Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
241.
▲
by
Dagger2
9mo ago
HTTP has the leeway to do that because they have an easier technical job deploying updates. If they only got one shot at changing HTTP, do you think they would have tied TLS to HTTP/2 or given up on HTTP/2 altogether?
242.
▲
by
Dagger2
9mo ago
v4 supports extension headers and over a thousand bytes of arbitrary payload so if the only thing you needed was a couple of bits in the packet, there was never any issue with finding them. The problem is that you can't use those bits
243.
▲
by
Dagger2
9mo ago
It's not that simple at all. For one thing, having a v6 network doesn't mean you can't have a v4 network. You can run v4 in exactly the same way you currently do, with exactly the same software, and it'll work no worse t
244.
▲
by
Dagger2
9mo ago
If you look hard enough you will find some, but it's not common. Half of the Internet is using v6. If a lack of firewall was as common or as dangerous as people think, the supposed security disaster would have already happened. It hasn
245.
▲
by
Dagger2
9mo ago
Yeah, you really can do that. The only caveat is that if you're using RFC1918, it greatly limits who can connect -- only your ISP, or another customer connected to the same shared VLAN your router is, or anyone that can physically at
246.
▲
by
Dagger2
9mo ago
That's a valid criticism of Proton VPN, but if it works even just on Linux it's sufficient to demonstrate that v6 doesn't eliminate the possibility of VPNs.
247.
▲
by
Dagger2
9mo ago
And because it's a layer 7 thing, so it only required updating the server and client software, not the OS... and only the client and server endpoints and not the routers in between... and because we only have two browser vendors who be
248.
▲
by
Dagger2
9mo ago
Proton VPN? And no, proxies were either never obsoleted or they were obsoleted by routing. Nothing to do with v6.
249.
▲
by
Dagger2
9mo ago
Wat? It, um. No, it doesn't do that. You can use proxies and VPNs in v6, and you're about as trackable by IP as you are on v4.
250.
▲
by
Dagger2
9mo ago
v6 has nearly 3 billion users. How is that abysmal? We've never done something like the v4->v6 migration before, on this sort of scale. It's not clear what the par time for something like this is. Maybe 30 years is a normal a
251.
▲
by
Dagger2
9mo ago
I think you've actually reinvented 6to4, or something morally very close to it. Each v4 address has a corresponding /48 of IPv6 tunnelled to it. The router with that IP receives the tunnelled v6 packets, extracts them and routes t
252.
▲
by
Dagger2
9mo ago
It keeps getting repeated precisely because it isn't gaslighting. And yet we still see people claiming that NAT is security. The only reason those networks aren't exposed to the whole Internet on v4 is because they're using
253.
▲
by
Dagger2
9mo ago
On company/university wifi networks, v6 cuts your v4 DHCP pool address usage by something like 70%, without hurting connectivity to v4 hosts.
254.
▲
by
Dagger2
9mo ago
Really? I get somewhere in the region of none to barely any, depending on the server. I mean, yes, you'll get a constant stream of them on IPv4 , but why would you run a server on v4 unless you absolutely needed to? The address space
255.
▲
by
Dagger2
9mo ago
NAT doesn't act as a security perimeter, and not having NAT doesn't mean that your devices are exposed to the Internet. NAT is about dealing with address space shortages, not security.
256.
▲
by
Dagger2
9mo ago
You'd think it would be long enough for people to realize that v6 is backwards compatible! Yet no, here we are, constantly dealing with people making the same damn claim that it isn't every single time a v6 story is posted. v6 i
257.
▲
by
Dagger2
10mo ago
Then the value is clear, isn't it? The value is that it gives you the ability to run a service. Maybe you don't want to do that today, which is fine -- you can simply not make use of the ability. If you ever change your mind, it&#
258.
▲
by
Dagger2
10mo ago
A quick workaround for that is to use one of the DNS servers from https://nat64.net/ . There are also people running reverse proxies specifically for GitHub, e.g. https://danwin1210.de/github-ipv6-proxy.php .
259.
▲
by
Dagger2
10mo ago
You can also e.g. monitor certificate transparency logs for hostnames. But the difference is that without NAT, knowing about one server on the network doesn't automatically give you the IP for every other accessible server on the same
260.
▲
by
Dagger2
10mo ago
That's what I meant. On v4, it's trivial to find every server that can be reached from the Internet, whether it was intentional or not. It's not so trivial on v6.
261.
▲
by
Dagger2
10mo ago
But v6 did do what you're describing here? They didn't use the reserved bit, because there's a field that's already meant for this purpose: the next protocol field. Set that to 0x29 and it indicates that the first bytes
262.
▲
by
Dagger2
10mo ago
Nope, you're on a LAN, and usually the router has a firewall that blocks inbound connections by default. Some OSs (like Windows) also have their own by-default firewalls that block connections from hosts on different networks out of th
263.
▲
by
Dagger2
10mo ago
v4 networks commonly only get one IP for the whole network, and people use NAT with port forwarding to make inbound connections work. With this setup, an attacker only needs to scan the 65536 ports on the router to exhaustively enumerate ev
264.
▲
by
Dagger2
10mo ago
If your low-level networking code (I assume you mean BSD sockets here) is correct, it shouldn't even need to be aware of v4 or v6. The BSD socket API is designed so that the addresses are in an opaque data structure that you just pass
265.
▲
by
Dagger2
10mo ago
Well, okay, show us how to follow those instructions then. "the :1 is short for :0001 basically" is easy enough: you get 2001::0001::0001. Then "just put that bit at the very end" -- but which bit? If it means the "
266.
▲
by
Dagger2
10mo ago
Random guess: PMTUD? Like on v4, some people fuck up their PMTUD and are incapable of realizing or fixing it, so you have to have some kind of workaround. If setting your client machine MTU to 1280 (`ip link set mtu 1280 dev eth0` or equiva
267.
▲
by
Dagger2
10mo ago
It's not from systemd though. glibc's NSS stuff has been around since... 1996?, and it had support for lookups over NIS in the same year, so getaddrinfo() (or rather gethostbyname(), since this predates getaddrinfo()!) have never
268.
▲
by
Dagger2
10mo ago
Hm, but systemd-resolved mainly doesn't provide DNS services, it provides _name resolution_. Names can be resolved using more sources than just DNS, some of which do support link-locals properly, so it's normal for getaddrinfo() o
269.
▲
by
Dagger2
1y ago
So... why? The article only mentions "the Medicube installer, based on OpenStack’s Ironic, “created completely wrong configurations for IPv6.”" and "Certain Dell BIOS implementations lacked complete IPv6 boot support, and whe
270.
▲
by
Dagger2
1y ago
And it is. That's exactly how deploying v6 works. In fact, even the packet format stays the same, which means you don't lose the ability to talk to peers that require the old format -- people would do more than hesitate if that
More ›