Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
25 ms
·
391.
▲
by
Dagger2
3y ago
v6 basically is v4 with more bits. You could do what you describe with it. The problem is that nobody has the authority to enforce such a timetable on the Internet as a whole, so that's not actually a workable plan.
392.
▲
by
Dagger2
3y ago
> Which means what is really necessary is a new IP protocol that will somehow, SOMEHOW (don't ask me how, I don't effing know) speak seamlessly to IPV4 and IPV6 You don't know how, and nobody knows how, because it's n
393.
▲
by
Dagger2
3y ago
What, something like this? $ ping 64:ff9b::8.8.8.8 PING 64:ff9b::8.8.8.8(64:ff9b::808:808) 56 data bytes 64 bytes from 64:ff9b::808:808: icmp_seq=1 ttl=113 time=8.75 ms Seems like we already have something very much like that.
394.
▲
by
Dagger2
3y ago
Yes. What were you expecting? There's no way for a v4-only device to reply to a packet from a v6 source address otherwise. The source address has to be mapped to an address the v4-only device understands, and then mapped back again for
395.
▲
by
Dagger2
3y ago
It does translate, but it doesn't work for ping because ping bypasses most of the stack by sending raw packets. Try something like `telnet ::ffff:192.168.0.1 80`.
396.
▲
by
Dagger2
3y ago
By reverse proxying. Run a load balancer on a single machine and have that reverse proxy connections to their destination. But what if you insist on not using a proxy for whatever reason? When people say "NAT", they're usuall
397.
▲
by
Dagger2
3y ago
Try NAT64. It'll let v6-only clients reach v4-only websites.
398.
▲
by
Dagger2
3y ago
We could, but it would have broken compatibility with v4 just as thoroughly as v6 did and so would have had the exact same deployment difficulties v6 has. In fact v6 mostly _is_ a minor tweak to v4; most parts of it are lifted directly from
399.
▲
by
Dagger2
3y ago
NAT64 handles the "public v4-only website" use case very well. I run my desktop without v4 today and it works fine. A few websites without v6 aren't a blocker to either deploying v6 or undeploying v4.
400.
▲
by
Dagger2
3y ago
> Just like when YouTube nailed the lid into the coffin of ie6. That was the work of a few people on the YouTube team, not the company itself taking a stand: https://blog.chriszacharias.com/a-conspiracy-to-kill-ie6
401.
▲
by
Dagger2
3y ago
The GP's statistic is probably raw bytes, and yes, a significant chunk of that will be the big video streaming sites, which mostly have v6. That's still a useful statistic, because part of the cost of v4 is NAT and NAT capacity is
402.
▲
by
Dagger2
3y ago
Large, sparse subnets are nice for their security benefits. For a 16-bit network, you can enumerate all active public servers by exhaustively port-scanning it; it takes something like a few hundred gigabytes of traffic, which is nothing the
403.
▲
by
Dagger2
3y ago
It's actually not that flawed, you've more or less invented 6to4. Every v4 address has an associated v6 network (basically 32.2.a.b.c.d.*), and you can send packets to that network by crafting packets that use protocol 41 ("6
404.
▲
by
Dagger2
3y ago
All that and no mention of IPv6? At least get the basics down first.
405.
▲
by
Dagger2
3y ago
Apple also made a claim that v6 connection setup is 40% faster: https://www.zdnet.com/article/apple-tells-app-devs-to-use-ip... (Not 1.4x faster overall, as you might think from the headline...)
406.
▲
by
Dagger2
3y ago
It's honestly not that hard. Looking at your other posts, you think it's hard because you're unfamiliar with it, because you're trying to overcomplicate it, and because you're trying to do everything all at once rat
407.
▲
by
Dagger2
3y ago
What you're asking for here is port forwards/DNAT, i.e. applying NAT to redirect an inbound connection. When people say "NAT", they're usually talking about SNAT/MASQUERADE, i.e. NATing outbound connections. If
408.
▲
by
Dagger2
3y ago
This is actually wrong, and dangerously so. Your router knows perfectly well where to forward any given packet to: it forwards it to the IP that's in the packet's "destination IP" header. If a connection comes into your
409.
▲
by
Dagger2
3y ago
Your subject says "is it costing me users?", but your message says "how many people will be unable to access the site?". These are two different things. If your site is slow, it will cost you users. v6 has measurably bet
410.
▲
by
Dagger2
3y ago
How do you expect compatibility with v4 protocols/software/hardware/routers/ISPs to work without using v4? That's a serious question. Do you have a way for this to work? Because I don't think it's possible
411.
▲
by
Dagger2
3y ago
A /128 on the WAN is normal. Addresses assigned by DHCPv6 (which is commonly used by ISPs for WAN address assignment) are assigned as /128. The important part is the delegated prefix, which you normally get via DHCPv6-PD and shoul
412.
▲
by
Dagger2
3y ago
That is also not accurate. Clients query both the A and AAAA records simultaneously up front, sort the replies according to the RFC3484/6724 rules, and then try each address in turn. The rules are somewhat involved but they roughly boi
413.
▲
by
Dagger2
3y ago
$ ping 0000000000321.216.230.240 PING 0000000000321.216.230.240 (209.216.230.240) 56(84) bytes of data. 64 bytes from 209.216.230.240: icmp_seq=1 ttl=46 time=142 ms Platform-specific syntax, excellent. That sure makes it sound
414.
▲
by
Dagger2
3y ago
That's not really true. Most people, companies and consumers alike, have networks of more than one machine and they actually really want those networks to be part of the Internet rather than being separate and using a proxy. You can&#x
415.
▲
by
Dagger2
3y ago
That's really not the biggest issue. DNS servers can handle this level of load just fine. People throwing out excuse after excuse (frequently wrong or ill-informed) for not doing v6 is a bigger issue. > For one thing, the format is
416.
▲
by
Dagger2
3y ago
It's not useless. v6 provides a vastly bigger address space. You're making the same mistake djb made: you've identified a problem, but rather than provide a solution, all you're doing is insinuating that somebody else sh
417.
▲
by
Dagger2
3y ago
That might well be true! It just doesn't seem to be possible. There's no point wishing for fewer breaking changes when the one thing you're doing all of this for -- longer addresses -- is the thing causing the breakage. I don
418.
▲
by
Dagger2
3y ago
At the very least then, you need it as a prerequisite for something else that you want. Or perhaps I'm assuming too much about your network here. Let me double-check: do you use NAT? You've said things about it, but do you use it
419.
▲
by
Dagger2
3y ago
I'm talking about the kind of NAT that everybody else is talking about here, the one you get in Linux by running "iptables -t nat -A POSTROUTING -o wan0 -j MASQUERADE". It has "-o wan0" so it only applies to outboun
420.
▲
by
Dagger2
3y ago
That would imply that NAT is some kind of firewall. It's not. NAT doesn't block connections, so it's not a firewall. In the first place, NAT is something you apply to outbound connections, not inbound ones, so how can it ch
More ›