9 ms·
CGNAT frustrates all IP address-based technologies (2019)
- superkuh 2y agoCGNAT providers are not ISPs. They're web service providers, WSP.
- bolognafairy 2y agoIn true Hacker News nerd style, an utterly meaningless, inconsequential, made-up squabbling over terminology.
- Sohcahtoa82 2y agoNot to mention incorrect.
- superkuh 2y agoIndeed classic: talking about the form of my comment instead of the content it addresses: that many ISP are incomplete because of CGNAT and do not provide real internet access (ie, being able to receive connections to tcp ports). These incomplete ISP without ability to participate in the internet should not be called ISP because of this lack. Your objection to the term itself is inconsequential. Do you deny the original posts claims? Is this just insult time? As for incorrect? How so? Perhaps "web service providers" is a bit glib and incomplete too, but it gets to the core of the issue here: ISP not providing internet service and only providing a limited subset. if the 'web' works that's all that really matters for advertising and getting people to pay them. Meanwhile most people aren't even aware of what they're missing and their inability to participate in the internet; but they, and especially their kids', educations are stunted by the lack of being able to participate, etc. And all of society is worse for it.
- arcza 2y ago"CGNAT providers" is like saying "DHCP providers" or "PPPoE providers". I've never heard of a "WSP". What if I send an email on port 25 (not web) via my "WSP"? LOL.
- slt2021 2y agoThe article tries to label something objectively good as something bad: >>One practical outcome is that government agencies find it harder to identify criminals behind particular IPv4 addresses. lol, lmao even. >>As a result, the agency says, investigations often involve examining and tapping the connections of many more people than really necessary. just incompetence abound, the police should suffer if they don't know how to do their job more effectively
- mike_hock 2y agoOne practical outcome is that IPv4 provides the privacy IPv6 was designed to sabotage. I'll be boycotting IPv6 for as long as it's possible.
- gruez 2y agoExactly. Even if you enable "privacy addresses", you'll be disappointed to find that they only rotate every 24 hours by default, so all your incognito tab browsing can be trivially linked back to you, if they're done in the same day as your regular browsing.
- orangeboats 2y agoYou already said the word "default". One can simply adjust the rotation time to 600 seconds or even shorter. The control is in _your_ hands. Unlike CGNAT, where the NAT owner is the one making decisions.
- gruez 2y ago>You already said the word "default". One can simply adjust the rotation time to 600 seconds or even shorter. 1. setting it to short intervals eventually causes issues, because it fills up your router's routing tables and eventually causes it to crash. 2. Having a short rotation period doesn't help because people typically don't time their incognito tab usages to when the privacy IP rotates. Moreover if you have any apps/tabs in the background that are logged in (eg. gmail), it can track your new privacy addresses as they're being rotated. The only way to fix this is to somehow integrate privacy addresses into the browser itself (ie. having separate privacy addresses for regular/incognito browsing), but that doesn't seem like it's going to happen any time soon. >The control is in _your_ hands. Unlike CGNAT, where the NAT owner is the one making decisions. You're trying to imply this is a bad thing but it's unclear how the CGNAT owner can sabotage anonymity in this case. You're mixing your browsing with tens or hundreds of other customers. That provides strictly better anonymity compared to privacy addresses that rotate but are shared by every app/tab on a given system.
- easterncalculus 2y agoGoogle IPv6 traffic hit an all-time high this week: https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html
- cyberax 2y agoAnd still below 50%. My personal benchmark: hotels. I have not seen a _single_ hotel that provides IPv6 on their WiFi. And I made a habit of checking this every time I check in. And I've seen a hotel that was giving out public IPv4 addresses (in Mountain View, CA).
- throw0101d 2y ago> And still below 50%. Depends on the country. US>50%; FR>80%: * https://www.google.com/intl/en/ipv6/statistics.html#tab=per-country-ipv6-adoption https://www.google.com/intl/en/ipv6/statistics.html#tab=per-...
- easterncalculus 2y agoTrending up at about 2-5% every year, so about to cross the threshold within the next few years. We're in the middle of the S curve.
- IcePic 2y agoGot IPv6 over wifi in a hotel in Costa Rica, really nice.
- teslabox 2y ago> I have not seen a _single_ hotel that provides IPv6 on their WiFi. Currently staying at a Hilton hotel in Tucson, Arizona that has IPv6. I only checked because of the submission about ipv6.me yesterday [0]. [0] https://news.ycombinator.com/item?id=43256298 https://news.ycombinator.com/item?id=43256298 I'm not there at the moment, but I definitely took note of having an ipv6 address displayed on https://ip6.me/home.cgi https://ip6.me/home.cgi
- 2y ago
- throw0101d 2y ago(CG)NAT can been a real cost to ISPs, especially smaller ones: > Our [American Indian] tribal network started out IPv6, but soon learned we had to somehow support IPv4 only traffic. It took almost 11 months in order to get a small amount of IPv4 addresses allocated for this use. In fact there were only enough addresses to cover maybe 1% of population. So we were forced to create a very expensive proxy/translation server in order to support this traffic. > We learned a very expensive lesson. 71% of the IPv4 traffic we were supporting was from ROKU devices. 9% coming from DishNetwork & DirectTV satellite tuners, 11% from HomeSecurity cameras and systems, and remaining 9% we replaced extremely outdated Point of Sale(POS) equipment. So we cut ROKU some slack three years ago by spending a little over $300k just to support their devices. * https://community.roku.com/t5/Features-settings-updates/It-s-2022-and-still-no-IPv6/m-p/854673/highlight/true#M35732 https://community.roku.com/t5/Features-settings-updates/It-s... * Discussion: https://news.ycombinator.com/item?id=35047624 https://news.ycombinator.com/item?id=35047624
- gunian 2y agokind of a linguistic tangent do we say american european or american british or is that taboo?
- somanyphotons 2y agocolonial american?
- throw0101d 2y ago"American Indian" is fairly standard nomenclature: * https://en.wikipedia.org/wiki/Native_Americans_in_the_United_States https://en.wikipedia.org/wiki/Native_Americans_in_the_United...
- 6SixTy 2y agoEuro American most likely would be the correct terminology, sort of whatever rolls off the tongue better. A lot of non-Hispanic white Americans are actually not British, but are instead a broad mix of European countries that varies depending on geography (e.g. Louisiana is very French). Even nailing it down to XYZ country in Europe is a bit of a stretch, as the European genepool isn't the most diverse thing in the world.
- apitman 2y agoRequiring web services and ISPs to retain detailed logs in perpetuity until IPv6 is universal would be one way to expedite the transition. But personally I don't think IPv6 is ever going to happen. There's simply too little monetary incentive for supporting it. For outbound connections NAT/CGNAT works fine. For inbound connections you can use SNI routing with a tunnel[0]. [0]: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling
- easterncalculus 2y ago> But personally I don't think IPv6 is ever going to happen. If you own a mobile phone you use it every day. IPv6 has already happened. > There's simply too little monetary incentive for supporting it. IPv6 allocations are orders of magnitude cheaper and wider than v4 allocations, which are already exhausted. > For outbound connections NAT/CGNAT works fine. For inbound connections you can use SNI routing with a tunnel[0]. All of these add latency, IPv6 reduces latency (particularly the more widely it is deployed).
- Nextgrid 2y ago> IPv6 allocations are orders of magnitude cheaper and wider than v4 allocations, which are already exhausted. Which is of no consequence to the incumbents who have enough existing stock to last them forever (with tricks like CGNAT/etc). The cost of IPv4s mostly impacts smaller players and/or new entrants, which works in favor of the incumbent ISPs.
- simoncion 2y ago> Which is of no consequence to the incumbents who have enough existing stock to last them forever (with tricks like CGNAT/etc). And yet, Comcast was one of the first nationwide ISPs to enable residential IPv6 service. Comcast is a Very Large ISP. They also happen to have switched ages ago to an all-IPv6 internal network because they ran out of non-routable IPv4 addresses many times over. I suspect (but do not know) that Comcast's experience with how much easier switching over made operations for them to have been a significant factor in providing IPv6 service to residential (and eventually business) users.
- LeoPanthera 2y agoTailscale's "How NAT traversal works" blog is a fascinating read: https://tailscale.com/blog/how-nat-traversal-works https://tailscale.com/blog/how-nat-traversal-works
- nfriedly 2y agoMy ISP, Metronet, is mostly CGNAT. That broke some things for me, so I called in and they gave me a "free" static IP to fix it. Except, once per year they start charging me for it and I have to call back, and then they make it free again.
- LinAGKar 2y agoWait, with OpenDNS you can change settings for everyone on an IP address just by connecting from the that same IP address? That seems horribly insecure.