12 ms·
It's crazy that major web sites still do not support IPv6. https://www.amazon.in https://www.amazon.in https://www.paytm.com https://www.paytm.com https://tw
by quaintdev 5y ago
It's crazy that major web sites still do not support IPv6.
https://www.amazon.in https://www.amazon.in
https://www.paytm.com https://www.paytm.com
https://twitter.com https://twitter.com
https://www.flipkart.com https://www.flipkart.com
https://www.hotstar.com https://www.hotstar.com
https://www.primevideo.com https://www.primevideo.com
https://news.ycombinator.com https://news.ycombinator.com
https://www.reddit.com https://www.reddit.com
Edit: Removed google.co.in, the website[1] reported it that it does not support ipv6, Now I tried again and google is in green.
[1] https://ipv6-test.com/validate.php https://ipv6-test.com/validate.php
- judge2020 5y agohttps://dns.google/query?name=www.google.co.in&rr_type=AAAA&ecs= https://dns.google/query?name=www.google.co.in&rr_type=AAAA&...
- distalx 5y agoELI5: Why does IPv6 adoption matter? What would happen if these sites don't migrate to IPv6?
- TchoBeer 5y agoWe eventually run out of IPv4 addresses and have to switch anyway
- zinekeller 5y agoThat doesn't work as an explanation. NAT was developed. CGNAT was developed. HTTP Host differentiation was developed. SNI was developed. STUN was developed. TURN was developed. The main problem with IPv4 to IPv6 migration is the, frankly, overzealous utopia that "they will migrate anyway". Worse, it's very different that doesn't allow for a simple upgrade option of "IPv4, but longer addresses" because IPv6 is designed to be fundamentally different. Which is more insulting considering that BGP was seamlessly upgraded from 65536 ASes to more than a million because they only changed the bits in an AS and nothing more. As a router developer, you only need to do the relatively minute changes of extended ASes than the (relative) mess that is IPv6.
- neurostimulant 5y agoAnd now the internet got worse because you're no longer have technical freedom due to these NAT popping up everywhere. For example, previously if you want to release a video/voice chat app, you just release it and be done with it. Now it won't work like that due to NAT, so you'll have to maintain some STUN and TURN servers just to make your app usable to general public. Think about how many potential innovation got stifled because of added costs and complexity turned some people away before they even started.
- Sunspark 5y agoI agree. It makes things much harder than it should be. I wanted to try installing the module into my router so it would pass the WebRTC test for STUN/TURN and perhaps make video even more efficient to allow point to point connection instead of having everything be relayed through a tertiary server, but there was no documentation and having never set up a STUN/TURN server before I couldn't get it to work. So I am dependent on what a third party has set up to facilitate connectivity. In the old days, you'd just connect to an IP address and that was it.
- wbl 5y agoIPv6 implementations are everywhere so the extra changes don't really impact networks.
- zinekeller 5y agoRegardless of monentary charges (and I'm very aware of them, APNIC is even considering grants to help in IPv6 because it's in limbo for so long), even if we activate IPv6 synchronously there's still many, many problems with it, even when you permanently dual-stack it. One is connectivity. Even theoretically we should have the same network connectivity (so to speak), you can feel the pettiness when Hurricane-Electric and Cogent fought exclusively on IPv6 (https://www.theregister.com/2018/08/28/ipv6_peering_squabbles/ https://www.theregister.com/2018/08/28/ipv6_peering_squabble...) I can't believe I'm saying this, but IPv6 isn't free (or at least costs the same as IPv4). Second is security. Yes, the world is no longer scannable, but consumer routers are a dud when it comes to IPv6 security. This router (https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0d...) has serious problems at IPv6 security, and because it's suffix is always at ::0000:0000:0000:0001 and you've eliminate around 18 bits more because of how networks are laid, you've got yourself an IPv6 botnet, which speaking by, how do you block them? A /64 would be a good start, but OVH provides a single address per server (https://www.ovhcloud.com/vps/compare/ https://www.ovhcloud.com/vps/compare/). That's it. Don't forget that fiasco with MAC addresses (https://datatracker.ietf.org/doc/html/rfc8981 https://datatracker.ietf.org/doc/html/rfc8981), but at least that's solved. Third, IPv6 should just work as you said. I wish that's true, but embedded devices will trip you up badly. Some don't fallback to IPv4 and instead try and try again using IPv6. This would be a concern while transitioning, but even after that, some would be still stuck because their servers are only operating on IPv4! Implementing IPv6 is not free lunch if you know the gritty details.
- throw0101a 5y agoBecause there are 'only' 2^32, roughly four billion, IPv4 addresses. There are also over eight billion people on this planet, and many of them have multiple computers (smartphones, tablets, laptops, desktops, etc). As a 'temporary' measure, Network Address Translation (NAT) was introduced so people could get one public IPv4 address and have multiple machines on the Internet behind it. The trade-off was the machines behind the NAT mechanism couldn't be reached from the Internet. This isn't a big deal for most consumption-based computing (fetching mail, watching videos), but there are use cases where you want to be able to talk to the other system, so yet another set of technologies had to be invented to allow punching holes through NAT (UPnP, NAT-PMP, PCP, STUN). But we're at the point in some place where there aren't even enough IPv4 addresses to give to ISP customers even if they're using NAT. So you have a private IP address for your home system, and then your router gets a private IP address on its "public" WAN connection, and you end up going two layers of NAT. There is an entire segment of IPv4 addresses (100.64.0.0/10) reserved for telco use and doubel-NATing: * https://en.wikipedia.org/wiki/Private_network#Dedicated_space_for_carrier-grade_NAT_deployment https://en.wikipedia.org/wiki/Private_network#Dedicated_spac... * https://en.wikipedia.org/wiki/IPv4_shared_address_space https://en.wikipedia.org/wiki/IPv4_shared_address_space We can continue this NAT-upon-NAT(-upon-NAT) silliness, or we can simply make the up-front investment and start pushing out IPv6 in more places. Your router still provides firewall protection, but reachability is a lot more straight-forward because the (potentially double) address translation goes away. Edit: fix a bunch of typos.
- osrec 5y agoIn your first line, I guess you mean to say ipv4 not ipv6.
- ugjka 5y agothere's also NAT64, 464XLAT that do ipv6 to ipv4 sorcery
- throw0101a 5y agoBeyond an ELI5, but correct. If you are on an IPv4-only or IPv6-only network, you can reach the other through various mechanisms. A lot of mobile/cell networks are IPv6-only, and so the telcos need a way to allow clients to reach IPv4-only systems.
- norenh 5y agoI would argue that the main reason is that we are stuck with a centralized Internet with a somewhat large initial step to start a new service. If everyone get IPv6 we are all able to be a first class citizen on the Internet, meaning I can run a webserver or whatever from home. Once I am ready I can move on to a hosting provider with all the extra costs and hassle it comes with. Without IPv6, we are stuck with a two tier system of Internet users. Basically consumers and providers where the step to become a provider is larger than when you can simply start from home with whatever scrap you have in your garage. IPv6 will also simplify a lot of things (being able to scrap NAT (note, you will still need a firewall) and avoid protocol issues for End-to-End services) but that is just a bonus.
- darzu 5y agoFrom a game developer/player perspective: there’s a crazy amount of complexity in connecting between two computers that wouldn’t need to be there in an ipv6 world. See all the NAT, TURN, STUN nonsense that webrtc has to deal with: https://developer.mozilla.org/en-US/docs/Web/API/WebRTC_API/Protocols https://developer.mozilla.org/en-US/docs/Web/API/WebRTC_API/... Today to use webrtc, u need a neutral server to help establish the connection like PeerJS does. This wouldn’t be needed in an ipv6 world. It’s nearly impossible to do pure peer to peer connections today.
- nsizx 5y agoLetting machines connect directly to each other in any context, and especially in the context of an online game, is a massive security and privacy risk.
- rjsw 5y agoYou can (and should) still have a firewall that only allows connections to specific ports when using IPv6.
- nsizx 5y agoStill you are revealing your IP address to the other parties, which will be more than happy to DoS you to force you to disconnect, exploit 0-days in the game networking code to crash your game or get your private info, know where you are located by IP geolocation... The idea of P2P in competitive videogames strikes me as absolutely insane
- onei 5y agoWhen using NAT, you're revealing the IP address of your router. I don't know about you, but I don't have so many devices running on my home network that would drown out what I'm doing. With NAT, you can still receive DoS attacks, still have your game networking exploited, and still be geolocated. The only remotely security-related benefit is that instead of your ports being exposed to the wild internet, they're exposed to your router which is more of a side-effect rather than an actual benefit. Its not a reason to not bother having a firewall.
- toast0 5y agoNAT and especially CGNAT has a tendancy to cause problems. I vividly recall an incident where Jio's CGNAT was dropping idle TCP connections after 10 seconds of idle. (They fixed it, but I don't know if they fixed it for all destinations or only special destinations). And, of course, I say dropping, rather than closing, because NAT usually doesn't send FINs to close sessions when they're dropped. So you only find out when you try to send more data. Some NATs don't even send RST when you send data on a connection it dropped, so you have to wait for a timeout. There's also a capacity issue. If you're serving your website via a single IP (common with load balancers), you can only have 65535 connections from each client IP (assuming https on port 443 only, using non default ports is often a non-starter); if the user's ISP is sharing a very limited pool of IPs with a large number of users, it's conceivable that all the connections to your site could fill up.
- deleted 5y ago[deleted]
- kortilla 5y ago> if the user's ISP is sharing a very limited pool of IPs with a large number of users, it's conceivable that all the connections to your site could fill up. Unless each of your users is establishing 600 connections to your site, this isn’t a realistic issue. I don’t know of ISPs that go beyond 1000:1 over-subscription.
- betterunix2 5y agoIPv4 address space exhaustion. NAT breaks end-to-end connectivity, making entire classes of applications difficult to deploy, and this is made worse when the NAT gateway is not under a user's control. NAT gateway deployed by ISPs represent a violation of the end-to-end principle and have to be even more complex and stateful than the NAT gateways users often deploy. If you are looking for a specific problem NAT introduces, one good one is that NAT forces users and application developers to use protocols that the NAT gateway properly supports (e.g. TCP, UDP) and to only use those protocols in ways that are "NAT-friendly" (e.g. easy-to-track client-server sessions that are initiated from the private side the gateway) or else to use some NAT-specific protocol as a crutch (UPnP/IGD, STUN, etc.). When both ends of a two-party protocol are behind NAT gateways it can become even more painful and possibly require a third party to be introduced to an application that is otherwise unnecessary for the application. So at a minimum IPv6 gets us back to the end-to-end principle where Internet peers connect directly to each other without having to negotiate with the network itself. There are a few other advantages, like the fact that users can get large, publicly-routed addresses spaces for their own use (e.g. ISPs giving users a /56 prefix), simplified bridging of private networks (very low probability of collisions in the private IPv6 range), simplified router configuration (link-local addresses are always available so there is no need to assign numbers to every link), and other assorted niche benefits. In theory IPv6 should mean routers become more efficient because it is easier to aggregate prefixes, which should generally benefit Internet users by reducing latency (though at this point there is not much room left for improvement there).
- tambre 5y agoAmazon enabled IPv6 for various CDN endpoints serving images and static assets this year. At least they've made progress. A few years ago when forcing Reddit to IPv6 through /etc/hosts many pages resulted in 500 errors, but they gradually fixed them.
- vbezhenar 5y agoWhy is it crazy? They don't gain anything by supporting IPv6.
- miohtama 5y agoIf you can do direct consumer mobile phone IPv6 to server IPv6 there are benefits in latency, throughput, congestion control, analytics and so on. A better user experience. Depending on the hosting setup and networks, this may or may not be significant.
- vbezhenar 5y agocarrier NAT is unlikely to introduce measurable latency, especially in wireless networks. I agree that IPv6 allows for better user tracking, probably that's one of the reasons to adopt it. For example iPhones are virtually indistinguishable from each other, so the only reliable way to track them is cookie or IP address.
- supertrope 5y agoIt costs money to buy and maintain CG NAT infrastructure. Local authorities will demand you log who had what IP address at the time of interest.
- ipv6_or_nat 5y agoIPv4 or CGNAT costs are not optional. You will have to pay them regardless of if you deploy IPv6 or not.
- toast0 5y agoIPv4 and CGNAT costs scale with usage. The more traffic you offload to IPv6, the less CGNAT capacity you need and the less IPv4 space you need; you need enough IPv4 addresses so you can give out unique IP:Ports for all concurrent connections to popular destination IP:Ports.
- praseodym 5y agogithub.com doesn't support IPv6 either, which is annoying because a lot of software uses GitHub for artifact distribution.
- nsizx 5y agoIn what way does getting your artefacts through ipv4 annoy you?
- paulcarroty 5y agoYeah, and Heroku too. Don't know how they going now, but 5-7 years ago were their popularity was crazy.
- est31 5y agoThe pain is most felt by the ISPs which need to supply lots of ip addresses to their customers, while you need only few ip addresses for running an internet service (compared to the number of users/customers). There is little improvement in user experience and you need to change a lot of infrastructure to also support ipv6 addresses. So websites don't do it, sadly.
- tzs 5y agoSome of those sites have mobile apps on the Apple app store. How does not supporting IPv6 on their site reconcile with Apple's requirement that apps that support networking work when on an IPv6-only network? I would have thought that an app that is purportedly an app for site X but that cannot actually talk to site X when on an IPv6-only network would fail that requirement, but maybe I'm overestimating what Apple actually checks. Are they only checking that the app will correctly attempt an IPv6 connection to the site?
- realityking 5y agoThe App Store only requires Apps to work on networks employing DNS64/NAT64 [0]. That means the app internally needs to be able to handle IPv6 addresses and not hardcore any IPv4 addresses as those can’t be reached. There’s no requirement that the service underlying the app is directly reachable via IPv6. 0: https://developer.apple.com/support/ipv6/ https://developer.apple.com/support/ipv6/
- rynes 5y agoOnce upon a time I had an original iPhone and a router that did nor have ipv6, but the App Store worked. So I don’t understand your "ipv4 addresses can’t be reached" part.
- tialaramex 5y agoOn some people's phones IPv4 addresses can't be reached. Their carrier doesn't bother moving IPv4 over a network that doesn't need IPv4. It does translation at the edge, and the iPhone is OK with that. Apple's requirement is that even though you know your server is definitely 10.20.30.40† on the public network, and you hate IPv6 you must not hard code 10.20.30.40 inside the app and ship that to the App Store. Once you reluctantly change it to a DNS name ten-twenty-thirty-forty.fuck-off-apple.example that resolves to 10.20.30.40 - Apple allows that. Because now when your app is used on some IPv6-only carrier network, the carrier goes "ten-twenty-thirty-forty.fuck-off-apple.example ?" and it gets 10.20.30.40 and it says that's an IPv4 address, don't use those around here, and it adds a translator step, it gives the phone an IPv6 address for ten-twenty-thirty-forty.fuck-off-apple.example and the phone connects to that address, which is a translator that connects to 10.20.30.40 on the IPv4 Internet. This stuff happens all the time and you don't notice. But if Apple allowed app vendors to just scribble IPv4 addresses inside their app software it would break. † No that isn't a public IP address. It's an example.
- amjd 5y agoYou're right about other sites, but Hotstar does support IPv6: $ dig +short AAAA www.hotstar.com www.hotstar.com-sni.edgekey.net. e35862.dscj.akamaiedge.net. 2600:140f:7800::1730:f420 2600:140f:7800::1730:f421 2600:140f:7800::17d7:d7b9 2600:140f:7800::17d7:d7a9 2600:140f:7800::1730:f449