4 ms·
This is the only topic that tempts me to create a throwaway account. (I have not given in) None of the IPv6 proponents are willing to acknowledge that IPv6 is a
by everdrive 5mo ago
This is the only topic that tempts me to create a throwaway account. (I have not given in) None of the IPv6 proponents are willing to acknowledge that IPv6 is a pain.
All of them seem to have gone to some secret seminar somewhere where they receive their talking points:
- Everyone who dislikes IPv6 doesn't know how NAT works and thinks it's the same as a firewall.
- There's absolutely no downside whatsoever to being publicly addressable. (also this is a good time to reiterate that NO ONE understands that NAT is not a firewall)
- 128 bit addresses are exactly as convenient and memorable as as 32-bit addresses.
- The entire internet would be hosting home servers if not for the evils of NAT.
- PunchyHamster 5mo agoYou forgot important thing: There will always be some security guy yelling that leaking your internal IP structure is bad. There will also be another clown that does IP whitelisting as security measure and refuses to just whitelist single /64|/24 network "because it is too wide" (I literally had this conversation last week with one of the clients) > - The entire internet would be hosting home servers if not for the evils of NAT. ISPs will find a way to fuck up
- adrithmetiqa 5mo agoIt would have been a success if they just called it ipv5.
- ahoka 5mo agoIPv6 is classic second system effect.
- tardedmeme 5mo ago[flagged]
- Ekaros 5mo agoI think if they just double the address length the people would still cry about how 111.211.234.231.189.243.253.100 too hard to write and remember... There is no helping with people.
- tardedmeme 5mo agoyeah and the global migration to add bits is already so expensive, if you're adding bits you shouls add a lot of bits so it only has to be done once. Wish they'd made it 256 bits actually, it could fit cryptographic hashes for secure routing protocols of the future.
- mixmastamyk 5mo agoOn extra byte shoved in a reserved field would have created 256 internets. That's two more for big countries and another for each small country and other planets. Then write in hex so addresses are shorter, require dhcp/sec etc, solved. My proposal for IPv7. ;-)
- throw0101a 5mo ago> On extra byte shoved in a reserved field would have created 256 internets. Ah yes, the old IPv4 with 'just' adding more address byte(s) idea (you "IPv7"): So you have to update DNS to create new resource record types ("A" is hard-coded to 32-bits) to support the new longer addresses, and have all user-land code start asking for, using, and understanding the new record replies. Just like with IPv6. (A lot of legacy code did not have room in data structures for multiple reply types: sure you'd get the "A" but unless you updated the code to get the "A7" address (for "IPv7" addresses) you could never get to the longer with address… just like IPv6 needed code updates to recognize AAAA, otherwise you were A-only.) You need to update socket APIs to hold new data structures for longer addresses so your app can tell the kernel to send packets to the new addresses. Just like with IPv6. In any 'address extension' plan the legacy code cannot use the new address space; you have to: * update the IP stack (like with IPv6) * tell applications about new DNS records (like IPv6) * set up translation layers for legacy-only code to reach extended-only destination (like IPv6 with DNS64/NAT64, CLAT, etc) You're updating the exact same code paths in both the "IPv7" and IPv6 scenarios: dual-stack, DNS, socket address structures, dealing with legacy-only code that is never touched to deal with the larger address space. Deploying the new "IPv7" code will take time, there will partial deployment of IPv7 is no different than having partial deployment of IPv6: you have islands of it and have to fall back to the 'legacy' IPv4-plain protocol when the new protocol fails to connect: * https://en.wikipedia.org/wiki/Happy_Eyeballs https://en.wikipedia.org/wiki/Happy_Eyeballs (This idea of "just add more addresses" comes up in every discussion of IPv6, and people do not bother thinking about what needs to change to "just" do it.)
- zadikian 5mo agoThe downside of publicly-addressable hosts is actually acknowledged in things like RFC 6092, but REC-49 is that routers provide a clear firewalling option that MAY be default-allow.
- kstrauser 5mo ago> Everyone who dislikes IPv6 doesn't know how NAT works and thinks it's the same as a firewall. It would be easier if IPvOld proponents didn't keep saying that it is. Seriously, every time this topic comes up, at least one person expresses horror at the idea of running IPv6 without a firewall, unlike their safely NAT-firewalled IPv4 setup. > There's absolutely no downside whatsoever to being publicly addressable. I won't say there's no downside, because such a thing is possible. It's just that I've never actually heard one outside weirdly contrived scenarios like "but what if they're not using a firewall", which is something you'd have to go out of your way to do. > 128 bit addresses are exactly as convenient and memorable as as 32-bit addresses. It's more realistic to say that IPv4 addresses are less horrid than IPv6, while still horrid. Who are all these people who don't like using DNS? > The entire internet would be hosting home servers if not for the evils of NAT. Um, true. I was on the Internet before NAT became popular, and P2P connections were the norm, not some weird thing you had to hack up with a STUN broker or such. NAT, more than any other single technology, worked to turn the Internet from a collection of peers to a producer-consumer arrangement. There's no scheme in which having the possibility of P2P connections is worse than only allowing client-server.
- zadikian 5mo ago"Who are all these people who don't like using DNS?" "It's always DNS," and mDNS is finicky too. At least, not reliable enough that I can never look at addresses again.
- da_chicken 5mo agoEveryone likes to use DNS. How do I use DNS on my home network to set up my home router? It's the same problem as TLS certificates on web interfaces for infrastructure. And the commercial solution is going to be "pay us a subscription fee so your home device can get an Internet management interface on top of all the egregious data collection".
- zadikian 5mo agoThe home solution is supposed to be mDNS. I just checked right now, my mDNS isn't working on my LAN, idk why.
- globular-toast 5mo agoThis comment would make more sense if you said why IPv6 is a pain. It just works for me.
- mixmastamyk 5mo agoWorks but addresses are unreadable. Ensuring security on a small network is more difficult than it needs to be when addresses are gibberish. Still not sure mine is on IPv6.
- globular-toast 5mo agoCan you give examples of when you need to know IPv4 addresses for security reasons?
- mixmastamyk 5mo agoWhen I write firewall rules I write the address into them. There’s multiple address6s per host and complex enough I give up.
- mwwaters 5mo agoSLAAC and link-local is very different from DHCP/NAT/etc. in IPv4 world. Link-local addresses are pretty arcane in IPv4 while they are a central idea in IPv6. That’s fine. As pointed out elsewhere, DHCP was relatively new when IPv6 was introduced. But it is a learning curve well past just knowing the difference between NAT and stateful firewall.
- deleted 5mo ago[deleted]
- boredatoms 5mo agoEveryone forgets you can NAT ipv6 just like you would v4
- zadikian 5mo agoYou can, but the recommendation is no NAT with v6. Most routers don't even support it.
- tardedmeme 5mo agoThat's also the ipv4 recommendation, which nobody follows because it doesn't work because there are too few addresses.
- ghusto 5mo agoIn troubleshooting, "It's always DNS" has become "If it's not DNS, it's IPv6". I don't even try to fix it. If I disable IPv6 and everything starts working, I move on.
- tardedmeme 5mo agoOn my network, if it's not DNS, it's IPv4. IPv6 just works. I wish websites would hurry up and get with the times so I could turn off this old pile of hacks already.
- pseudohadamard 5mo agoTheir NAT-phobia was legendary, and it carried through to other WGs as well like IPsec. The fact that IPsec broke NAT was a feature because it would force everyone to move to IPv6 ,for example. The crazy was strong in those ones.
- AshamedCaptain 5mo agoBut NAT is _not_ a firewall. It's entire purpose is to allow traffic through. There's a million dozen tricks attackers can play, e.g. tricking a PC into sending traffic to some address will usually allow all traffic from that address back into one's precious network. This is a common misconception and very dangerous -- I see a lot of people, ISPs even, who seem to think NAT is enough and you only need the firewall for IPv6.