Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
Dagger2
4mo ago
If my firewall logs are representative, about 2%.
32.
▲
by
Dagger2
4mo ago
Why the double standard? v6 already gives you what you're asking for here: you can turn it on without thinking about it, but actually using the extra addresses from it requires reconfiguring some things (not everything, mind). Why is t
33.
▲
by
Dagger2
4mo ago
But subnetting in v6 is so much easier than in v4? And it's specifically because of the hex. You don't even need to calculate it, in your head or otherwise, because you just subnet based on characters: 2001:db8:42:1xxx::/
34.
▲
by
Dagger2
4mo ago
What's the par time for L3 protocol migrations on the Internet at its current size? Bear in mind we've never done a project of this complexity and scale before. I'm sure we all wish it had been faster, but how can you possibl
35.
▲
by
Dagger2
4mo ago
Why is it less effective on v6? You just ban the /48 or bigger.
36.
▲
by
Dagger2
4mo ago
Note that even a MAC-derived link-local may not be unique, since the same MAC can be on both networks (e.g. with VLANs, or if you assign MACs to hosts instead of NICs).
37.
▲
by
Dagger2
4mo ago
Note you can also advertise a ULA prefix without the A flag. The advertisement tells other machines that the IP is on-link, and they can use their own GUA addresses to connect without needing a ULA address of their own. You could also assig
38.
▲
by
Dagger2
4mo ago
mDNS on link-locals is what makes the "plug computers and printers into switch" case work. It would have been NetBIOS originally but mDNS is how it's done today.
39.
▲
by
Dagger2
4mo ago
I very much didn't test it, but this patch might do the job on Firefox (provided there's no code in the UI doing extra validation on top): --- a/netwerk/base/nsURLHelper.cpp +++ b/netwerk/base/n
40.
▲
by
Dagger2
4mo ago
Routing tables don't work here, because the routing table looks something like: fe80::/64 dev eth0 proto kernel metric 256 pref medium fe80::/64 dev eth0.11 proto kernel metric 256 pref medium fe80::/64 dev eth0.
41.
▲
by
Dagger2
4mo ago
They'd be more common if browsers didn't completely break handling them.
42.
▲
by
Dagger2
4mo ago
The most amazing part about this is that Microsoft used a public domain for it and then lost the domain registration .
43.
▲
by
Dagger2
4mo ago
I've never really got why this is so complicated. My interpretation of [] syntax in URLs is "[ enters into a raw address mode", "] exits the raw address mode" and "the characters between the brackets are opaque
44.
▲
by
Dagger2
4mo ago
Previously on HN: Parsing IPv6 Addresses Crazily Fast with AVX-512: https://news.ycombinator.com/item?id=48245311 Parsing IPv6 Addresses Crazily Fast with AVX-512: https://news.ycombinator.com/item?id=482613
45.
▲
by
Dagger2
6mo ago
I intended the quoted part to mean something like "they did consider adding extra octets to v4 addresses and setting those octets to zero to mean v4". It's not like they weren't able to come up with that idea. It's
46.
▲
by
Dagger2
6mo ago
Ah, okay. In that case v4 doesn't have a firewall by default either. That's precisely why routers come configured with a firewall that blocks inbound connections from the WAN -- because the protocol itself doesn't have a fire
47.
▲
by
Dagger2
6mo ago
> It looks like doing this has the disadvantage that it erases the baked-in "This shouldn't be used for global-scope transmissions. I tried with the kernel-generated LL and my kernel does attempt to use a link-local source when
48.
▲
by
Dagger2
6mo ago
Of course you can say the same for v6. Blocking connections that go from WAN to LAN by default has the same effect on both protocol families. If you assume that having the appropriate firewall rule to do that is the default then inbound con
49.
▲
by
Dagger2
6mo ago
Yup, repeatedly. It's true that almost everything comes with a firewall rule that blocks new connections from the WAN to the LAN, so in practice these connections will be blocked on most things by default. But they come with this rule
50.
▲
by
Dagger2
6mo ago
It will, and if you test it then it does. NAT doesn't apply to inbound connections if you don't have a matching port forward rule, so it kind of doesn't matter how NAT works here. This is pure routing, not NAT.
51.
▲
by
Dagger2
6mo ago
But mine was that you don't need to do this as an intellectual exercise, because we got basically all the things you're asking for. We have address extensions in v4 packets, we have NAT to help with partial upgrades, and we have a
52.
▲
by
Dagger2
6mo ago
Yes, of course they were all parallel protocols -- because your problem here is that v4 doesn't _have_ variable-length addresses. It's trivial to imagine a version of v4 that does, but that version would also be a parallel protoco
53.
▲
by
Dagger2
6mo ago
Real in what sense? Lots of people have come up with alternate L3 protocols for the Internet. For example, check out [1] which goes up to 999.999.999.999.999, or [2] which gets updated with some typo fixes every 6 months each time it's
54.
▲
by
Dagger2
6mo ago
> Actually, what's up with your link-local addresses? They have really odd flags on them. They were probably configured by one of the fancy network config daemons (systemd-networkd, dhcpcd or similar). They like to take over RA proc
55.
▲
by
Dagger2
6mo ago
> we could have baked address extensions into the existing packet format's option fields and had a gradual upgrade that relied on that awful bodge that was (and is) NAT We did and do have this. I wrote about the option fields part i
56.
▲
by
Dagger2
6mo ago
I said "whenever anybody says it's bad and tries to come up with a better alternative, they end up coming up with something equivalent to IPv6", and that's what you did here. And as predicted, it was 6to4 you reinvented.
57.
▲
by
Dagger2
6mo ago
(Long post was long so I split it into two short... shortish... uh... here, enjoy two walls of text instead of one.) > I am not an IPv6 hater...just giving observations that when you introduce a breaking change, and add additional fricti
58.
▲
by
Dagger2
6mo ago
The getent output shows that addresses are being sorted properly for a machine without v6. apt-get and other properly-written software will try the addresses in the order listed there, i.e. all v4 addresses first and only then the v6 addres
59.
▲
by
Dagger2
6mo ago
It'll prefer ULAs when connecting to hosts without A records. Programs will use ULAs if you connect to an IP literal, or if connecting to the A records fails. Also, Linux/glibc will prefer ULAs if you have a ULA assigned to the ma
60.
▲
by
Dagger2
6mo ago
This part is exactly the problem I was talking about: root@ubuntu-server:~# apt-get update ... Could not connect to security.ubuntu.com:80 (91.189.92.23). - connect (111: Connection refused) Cannot initiate the connection to securit
More ›