7 ms·
Our world. It was a good design in our world. I don't think v6 is the absolute pinnacle of protocol design, but whenever anybody says it's bad and tries to com
by Dagger2 6mo ago
Our world. It was a good design in our world.
I don't think v6 is the absolute pinnacle of protocol design, but whenever anybody says it's bad and tries to come up with a better alternative, they end up coming up with something equivalent to IPv6. If people consistently can't do better than v6, then I'd say v6 is probably pretty decent.
- api 6mo agoIn retrospect I think just adding another 16 or 32 bits to V4 would have been fine, but I don’t disagree with you. V6 is fine and it works great. All the complaints I hear are pretty much all ignorance except one: long addresses. That is a genuine inconvenience and the encoding is kind of crap. Fixing the human readable address encoding would help.
- vbezhenar 6mo agoIPv4 is absolutely fine. Consumers can be behind NAT. That's fine. Servers can be behind reverse proxies, routing by DNS hostname. That's also fine. IPv4 address might be a valuable resource, shared between multiple users. Nothing wrong with it. Yes, it denies simple P2P connectivity. World doesn't need it. Consumers are behind firewalls either way. We need a way for consumers to connect to a server. That's all.
- estimator7292 6mo agoYeah, if you ignore literally every use of the internet except "check Facebook" then it's perfect. Unfortunately, the internet is used for a lot more than using one of the six gigantic centralized websites.
- moffkalast 6mo agoI used to think that too, but outside of our niche bubble most people genuinely do only be web browsing. Speaking of that, why don't we just keep ipv4 for ourselves and let them eat ipv6?
- betaby 6mo agoMost people browse Facebook/Youtube over IPv6 as a matter of fact and that work perfectly.
- Lt_Riza_Hawkeye 6mo agoYou're the reason I have to call my ISP to host a minecraft server for a couple of my friends.
- mort96 6mo agoNo, they're not. That's other weird policies specific to your ISP. With IPv4 + NAT, you have a public IP address. That public address goes to your router. Your router can forward any port to any machine on your LAN. I used to run Minecraft servers from a residential connection on IPv4, it was fine. Never had to call the ISP.
- voxic11 6mo agoNope, CGNAT means I need to call my ISP. We now have 2 levels of NAT because the IPv4 address situation has gotten so bad they can't even give every residence its own public IP. If your ISP hasn't adopted it yet its likely they got lucky and bought a ton of IPv4 addresses a long time ago when they were cheap and have decided using them is cheaper than upgrading their network to support CGNAT.
- Symbiote 6mo agoThis assumes the ISP allocates a public IPv4 address. In many countries they don't have enough, so you have CGNAT.
- deleted 6mo ago[deleted]
- mort96 6mo agoThat's a fair point. In my mind, residential ISPs give out public IP addresses and CGNAT is just for cell phones. But I recognize that the philosophy of, "we don't need to solve IP address exhaustion, we just need to keep people able to access Facebook" leads to CGNAT or multi level NAT. Still, I do think that the solution of, "one IPv4 address per household + NAT" is a perfectly good system. I view the IPv6 mentality of giving each computer in the world a globally unique IPv6 address as a non-goal.
- Fnoord 6mo agoIPv4 usage in its current state would've been much more limited and annoying in a world without IPv6. Therefore, IPv4 exists as-is thanks to others adopting IPv6.
- RIMR 6mo ago> Yes, it denies simple P2P connectivity. World doesn't need it. Worth pointing out that this article was written by the now-CEO of Tailscale. I don't know if "The world doesn't need P2P connectivity" is a compelling take.
- fc417fc802 6mo agoWith the obligatory caveat that I am but a single datapoint, I use various P2P apps through multiple levels of NAT without issue and I very intentionally prevent devices on my local LAN from being publicly reachable. So it rings true to me. I do wish ISPs would refrain from intentionally breaking things though. It ought to be illegal for them to block specific ports or filter specific sorts of traffic absent a pressing and active security concern.
- jrm4 6mo agoThis comment exemplifies my worst fear and reinforces my somewhat incomplete idea that IPv4 is perhaps overall safer for the world, and that "worse is better" depending on what you're optimizing for. Roughly, it's my belief that an IPv6 world makes it easier for centralizing forces and harder for local p2p or p2p-esque ones; e.g. an IPv6 world would have likely made it easier to do bad things like "charge for individual internet user in a home." The decentralization of "routing power" is more a good thing than bad, what you pay for in complexity you get back in "power to the people."
- deleted 6mo ago[deleted]
- MrDOS 6mo ago> easier to do bad things like "charge for individual internet user in a home." This idea comes up in every HN conversation about IPv6, and so I suppose this time it's my turn to point out RFC 8981[0]. tl;dr: typically, machines which receive IPv6 address assignment via SLAAC (functional equivalent of DHCP) periodically cycle their addresses. Supposed to offer pretty effective protection against host-counting. 0: https://datatracker.ietf.org/doc/html/rfc8981 https://datatracker.ietf.org/doc/html/rfc8981
- deleted 6mo ago[deleted]
- throw0101a 6mo ago> IPv4 is absolutely fine. Consumers can be behind NAT. I don't want our communications infrastructures to be just for consumers.
- kalleboo 6mo agoA lot of us don't like this "you will own nothing and you will be happy" kind of energy.
- deleted 6mo ago[deleted]
- fortran77 6mo ago> Fixing the human readable address encoding would help Yes! They need an alternate encoding form that distills to the same addresses. My machines Link-local IPV6 address is "fe90::6329:c59:ad67:4b52%8" If I try to paste that into the address bar in Edge or Chrome (with the https://) it does an internet search on that string! No way around it. I have to do workarounds like: "http://fe90::6329:c59:ad67:4b52%8.ipv6-literal.net:8081/ http://fe90::6329:c59:ad67:4b52%8.ipv6-literal.net:8081/ All to test the IPv6 interface on a web server I'm running on my local machine.
- pocksuppet 6mo agoAn IPv6 literal hostname in a URL must be surrounded by square brackets.
- fortran77 6mo agoChrome and Edge still do a search on it in my default search engine even with [] https://[fe80::5ad6:9567:26b7:763b%18]:8081/ Even Hacker News doesn't think it's a link
- deleted 6mo ago[deleted]
- 1718627440 6mo agoOn Mozilla Firefox after reenabling the separation into URL and searchbar it reports: "Invalid URL – Hmm. That address doesn’t look right. \n Please check that the URL is correct and try again." What does the '%' mean in there?
- pocksuppet 6mo agoFor link-local addresses, the part after % identifies the link. It's platform-specific - in Linux it's the interface name and in Windows it's an ID number.
- Dagger2 6mo ago
- pocksuppet 6mo agoIf you add new bits to v4 you invent an incompatible protocol, and you should add a lot of bits so you'll never have to invent another incompatible protocol again. You can also fix the minor annoyances in v4.
- bombcar 6mo agoFlexible! The first byte tells you how many bytes of addressing you have. Perfect and future proof!
- jasomill 6mo agoAt best future-resistant. True future-proofing would require representing address length as an arbitrary-precision nonzero unsigned integer. Since allowing a zero-length network address format would serve no purpose other than to pointlessly complicate standards definitions, you could trivially and without loss of generality interpret zero to denote some extended-length address length representation to be defined in a future version of the standard.
- tremon 6mo agoHardware implementations typically do not like variable-size fields. Not just because the total header size becomes unpredictable, but because it means any following fields no longer have a fixed offset, and that complicates parsing.
- perennialmind 6mo agoIPv4 was designed with extension headers: it boggles my mind that simply using the headers to extend the address was never seriously considered. It was proposed: https://www.rfc-editor.org/rfc/rfc1365.html https://www.rfc-editor.org/rfc/rfc1365.html It still would have been a ton of work, but we could have just had what IPv6 claimed to be: IPv4 with bigger addresses. Except after the upgrade, there'd be no parallel system. And all of DJB's points apply: https://cr.yp.to/djbdns/ipv6mess.html https://cr.yp.to/djbdns/ipv6mess.html
- api 6mo agoHere’s my understanding. The people involved in core Internet protocol design were used to the net being a largely walled garden of governments, corporations, universities, and a small number of BBSes and niche ISPs. Major protocol upgrades had happened before, not just for the core protocol but all kinds of other then-core services. It had been a while but not that long, I think less than 20 years, and last time it was pretty easy. They assumed they could design something better and phase it in and all the members of the Internet community would just do the right thing. That’s probably what made them feel they could push a more radical upgrade. Unfortunately they started this right as the massive tsunami of Internet commercialization hit. Since V6 was too new, everyone went with V4. Now all the sudden you had thousands of times more nodes, sites, and personnel, and all of them were steeped in IPv4 and rushing to ship on top of it. You also lost the small town atmosphere of the early net where admins were a club and could coordinate things. Had V6 launched five years earlier V4 would probably be dead. V6 usage will probably keep creeping up, but as it stands we will likely be dual stack forever. Once the installed user base and sunk cost is this high the design is fixed and can never be changed without a hard core heavy handed measure like a government mandate.
- iknowstuff 6mo agoiOS is benefitted from a heavy handed mandate so that it and all of its apps sing on IPv6 only networks. They just need to expose IPv4 internet as IPv6 addresses.
- pocksuppet 6mo ago
- pocksuppet 6mo agoYou would have ended up with a protocol identical to IPv6, but with fewer address bits. If you add *any* address bits you've already broken protocol compatibility and you need to upgrade the entire world. While you're already upgrading the entire world, you should add so many address bits that we'll never need more, because it costs the same, and you may as well fix those other niggling problems as well, right?
- zrail 6mo ago> they end up coming up with something equivalent to IPv6 Not just that. Almost every single thing people think up that's "better" is something that was considered and rejected by the IPv6 design process, almost always for well-considered reasons.
- notepad0x90 6mo agoYou know that's not what he meant. the world is always changing. it was designed in 1998 by networking gear companies, with their own company needs in mind. It wasn't engineered with end user, or even network administrators and app developers in mind. The only reason it's around is because of sunken cost fallacy and people stuck in decades old tech-debt. A new protocol designed today will be different, much the same as how Rust is different than Ada. SD-WAN wasn't a thing in 1998, the cost of chips and the demand of mobile customers wasn't a thing. supply/demand economics have changed the very requirments behind the protocol. Even concepts like source and destination addressing should be re-thought. The very concept of a network layer protocol that doesn't incorporate 0RTT encryption by default is ridiculous in 2026. Even protocols like ND, ARP, RA, DHCP and many more are insecure by default. Why is my device just trusting random claims that a neighbor has a specific address without authentication? Why is it connecting to a network (any! wired,wireless, why does it matter, this is a network layer concern) without authenticating the network's security and identity authority? I despise the corporatized term "zero trust" but this is what it means more or less. People don't talk about security, trust, identity and more, because ipv6 was designed to save networking gear vendors money, and any new costly features better come with revenue streams like SD-WAN hosting by those same companies. There are lots and lots of new things a new layer-3 protocol could bring to the scene. But security aside, the main thing would be replacing numbered addressing with identity-based addressing. It all comes down to how much money it costs the participants of the RFC committees. given how dependent the world is on this tech, I'm hoping governments intervene. It's sad that this is the tech we're passing to future generations. We'll be setting up colonies on mars, and troubleshooting addressing and security issues like it's 2005.
- unethical_ban 6mo ago>There are lots and lots of new things a new layer-3 protocol could bring to the scene. But security aside, the main thing would be replacing numbered addressing with identity-based addressing I don't know much about MPLS and only know IP routing, but that quote above sounds very hand-waving. How do you route "identity based addressing"?
- notepad0x90 6mo ago
- m463 6mo agoyou're implying that they could not have done better. I think they "shipped it" and washed their hands of it. But I think there should have been more iterations, until we got a little more ipv4+ and less ipv6.
- tadfisher 6mo agoThey shipped it because it was done. Everything since has been round after round of RFCs trying to adapt IPv4 workarounds to the IPv6 world.