98% of sites on Cloudflare now use IPv6
blog.cloudflare.com
blog.cloudflare.com
The linked site [1] has a download of 134k hostnames. Filtering for the Cloudflare prefix, 2400:cb00:2048, there are still plenty of sites sharing an IP. For example, www.monolith.agency (a design agency) is on the same IP as www.bobshouseofporn.com (porn).
Maybe the same company hosts both websites, and it's not Cloudflare's issue, but that seems unlikely for a US porn site, Quebec design agency, Brazilian health site and Spanish programming site.
Google have 13,000 sites on the same IP, 2607:f8b0:4005:808::2013, looks like Blogger.
[1] http://www.employees.org/~dwing/aaaa-stats/
Something like:
egrep --only-matching 'IPv6.+? ' ips | sort | uniq -c | sort -n | grep 2400:cb00:2048"Sorry, your website is blocked by default on all ISPs. It's to protect the children."
monolith.agency has address 104.28.8.19
monolith.agency has IPv6 address 2400:cb00:2048:1::681c:813
Notice that the IPv4 address is embedded in the last 32 bits of the IPv6 address. I would assume that this allows both addresses to be generated from the same configuration, rather than trying to keep two copies in sync.1. Make me solve it only once every X minutes/hours.
2. Make the defaults to be one step down in security, probably most webmasters don't want to block legitimate people using VPN.
3. Make it dynamic, so only those under suspicion have to do it. And consider being using a VPN NOT to be enough suspicion for it.
Right now I have to choose either to:
- Compromise my security: don't like it now, cannot do it when I start working with the new company I'm going to work
- Solve hundreds of "I'm not a robot" per day
Maybe apply some netfilter or proxy magic to push traffic to port 443 over the wifi and everything else through the vpn?
Any clue why they only crawl via ipv4?
Are you proposing that Google should crawl ipv6-only web sites? And then serve those results to whom, exactly? (I don't think there is any reliable way of knowing whether an HTTP client that's connecting to you via ipv4 is also capable of ipv6?)
I'm just wondering why Google doesn't seem to use ipv6 where available.
If both v4 and v6 access is available, what is the extra value of doing the indexing using v6 rather than v4? (The indexing process itself would add very little to the global usage of v6, comparatively speaking.)
And Facebook seems to prefer ipv6, I guess there's a reason for that.
http://www.theregister.co.uk/2016/11/11/facebook_zuckerberg_...
> Another effect of the default policy table is to prefer communication using IPv6 addresses to communication using IPv4 addresses, if matching source addresses are available.
If even Google with its huge network of crawlers doesn't see the need to communicate via ipv6, why should there be any demand?
Send XHRs to a v4 subdomain and a v6 subdomain, check which requests succeed.
I guess they could also move this checking to the user agent (because they control Chrome) to have the check performed before the user is actually waiting for results and milliseconds matter. Introduce some ugly but pragmatic HTTP header, like "Accept-IP: v6". :)
So, this way they could serve v6-only results reliably to clients that can access either both v4 and v6. (People who can only access v6.. that must be a very special kind of people.)
There is a great use-case for IPV6 for IOT where each device gets its own IPV6 address. IPV6 addresses are appearing more like MAC addresses at this rate as IPV6 is not exhausted yet.
The world will be a completely unrecognizable place when this is even a slight concern.
But seriously, there's an astronomical # of addresses in IPv6. You're probably right that if we ever exhaust that space, we'll probably be communicating between planets by then.
And they were right!
Do you really want your IOT devices to be directly addressable on the internet? It's my understanding that having devices behind a router is safer. I go a step further and disable UPnP on my routers and everything still 'just works' including network printing.
I have a gigabit fiber (to the home) connection which terminates at a device with 4 Ethernet jacks. They all work, I've tested connecting directly to them with a laptop, but I plug a router into it and all devices connect through that router instead. It's the 'stateful firewall' aspect of using a router that I want for improved security. https://en.wikipedia.org/wiki/Stateful_firewall
You supposed to control access with firewall, and controlling security is much easier when computer/device has a routable address.
Though, IoT devices should probably be restricted of any Internet access based on their security track record (but again, this is orthogonal to being directly addressable).
I still don't see a reason for the average consumer to have a static, reachable IP for their devices. I see privacy concerns but no advantages.
https://www.google.com/search?q=site:ipv6.whatismyv6.com
"You are connecting with an IPv6 Address of: 2001:4860:4801:6::1f."
I'm still trying to figure out how to set up static IPv6 so I can access my computers at home without a NAT, but it's very convenient otherwise!
All Compute Engine networks use the IPv4 protocol. Compute Engine currently does not support IPv6. However, Google is a major advocate of IPv6 and it is an important future direction.
He forgot to add that this only applies to dual-stack hosts...
So an IPv4-only website should not incur any delay.