12 ms·
Internet Protocol Version 8 (IPv8)
- wg0 6mo agoSeems to be very censorship friendly protocol from grounds up.
- sourcegrift 6mo agowhy cant they do an ipv5 with 64 bits of address soace for us humans?
- SwellJoe 6mo agoSounds like this is exactly that. Too bad they didn't do that first, and we've had a couple decades of failing to widely adopt IPv6 because it's too complicated and confusing. "1.7. Backward Compatibility and Transition IPv4 is a proper subset of IPv8: IPv8 address with r.r.r.r = 0.0.0.0 = IPv4 address Processed by standard IPv4 rules No modification to IPv4 device required No modification to IPv4 application required No modification to IPv4 internal network required IPv8 does not require dual-stack operation. There is no flag day. 8to4 tunnelling enables IPv8 islands separated by IPv4- only transit networks to communicate immediately. CF naturally incentivises IPv4 transit ASNs to upgrade by measuring higher latency on 8to4 paths -- an automatic economic signal without any mandate."
- sourcegrift 6mo agoHow can we adopt this 30 years back!?
- SkiFire13 6mo agoIPv6 doesn't require modifications to IPv4 devices, applications, networks etc etc either. You just cannot reach IPv6 networks and devices from them, and the same applies to IPv8. 8to4 is nothing innovative because 6to4 already exists. In the end this proposal has all the disadvantages of IPv6 with less advantages.
- jamieone 5mo agoSkyFire, This is not true, and you obviously have not read the specification. In IPv8 when a station ARPs it ARPs using ARP8 and if there is no response 50ms later it ARP4. If that station replies than IPv8 sends IPv4 packets to that station for the remainder of the ARP time out session. Except for the r.r.r.r section of the header the rest of the payload IS ipv4. So to encapsulate between an IPv4 network and an IPv8 network all there is from 4 to 8 add 0.0.0.0 as the source, and asn as the destination. From 8 to 4 remove the 0.0.0.0 as the ASN destination and forward the IPv4 packets. When you need to traverse from 8 to 4 (or several 4s) to an 8 each ASN has an IPv4 anycast address that is on every IPv8 router and the packets are sent to that address, allowing them to find their way through the internet without tunnels. It is the absolute compatibility of the payload of IPv4 and IPv8 that makes this easy and teniable.
- Hikikomori 6mo agoBecause extending ipv4 has all the same problems as ipv6.
- stingraycharles 6mo agoDid you read the proposal? It proposes 64 bit address space.
- repelsteeltje 6mo ago* Censorship friendly, and * Surveillance friendly. What more do you want?!
- red-iron-pine 6mo agomind control
- suriboy 6mo ago[dead]
- 19skitsch 6mo agoInteresting… Feels like a beautifully designed network for a world where operators trust each other more than they actually do
- absynth 6mo agoIt probably has age verification on every packet.
- kube-system 6mo agoYeah but they failed to adjust for age drift that may occur during the round trip latency of the packet. Unfortunately at intergalactic scale this error can be significant
- Hamuko 6mo agoCan I skip age verification by using UDP?
- ButlerianJihad 6mo agoIf your packet fails age verification at the router level, it will light up the EVIL bit, and then you're in a world of hurt, man!
- deleted 6mo ago[deleted]
- rocqua 6mo agoI hate to be this dismissive, but it feels like an academic with a paternalistic streak looked deeply at how the Internet works, saw lots of different protocols and weird design decisions, and decided: this is not coherent enough. Then he figured, I'll make all the decisions now, that way it'll be coherent. And let's give every subnet a centralised source of trust and management. That'll make the design so much cleaner! By which I mean to insinuate there's a lot of nuance and learned lessons in the current situation that this design seems not to learn from. Even though it did learn some lessons, I don't think this passes 'Chestertons fence'
- red-iron-pine 6mo agonah. this is palantir operating through a bermuda holding company trying to shoe-horn oauth into every single packet to force every single click ever to be authenticated against a persona. the goal is 1984.
- tptacek 6mo agoObvious reminder that anybody can publish an Internet-Draft.
- otterley 6mo agoAlso, who is the author? He seems to have appeared from nowhere, like Satoshi Nakamoto. Maybe it’s just Claude posing as a network engineer.
- wmf 6mo agoI think you would have to be an outsider to come up with this proposal because it challenges many sacred cows of the IETF establishment. It has no chance of being taken seriously and I personally disagree with a bunch of the decisions but it's entertaining to ponder what kind of mindset would produce this.
- Ekaros 6mo agoInsider would understand that there is non-existing chance of any new IP protocol being even considered or taking off. And thus any effort spend on it would be complete waste. Best you can do is work on some addition or backwards compatible new functionality.
- albinn 6mo agoOne of the main (vocal) issues people seem to have with IPv6 is that the addresses are hard to remember. But having eight different three digit numbers (r.r.r.r.n.n.n.n) does not seem any easier unfortunately.
- sschueller 6mo agoI though the whole concept in IPv6 of remembering addresses is that you don't. That is IPv4 thinking...
- PhilipRoman 6mo agoI see this point a lot but it never really made sense to me. What exactly does IPv6 bring to the table that makes it unnecessary to remember IP addresses? Especially for anything more advanced than just looking up a hostname.
- jeroenhd 6mo agoIPv6 addresses can be plenty memorable. Mine starts with 2a10:3781:xxxx, and the rest of the address is whatever I want it to be. About as recognizable as my IPv4 address. If I wanted to memorize the addresses for some reason (maybe I broke DNS or something?), I'd just start numbering devices at 1 and keep going up.
- gck1 6mo ago> maybe I broke DNS or something I break my DNS very often, or at least, often enough that it'd become nuisance that I can't instantly recall IP address of every machine in any of my 5 VLANs, AND type it in manually within 3 seconds. With IPv6, I'd have to drop whatever I'm doing and fix my DNS first.
- jeroenhd 6mo agoIf you use SLAAC and don't use mDNS, I suppose, maybe? But if you break DNS often enough that you need to remember IP addresses, you can just do DHCPv6 if you want IPv4-like address allocation. It'll be even easier because you can use numbers greater than 254 for your local devices, or l33t-style hex addresses, without setting up routed subnets when you exceed your /24 like on IPv4.
- chromacity 6mo agoI guess I was right to wait out IPv6... But more seriously, it gives me a pause when we try to bake more complex, application-centric logic into foundational protocols. The list of assigned IPv4 and TCP option numbers is a graveyard of tech experiments, but at least we had the sense to separate them from the main protocol. Baking JSON web tokens and OAuth into IP seems kinda crazy from that point of view. Is this what we want to commit to for the next 40 years? I kinda wish that IPv6 just used this ("IPv8") addressing scheme and left everything else the same, though. I think the expectation that IPv6 should entail an architectural rethink for existing networks really slowed us down. Fun fact: at this point, IPv6 is 30 years old, we're still under 50%, and growth is visibly tapering off.
- FpUser 6mo agoHow do we secure internet to the point it does not work anymore. Well except government and big corporate sites
- _ache_ 6mo ago> IPv8 does not require dual-stack operation. The whole thing isn't a joke because of this. Technically, it's IPv4++ and that about it. > Every manageable element in an IPv8 network is authorised via OAuth2 JWT tokens What ?! I'm not sure it's the path I want to follow.
- jojobas 6mo agoDouble checked the publication date, it's not April 1st.
- Induane 6mo agoI thought it was a joke but someone is serious. This is one of the worst things I have ever heard of proposal wise. The worst. I can't even. Literally.
- linohh 6mo agoProbably someone had an adderal fueled night with an LLM, that's just completely mad.
- timokoesters 6mo agoThis document is an Internet-Draft (I-D). Anyone may submit an I-D to the IETF. This I-D is not endorsed by the IETF and has no formal standing in the IETF standards process. https://datatracker.ietf.org/doc/draft-thain-ipv8/ https://datatracker.ietf.org/doc/draft-thain-ipv8/
- stingraycharles 6mo agoYes, and assuming it will not become popular, this will expire / not renew in 6 months. It’s also worth noting that the author is affiliated with a company based in Bermuda. So it doesn’t feel like it comes from a legitimate institute. For all i know this was vibe-written by an AI in an afternoon.
- sleepychu 6mo agoI must be missing something, why aren't their legitimate institutes based in Bermuda?
- deleted 6mo ago[deleted]
- kennywinker 6mo agoI believe Bermuda is a tax shelter country, which means people and companies register there to hide identity and income from the nations they live and do business in. Because of that, the vast majority of businesses registered in bermuda are not legitimate institutions - they are shell companies defrauding their home nations.
- OutOfHere 6mo agoAnd the home nation's governments defraud their people with unnecessary wars, wasteful spending, unpayable debt, and excessive inflation. There comes a time when paying less tax is the right thing to do.
- speedping 6mo agoI'm working on my IPv9 proposal as we speak. It has an LLM validating the contents of every packet. Gotta stay ahead of the curve.
- QuercusMax 6mo agoI've got a spec for ipv11. Why? Because it's one more than 10.
- lamasery 6mo agoCan’t you just make ten… one larger?
- aragilar 6mo agoThey're referencing https://en.wikipedia.org/wiki/Up_to_eleven https://en.wikipedia.org/wiki/Up_to_eleven (and you're one of today's lucky 10000: https://xkcd.com/1053/ https://xkcd.com/1053/).
- MattPalmer1086 6mo agoI think they are also riffing off the spinal tap scene, where he says "can't you just make 10 louder?".
- cassianoleal 6mo agoI think that's what your comment parent is referencing as well
- deleted 6mo ago[deleted]
- MattPalmer1086 6mo agoLooked like they missed that their parent post was already doing that. As another poster points out: wooosh!
- pmontra 6mo ago> East-west security -- traffic between devices within a network -- is enforced by ACL8 zone isolation. Devices communicate only with their designated service gateway. The service gateway communicates only with the designated cloud service. Lateral movement between devices or zones is architecturally prevented by the absence of any permitted route to any other destination. I must be missing something or misinterpreting that section because if there is no "lateral movement" how do people in an office print a file, access a network drive, connect to the Exchange server? And those are only the most naive scenarios.
- dijit 6mo agoBy using a cloud provider, obviously. Local networks are too dangerous to be trusted. If its not going through Azure you shouldn’t be allowed to connect to your peer devices. (/s. if that is needed).
- red-iron-pine 6mo agodon't give MS and GOOG ideas
- ptx 6mo agoPresumably they pay cloud vendors for cloud printing, cloud storage and cloud groupware, so to send something on the local network they simply send it to the cloud vendor and then download it again. That's what people in our office do. Very helpful for the cloud vendor's profitability.
- jamieone 6mo agoThat's a good question and the core over-states it. The east-west means that natively clients don't arp and icmp from each other they do it from ACL8 on the GW. Your printer registers, you mark it anonymous, anyone can get to it, and when you arp for it, it answers. But when you have 2,000 clients on a vlan and you want 1999 of them to only reach the internet and not each other, you make one rule at the ACL server. It means everything goes to the ACL8 server for a decision even on the local network.
- magicalhippo 6mo agoIPv8 does not require dual-stack operation. There is no flag day. 8to4 tunnelling enables IPv8 islands separated by IPv4- only transit networks to communicate immediately. How is this different from IPv6? We've had 6to4 for ages, the problem is the other direction: how does a IPv4 host initiate a connection to a IPv8 host? Existing IPv4 applications use the standard BSD socket API with AF_INET and sockaddr_in. The IPv8 compatibility layer intercepts socket calls transparently -- the application has zero IPv8 awareness. Except many IPv4 applications use the addresses of the source or that they bind to in some form. If it's secretly an IPv8 behind their back that'll break.
- wmf 6mo agohow does a IPv4 host initiate a connection to a IPv8 host? If you give up on P2P it just doesn't. All servers have IPv4 and NAT64 (or whatever they call it) handles v6-only clients.
- magicalhippo 6mo ago> If you give up on P2P it just doesn't. Sure, but then it's not as "plug and play" as they make it out to be. Many multiplayer games rely on P2P these days for example.
- criticalfault 6mo agodoes ipv6 require Dual Stack Operation?
- kalleboo 6mo agoNo, it doesn't. For example, many mobile networks are IPv6-only.
- Hikikomori 6mo agoYour local router sees the dns request, does some lookup, sees that its in a different ipv8 network, creates some tunnel to it. Seems like only the end client isn't aware of ipv8.
- LeoPanthera 6mo agoThis is not a serious proposal and we should not treat it as such. And I apologise in advance for the length of this comment. "IPv4 is a proper subset of IPv8. No existing device, application, or network requires modification. 100% backward compatible." This cannot be true. Section 5.1 states that IPv8 uses version number 8 in the IP header Version field and the header is 8 octets longer than IPv4's. Any existing IPv4 router, switch ASIC, NIC, host stack, or firewall that sees a Version=8 packet will fail to parse it (most will drop it). Backward compatibility is logically impossible when the wire format is different. The spec simultaneously demands sweeping new machinery everywhere: new socket API (AF_INET8), new DNS record type (A8), new ARP (ARP8), new ICMP (ICMPv8), new BGP/OSPF/IS-IS, mandatory certified NIC firmware with hardware rate limits, mandatory Zone Servers, mandatory OAuth2 on switch ports, mandatory persistent TCP/443 to the Zone Server from every end device, and a new IANA version-number assignment. "No modification required" is contradicted on nearly every page. IP version 8 is already historically assigned (it was PIP, later folded into the IPv6 effort). The draft's IANA request ignores this. The ASN model conflates identity with location. ASNs are organizational identifiers assigned by RIRs, turning them into the 32-bit routing prefix means an organization cannot change providers, multihome with provider-assigned space, or use PI space the way networks do today. Every organization that wants public IPv8 connectivity must now hold an ASN - roughly a 1000x increase in ASN allocation. The /16 minimum injectable prefix rule eliminates essentially all of today's BGP traffic engineering and most multihoming patterns. Cross-AS Cost Factor (CF) requires every AS on Earth to trust the metrics injected by every other AS, including a "economic policy" component. BGP is policy-based precisely because ASes do not trust each other's metrics, this has been understood since the 1990s. The Zone Server kitchen sink (DNS + DHCP + NTP + OAuth + telemetry + ACL + NAT + WHOIS validation + PVRST root) concentrates a dozen unrelated functions into one box on one hardcoded address (.253/.254). This is an operational and security anti-pattern. PVRST is mandated. PVRST is a Cisco-proprietary spanning tree variant, mandating a vendor-specific protocol in a Standards-Track draft is a non-starter for IETF. The companion drafts (WHOIS8, NetLog8, Update8, WiFi8, Zone Server, RINE, routing protocols) are all by the same author, none have working-group review, and the core draft depends on all of them to function.
- quotemstr 6mo agoI was waiting for the proposal to describe the header field where the sender would indicate which of the four simultaneous days in one 24-hour rotation of the earth he inhabited.
- PaulKeeble 6mo agoIn many regards IPv6 was a change that went too far and didn't go far enough all at the same time, although slowly but surely it is being adopted. Something like this had a better chance at adoption precisely for how little it changed things. The most radical part is the merging of all services into one central blob and I think that is going to be the part most people take exception too especially oauth. It doesn't solve fundamental issues like roaming with mobile devices, something that now is really important to get rid of a lot of complexity that has built up.
- chewbacha 6mo agoMy immediate first thought is if the XKCD standards comic https://xkcd.com/927/ https://xkcd.com/927/
- Retr0id 6mo agoDon't forget the equally serious IPv7 https://www.ietf.org/archive/id/draft-ipv7-2025-00.html https://www.ietf.org/archive/id/draft-ipv7-2025-00.html
- Lammy 6mo agoRelevant Lain: https://lain.wiki/wiki/Protocol_7 https://lain.wiki/wiki/Protocol_7
- flomo 6mo agoLots of fishhooks in there, so lets see how this goes. (some are pretty obscure)
- zadikian 6mo agoI get making it a superset of v4, but what's up with the oauth stuff?
- red-iron-pine 6mo agoauthenticate every packet to a user. track every single ping, site visit, chat, etc.
- compounding_it 6mo agoThe solution to the solution to solve a problem is to create a new problem.
- usui 6mo ago> Every manageable element in an IPv8 network is authorised via OAuth2 JWT tokens served from a local cache. Every service a device requires is delivered in a single DHCP8 lease response. Isn't it 2 weeks late for April Fools'?
- deleted 6mo ago[deleted]
- zythyx 6mo agoI'm not going to pretend I know all about IP routing and networking. I understand enough of it to have a home server all appropriately set up with IPv4. But what makes this quote a problem? I mean, it seems a bit excessive, but I don't understand why...
- deleted 6mo ago[deleted]
- bnjms 6mo agoJust a gut check but it feels ugly to put auth in an L3 proposal.
- Alifatisk 6mo agoI feel the same, I guess using JWT is the joke here?
- vasachi 6mo agoIP is what, four layers of protocols lower than OAUTH?
- conorcleary 6mo agoand they might as well earmark oauth3
- anilakar 6mo agoOAuth8, you surely meant.
- fivetimestwo 6mo agoIs this AGI ?
- imoverclocked 6mo ago> IPv8 also resolves IPv4 address exhaustion. Each Autonomous System Number (ASN) holder receives 4,294,967,296 host addresses. The global routing table is structurally bounded at one entry per ASN Yes, let's conflate routing and addressing while throwing out decades of IPv6 implementation and design. (/sarcasm)
- RobotToaster 6mo agoThere's already an ipv8 https://www.rfc-editor.org/rfc/rfc1621 https://www.rfc-editor.org/rfc/rfc1621 There's also at least three ipv9s, only one of which was a joke https://en.wikipedia.org/wiki/List_of_IP_version_numbers https://en.wikipedia.org/wiki/List_of_IP_version_numbers
- deleted 6mo ago[deleted]
- deleted 6mo ago[deleted]
- hathym 6mo ago[dead]
- zerof1l 6mo agoEither a joke or vibe-coded. Whole thing is nonsense.
- m4r1k 6mo agodead on arrival.
- allixsenos 6mo agoThis is the best piece of speculative fiction I've read in the last year :D :D :D :D I didn't make it past page three. Enjoy responsibly.
- johnea 6mo agoI'd judge IPv8 based on what DJB has to say about it...
- EvanZhouDev 6mo agoTo be clear, when I posted this, the title of the post was "IPv8 Proposal". However, it seems to have been edited at some point to be "Internet Protocol Version 8 (IPv8)" thus becoming a misleading title and seems to have gotten his post flagged. Not sure how that happened, or why.
- dark-star 6mo agoAt first glance this looks like a joke. But if you look closer, it looks really workable (well, maybe except those "mandatory NIC-enforced security" bits) I'm hoping someone will be brave (or stupid) enough to actually implement this. I have a personal ASN number that I'm willing to participate with :)
- Dagger2 6mo agoBig parts of it are copied straight from v6's approach, so it's kind of inevitable that at least those parts would be workable -- because they're workable in v6. But of course, you might as well just use v6 at that point.
- ipv8wiki 6mo ago[dead]