- kortilla 6y agoYeah, that extra 16 bits is a game changer. The whole v6 debacle wouldn’t have happened if v4 was 48 bits. It’s funny, there is an interview with Vint Cerf where he mentions the choice of 32 bit address space for ipv4 was essentially pulled out of a hat and it could just as easily have been 48/64/24.
- i_like_to_post 6y agoDo you ever configure, type or have to share MAC addresses? Probably not. On the other hand, most devs / technical staff type IPs into the browser and terminal daily.
- kortilla 6y ago> On the other hand, most devs / technical staff type IPs into the browser and terminal daily. No they don’t. Configure a DNS server and type these in once. Any time I see IP addresses passed around it’s a sign of broken infrastructure. (It also means you aren’t using tls or you’re training people to accept cert errors)
- i_like_to_post 6y ago> No they don’t Oh yes they do. > Any time I see IP addresses passed around it’s a sign of broken infrastructure Nope. > It also means you aren’t using tls or you’re training people to accept cert errors So, let me get this straight. You have a server that's behind CloudFlare, and you're claiming we should use DNS and TLS to SSH into it?
- Symbiote 6y agoIPs should be passed to the DNS server, yes. Every server/VM I control (~200) has a DNS entry. Every active IP has a reverse (PTR) entry. I have a monitoring task to check for missing DNS entries, as it usually suggests a problem (i.e. we've deployed or undeployed something incompletely).
- kortilla 6y agoI think you’re confused a bit, so let’s split apart the use cases to be clear why IPs are bad in both cases. You said devs and technical staff were typing IPs into their browsers. Presumably this means the address bar, which breaks TLS. SSH derives a big chunk of security from key caching. If you’re using IPs you now can’t have an IP change without triggering key warnings on the SSH clients for a new key at a minimum or (worst case) a breach.
- i_like_to_post 6y ago> You said devs and technical staff were typing IPs into their browsers. Presumably this means the address bar, which breaks TLS. Looks like you got confused. I didn't say that. You just assumed that. > SSH derives a big chunk of security from key caching. No, it does not. It is pointless to fill DNS entries for hosts that are supposed to have their IPs hidden behind DDoS mitigation services like CloudFlare. The whole purpose of the exercise is to not leak the IP addresses. You SSH into your servers via IP, the IP gets cached with the key. There is no difference compared to having a DNS entry, except for the fact that you do not leak the server IP. > If you’re using IPs you now can’t have an IP change No one wants IP changes on externally facing hosts. You keep the IP static and if something happens with the server, you just reassign the IP.
- jaifraic 6y agoBut how often do people have to write down or dictate IP addresses?
- Avamander 6y agoYou do know you don't have to write out all the zeros in an IPv6 address?
- i_cannot_hack 6y agoTo be fair, your example would (according to the official spec) be shortened to 2001:cdba::3257:9652, which would not be hard to communicate over the phone.
- Symbiote 6y ago+44 115 1234 123 is also more difficult to explain than "0115 1234 123" or even "1234 123", but it enables the whole world to telephone that number. What alternative do you propose, that gives us more addresses but isn't longer? (IPv4 has fewer addresses than people)
- knorker 6y agoWhen's the last time you gave an IPv4 address over the phone? I've been in networking for 30 years, worked for multiple multinational ISPs, and the answer is basically never.
- benhurmarcel 6y agoEvery time I call tech support at my job so that they can remote in. Granted, it's the IP on the company's network so it can stay IPv4 forever.
- adventured 6y ago> When's the last time you gave an IPv4 address over the phone? 1990s, Quake.
- lizknope 6y ago6 months ago. I let about 10 family and friends connect directly to my home server. My firewall blocks everything except for these 10 IP addresses. I did get tired of having them figure out their IP address so now I just tell them to access a dummy page page on my external VPS and I check the web server log to see their IP to add to my firewall config.
- knorker 6y agoSo in other words IPv4's shorter addresses didn't help at all? And also it seems like a lot to sacrifice in order to make something marginally more helpful about once or twice a year. Also why would you say it over the phone? Would you not ask them to email or IM it? I can't count the number of times passwords and names have been misunderstood over the phone. Numbers? Basically always at least one number is misheard.
- austincheney 6y agoYou are confusing a difference of opinion on the style of output opposed to the functional operation. IPv6 works very well.
- deadbunny 6y agoI mean 2001:cdba::3257:9652 is about the same as ipv4...
- i_like_to_post 6y agoI see how the crowd here is downvoting me heavily for just stating the simple truth that IPv6 is inconvenient, when compared to IPv4. But if it was false, an IPv4 address wouldn't cost $20-$30 (vs $0 for IPv6) and Amazon wouldn't be hoarding $2B worth of them, would it? Ok then.
- detaro 6y agoYou can't imagine there are other reasons for difficulties in replacing a core component of the internet other than "longer numbers are harder to type"?
- i_like_to_post 6y agoIPv6 was released in 1995 -- that's 25 years ago. If it didn't suck, don't you think we would have forgotten about IPv4 by now. Or do you also have many devices around running Windows 95?
- detaro 6y agoYou claimed one specific issue with it, you don't get to play the "but it has other problems too!" (it indeed does) card now. It being badly designed in some ways is indeed part of the "other reasons".
- deleted 6y ago[deleted]
- i_like_to_post 6y agoIn other words, you realized you lost the argument and now you're just salty. okay.