7 ms·
> What are the practical implications for internet users and infrastructure maintainers? For users: the widespread deployment of NAT has eliminated global end-
by ATsch 4y ago
> What are the practical implications for internet users and infrastructure maintainers?
For users: the widespread deployment of NAT has eliminated global end-to-end connectivity of the internet. That drives further centralization of the internet, as offering services requires expensive purchases of IPv4 space, big central NAT gateways and makes p2p applications difficult to impossible.
For infrastructure maintainers: the increased address space makes it possible again to allocate addresses as you wish. There's no need to architect your network around IP address scarcity. You can allocate pretty much as many networks as you want, for whatever you want, without worrying it's going to be too small.
- m463 4y agoalso privacy (although there are privacy extensions for ipv6)
- throwaway894345 4y agoCan you convince me that end-to-end connectivity is desirable in most cases? I certainly don't want ingress from the public Internet to devices on my home network in the general case, and I think it's kind of nice that the Internet only knows the address of my router rather than that of my physical machine (of course, there are other ways to fingerprint devices, but let's not make it easier than necessary). You definitely want a gateway to implement firewall rules, and I'm not sure whether I care if that gateway is doing NAT as well or not? What can I do with a non-NAT-ing gateway? The only thing I can think of is that cloud IP addresses aren't as carefully guarded (I don't get up-charged for an un-associated elastic IP address).
- chongli 4y agoI certainly don't want ingress from the public Internet to devices on my home network in the general case This is ultimately an operating system issue. For most of the history of the web, we've used NAT routers and firewalls as a fig leaf over the operating system issue. What is it? Operating systems are extremely promiscuous about listening for traffic on a multitude of ports. Operating systems are promiscuous about including a vast number of daemons running in the background handling a variety of tasks. Operating systems are promiscuous about running a bunch of daemons that phone home all the time. All of this stuff is completely opaque to the user. All of it occurs on a default opt-out basis. All of it requires an extraordinary amount of knowledge for the user to feasibly withdraw consent. This is the operating system problem. In another world, I can envision computers running operating systems which are totally transparent and easily understood by their users. All running services would be opt-in and users would be fully aware of exactly what's happening on their machines. That would be the world where end-to-end internet connectivity is highly desirable.
- mschuster91 4y ago> In another world, I can envision computers running operating systems which are totally transparent and easily understood by their users. All running services would be opt-in and users would be fully aware of exactly what's happening on their machines. That would be the world where end-to-end internet connectivity is highly desirable. Even then, you have the issue of bugs - not just in the programs themselves, but also in the kernel-mode stack and even in the hardware. As long as something is reachable from the Internet, it will get scanned and assaulted from the Internet - and the lower your attack surface is, the better.
- chongli 4y agooperating systems which are totally transparent and easily understood by their users I sort of glossed over this part so now I have a chance to elaborate. Alan Kay has put a ton of thought into this issue [1]. He firmly believes that we can build an operating system and application software with an extremely small footprint (LOC's) so that a single person can understand the whole thing. Since he gave that talk, we've moved further and further away from Kay's vision. We've made things more and more complex, opaque, centralized, and difficult to change. We've given away our future to big tech companies. Heck, we've even given away the past. We've lost much of the freedom we had back in the 90's, let alone the 70's and 80's when Kay did so much of his work. We're going to have to work incredibly hard just to regain what we've lost. [1] https://www.youtube.com/watch?v=oKg1hTOQXoY https://www.youtube.com/watch?v=oKg1hTOQXoY
- jamiek88 4y agoNo one human mind could ever grok the entirety of say, iOS or Android. Do we just go back to the software Middle Ages?
- throwaway894345 4y ago> This is ultimately an operating system issue. It's ultimately an issue at every layer, hence "defense in depth". Every layer does its part for security, we don't punt because some other layer ought to handle it.
- toast0 4y ago> Can you convince me that end-to-end connectivity is desirable in most cases? p2p communications can be nice for latency sensitive communications. Sometimes it's faster to communicate from user A to user B directly instead of going from user A to server Z to user B (although, sometimes it's not faster... if latency is important, you really have to try all the accessible paths and use the best one, keeping in mind that paths may have asymmetric latency, so maybe you want A to send to B directly, but B should send to A through an intermediary; and path latency isn't static, so for a long session, if it's important, you need to probe throughout and change thigns around) But, maybe you don't want your connection to be a full peer capable of receiving as well as initiating connections, you can run a stateful firewall on your end and drop incoming initiations. You'll still benefit from having end-to-end connectivity because it means your ISP can process your packets with basically no state, so there shouldn't be problems with connection state timing out and your connections being dropped without warning. If you run your own stateful firewall, you may still have that problem, but you might have less state required for a stateful firewall instead of a NAT, so maybe you can manage more connections.
- deleted 4y ago[deleted]
- throw0101a 4y ago> Can you convince me that end-to-end connectivity is desirable in most cases? I certainly don't want ingress from the public Internet to devices on my home network in the general case […] In the IPv4 case you have NAT and a firewall. If you have some software that you want others to connect to (communication, gaming, etc) you have to punch a whole through the firewall (via UPnP, PCP) and then the software has to use a bunch of protocols to figure out what the public IP address of your router is: see STUN, TURN, etc. See "How NAT traversal works": * https://tailscale.com/blog/how-nat-traversal-works/ https://tailscale.com/blog/how-nat-traversal-works/ * https://news.ycombinator.com/item?id=30707711 https://news.ycombinator.com/item?id=30707711 (2022) * https://news.ycombinator.com/item?id=24241105 https://news.ycombinator.com/item?id=24241105 (2020) With IPv6 you just have a firewall, which you punch a hole through when needed (UPnP, PCP) and you're done (because there's no futzing about with determining the network address). When the P2P session is done the whole is closed and you're protected again. So if you have a 'home network', it cannot be reached from the Internet by default. Note: you already have a device that's always on the Internet: your mobile phone. Lots of telcos are IPv6-only and you there's not NAT or firewall between it and the Internet.
- nikanj 4y agoIn most cases no, but then again in most cases you would be perfectly happy with all your traffic going through a http(s) only proxy. The two biggest use cases for direct p2p connections are multiplayer games and video calling. Latency is unavoidable if your traffic has to bounce around a third-party
- throwaway894345 4y ago> In most cases no, but then again in most cases you would be perfectly happy with all your traffic going through a http(s) only proxy. Not at all--end-to-end encryption is still a very desirable property. I certainly don't want a consumer router decrypting my browser traffic even if it is re-encrypting it to send to my device. I'll tolerate HTTP proxies on the server side when I'm administering the proxy and I need layer 7 routing, but I want to avoid it wherever possible. > The two biggest use cases for direct p2p connections are multiplayer games and video calling. You still have to punch a hole in your firewall either way. The only advantage ipv6 has is that you can have two hosts listening on the same port (whereas port-forwarding in a NAT context only works for 1-host-per-port). Tangentially, I was never a big fan of player-hosted games anyway because they tended to be more vulnerable to cheating and the host always had an unfair advantage (or else a dramatic penalty in the case of lag compensation). Moreover, it's much easier to send a malicious packet directly to another player than it would be to send it to the server and convince the server to proxy it through bit-for-bit (although a poorly written game server might still do just that).
- _carbyau_ 4y agoI love player hosted gaming. But the people I game with are looking for "fun experiences" (kinda like going to a movie as a group, but more interactive) rather than competitively climbing a leaderboard. Different use cases beget different requirements.
- anthropodie 4y ago> You still have to punch a hole in your firewall either way. No you don't have to do hole punching.
- anthropodie 4y agoThis discussion always comes up in IPv6 threads. Here are some resources https://www.f5.com/services/resources/white-papers/the-myth-of-network-address-translation-as-security https://www.f5.com/services/resources/white-papers/the-myth-... https://hn.algolia.com/?dateRange=all&page=0&prefix=false&query=nat%20is%20not%20security&sort=byPopularity&type=all https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
- imoverclocked 4y agoBeing able to talk directly between peers has advantages. Most services today basically require some kind of arbiter who has a public IP address. While there are ways to poke holes in NAT, it’s not really scalable. Also, you might be behind more than one level of NAT and not even realize it today. eg: When I ask a website for my IP, it shows something different than what my hotspot is assigned… and my hotspot is not reporting an RFC1918 address. This means I am already sharing ports with someone else on the public IPv4 address that the world sees. Also, no http proxy in the middle here. As for obscurity of addresses, NAT is pretty easily guessed in most scenarios today. IPv6 has far more address space per network making it really hard to scan. That combined with privacy addresses that change constantly is a pretty compelling reason to use IPv6 over IPv4+NAT if what you care about is people not being able to guess your IP.
- throwaway894345 4y ago> Being able to talk directly between peers has advantages. Most services today basically require some kind of arbiter who has a public IP address. Right, but you can't do this without punching holes in your firewall, and I assert that's not a desirable tradeoff, at least for consumer use cases. As far as I can tell, you still need an arbiter with a public IP address. > While there are ways to poke holes in NAT, it’s not really scalable. Agreed, but this is a relatively infrequent problem. It seems like there is some belief that IPv6 is going to make p2p stuff painless, but for most use case it's still going to require poking holes in something; however, for a few use cases (e.g., 2 game consoles in the same network) it will be significantly better. I definitely agree that there's some benefit to foregoing NAT, but it doesn't seem like it will improve most use cases and it certainly doesn't seem like it will deliver the painless p2p experience that many people expect. > As for obscurity of addresses, NAT is pretty easily guessed in most scenarios today. IPv6 has far more address space per network making it really hard to scan. That combined with privacy addresses that change constantly is a pretty compelling reason to use IPv6 over IPv4+NAT if what you care about is people not being able to guess your IP. My concern about obscuring addresses was more about making fingerprinting more difficult (some website can't just see my IP address and associate it with my identity), albeit this isn't a well-founded concern, and it could be mitigated by rotating IP addresses.
- nybble41 4y ago> I certainly don't want ingress from the public Internet to devices on my home network in the general case This is a job for a firewall. NAT is not a firewall. You can easily filter incoming connections to untrusted devices when using IPv6, with the advantage that when you want to allow a certain kind of traffic in you can do so without messing around with port forwarding or dealing with multiple devices competing for access to standard port numbers on a single public IP address. That's assuming you actually get a public IP address; if you're behind CGNAT then port forwarding isn't even an option, since it would need to be configured on the ISP's side and not just in your router. If you enable UPnP for automatic port forwarding, as most do, then NAT isn't blocking much of anything. The only difference between NAT with UPnP and IPv6 with no filter preventing incoming connections is in whether devices which open ports but don't set up forwarding can assume that incoming connections probably came from the same local network. However, it's considered poor practice to treat access to the local network as a means of authentication. (Note that with NAT alone if your router receives a packet addressed to your local network's private IP range, and not the routers public IP address, it will forward it unmodified; preventing that is a firewall function, not a NAT function.) > and I think it's kind of nice that the Internet only knows the address of my router rather than that of my physical machine If you use IPv6 with privacy extensions enabled then the Internet will only know your /64 network prefix, which is basically the same thing (unique per subscriber and subnet). The rest of the address will be randomly generated and short-lived, unless you choose to assign an additional long-lived address e.g. for a server. > I'm not sure whether I care if that gateway is doing NAT as well or not? What can I do with a non-NAT-ing gateway? Doing NAT isn't the problem, requiring NAT is. When the architecture requires NAT devices can't receive incoming connections without port forwarding even when you want them to. We've gotten rather good at working around NAT's limitations (not without cost), but with IPv6 those workarounds are unnecessary. For example, any peer-to-peer multiplayer game, video chat, or file transfer app where both sides are behind NAT depends on third-party servers for NAT traversal. (Note that the fact that this works at all without actually forwarding all data through the third-party servers shows that NAT is not a reliable system for preventing incoming UDP connections: it can be tricked into thinking a connection is already established.) With IPv6 you don't need the third-party servers as the peers can connect to each other directly.
- 4y ago
- gorgoiler 4y agoYou get to use 16 bits of the address to chop up hierarchically for your site. You get a /48 and each of your networks gets a /64, with hosts picking random 128 bit addresses in each. The 16 bits in between the two subnets mean you have room to breathe for doing whatever you like. Maybe 64k VLANs, or maybe a hierarchy with semantic meaning. You don’t need an IPAM tool if the addresses have meaning. My favourite: you can route a /56 to a Docker host and have 256 separate bridged networks, all globally routeable. You never need anything like that, but the open space is refreshing. Like I said: room to breathe.
- clord 4y agoAlso in this line of thinking: hosts can be assigned an entire subnet, and applications can get individual /128s. This way, a single host can provide a bunch of independent services, which can be broken out into real machines as the system grows without renumbering.
- gorgoiler 4y agoI think the more important use case is tempaddrs. You don’t have to use the same address all the time, or even at the same time. You can just make up random addresses for each connection if you like, though in practice the rotation is much slower.
- Dylan16807 4y agoIs there a reason to give each host a subnet in that scenario? You don't need to do that just to let a host grab 50 IPs. Actually, if you want to avoid renumbering, don't you want to have that whole block of servers share a subnet?