11 ms·
IPv6 Deployment Status
- menotyou 3y agoCitation "IPv6 was designed to restore the end-to-end model of communications with all nodes on networks using globally unique addresses. But considering this, IPv6 may imply privacy concerns due to greater visibility on the Internet."
- AndyMcConachie 3y agoThe IETF has never gotten off its anti-NAT high horse.
- mikecoles 3y agoNAT is horrible.
- BrianGragg 3y agoLeaned on heavily to protect cheap IOT devices. Could you imagine the bot armies if every IOT device was NOT behind a NAT?
- Zen1th 3y agoNAT shouldn't be used as a replacement for a firewall. So the answer was always to set up a firewall.
- deleted 3y ago[deleted]
- Dalewyn 3y agoThe virtues of NAT lie more in their nature of being blanket blacklist firewalls by default. This can indeed be replaced with firewalls on each IPv6 client, but you have to concede that just putting a router between your computer and modem adds a ton of security for very little effort or know-how. But NAT in itself is a workaround for IPv4 limitations with significant problems, which has become permanent because there's nothing as permanent as temporary solutions.
- Symbiote 3y agoEvery IPv6 router for home or small business use is initially configured with a default-deny firewall. The same for every router supplied by an ISP. This is so basic that any argument against it needs some strong evidence. You can search "IPv6 pinhole" and find plenty of documentation from router manufacturers and ISPs on this.
- briffle 3y agoNAT is not a firewall. NAT is a 'hack' that some firewalls use. My university only used routable IP addresses, but due to the wonders of firewalls, you could not connect to the HP printers in the library over the internet. Even though it had a routable IP.
- throw0101b 3y ago> Could you imagine the bot armies if every IOT device was NOT behind a NAT? Why? Firewalls have been around since before 1994, when Cheswick and Bellovin literally published the book on firewalls: * https://en.wikipedia.org/wiki/Firewalls_and_Internet_Security https://en.wikipedia.org/wiki/Firewalls_and_Internet_Securit...
- jiggawatts 3y agoEverybody looks like they're riding on a high horse when you're lying in the gutter.
- throw0101b 3y ago> The IETF has never gotten off its anti-NAT high horse. You say this like it's a bad thing. Why should it be necessary to have to deal with all the extraneous infrastructure of STUN/TURN/ICE just for basic connectivity? * https://en.wikipedia.org/wiki/STUN https://en.wikipedia.org/wiki/STUN * https://en.wikipedia.org/wiki/Interactive_Connectivity_Establishment https://en.wikipedia.org/wiki/Interactive_Connectivity_Estab... You have your stateful firewall that does default-deny, only allowing in packets that are replies to internally-initiated sessions. If you need to do hole punching you have UPnP or PCP (which also allows for authentication of requests): * https://en.wikipedia.org/wiki/Internet_Gateway_Device_Protocol https://en.wikipedia.org/wiki/Internet_Gateway_Device_Protoc... * https://en.wikipedia.org/wiki/Port_Control_Protocol https://en.wikipedia.org/wiki/Port_Control_Protocol
- rmwaite 3y agoNAT is a terrible hack
- midasuni 3y agoYet many implementations don’t do it and still do nat, and stateful network firewalls pretty much mean it’s meaningless anyway.
- ajsnigrutin 3y agoThe only difference is, that you're not "protected" by nat, so packets going back to you, can go back to you (but this is solved by a simple firewall installed by default on pretty much any ipv6 enabled CPE). With ipv6 privacy extensions, your IP address changes every few minutes (withoin the same /64 network) so it's not a lot different (privacy wise) than today, wher that whole network would be hidden behind a single IPv4 address.
- aPoCoMiLogin 3y agoNAT doesn't protect anything, firewall does that
- Gigachad 3y agoEvery consumer router I have seen blocks all incoming connections on ipv6 by default in pretty much the same way nat does. The only difference being that the UI allows multiple devices to listen on the same port now.
- dale_glass 3y agoIPv6 is actually better for privacy. First, the IPv4 address space is tiny. Say, a PING packet is 84 bytes, so pinging the entire IPv4 address space will take you all of 336GB of traffic each way (not even accounting for the reserved parts). That can be done in the space of an hour in a decent connection. So things can and are being trivially found by brute force. If a vulnerability is found in something interesting you can bet that by tomorrow lots of nefarious people figured out who can be broken into. Second, IPv6 has the privacy extensions, which means that even if somebody knows your address today, this has a very limited lifetime to it. Privacy extensions regularly randomize your IP address. Under IPv6 even normal people can get more address space than can be reasonably scanned. This makes it harder to identify machines permanently, makes it harder to figure out how many machines there are and makes brute force scanning extremely impractical.
- ectospheno 3y agoThe privacy is real. Moved to only binding ssh to ipv6 addresses on the internet. Cleanest ssh logs you will ever see. Basically invisible.
- ramshanker 3y agoAll we need is ONE major website to declare 24 Hour brown-out for IPv4 and put a message something like "Contact your ISP to upgrade your connection". Alas, publicly traded companies....
- pantalaimon 3y agoGitHub not being available via IPv6 is the biggest hurdle because so much depends on it.
- josephcsible 3y agoThat's a hurdle to moving clients from dual-stack to IPv6-only, but it's not a hurdle to moving clients from IPv4-only to dual-stack, which a lot of ISPs still haven't done yet.
- nextweek2 3y agoI know the Azure Application Gateway is meant to be getting ipv6 support later this year, it is certainly the reason why my services are ipv4 currently. I’d expect GitHub to have moved to Azure since the buyout. The IPv6 adoption seems more tied to Azure/AWS/GCP support than anything else.
- briffle 3y agoI often thought if Netflix started doing Live sports on IPv6 multicast, that might finally change things with all the home internet connections..
- roody15 3y agoThink you will need more than that!! Rollout has stagnated for over 20 years.
- Gigachad 3y agoWhat? The google ipv6 tracking page shows linear growth. Iirc we are close to tipping over to 50% of users on ipv6. Especially with the development of Asia and Africa, ipv6 still looks like it will eventually be the default.
- eknkc 3y agoAt this point I'm personally convinced that ipv6 is a failed technology. It used to be interesting to see the news about new ipv6 deployments, adoption ratings etc. Now I basically don't care.
- pantalaimon 3y agoI've been using IPv6 at home and at work for years now - without noticing it much.
- neilalexander 3y agoYou're not supposed to care about it. IPv6 really has two motivating factors: the first is to simplify the IP stack, the second is to increase the scale of the address space. It's not supposed to be exciting, it's supposed to be a change we make because it obviously makes sense to do. I also don't think IPv6 is a "failed technology" at all. If you've used almost any zeroconf service on an Apple product recently (AirPlay, AirDrop, AirPrint, HomeKit, so on) then you've been almost certainly using link-local IPv6. If you've used Spotify Connect or Sonos, there's a very good chance that's been over link-local IPv6. If you have any Thread or Matter smart home appliances, they generally communicate using IPv6 too. Most devices connect to Chromecasts over link-local IPv6. You've quite likely been connected to IPv6-capable Wi-Fi networks before and you probably never noticed. IPv6 is actually pervasive in all sorts of places.
- jiggawatts 3y agoMost phone companies now provide IPv6 natively over their 4G/5G service, and IPv4 goes through carrier-grade NAT.
- hyperionplays 3y agoPretty sure all xbox services use v6 where possible as well.
- ectospheno 3y ago
- pantalaimon 3y agoDoes anyone know why German universities are so slow to deploy IPv6? Almost none has their website reachable over IPv6 or IPv6 on their internal network.
- ori_prior 3y agoDepends on the technical expertise of the staff, I guess. My alma mater (FAU Erlangen, https://fau.de https://fau.de ) did have some internal and external IPv6 already back when addresses were still 6bone 3ffe::, 20 years ago. Don't know since when the main website has been IPv6-reachable, but it has definitely been over 10 years.
- Isolus 3y agoMost German universtities have applied at an early stage for a class B network block therefore they have little pressure. When I asked the IT staff at my university years ago, they said that there are still some very old routers without IPv6 support in use. And since everything seems to work with IPv4 for the university administration, there is no money for new ones.
- hyperionplays 3y agoIf only the android devs would implement dhcpv6 ffs.
- josephcsible 3y agoWhy do you need that? What's wrong with SLAAC and RDNSS?
- throw0101b 3y ago> Why do you need that? What's wrong with SLAAC and RDNSS? It's handy in many situation where you want to assign specific devices specific addresses, or at least make a log of dynamically chosen addresses (e.g., networks with auditing requirements).
- magicalhippo 3y agoI got a local NTP server and I want to assign it to my network clients. AFAIK the only way is via DHCPv6.
- Avamander 3y agoMost clients ignore that anyways. Like literally only a few Linux distributions add local DHCP ones to their server list. In 99.99% of the cases you have to intercept or reconfigure.
- josephcsible 3y agoToo bad that this never seems to have gone anywhere: https://datatracker.ietf.org/doc/html/draft-bcd-6man-ntp-server-ra-opt-00 https://datatracker.ietf.org/doc/html/draft-bcd-6man-ntp-ser... Also, does Android even use NTP servers that are advertised over IPv4 DHCP? I don't think so, and if not, then is this really a reason?
- pantalaimon 3y agoMost home routers don't even implement it, which is a shame since Prefix Delegation really has a use case in the home network.
- AndrewDucker 3y agoFrom the article, in millions of users: Jan 2018 - 513.07 Jan 2019 - 574.02 Jan 2020 - 989.25 Jan 2021 - 1,136 Jan 2022 - 1,207 A growth rate of 24% Looking at Google's IPv6 stats: July 2019 - 29% July 2020 - 33% July 2021 - 36% July 2022 - 42% July 2023 - 44% Or an increase of about 3% each year.
- throw0101b 3y ago> July 2023 - 44% What's the worldwide average. For the US specifically it's the majority of traffic at 53%: * https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html
- LinuxBender 3y agoIs there a breakdown by network type? e.g. Cellular Network, VPS Provider, Home ISP, IoT, etc... The reason I ask is that last numbers I saw somewhere were thrown off by VPS providers and cellular providers. Cellular had no choice but to go IPv6 due to sheer numbers of users. VPS was easy due to the ephemeral nature of VM's. People could slowly adopt it at their own rate.
- throw0101b 3y ago> The reason I ask is that last numbers I saw somewhere were thrown off by VPS providers and cellular providers. How are these situations "throwing off" the numbers? There seems to an underlying assumption in this statement that if you (e.g.) stream a Youtube video from your cell phone (over IPv6) it is "invalid" (less valid) but if you stream it on your desk/laptop from your (IPv4-only) home or work's ISP it is (more) "valid". > Cellular had no choice but to go IPv6 due to sheer numbers of users. Of course they have a choice: they could spent millions of dollars getting IPv4 address for their customers, or they give IPv4 shared space [1] to all the devices and spend millions on CG-NAT equipment. No IPv6 needed. Every IPv6 connection is just as valid as every IPv4 connection. [1] https://en.wikipedia.org/wiki/IPv4_shared_address_space https://en.wikipedia.org/wiki/IPv4_shared_address_space
- SirMaster 3y agoWhat happens to all old software that is more or less "hard-coded" to use IPv4 addresses? Will there be an OS layer that can run an app in IPv4 compatibility mode of some sort?
- tambre 3y ago464XLAT should be the solution for this [0][1]. Requires network and OS support. [0]: https://datatracker.ietf.org/doc/html/rfc6877 https://datatracker.ietf.org/doc/html/rfc6877 [1]: https://en.wikipedia.org/wiki/IPv6_transition_mechanism#464XLAT https://en.wikipedia.org/wiki/IPv6_transition_mechanism#464X...
- Gigachad 3y agoOld software shouldn’t be connected to the internet.
- BrandoElFollito 3y agoWhen changing my ISP I suddenly jumped in the world of IPv6 without any warning. Oh boy. I've been working in IT for 30 years, managed plenty of servers, host services at home, develop FOSS and whatnot but never got interested in IPv6. And I must say that this is a scary world. Some of my devices suddenly were getting their DNS settings from something else than the DHCP, I had to learn quickly about RA and other anagrams. I was super worried about the exposition of my services - something I completely controlled in IPv4. With this in mind, I think that IPv6 is too complicated. It does not have that sweet spot between "plug the green cable to the socket called ETH" and "I am going to try to squeeze some extra bits into the datagram".