5 ms·
Networking software and routers without ipv6 should be considered a security issue at this point and should have CVEs assigned against them. It's amazing how we
by xacky 2y ago
Networking software and routers without ipv6 should be considered a security issue at this point and should have CVEs assigned against them. It's amazing how we deprecated unencrypted http across the internet but still use the equivalent for ip addresses.
- john01dav 2y agoIpv4 is deeply flawed and needs to be replaced, but how is it insecure? CVEs are specifically for security issues.
- lagniappe 2y agoThis is NOT how the CVE system is used.
- DaSHacka 2y ago> It's amazing how we deprecated unencrypted http across the internet but still use the equivalent for ip addresses. This makes no sense, http is flawed because its unencrypted and allows MITMing information. IPv4 is flawed merely because it doesn't have enough addresses. How are these two comparable? Your proposed "solution" is overkill and is completely ridiculous.
- itchyouch 2y agoIt’s not a logical argument, but if we only take the part about the transition to https, the difference was that https and http coexisted with mostly full compatibility to go between the 2 for its whole life. And it lives at layer 4. A more cogent argument is that IPv4 and IPv6 have not fully coexisted like http/https, where you can pull the ipv4 rug out and every packet has an ipv6 path like http to https did. Also more profoundly, https conversion had the benefit of every operator being able to transition on their own time frame. And people can still opt to use http if they so choose. IP not having that luxury is a profound problem.
- simoncion 2y ago> ...https conversion had the benefit of every operator being able to transition on their own time frame. ... IP not having that luxury is a profound problem. This I don't get. I expect that Google will be far more likely to make it extremely difficult (or perhaps impossible) to use Chrome to visit non-TLS-wrapped HTTP sites on the Internet in the next five years than the operators of the various networks that make up the Internet are to just shut off IPv4 on their network. I expect IPv4 will not be shut off within the lifetime of anyone posting on this forum today... and why would it be? Once just about everyone has well-functioning IPv6 access, release a recommendation to ISPs that unless a customer has an even vaguely-reasonable need for a globally-routable IPv4 address, that ISPs substantially reduce their IPv4 usage by providing IPv4 service to their customers through some CGNAT. This would ensure that the few remaining hosts with IPv4-only service will remain reachable, that any customers who can bother to write a letter to their ISP asking for a globally-routable IPv4 address can get one, and a ton of IPv4 space gets opened up for whatever we might need to do with it in the future... just in case.
- fullspectrumdev 2y agoAh yes, more abuse of the CVE system. Real Linux foundation vibes off this.
- tsimionescu 2y agoIPv4 is exactly as secure as IPv6.
- xacky 2y agoSo surprised that hacker news is stuck in ipv4 land. Even if you disagree with the method, I do not consider a device not capable of IPv6 to be using the real internet anymore. It's the same with the housing market where people would rather speculate on IPV4 houses instead of building plentiful IPv6 apartments.