21 ms·
AWS adds an extra 5.5M IPv4 addresses
- korethr 5y agolow whistle I imagine they paid a pretty penny for those /12s. A thought comes to me: If IPv6 adoption continues to drag along, and AWS/Azure/GCP continue to expand their IP blocks like this, how quickly are we in danger of the cloud providers effectively being the Internet?
- Ambroos 5y agoI guess there's a large pool of IP addresses used by residential ISPs that could be recycled relatively easily. When I lived in Ireland I only got a public IPv6, my IPv4 was behind CG-NAT. The nerd in me wasn't a fan of that on paper, but in reality I didn't have any issues with it. I could see ISPs making a quick buck by switching to CG-NAT on IPv4 so they can sell off their IPv4 blocks. Those IPs being recycled for servers/services doesn't seem too risky, given that they're not typically hosting anything.
- 2Gkashmiri 5y agoI find the ipv6 address scary because IP geolocation gives that in the same city district. Cgnat would be better because the server would see ipv4 of the ISP. I don't know, is there a way to not show my ipv6 and fall back on cgnat address because that looks much more secure in terms of not getting doxed and ad tracked.
- sp332 5y agoSure, just disable IPv6 support in your OS.
- 2Gkashmiri 5y agoapparently android doesnt allow that on wifi so out of luck.
- andruby 5y agoI assume a vpn, ssh tunnel, wireguard or any other type of proxy would hide your residential ip.
- tolien 5y agoThat’s not inherent to IPv6 though, your ISP chose to be more specific in the location data for those addresses. If it’s sufficiently detailed as to “dox” you, maybe ask them not to do that?
- wu_187 5y agoBoth AT&T and Comcast do this with IPv4 as well.
- tolien 5y agoYeah, NTL/Virgin Media in the UK do the same in that their IPs geolocate to where the node/head end is. In a city, it's not going to be specific enough to uniquely identify you but it's still weird seeing ads that aren't that far away. On the other hand, the IPv4/v6 addresses on my A&A connection geolocate to either London or Bracknell (where their office is), about 400 miles away. I get a lot of pointless ads for things in Surrey that I have no intention of visiting.
- 2Gkashmiri 5y agoi have never used google search but the other day someone used that infront of me and on the bottom i saw what appeared to be "pin code for approximating your current location for local results" and something to that end. that scared me big time because this was like my home pin code, my small city has like 30 so this is narrowing me down to a single one which i am not comfortable with
- tolien 5y agoRight, but is Google doing this with the information they get from your IP address or something else entirely? Is it just coincidence that your IP address corresponds to your ISP’s office which happens to be relatively local? With loose enough permissions your browser has a geolocation API that, depending on your device, will be a hell of a lot more accurate (if you have Wi-Fi hardware it can use that to work out where it is relative to the known locations of the SSIDs it can see, or straight-out use GPS). None of this has anything to do with IPv6 - you give away some location information with your username and profile on this very site, for example.
- JPDeckers 5y agoProblem with CGNAT is the costs involved in bookkeeping for law enforcement. Where an IPv4 solution for your clients only needs change-logging on IPbinding-to-client level, the CG-NAT requires you as an ISP to log every outgoing IPv4/port combination with timestamp to client mapping. Which requires A LOT more storage and much more expensive equipment. Going rate per IPv4 is up to $40 nowadays, selling of your v4 block might not be cost-efficient.
- deleted 5y ago[deleted]
- minimaster 5y agoDisclaimer: I work with this stuff and might be a little biased to certain vendor solutions. A good CGNAT implementations have support for static blocks: the subscriber always ends up a a specific ipnumber+portblock combination. (Each subscriber is assigned a specific number of exit ports and this all just logged once during startup so you always know where each subscriber ends up). Should they run out of their assigned portblock, there are pools which you can borrow from (these need then to be logged who borrowed at what time etc). So all in all there is less logging than when everything was dynamic.
- endre 5y agoAnd law enforcement inquiries barely contain source port information, or precise time. Most of then go like: who had this IP in $this-two-weeks-window. No source port, no destination IP/port.
- philderbeast 5y agothat will just lead to a whole lot of "we dont have that information" or alternativly, "all of these 10000 people used that, have fun!"
- floatboth 5y agoAnd isn't that the privacy we all would really enjoy? :D
- einpoklum 5y ago> WThe nerd in me wasn't a fan of that on paper, but in reality I didn't have any issues with it. No issues? So, how are people supposed to be able to access your machine then?
- sp332 5y agoI usually used Teamviewer.
- tehbeard 5y agoWhy should I want people to be accessing my personal desktop/laptop/tablet?
- edoceo 5y agoIt's cause you want to get to your home boxen from outside.
- dbmnt 5y agoThere are other solutions to this problem now. Tailscale comes to mind.
- chrisseaton 5y agoSurely you know this is a super niche requirement? You can use IP6 or a commercial rather than domestic ISP if you really need to do it.
- olyjohn 5y agoIt might not be so niche if we weren't all behind NAT firewalls. There would probably be a whole lot more applications that do direct connections between two people, and eliminate the middle-man. There's a reason every major service out there has their applications set up in some cloud to relay the messages back and forth between clients.
- sp332 5y ago
- dehrmann 5y agoI've had a static ipv4 address on a home internet connection for almost 10 years, now. They're out there...
- phatfish 5y agoYup, ISPs in countries that got a nice big block if addresses in the early days can still manage this. I have a cable connection that was originally provided by NTL (now Virgin Media). My IPv4 address changes about once a year now as they do upgrades/maintenance. It used to change even less.
- throwaway3b03 5y agoI used to have that. Then all residential customers were put under a CGN, and you can ask for a dedicated, public IP, free of charge. I imagine 99.9% of users can't tell the difference so the ISP saved a lot of IP space, while customers are just as happy.
- globular-toast 5y agoThat makes me realise there is an incentive for ISPs to hold out on supporting IPv6. If IPv6 was widely supported then their IPv4 blocks would be worthless. I wonder how many will be holding out on deploying IPv6 until they can offload their still-valuable IPv4 addresses.
- littlecranky67 5y agoIPv6 adoption is just sad. Sharing an anectode: Back in 2002, I was using a 56k modem on a linux box 24/7 from home with a dialup flatrate. Being an avid IRCnet user, I setup an IPv6 tunnel with a tunnel broker (I think it was Hurricane Electric - it was before Aiccu was a thing) and connected to the IPv6 IRCnet servers. There was once a channel #uptime which was a contest: On start of contest, everybody in channel got voice - and the person to last hold voice would win (you lose voice when your TCP connection disconnects). Even so I had a forced disconnect every 24h, amongst over 100 users (mostly Servers, Bouncers, Universities etc.) I ranked 6th place in the end (after couple of weeks), because my ipv4 dialup was reconnecting fast enough to receive the buffered ipv6 tunnel pakets from the broker. Today I have no more IPv6 since SIXXS shut its doors a couple of years back, and my provider (o2/Telefonica) hasn't roled it out to me yet. Looking back those 19 years, the availability and state of IPv6 has worsened for me - even though IPv4 shortage was known back then.
- wvh 5y agoSame story here. I think I had IPv6 around 2000 with HE and then SIXXS, and my university back then already assigned IPv6 addresses. Now in 2021, I don't think I have had an IPv6 address assigned either at home or at work for quite some time. It's hard to understand why they don't just push through since there clearly are no real technical problems as witness by those few countries with major providers that actually actively use IPv6 (only).
- hamburgerwah 5y agoHaving just realized my internet provider, cox, does not actually support ipv6 for the 2 million plus subscribers in my state I think it is safe to say that ipv6 is dead and will never take the place of ipv4 in our lifetimes. Don't get me wrong. They say they support it, they have lots of PR that says the support it but in fact as a subscriber they do not.
- deadmutex 5y agoEhn, I don't know if you can go from "my internet provider, cox, does not actually support ipv6" to "I think it is safe to say that ipv6 is dead". There are much more comprehensive ways to look at ipv6 adoption, e.g. https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html
- BikiniPrince 5y agoMine had some beta program years ago. You had to find a number to call which was hidden away in a locked filing cabinet hidden away in a disused lavatory. They were purchased recently and maybe there is hope now.
- lashloch 5y agoin our lifetimes. you don't think ipv6 will overtake ipv4 in the next 50-odd years? think about the year 1971 and what was thought possible then
- skuhn 5y agoOvertake: yes. The ability to launch a public-facing, commercial service and pretend like IPv4 never existed and you don't have to worry about it at all? Probably not within our lifetimes.
- cm2187 5y agoI am not sure about that. When IPv6 support nears 95%, the pressure will be on those few ISPs to give access to those areas inaccessible from v4. Think of all these websites that need to be cheap and are happy enough with reaching 95% of the audience: blogs, small businesses, anything education related, etc. That should help going from 95 to 100.
- skuhn 5y agoPublic auctions (which they didn't use) are currently in the $45-50 per IP ballpark. At that price it's $247.5 million worth of IPs. At auction the larger networks tend to go for less money per IP since there is a smaller market of people who want and can buy them (you have to be approved by ARIN/RIPE/etc. for the allocation size), which drives the price down.
- korethr 5y agoWhat's the cutoff for larger networks where the price starts to go down? Would say, a /16 count? Or does that effect kick in as low as, say, a /20?
- skuhn 5y agoI think that it starts to have downward pressure at /22 to /20. You can see Hilco's historicals at [1]. Not all purchases are done in public though. It seems to me like an arbitrage opportunity, since /24 and /23 networks have many more potential buyers. But you have to be approved with a regional registry for the amount of space in order to buy it. Observing things from the buy side, I suspect that IP space is being brought to auction in a slow but steady trickle so as to maintain upward momentum on prices. The price has approximately doubled in the last year. [1] https://auctions.ipv4.global/prior-sales https://auctions.ipv4.global/prior-sales
- oarsinsync 5y ago> But you have to be approved with a regional registry for the amount of space in order to buy it. This hasn’t been my experience in RIPEland since post IPv4-exhaustion. Is this an ARINism?
- skuhn 5y agoThat's my understanding with ARIN, yeah.
- Aeolun 5y agoThat’s not actually too expensive, considering they make that money back in a few months if all those IP’s are hosting even their smallest server.
- Ericson2314 5y agoYeah I would like the FTC go after new IPv4 deployments / mandate dual stack on anti-trust grounds.
- korethr 5y agoThat's an interesting idea. I don't know if the FTC has the authority to do so under the current powers given to it by Congress, and I don't know if I'd like the precedent of them trying without Congress so delegating that power. I'd be totally willing to discuss Congress delegating them said authority.
- IncRnd 5y agoHow does IPv4's use translate to anti-trust?
- usr1106 5y agoControlling 200 times more of a critical resource than the next competitor does not sound like healthy competition.
- netr0ute 5y agoThat's if you can define IPV4 as a critical resource. But because anyone can assign any IPv4 address to anything and advertise it with BGP, it can't fit the definition of that.
- remram 5y agoThere would be penalties for that, maybe even legal ones. How easy it is to steal does not really factor in whether it's a critical resource.
- netr0ute 5y agoCan it be defined as property? I could make a Internet The Second using isolated networks and advertise whatever I wanted. It's not like digital movies and music where it's defined as property under copyright law because it's a creative work.
- StreamBright 5y agoIPv6 is trying to do too much in my opinion. This is partially why adoption is slower than it could be.
- kazen44 5y agoin what way? IPV6 is in many ways a simpeler protocol then IPv4. for instance, it has a significantly simpeler header then IPv4, it does not duplicate the broadcast behaviour of ethernet but relies on multicast instead. Some parts of IPv6 are complex (mainly, IPsec) but those are not required to get an operational ipv6 network. SLAAC & NDP are both significantly more simple then ARP and Automatic addressing under ipv4.
- wu_187 5y agoI've worked in the cloud hosting industry for a decade and a half. The entire time, we were warned about the IPv4 shortage and how we needed to switch to IPv6 soon(tm). Well, things haven't changed. Everyone is dragging their feet on IPv6 adoption from hosting providers, ISPs, hardware manufacturers, and software developers. I predicted this years ago and always said that it would require a government mandate to move on from IPv4. I honestly believe we are going to ramp up NAT in the coming years before really doing away with IPv4.
- xvilka 5y agoSome countries did exactly that, China for example. Most of the infrastructure, ISP networks, even user applications here is now IPv6 or ought to be in a few years [1]. [1] https://www.theregister.com/2021/07/26/china_single_stack_ipv6_notice/ https://www.theregister.com/2021/07/26/china_single_stack_ip...
- toxik 5y agoTo be fair, this is exactly the type of thing you’d expect China to be good at, unilateral decision making.
- syntheticnature 5y agoAlso, when your country's population is such that the entire IPv4 address space could only allow three addresses per resident, with that ignoring all reserved / multicast restrictions...
- vmception 5y agoBenevolent leader is the best case of government, it is just improbable and of course it is too risky for any dissenter, and the successor is never as good. So people go for inclusive forms of government, which produces average case results more often.
- nousermane 5y agoNAT is ramping up on client side. Many home-internet connections are now NATted twice - in CPE, then again in CGN. On the server side, in contrast, NAT is winding down. 15 years ago, it was common to have either DMZ-style NAT, or on AWS you had to have NAT (they call it EIP). Nowadays, having a CDN or could-native load-balancer in front of your server is increasingly common. And behind those, that server just don't need a public IP (maybe only a shared outboud NAT for OS updates). That is - if you have a server at all (and not moved to lambda, S3, etc...)
- liveoneggs 5y agoietf and friends could have made ipv6 only address the shortage but decided to change a bunch of other stuff too
- goodpoint 5y ago> are we in danger of the cloud providers effectively being the Internet? Between cloudflare and AWS/Azure/Google most of the Internet is an oligopoly right now. Interesting how nobody else replied to this part of your comment.
- Frost1x 5y agoWell, when the internet cartel pays your bills... Technology certainly scaling and improving but it's being concentrated in fewer and fewer hands. In the past I could compete with most sophisticated companies, it wasn't unattainable. Barrier to entry is simply too high now. No single or small team of developers and technologists is going to compete with AWS.
- MichaelZuo 5y agoWordpress?
- koksik202 5y agoI wonder if we see large use of IPv4 and IPv6 adaptation how tricky it will be to adapt and be able to have enough FIB in boxes to hold all those resolutions I wonder how many companies will go into buying beefy chassis rather than implementing some some low level fragmentation for two families
- deleted 5y ago[deleted]
- IcePic 5y agoOf course that is how it will end. Noone thinks that this is a bad idea, to only allow customers of those three to host a service, because that is the current mindset. When they own all the v4 ips, we will have no choice but to hot on their infra or not host at all. At that time, someone might think that IPv6 with all its faults might have been a good idea after all, but then it will be too late, since "v4 seems to work, all clients behind 2-3-4 layers of NAT, everything tunneled in HTTP/4.5 on a single port outwards to your VPS/VPN". Not being able to host a game on your home computer, not being able to start a service unless GCP/Azure/AWS allows you to will be the end of the internet as we used to know it. Extra fun for anyone not being american enough to want to be a customer of the big three.
- sigstoat 5y ago> When they own all the v4 ips ... there won't be any value in them any more. if the only folks left who can use IPv4 are the hosting providers ("big three" or not), then nobody will be using using IPv4 to contact all the hosted services. large swaths of users have IPv6 available to them. if there starts being some inconvenience to not having 6, we can be sure adoption will pick up even faster. https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html
- IcePic 5y ago>> When they own all the v4 ips >... there won't be any value in them any more. and upto that point, it will be SUPER expensive for you to try to get one (or 256), which they can pay since they have monopoly on them, and you only needing one can't.
- anthropodie 5y agoIPv6 will never happen without someone forcing hands of big corps and ISPs to switch to Ipv6. Imagine all social media and streaming services, disable ipv4 within a month. These are not critical services but still will force ISPs to make the switch.
- korethr 5y agoYears ago, when I perhaps more naively believed in the benevolence of Google, and that wisdom of the Elder True Nerds who worked there would lead us to The Future, I might have applauded them throwing their weight around doing something like that. Possibly with a condescending paternalistic attitude like, "dragging the unwashed masses kicking and screaming into the the future they're too stupid to realize just yet that this will be better for them." I am no longer so young and naive. Now, there is no doubt in my mind that such a move by Google or the other tech giants would not be made out of benevolence, but because by doing so, somehow, would net them yet greater control over the flow of information across the world. Whether out of an authoritarian desire architect society the right way this time, or chasing their profit margin as far down the asymptote as they can measure, the resultant 1st through Nth order effects would probably be the same for the rest of us.
- corty 5y agoControl is one argument, but I'd go with the money argument: All the big cloud providers like Google and AWS as well as the small ones like Hetzner do have an incentive to keep IPv4 going as long as possible. They can charge a premium for things IPv4 "because addresses are scarce". Charging a premium means more profit margin. At the same time, they do not need to invest in more than lip service for IPv6 support in their offerings: No cloud provider has any comprehensive IPv6 offering, most services don't do IPv6. The edge ones maybe do, but there are always sharp edges, missing docs and general pain, pushing everyone back to IPv4 where the profits are.
- bpodgursky 5y agoI thought ISPs were actually doing pretty well? Big corps are moving slowly but I think it's mostly limited to internal NATted networks, which frankly nobody has an incentive to upgrade. We're getting there... slowly.
- jagger27 5y agoWho the heck has a couple /12s and a /13 just lying around unused? And there are even some earlier pickups of two /10s: 252.0.0.0/10 and 44.192.0.0/10. Wow.
- bushbaba 5y agoLook at who still has their assigned /8. Gonna be funny how well likely live to see ipv6 run out of ip space leading to ipv8! https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_address_blocks https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addre...
- jagger27 5y agoI knew about Apple and AT&T. DoD is really hoarding them, wow.
- selectodude 5y agoHonestly prudential is the one that stuns me. They’re an insurance company! Why do they need all those?!
- lmm 5y agoThey probably got a /8 early and gave each regional office their own /16, so they'd have to unpick all the addresses they're currently using before they could sell off any.
- Dylan16807 5y agoI'm sure they could split it into /16s and sell off the empty ones.
- axaxs 5y agoSame with Ford. And while I do think the addresses should be returned, they should get market value or above for them. We should not punish companies for buying into the future, which turned out to be a great investment.
- seligman99 5y agoAs always, if anyone has any suggestions on tracking and stats they'd like to see for this on the repo, I'm always welcome to ideas.
- techsupporter 5y agoMeanwhile, Hetzner just added a staggering $19/address setup fee and a soon doubling of prices for IPv4 addresses from them ostensibly due to the rising costs of getting addresses, yet still has virtually no support for IPv6 on their offerings outside of a /64 per dedicated server. https://docs.hetzner.com/general/others/ipv4-pricing/ https://docs.hetzner.com/general/others/ipv4-pricing/
- RedShift1 5y agoWhy would you need anything other than a /64 on your server?
- TheChaplain 5y agoHuh? I've been using IPv6 on their cloud instances for years, and it works just perfect.
- kolaente 5y agoYou also get a /64 on their cloud servers, one subnet per project iirc.
- Aeolun 5y agoHow is a /64 per dedicated server no support?
- remram 5y ago/64 seems pretty standard, unfortunately. It's what I get on OVH. There's also way worse providers, like Digital Ocean with a /124, and LightSail with /128.
- tom7 5y agoWhen will they admit that ipv6 naming schene was a mistake and nobody can remember these addresses?
- jghn 5y agoThis was all a big emergency 25 years ago until IPMasquerade/NAT came out. Yeah, we should migrate to IPV6 now but it's just so much less important.
- LeoPanthera 5y agoThe DoD still owns 14 class A blocks, right? And is 240.0.0.0/4 still "reserved"?
- mjevans 5y agoMany firewalls that don't expect IPs in that block to be valid will just drop the packets as bogus.
- andrewjf 5y agoI’m a huge IPv6 advocate, but I can’t imagine we’re not better off releasing 240.0.0.0/4 to RIRs and fixing stuff that makes that assumption. That’s an enormous amount of IP space.
- mjevans 5y agoThe argument against that is to 'deploy and fix IPv6', since this just kicks the can down the road, which has already been going for at least 20 years at this point. "The first RFC to standardize IPv6 was the RFC 1883 in 1995, which became obsoleted by RFC 2460 in 1998. In July 2017 this RFC was obsoleted by RFC 8200, which elevated IPv6 to "Internet Standard" (the highest maturity level for IETF protocols)." https://en.wikipedia.org/wiki/IPv6 https://en.wikipedia.org/wiki/IPv6
- rnhmjoj 5y agoYes, and it may be possible they will be sold[1]. From the article it looks like they're identifying unauthorized use of their space, while clearing the addresses from firewalls to become really routable. [1]: https://arstechnica.com/information-technology/2021/04/pentagon-explains-odd-transfer-of-175-million-ip-addresses-to-obscure-company/ https://arstechnica.com/information-technology/2021/04/penta...
- southerntofu 5y agoLast October, Amazon bought ~4 million addresses by bribing the corrupt technocrats of a radioamateur "non-profit" organization. Fuck Amazon, fuck those corrupt technocrats (like the ICANN/.org team who tried to sell the TLD). It's incredible what this kind of people can get away with. Previous discussion on HN: https://news.ycombinator.com/item?id=24753654 https://news.ycombinator.com/item?id=24753654
- nsizx 5y agoWell, if that organisation didn't have a use for those addresses... I don't see what the big deal is.
- itsbits 5y agoI think the question is why not sell them openly instead sell them via backgate..
- nsizx 5y agoI assume Amazon came to them and offered the money and they accepted. I don't see anything shady about that. How do you sell something "openly"? Via an auction website? Is that standard procedure for everything these people sell?
- southerntofu 5y agoStandard Internet procedures for IP addresses is apply to your Regional Internet Registry for addresses, and the panel decides who will make best use of them (usually smaller/newer providers are prioritized). You only pay administrative/membership fees for the addresses because IP addresses are technical bits not property... everyone operates addresses but nobody owns them. That people sell food and houses is disconcerting in the physical world and creates real problems for real people where some can't afford to eat or have a roof over their head despite a global abundance of resources. That people do the same in the virtual world, with literal numbers, is beyond the scope of comprehension: pure madness.
- turminal 5y agoDoes similar data exist for other cloud giants?
- Ekaros 5y agoSo one solution for IPv4 shortage is for hosting providers to own all IP space... Not sure if anyone has done projection when will that one happen.
- laurent92 5y agoAnother huge problem is that companies are handling out IPv6 by bulks of /128 subnets per machine, and many experts encourage “one IP per service on the machine”, adding “it’s good for security since it’s harder to scan all ports of all subnet IPs. So at that pace, I still wonder how IPv6 will not run out of IP as quickly as IPv4. One IP per server should be the norm.
- audron 5y agoEven if you reduce it down to /48 subnets you have 281,474,976,710,656 of these, ~65k times more than the entire IPv4 space, your usual assignment to a machine is a /64 which are about 4.2 billion times the amount of the IPv4 address space, about 18 quintillion. Thats enough addresses to give every one of the 8 billion humans on this planet, two billion /64 subnets. Which I'd say should be enough for the moment.
- tkiolp4 5y ago> 65k times more than the entire IPv4 space Last week I was thinking about a system to automatically cut my hair the way I exactly want (precision up to the millimeter and per hair). So, one way would be by using cheap microrobots*. The On average we have around 100K hairs on our heads. Let’s say you buy 100K microrobots to cut your hair. Each of these microrobots could have their own ipv6 (because, why not) so that you can control them via your phone. So, suddenly you have there one person using 100K ipv6 addresses. So, whenever people say “ipv6 should be enough for now”, I always think “well, it depends on how they are used!”
- umanwizard 5y agoIf every person in the world simultaneously had 100,000 IPv6 addresses, that would represent a tiny, trivial fraction of the available space.
- zauguin 5y agoWe have less than 8 billion people on the world which corresponds to about 2^33. Let's assume that (given that we already have issues with sustainability) we will have much bigger issues than IP addresses if we ever reach more than 128 times that. So we are at less than 2^40. (Realistically I would expect much less, but let's be safe) Than the question is how many addresses everyone needs. Currently we assign subnets. Let's provide everyone with 1024 subnets for client devices and an additional 1024 servers each with their own subnets. So 2^11 subnets each. So we end up requiring 2^51 subnets, while we have 2^64 available, thereby only using less than 0.013% which provides plenty of room to reconsider if any of these approximations turn out to be wrong.
- tedk-42 5y agoIn the consumer space this doesn't matter much. Most internet users at home could have their IPv4 address removed and only provided an IPv6 one. Mobile internet is commonly served only by IPv6. It's the hosting/server space where IPv4 matters and will probably be like this for the next 20 years. This will be harder than the python 2 -> 3 migration. We'll continue to come close to running out of IPv4 addresses but we won't ever ween off them completely in the server space.
- umanwizard 5y ago> Most internet users at home could have their IPv4 address removed and only provided an IPv6 one. > Mobile internet is commonly served only by IPv6. These aren’t true. There are still some big consumer-facing sites that are IPv4 only — notably twitter.com and amazon.com. I can definitely still access both from my mobile device.
- niij 5y agoMy understanding is that there is some sort of translation taking place with 6to4, NAT64, ??? So while amazon.com may not have AAAA records/ipv6 it is still reachable by properly configured ipv6 clients with some sort of middleman to translate.
- deleted 5y ago[deleted]
- remuskaos 5y agoAs far as I know, these middlemen are deployed by the respective ISPs and are not a core function of ipv6. I've had the 6to4 (or AFTR, I'm still not sure which) fail on my ISP and could only reach ipv6 enabled hosts, sometimes for hours.
- niij 5y agoNot strictly required for the ISP to run it, I think Hurricane Electric did/does run something like those for free. But in general, yes, it's on the clients to handle.
- cankut_orakcal 5y agoPlease saw off the head of Mr. Cankut Orakcal. You can stop the coronavirus pandemic, the next 9/11 or financial crisis. Decapitate on sight as needed.
- deleted 5y ago[deleted]
- mwcampbell 5y agoI wish that instead of buying more IPv4 blocks, AWS would drastically lower the price of NAT gateways, then charge extra for EC2 instances and Fargate tasks with public IPs, to make it a no-brainer to stop wasting public IPs. As it stands, it's cheaper to waste public IPs than to use NAT gateways. Addendum: I also wish I could volunteer to be switched over to CGNAT for my personal IPv4 traffic. This discussion got me thinking about what it would take to get my company's IPv4 footprint down to zero. Might as well do that for myself as well if I could.
- moduspol 5y agoYep. Or even give me a CG-NAT adoption. I have plenty of use cases where I only use a public IP address in AWS for Internet connectivity without any need for new incoming connections. For those, I'd be totally fine with a CG-NAT address.
- mwcampbell 5y agoI wonder if we could hack that for ourselves by having our EC2 instances or Fargate tasks do all outgoing Internet access indirectly through Lambda functions.
- remram 5y agoI noticed that too on GCP. Many of my workloads don't need a public address but it's still simpler and cheaper to set one.
- bob1029 5y agoI've been making us use a NAT gateway for all of our EC2 instances since the dawn of time. Only those that need to be directly touched on specific ports get dedicated IPv4. I can count all of our public IPv4 addresses on 1 hand, and that includes a static comcast address for a branch office. Using auto-assigned IPv4 should not be default, IMO. If I just did what amazon wanted me to without thinking, we would be consuming 5-6x more IPv4 addresses than we otherwise need to.
- 5y ago
- fortran77 5y agoWow! IPv4 addresses are like oil. We think we've run out, then we get better methods like "fracking" and "shale oil" and we can squeeze out a few more barrels of them.
- roody15 5y agoIn my experience working IT at some public universities and some private education facilities there is a negative incentive for adopting IPV6. Often in these environments bandwidth use it up even on the LAN side and dual stack IPv6 simply causes unnecessary traffic that impacts negatively network performance. This was not the case in my experience 7-10 years ago.
- saranagati 5y agoAmazon didn’t just buy these addresses, an AWS service was just assigned them due to some future known growth. Amazon bought the rights to use all of the 3/8 network years ago and is just now allocating some additional subnets of that to AWS services.
- oars 5y agoThe repo notes 3.48.0.0/12 and 3.152.0.0/13 as new IP ranges but I thought it was already well known that they owned 3.0.0.0/8? It's even been discussed on HN previously: https://news.ycombinator.com/item?id=18407173 https://news.ycombinator.com/item?id=18407173
- kseifried 5y agoYou want proof that people don't yet trust IPv6? Simply lookup SPF records, very few (like <5%) of domains list IPv6 records in their SPF record, for example Google and Outlook do, but aol.com/yahoo.com do not. Email is a critical service and the fact most people aren't using IPv6 to deliver email yet is a telling sign. dig -t txt DOMAIN | grep v=spf1 and walk the records and includes for "ip6:...". Good luck finding any.