5 ms·
It's too bad that other providers are not offering this yet. For example, my provider says: > At this time Optimum is not providing IPV6 addresses. In the fut
by devicenull 13y ago
It's too bad that other providers are not offering this yet. For example, my provider says:
> At this time Optimum is not providing IPV6 addresses. In the future we will support users wishing to connect to IPv6-only sites. Currently, web site operators today are compatible with both IPv4 and IPv6 to ensure their sites are reachable by everyone. When IPv6 becomes the standard, which currently it is not, we will provide support for it.
If you don't have native IPv6 yet, ask your ISP why!
- ams6110 13y agoWhy do I need or want native IPv6? Everything works fine on IPv4 NATed behind my home router.
- dubfan 13y agoBecause to traverse that NAT, you need to either forward ports manually in your router (one of those activities that seems second nature to techies but is obscure to everyone else) or use UPnP (an ugly, insecure hack). IPv6 solves the need to resort to this.
- simoncion 13y agoHow is UPnP more insecure than having a publicly routable IP address? Assume that the machine running UPnP behind a NAT and the machine with the publicly routable IP both have correctly configured firewalls.
- voltagex_ 13y agoDefine correctly - most consumer routers will respond to a uPNP forwarding request from anywhere - what if that's a Java applet running on a compromised ad network?
- simoncion 13y agoSo what if it is? Even if the uPnP daemon on that router is so broken that it responds to requests from the WAN that configure forwarding rules for machines on the LAN, how is this less secure than having a publicly routable IP for every one of the machines on the LAN? To answer your question, assume that "correctly" is at least as secure as the default Windows Firewall configuration (with user-entered exceptions for video games and whatnot).
- voltagex_ 13y agoA java applet can make the request from your LAN IP, and forward whatever port to whatever other port - as well as whatever other odd features are baked into the uPnP daemon. Anyway, the advantage for a developer is that we no longer have to do silly NAT traversals and deal with broken/incomplete NAT implementations. Security, as always, is left as an exercise to the reader. You can close ports with a firewall, by not running services on that port or via NAT. I know which one I'd rather deal with.
- simoncion 13y agoNot having to deal with a NAT is a godsend. I know. I've had a block of publicly routable IPv6 addresses for five or eight years now. I notice that you haven't addressed the question I asked in the first comment of mine that you responded to, and again in the second comment. I effectively asked "How is uPnP more insecure than giving the machines on your LAN publicly routable IP addresses?". I've heard people say that uPnP is insecure, but I haven't heard anyone back up that assertion with any information. Even something as weak as anecdata! I asked the question that I did in order to understand the reasoning behind that assertion. > You can close ports with a firewall, by not running services on that port or via NAT. I know which one I'd rather deal with. I don't. I'm curious, which one you'd rather deal with, and why?
- voltagex_ 13y ago> I've heard people say that uPnP is insecure, but I haven't heard anyone back up that assertion with any information. uPnP as a spec doesn't seem to have any security (authentication/authorization) baked in. I'd find you a reference from upnp.org but they're making it difficult to search. As an implementation - have you had a look at any firmware from consumer-level routers recently? Sorry, more anecdata. The only flaw I can remember is http://upnp.org/news/documents/UPnPForum_IGDSecurity_PressRelease_Feb2013.pdf http://upnp.org/news/documents/UPnPForum_IGDSecurity_PressRe... Even with a good implementation, if I can execute code from any device on your network, your phone, your Smart TV/fridge, your PC, then I can forward ports to wherever I like. I know, I've accepted the risk too by keeping uPnP turned on in my network. > You can close ports with a firewall, by not running services on that port or via NAT. I know which one I'd rather deal with. I don't want to deal with any more NAT implementations. It wasn't so long ago that the size of the tables on consumer-grade routers were small enough that BitTorrent et-al would fill the NAT & TCP tables and cause disconnections or router crashes. NAT is a hack and we should be moving away from it.
- tedunangst 13y agoSince Comcast is handing out /128s, now you get to enjoy the thrill of IPv6 and NAT!
- simoncion 13y agoI don't know where you are, but I'm a Comcast customer in San Francisco. I have a /64 assigned to me through Prefix Delegation ( http://en.wikipedia.org/wiki/Prefix_delegation http://en.wikipedia.org/wiki/Prefix_delegation ). My router talks to Comcast's router over a link-local address. I know, a /64 isn't a /56 or even a /48 like they should be handing out, but it's a far cry from a /128. Where are you seeing /128s being handed out? Are you sure that your router isn't misconfigured in some way? If you're basing your information on the info here: http://www.comcast6.net/index.php/ipv6-deployment-faq http://www.comcast6.net/index.php/ipv6-deployment-faq do know that it's out of date. The bug mentioned in Toastman and Shibby builds has been fixed for quite a while. (Indeed, I'm running unmodified Shibby on my router [with some firewall rules to patch over some crappy daemon interface binding decisions that the guy made.].) EDIT: agawa reports that Comcast is handing out /60s. I'll play around a bit with my network this weekend and see what I've misconfigured/misunderstood.
- agwa 13y agoComcast should give you up to a /60 if you ask for it, no matter where you are: https://secure.dslreports.com/forum/r28725662-IPv6-ALL-areas-support-60-now https://secure.dslreports.com/forum/r28725662-IPv6-ALL-areas... Indeed, I can get a /60 here in the Bay Area.
- simoncion 13y agoI'll try to play around with my network this weekend. It might be mis-configured, or I might just be stupid. Thanks much for the information!
- simoncion 13y agoSo, it looks like I can ask for a /60, and I get offered a /60 and a /64. (I can ask for a /61, and I get offered a /61 and a /64.) Unfortunately, the /64 is offered with a higher priority, so the router uses that. A thread on dslreports.com indicates that this might be because I had a recently released lease on the /64, so I'm gonna release the lease for three or four days to see if that will fix the issue.
- SudoNick 13y agoLets ask the other question too: why do I not want IPv6? It seems to me that NAT serves a very useful role in terms of helping to hide information about your internal network (the devices on that network, their roles and activity, etc). I'm not well versed in IPv6 address assignment or Comcast's setup, but IIRC there are scenarios (SLAAC?) where IPv6 IP Addresses include an Interface Identifier that is derived from the manufacturer assigned hardware address. Which would allow a device's activity to be tracked over time and across the different networks it connects to. Which can reveal information about the type of device and potential vulnerabilities (to those who have access to the hardware address assignment database). Which can even reveal information about who purchased the device (to those who have access to purchase records that contain the device's hardware address).
- ancarda 13y ago>When IPv6 becomes the standard, which currently it is not, we will provide support for it. Except that it won't become the standard if nobody adopts it.
- devicenull 13y agoI never said it was a good reason :/
- p1mrx 13y ago> When IPv6 becomes the standard ... we will provide support for it. Here's a standard you can refer them to: http://tools.ietf.org/html/rfc6540 http://tools.ietf.org/html/rfc6540