5 ms·
The thing about IPv6 is it has significant switching costs but almost no benefit to end users. The exception, I guess, is network providers who are struggling w
by kelp 4y ago
The thing about IPv6 is it has significant switching costs but almost no benefit to end users. The exception, I guess, is network providers who are struggling with a shortage of v4 addresses.
We've been trying to get people to switch since the late 90s/early 00s. And it's only now making progress because IPv4 address have an actual cost which keeps increasing.
But I think IPv6 is huge example of second system syndrome. Instead of just solving the obvious and most important problem of IP address exhaustion, we piled on a whole bunch of other requirements, greatly expanding the scope, increasing switching cost, and dragging out the migration for literal decades. Here we are 20+ years later with only 40% adoption of IPv6...
And I can see the temptation to bundle in all those other changes, since this might be the big opportunity to get them out there. But seems like we could have come up with a simpler and easier to switch to alternative that would have solved the acute issue much faster.
Instead we're here muddling through.
- candiddevmike 4y agoIf memory serves me right, one of the biggest selling points for IPv6 to end users (at the time) was it's "built in" support for IPsec (ESP and AH are standard extensions in the protocol). These days I'm not sure how beneficial something like this would be, Wireguard outperforms it AFAIK.
- wmf 4y agoThat whole thing was kind of a lie since you can't force hosts to implement IPSec and IPSec was immediately backported to IPv4 anyway.
- londons_explore 4y agoAs soon as adoption starts hitting 80%, lazy sysadmins won't bother setting up ipv4 support, and suddenly the ipv4 internet will get less useful, and things will snowball to IPv6 (in public at least - I'm sure internal company LAN's will remain IPv4 behind a proxy for decades more). To get from 40%to 80% just requires a few ISP's to make it the default on their routers, which they have an incentive to do as soon as they run out of IP's and CGNAT starts to get expensive to run. Enabling IPv6 immediately halves the load on the CGNAT boxes because all the CDN traffic immediately uses IPv6.
- fomine3 4y ago> To get from 40%to 80% just requires a few ISP's to make it the default on their routers What you mean? I think what's needed is IPv6 support by ISP and make Happy Eyeballs on client to strongly prefer IPv6, not router.
- DocTomoe 4y ago> I'm sure internal company LAN's will remain IPv4 behind a proxy for decades more IPv4 will continue to exist in limited capacity as long as network hardware supports it. With increasingly more network hardware suppliers phasing out IPv4 support for cost reasons, we will see it dying quickly.
- yyyk 4y agoInternal company LANs will never switch, both for cost reasons and because IPv6's addressing choices are badly suited for it. Maybe one day companies will abolish the internal LAN and move to zero-trust, but until they do IPv4 will stay. That's a big enough market to be supported indefinitely.
- naikrovek 4y ago> significant switching costs but you don't have to switch, you can have both at once.
- wmf 4y agoWhich costs even more.
- naikrovek 4y agonot really. turning off ipv4 on a given network would cost approximately nothing. having ipv4 while you bring up ipv6 lets you learn as you go and adapt as you learn, and is of value. there doesn’t even need to be a cutover, they coexist. its not even like there is a significant hardware cost; all network gear for the past 15+ years has supported ipv6; you get it for free when you buy hardware that works with ipv4.
- thayne 4y agoI kind of wonder if it would be worth making an ipv7 that is less ambitious than ipv6, and focuses on having an easier upgrade path from ipv4. But then we would have three competing standards...
- zaik 4y agoShould be called ipv5.
- thayne 4y agoIpv5 is already taken.
- iseanstevens 4y agoCauses all kinds of issues with people’s consciousness becoming digital. Source: Serial Experiments Lain
- exabrial 4y agoI’ve advocated for this as well and find it a surprisingly unpopular opinion on HN.
- yyyk 4y agoIt's far too late for that. We'll be stuck with dual-stack for a long time.
- thayne 4y agoYeah, it might have been a good idea 15 years ago or so, when adoption was low and it was apparent that the switch wasn't happening fast enough, but now ipv6 is used enough that introducing yet another version of ip will just make things worse.
- p1mrx 4y agoI think you're confusing "unpopular" with "technically impossible".
- tenebrisalietum 4y agoIP address exhaustion isn't the only issue - subnetting was never meant to be as complex as it is. End users shouldn't care about addresses. Optimally you shouldn't be specifying raw Ip addresses anywhere. It's why we have DNS and discovery protocols. IPv6 helps this. It drastically simplifies subnetting and eliminates the need for NAT.
- jiggawatts 4y agoQueue the million network admins complaining about how IPv6 addresses are hard to memorise. Meanwhile mucking about with IP addresses manually is an IPv4 problem that the automation of IPv6 largely eliminated. “Show me how your new system solves problems only the old system has, or I won’t adopt it!”
- tempnow987 4y agoIPv6 does neither in most cases unfortunately. IPv6 could blow routing tables sky high. We burn 64 bits of the space (!!) on the "privacy extensions" changing part of ipv6 which is totally insane, and so you have a constant churn for 64 bits of the space. This churn complicates a fair bit of local area network address use. You can get a static IPv4 block if you need it with business class service as well for that site. Despite claims it's a total pain to get IPv6 static blocks assigned by ISPS. Your internal network can be subnetted however you like if you do any site to site VPN if using NAT. you are not dependent on uplinks at all. Now if you have a business with a bunch of sites, not all may have full BGP etc setups. For example, you might do a dual WAN link - one fiber at 1gbps, another at 300mbps for backup. This is seamless with IPv4 in most cases. With IPv6 - if your routes flap, you have to readdress everything on your entire network (!!!) for that site. And these updates are SLOWER and worse from what I've seen then WAN failover on the NAT. So then you can try to do the workarounds (network prefix stuff). So if you flap around a bit the network is done. This could just be a tech reconfiguring things and pulling a cable and putting it back in seconds later. And the list goes on. Network prefix stuff is poorly supported. You are basically forced into dual stack mode. Etc.
- shmerl 4y ago> The thing about IPv6 is it has significant switching costs but almost no benefit to end users. Real scenario - developer of Valheim initially released the game on Itch.io but then removed it from there, saying that it now has to rely on Steam services for NAT traversal for its multiplayer, making it tied to Steam in result. Clearly if IPv6 would have been available there wouldn't have been the need for such services, no? So I'd say end users are bitten by this, just not in obvious ways for them to start complaining about it.
- wmf 4y agoInstead of NAT traversal IPv6 is going to require firewall traversal.
- dx034 4y agoAbsolutely. I'll say it again and again, I like NATs, especially for home setups. They help hiding devices from the public that never need to be accessible outside of a LAN. And you can never trust home router firewalls to be configured correctly. If all devices had their unique IP address, we'd see much larger botnets out there.
- shmerl 4y agoYou don't need any traversal services for that though. You can set up port forwarding as needed on you router if something requires special access. Problems start with NATs that you can't control.
- tenebrisalietum 4y agoIf your router's firewall is set to not allow incoming traffic to an IP behind it, then the IP isn't going to be accessible, and it doesn't matter who knows the IP. This is much simpler than NAT. Your device also isn't hidden too much if a NAT router lets it have the ability to make outgoing connections - it's just less convenient to access. You might see more attacks targeting specific internal IPs if NAT never existed more but it doesn't necessarily follow that NAT is preventing or reducing botnets. Dos/DDoS attacks can be focused a your router with or without NAT.