All quiet in the IPv4 Internet?
blog.apnic.net
blog.apnic.net
When we were assigning IP addresses for the dorms at Berkeley, we gave every dorm a /24, and then reserved the first 50 IPs for "future use" and "internal use". Most of those were never used. And unless 200 people signed up per building, some of the top end was missed too.
My understanding is that they have since fixed this on the wifi since many people bring three or four devices now, but the hard wired connections are still poorly utilized.
Much like your setup the first 25 were reserved. In addition anything past that was rate limited. I recall anything past that was ~10->25Mbs. Going into the lower range though got around 500Mbs. I know similar stories from other state employees. The times when IPs were more prevalent.
Which is, of course, how it's supposed to be. I used to host a website from my dorm room.
Every device on the Internet should have a public IP address!
We don't need every network-connected device, with all their flaws accessible to the world. Unfortunately, IPv6 will not help us there.
In a perfect world you'd get your ipv6 prefix from your ISP, and have your firewall white list specific outbound suffix addresses.
If you need topology privacy you'd shuffle your /64 every once in a while.
(The IPv6 solution here is Unique Local Addresses, where fdXX:XXXX:XXXX::/48 are all permissible local networks, and if you use a decent RNG to generate the 40-bit number XXXXXXXXXX, you're unlikely to hit a collision with any other actual, active site, let alone one you might want to route to.)
SixxS even runs a registry for ULA prefixes: https://www.sixxs.net/tools/grh/ula/
Put in your MAC address, get back a ULA. Then register it so that in the future if someone happens to have the same mac address you don't accidentally use the ULA.
I happen to be of the opinion that /dev/urandom is more likely to comply with RFC 4086 than the suggested algorithm, but I may have an unfairly low opinion of the distribution of timestamps and MAC addresses.
Of course, IP address might not have the same physical boundaries, but instead they have organizational barriers, which can be equally tricky ones, if not trickier.
The bottom line is that we suck at resource management and distribution at nearly every field.
If it cost $1/year*address most entities with a /24 or /22 would barely notice, but HP might decide that they don't need 33.5 million IP addresses after all.
IPV6 is massive in part so we can get back to sensibly slicing up subnets and keep routing tables small.
Recall AllAdvantage.com, which had a pyramid-scheme style payout for installing spyware on your computer and browsing the web. Payout capped after browsing 48 hours per month with the spyware on. One of the guys trimmed down Win95 and bought a student VMWare license. A gig of RAM was about $4k at that time. He scripted everything up so that at boot time, the Win95 guest would mount an SMB share from the host, remove the first line from a shared CSV file containing fake account details, and proceed to register a fake account at AllAdvantage with him as the referrer, and randomly browse for 48 strait hours (using a local caching web proxy) like a meth head on a bender, and then shut down. Monitoring software on the host would see the shut down VM and spin up a new one with a new IP. The VM IP assignment code hopped all over the /16 to reduce suspicion. AllAdvantage went out of business before it failed to ban him. 30 VMs ran simultaneously. In a 30-day month, he had 450 VMs run, and got just under $2 in referral fees per VM. The fake accounts never made enough money to get cheques mailed to their fake addresses, so AllAdvantage didn't get returned mail or un-cached cheques, but he was still very surprised that he never got caught. He figured he had less tan 50% chance of making it 4 months and paying off his 1 GB of RAM. He wasn't really doing it for the money, but saw it more as a kind of cat-and-mouse game.
He was always doing stuff like that, enjoying being the mouse in a cat-and-mouse game, with almost none of it for money. He just got a kick out of seeing people doing silly things and demonstrating the silliness of their ideas. You can get into a fair amount of mischief with a /16, which is presumably why now they only route the first /24 to the house.
He also had a poker bot running for a while (on sites that didn't mention bots in their ToS) and kept complete logs of cards seen and player actions. There were plenty of players who could beat his bot, but his bot would refuse to sit down at tables with players with too good records against it. With three credit cards running three accounts, that poker bot was paying his rent for the first year or two after he moved out of the fraternity house.
He told me a couple of times that he'd give me FTP access to his logs, but never got around to it. When I heard that RC4 had a bias in its key schedule, I thought a bit about how to make an unbiased shuffle, and figured that a lot of people would use a naive biased shuffle. I was curious if my friends poker hands would show such a bias. I also wanted to check against the Perl, GNU C, MS C, and Visual Basic built-in rand() implementations, checking for srand(time()) and srand(time()^getpid()). (Perl still ruled the web in those days.) Later, an academic paper came out explaining that the most common poker site software was written in Pascal, and had both flaws I wanted to look for (plus another flaw due to an off-by-one error in the author's understanding of the Pascal Random() API.) I didn't think to look at popular Pascal implementations' pseudorandom number generator implementations, so I doubt I would have found the predictable prng seeding flaw via my friend's logs, but there's a chance I would have. I'm not sure how much an edge in poker the shuffle bias flaw gives, but I imagine it's tiny.
Paper: http://arxiv.org/pdf/1606.00360.pdf
Edit: If you have some time and like high quality networking commentary (aka 'rants'), I strongly recommend to listen to this packet pusher episode with Geoff Huston, where he plays devil's advocate for IPv4.
http://packetpushers.net/podcast/podcasts/show-275-future-of...
Video: https://ripe68.ripe.net/archives/video/131/
Slides: https://ripe68.ripe.net/presentations/156-2014-05-12-bgp2013...
[EDIT] In another talk he indicates where you can get that kind of data on the Internet address space: http://www.routeviews.org/
An example of a real world effect is one of the largest fibre ISPs in the U.K. They are the only provider afaik to assign users internal IPs, which is then NAT'd. This then gets NAT'd on the router again - double NAT, woohoo! :) I know they desperately tried to get enough public space for all their customers, but were unable to buy a large enough space for it, so were forced into this position.
Interestingly, the U.K. has at least two /8 ranges that aren't even advertised on the public internet, owned by MoD (25/8) and Department of Work & Pensions (51/8). That's 32 million addresses unused as far as anyone can tell from the outside.
Are you able to name the ISP?
I think BT's cheaper broadbands do this, for one.
Fortunately some of those can un-NAT you if you ask politely.
And they usually call it "web access" or something similar, never speaking of an "Internet connection". Which is what it is, a way to access websites and usually not much else.
Maybe some ISPs will implement the Port Control Protocol [1] at some point, which would allow port forwarding with the DS-Lite NATs.
Sadly, that's only half correct. Yes, nat traversal usually works to establish connections. But in practice port mappings are not necessarily the same thing as NAT table entries. If your p2p application contacts a lot of endpoints, even from the same source port, this can eventually lead to saturation. At that point you'll get packet drops and ICMP errors.
In other words, on some aftr implementations p2p can lead to resource exhaustion, leading to a pretty bad ipv4 experience.
> Maybe some ISPs will implement the Port Control Protocol [1] at some point, which would allow port forwarding with the DS-Lite NATs.
Some already do. The CPE can forward local mappings to the AFTR.
Webpass is an example of a "good" ISP that does this. It's my only qualm with them. Besides that they are outstanding. IPv6 works great.
I'm of the opinion that this is probably the future for all residential internet users - ISPs that put everyone on an IPv4 NAT so that grandma can still get her hotmail and yahoo, while hopefully providing unencumbered IPv6 access for everything else that requires a real network connection.
Unfortunately this still screws me over because nobody who I might want to connect to my home network has IPv6 yet.
It would help me a lot if all (mostly proprietary) software vendors would finally start supporting IPv6.
[1] http://arstechnica.co.uk/information-technology/2016/08/sky-...
1: http://www.ipv6.org.uk/wp-content/uploads/2016/07/UK-IPv6-Co... 2: http://www.ipv6.org.uk/blog/
> so were forced into this position.
Well it's not like they could have deployed IPv6 (with NAT64) instead (/rant). Most ISPs around here (France) provide IPv6, some of them since like 10 years ago.
Not supporting IPv6 today is just ridiculous, and I've jumped ship† regularly during those 10 years, explicitly mentioning IPv6 (lack thereof or unsatisfying support) as the reason when cancelling. I understand that not everyone has this chance (due to choice availability) to pressure their ISPs, but seriously they weren't forced: they dug themselves into this hole.
† One of them even dropped a previously perfectly functional IPv6 support for me purely due to a contract update and argued it wasn't possible to bring it back. Seriously.
As mobile devices migrate to IPv6, the address space problem should be less. It's too bad that most mobile devices don't have permanent IPv6 addresses - more peer to peer applications would be possible.
http://www.worldipv6launch.org/major-mobile-us-networks-pass...
Discussion: https://news.ycombinator.com/item?id=12338993
Now everybody's pretty much out. So I don't know DO's blocks, but very likely if they're running out they're having to buy more. Depending on how they cut it up a /16 -- I know they have at least one /16, because it came up here yesterday -- can serve at least 60,000 droplets or so.
I thought it was interested that only a couple of years ago paying for IPs was very much against policy and now they even have pointers to brokers on the APNIC website.
Selling things for what the market will bear is the only way we've managed to figure out to fairly provide resources to those who want them the most.
Bah.
mostly affected people that were getting addresses for "free".
There are still a lot of "free" IPv4 addresses out there.
The problem is the cost of IPv4 addresses is not evenly applied. There's hoarding by some early adopters. E.g. I see that Stanford gave back its original /8 allocation, but MIT did not.[1] And why is Prudential Securities still sitting on a Class A block?
If MIT or Prudential had to pay 16,777,216 * $10 per month for their IP addresses, you can bet that most would be returned within 48 hours! Even if they had to pay only $16 million per year, you can bet they'd return most of those addresses.
A true capitalist solution to the IPv4 "shortage" never happened. That's why you have the current situation. Some organizations are sitting on huge swaths of unused addresses, others (the free market) are forced to pay $10 per month.
There are about 4 billion possible IPv4 addresses (sure, some are reserved for e.g. multicast, but those could have been reclaimed). If each and every IPv4 address cost $10 per month, there would never have been a need for IPv6. Even if each and every IPv4 address cost only $1 per month (about $50 billion per year in aggregate), there would never have been a need for IPv6. Or at least IPv6 could have been postponed for a while and "done right".
[1] https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addre...
IPv4 markets are a dead-end and are no substitute for a real solution.
For reference, there's about 630k active BGP entries, with 50k more per year. It would only accelerate the death of those routers by six months, 24k entries, to split up everything larger than /16.
If you want to compare to real estate, it is more like building a completely new city in the middle of nowhere. Initially the costs are high because you have to build new infrastructure. Initially, there is nobody there so there is no incentive to move to the new city.
As the new city gets popular, everybody who has real estate in other cities may feel compelled to get real estate in the new city as well, but they don't have to give up their old property.
IMO Postel's allocation of IP addresses can be rationalized from a capitalist viewpoint as a form of homesteading. Some people end up with windfall profits three decades later, but it's a small price to pay for a peacefully functioning market. Owning a $100M asset that's underutilized is already an economic incentive to free up addresses (just don't tell my company); a Georgist property tax on IP addresses would provide even more incentive but it would also likely cause a revolt.
Since there are going to be 4B devices on the Internet soon if not already, talking about "there would never have been a need for IPv6" seems to imply the existence of an address-less underclass.
Yeah I really screwed up on that one!!!
I got confused because often the retail price is in that range. E.g. Comcast Business will give you a static IP for $20/month.[1] But reading further, they will give you 13 extra IPs for $40/month, so clearly I didn't think it through.
[1] I can't link directly to that information on Comcast's site, but it can be found here by clicking on Static IP pricing. https://business.comcast.com/internet/business-internet
I "rent" a static IP from my ISP (Internode) because IPv6 still breaks random devices on my network (Xbox One, I'm looking at you).
Although in this case becoming an ISP isn't impossible, it's certainly out of my reach.
Once you've done that, buy transit from a provider in your data center or office building, set up a BGP speaker (Quagga, BIRD, GoBGP), and announce your IP space (has to be at least a /24 for IPv4, and a /48 for IPv6).
This whole process can be done in under a month.
To sell internet connectivity here you must have a carrier license from ACMA. I've heard that it costs ~3k to get one. Which makes setting up an neighbourhood ISP just expensive enough that no one bothers. (this is on top of all the normal costs you mentioned)
- Transit (500Mbps on a 10G port can be had for ~$300/mo in major DCs)
- a /24 or larger IPv4 prefix (Can be free/cheap from your transit provider) or buy one from a broker (usually only /22s and up, @ $6-12/IP)
- a /48 or larger IPv6 prefix (Usually free/cheap from your transit provider) or you can get one from ARIN for ~$2000/yr (for a /32)
- an RIR membership (< $500/yr)
- an ASN (~$500 from your RIR + $100-200/yr)
source: I've done this myself, and helped others do it.
People have asked me my thoughts on IPv6 adoption, and I have to honestly say I'm pretty bearish on IPv6 being quickly adopted. I try to enable IPv6 on all my friends' routers, but even today, many routers, though they support 6 (notable exception being DD-WRT.. WTF), don't enable it by default, which means they don't enable the dual-stack configuration needed for transition. People then place these routers in a dusty area under their computers or behind their couches, where they sit, basically untouched, for 10+ years until they blow up and require replacement.
The people I've talked to that happen to control a lot of IPv4 addresses tell me that even at the current ~$10-12/ip strike price, nobody is interested in selling because the IPs are more valuable to them for use with datacenters and leasing than for selling them at auctions. And nobody's putting pressure on the people that own huge IPv4 subnets (and I genuinely doubt use all of it) to start splitting them up and releasing them. Not to name names, but the original developers of the Internet come to mind (huge research universities like MIT).
As such, I'm expecting the price of IPv4 addresses to increase substantially over the next 10 years, and I'm really not anticipating that price to drop for longer than that even. Because at the end of the day, if you want to support everybody, you need 4. And even today, dual stack is not the default option (despite ISPs like Comcast being ready for it). IMHO, If you need IPv4s for something like an Anycast network or a hosting service, the time to get them is now.
As for IPv6 transition, the best way to improve this problem is to do your part to get ready for it: https://blog.apnic.net/2016/05/04/you-have-ipv6-turn-it-on/
In my neighbourhood in Canada, looking at the wifi routers, 80% of my neighbours are running the default configuration of their ISP.
Also, people need to replace their modems more often than we think. In the past 5 years we had the switch from 5mbps DSL to FTTO (25-30mbps) and now the switch to FTTH. A neighbour switched from 5mbps DSL to FTTH, for basically the same price (but the same ridiculously low monthly quota). He's using FTTH for an empty house to connect his alarm system to the monitoring company. In 6-12 months (rumours were 2017-Q2 unless they * again), when Bell finally decides to enable IPv6, that network will be IPv6-enabled.
If your grandma installs ElasticSearch on her box, she won't get pwned because it listens on 0.0.0.0 on her laptop and she didn't get the latest updates and is vulnerable to RCE.
One would hope that SoHo routers that ship with IPv6 support are configured that way by default so they mimic the apparent behavior of NAT (though NAT is not, and is less effective than a firewall).
NAT is an ugly hack. Uglier yet when you remember that the internet is not only TCP.
Let me rephrase it correctly: implementing that uses less memory than IPv6 NAT.
Yet, all the practical implications from my previous comment are gone. This correct version is useless.
I've tried calling and public shaming Wide Open West to no avail. They don't seem to care at all. Time Warner Cable is the next fastest ISP (and they do support IPv6), but they want almost the same price for 1/12th the speed (600mbit/s WOW vs 50mbit/s TWC); so I begrudgingly stick with WOW anyway =(
And all service websites could jump on the ipv6 bandwagon without hiccups.
By encoding, I mean every ipv4 segment would be encoded as a hexadecimal set and that would be merged into an ipv6 category under a special prefix.
It can't, period. Ipv4 devices cannot route to ipv6.