Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
331.
▲
by
Dagger2
3y ago
...are you going to do this experiment or not? I've got the whole setup just waiting for you.
332.
▲
by
Dagger2
3y ago
That's not how v6 works in Debian, or really anywhere. For one thing, you can't reach a domain with v6 if there's no AAAA record, so it certainly won't be trying to reach "all domains" with v6. If your network
333.
▲
by
Dagger2
3y ago
They make more money from selling servers than they do from selling v4 addresses. There's a limit to how many v4 addresses they can get, so they'll make more money if they can sell servers without v4 addresses -- otherwise the lim
334.
▲
by
Dagger2
3y ago
No, it won't. All that's needed is an inbound route to your router, and NAT can't prevent that route from existing. It doesn't matter if you have ISP control or not. I'm not seeing any gre packets from you. Are you
335.
▲
by
Dagger2
3y ago
That's not quite how routes work, but... of course it does. Outbound connections wouldn't work otherwise.
336.
▲
by
Dagger2
3y ago
Do you mean, say, one device that's on Ethernet and one that's on WiFi? Most people have their Ethernet and WiFi setups bridged so they count as the same link. If you actually mean two separate networks, where traffic has to be ro
337.
▲
by
Dagger2
3y ago
You can't do it in practice because everybody has firewalls, and also widespread use of RFC1918 in v4 makes it hard to even send the right packets to the right place. I wasn't arguing that; my point was just that NAT won't st
338.
▲
by
Dagger2
3y ago
The fact that it works at all disproves your "you can't do it" claim. I didn't misconfigure the router here. Please ask for whatever config info would convince you of that. It's true that most router devices you buy
339.
▲
by
Dagger2
3y ago
You simply can. NAT doesn't give any security whatsoever. Here's an unsolicited connection to an internal host over a router that's doing NAT: (192.168.0.101)$ echo "Hello from inside" | nc -vlp5000 Connection
340.
▲
by
Dagger2
3y ago
You don't actually need to use Local:Address:A as a source to connect to Local:Address:B, you can connect from Global:Address:A. To make it more specific: if you advertise both 2001:db8:1::/64 and fd00::/64 as on-link on your
341.
▲
by
Dagger2
3y ago
It's ARIN's job to call BS on BS justifications, otherwise they're not following the policy, they're following whatever they allow. "The purpose of a system is what the system does" and all. That's an inte
342.
▲
by
Dagger2
3y ago
It's not really, it just spends a lot of time waffling on about bus networks and mobile IPs and then makes some weird claims about the IETF that don't seem to match reality. v6 is designed the way it is precisely because it needs
343.
▲
by
Dagger2
3y ago
They might have included them in the published policy, but it seems they aren't in whatever policy they're actually following.
344.
▲
by
Dagger2
3y ago
I've talked from v4 clients to v6 servers before, and I've accepted v4 connections to v6 servers. How can it be so clear that it's not possible when I've done it before? > As for TUBA, the transition plan incorporated
345.
▲
by
Dagger2
3y ago
Hm... according to that draft, TUBA's transition story is dual stack, which is the same as the main transition approach for v6. How come it's sane for TUBA but not sane when v6 does it? > As for current v6 being interoperable w
346.
▲
by
Dagger2
3y ago
Can you tell us what the better transition story was? As far as I can tell, v6 is already approximately as interoperable with v4 as it's possible to be. I don't get your claim that it's a separate island at all. It's not
347.
▲
by
Dagger2
3y ago
And for $256,000/year you can... exhaust the entirety of 2000::/3? Yeah, that's not okay. Either the price needs to go up a lot or they need to include factors other than money in the allocation criteria.
348.
▲
by
Dagger2
3y ago
It's not being burnt, there are two useful things we're doing with the 64-bit network size: * Sparse networks. 64 bits is too big to feasibly do a brute force scan on, which reduces how often servers get exploited by random networ
349.
▲
by
Dagger2
3y ago
The post you replied to was talking about stateful NAT. Stateful NAT doesn't firewall either. If you do what they described, you'll be able to connect in just fine unless there's a separate firewall blocking it.
350.
▲
by
Dagger2
3y ago
You can't tell if there's a port or not, e.g. http://2001:db8::1:8080/ . Is that 2001:db8::1 or 2001:db8::1:8080?
351.
▲
by
Dagger2
3y ago
You can use certainly v4 for however long you like, but you still need to use v6 as well, because you can't connect to v6 addresses using v4. (If you could, we wouldn't need v6 in the first place.) If you want to avoid v6 altogeth
352.
▲
by
Dagger2
3y ago
What happens if you try to reach e.g. https://loopsofzen.uk/ ? It sounds like it's not going to work. Nobody is suggesting you stop using v4 on your LAN, but you do need to use v6 on it.
353.
▲
by
Dagger2
3y ago
The reason it's problematic is the same reason we need a new protocol in the first place: because the old one isn't enough. You've spent longer talking about not deploying v6 than you would have done deploying it. I said this
354.
▲
by
Dagger2
3y ago
We spent a significant amount of effort designing v6's deployment strategy to make sure this would be the case -- that it could be deployed without disrupting existing network setups. It's supposed to work like this. Don't tw
355.
▲
by
Dagger2
3y ago
Good! If we did then we should've made it bigger. We don't know exactly how many address bits we're ultimately going to end up needing. Our only options are to go for "too big" or "too small". Giving how m
356.
▲
by
Dagger2
3y ago
Not really, it just spends a lot of time waffling on about bus networks and mobile IPs and then makes some weird claims about the IETF that don't seem to match reality. v6 is designed the way it is precisely because it needs to run on
357.
▲
by
Dagger2
3y ago
URLs use : to separate the IP and port. There needs to be some way to disambiguate that from the colons in the address.
358.
▲
by
Dagger2
3y ago
Can we? People continue to use both even after newer versions are released. I don't think it was horribly conceived. I think it's close to the best we can do given the constraints we're working under. These constraints includ
359.
▲
by
Dagger2
3y ago
Have you looked at what's actually getting deployed? It's mostly no NAT and firewalls, so the signs actually seem to be pointing to "yes". Even without a firewall, a /64 is an extremely large amount of space. It
360.
▲
by
Dagger2
3y ago
Nobody is in a position to EOL v4. We'd need a planetary government for that, and we don't have one. It would be nice, but we have to work with what we've got and not what we wish we had. I run my desktop with no v4, so it&#x
More ›