Aussie ISP gets eye-watering IPv4 bill, shifts to IPv6
theregister.co.uk
theregister.co.uk
That's even worse. I read a definition of Internet long back which I vaguely remember
A network of devices where each device is assigned with unique IP address so that they can communicate with each other. No central party is needed for two devices to connect with each other!
This always fascinated me. But NAT breaks that definition or was the definition wrong? It no longer holds true. IPV6 is the only hope. I've wrote more about it here
https://www.ankshilp.in/post/the_broken_promise_of_internet/
I have other hopes to get IoT more secure. Open source firmware, for starters. Support contracts where you don't buy the hardware but buy a working (and insecure isn't working) device.
The problem with IPv6 is that it is a chicken-egg problem. Those who get CGNAT plus native IPv6 are part of the unfortunate bunch who are not using native IPv4 (and therefore miss out on certain IPv4-only services). Meanwhile, the IPv4-only services are causing issues for CGNAT. The logical conclusion is that everyone who currently offers IPv4-only should (and should've been) focusing on adopting native IPv6 dual stack. The continuous procrastination, out of greed and egocentric thinking, is what caused the current situation in the first place.
My ISP tried to shove CGNAT with native IPv6 through my throat. My modem was unstable. BitTorrent didn't work well anymore. I could not use services over LTE anymore (my LTE provider, actually same provider as my cable, used IPv4-only back then; don't know now). I relied on that to work. So they gave me what I had before: IPv4 only. Why not dual stack first?
Though it doesn't give any protection against local scanning.
This is security by realistic approximation of compute capacities and basic probability math.
Aka. good security
Such as github, for example. Something that really surpised me when I setup an IPv6-only virtual machine and then went to clone some projects to setup the host.
People on HN like to say that "security through obscurity" is not security at all. But there's a reason that the military puts its secret stuff out in the middle of nowhere.
Truth is, right now iot devices are protected by nat (your router) and maybe cgnat too (if your isp is good enough and provides that service). With ipv6 those devices will lie exposed to the wan. I hardly see how that’s an improvement.
Also don’t trust regular devices. Windows disabled privacy extensions because of a bug (not sure if it’s fixed already). https://social.technet.microsoft.com/Forums/windows/en-US/57... — I trust my router’s nat much more: it can’t be disabled because of a bug ;-)
You're planning to just get rid of your firewall when you don't need it for NAT anymore?
Some machines’ TCP stacks can be crashed with a single packet. Some IoT devices can be added to botnets. Some get patched.
I think you are blaming too much on ipv6, much of which exists today in the ipv4 world.
You can always set up your router to be a stateful v6 firewall and block wan-to-lan accesses you don’t like or want, much the same way NAT works today, on an outbound-before-inbound model.
Assign themselves addresses randomly ("privacy addresssing") OR Assign themselves addresses based on their EUI64 (a hardware unique ID burned into them at the factory, as in MAC address)
It's feasible to try scanning a known /64 for addresses based on a specific manufacturer's EUI64 block. Maybe Sony brand smart TVs for example. It'd take a bunch of traffic, and thus time, but it could be done.
But it isn't feasible to try scanning the whole /64 for random assigned addresses. You're going to need to send _many terrabytes_ of probe messages to that network. Even over a gigabit network link inside a data centre that might take hours and cost a not insignificant amount of money, to a home or office network it's going to flood the system (causing somebody to make a support call) and take weeks to execute.
Ignore the network practicalities and think just about the economics. Suppose it costs me one millionth of a penny to scan an IP address. I can scan the entire IPv4 Internet for less than $40.
But on the IPv6 Internet, at that price $1 billion only scans me one /64 network. My home has several of those. If you could somehow steal my entire net worth by breaking into a device on my network but first you had to scan all the addresses you're _losing_ money on the deal.
Masquerading NAT is not a security feature. You need state tracking to build a masquerading NAT (so that your residential gateway knows which internal machine to route reply traffic to), and once you have state tracking, you can build a stateful firewall. It doesn't matter which version of IP is carrying the traffic, it still has to go through your gateway before it can get to you, and the gateway can do all the policing you want it to.
If you want certain services on your internal machines to be reachable from the outside over IPv6, you open up that service's port in your gateway's firewall configuration, which is ... exactly what you do for IPv4 too.
OpenWRT (a popular third-party residential gateway firmware) has a stateful IPv4 and IPv6 firewall and DHCPv6/PD support out of the box. You flash it, and if your ISP provides IPv6, you're done. If they don't, you can set up e.g. a 6in4 tunnel with Hurricane Electric, and you're done.
It's not complicated. Yes, you have to learn some things, but they're the same things you had to learn when you were starting out with IPv4.
Moreover the wasteful norm to rely on /64 subnets and other, similar more practical than privacy-conscious design decisions diminish the potential to stay pseudo-anonymous.
the following operating systems use IPv6 privacy extensions BY DEFAULT:
All versions of Windows after Windows XP
All versions of Mac OS X from 10.7 onward
All versions of iOS since iOS 4.3
All versions of Android since 4.0 (ICS)
Some versions of Linux (and for others it can be easily configured)
For routers, then I have no way to tell. But I would be surprised if stateless addressing wasn't the default on the vast majority of retail routers.[1] https://www.internetsociety.org/blog/2014/12/ipv6-privacy-ad...
Despite IPv6, you still need CGNAT, because not every site/service is available over IPv6. It's fine as long as it's a stopgap, not the main solution.
- v6<->v6 does not require NAT
- v6<->v4 requires NAT but does not require your v6 device also have a v4 address
Until the v6<->v4 is no longer needed you will always have some form of NAT as there aren't enough addresses to give everyone a v4.
NAT64 is better than CG-NAT (single NAT vs double NAT) and they both solve the same problem.
Since most consumers don't care, and CG-NAT bandaids the problem I don't see how the market will be motivated to spend the time/money to bring us IPv6. We're probably going to be stuck with shitty bandaid solutions for a while
Very slow internet at my AirBnBs, generally very poor WiFi availability and speeds in public, the co-working space I’m in (that is otherwise excellent) is a similar speed to my home connection in London.
Above all, latency makes some websites considerably less pleasant to use, and SSH to most places is painful. I know that’s not something the local market can necessarily fix though.
This is not visa advice.
I'm one of the few lucky ones with FTTP which gets me close to 100mbit speeds. But as soon as I have to connect to a server outside of Oz I am pretty much back to (high) ADSL speeds. Latency to the US and Singapore (the two closest international backbones) is around 150-200ms. It's around double that for Europe. At peak times those backbones get very congested.
Funnily the only country I've been to that has faster and more consistent 4g was Japan.
I'm glad other people are having more luck with them.
For your own infrastructure, re-using the same addresses over and over, as in a CG-NAT scheme, makes it far easier for mistakes to happen and far harder to diagnose them. Your network becomes a fragile component that your own network engineers are frightened to touch, hurting your ability to compete as a network provider.
What's 10.20.30.40? Your own notes show you use 10.20.30.40 in Sector A of the country for a Cisco router but you also named a different device, a microwave transceiver in Sector B of the country 10.20.30.40 with the NAT supposedly separating the two. So packets supposedly "from" 10.20.30.40 could be the Cisco router playing up again, but they could be that microwave transceiver misbehaving, or they could be CPE leaking a customer's internal addresses into your CG-NAT network. If you try to "solve" this over the network you might end up talking to a "different" 10.20.30.40 than the one causing problems and make things worse.
Once you realise you want IPv6 internally, it's not a huge leap to realise that you might as well at least _offer_ this to customers too.
But until all web sites and services have migrated to IPv6, each smartphone still needs an IPv4 address, right? How does introducing IPv6 internally solve the problem you described, if a significant portion of traffic is still using IPv4?
[0] https://www.internetsociety.org/resources/deploy360/2014/cas...
For those smartphones, the other half of the equation is 464XLAT adaptors at the edge of your network. So no, the smartphones don't get given IPv4 addresses at all.
What happens there is split into two scenarios
1. User goes to Facebook. Facebook has IPv6, everything just works, no extra expense
2. User goes to My Cat Blog. My Cat Blog is IPv4-only but two layers of NAT64 make it work anyway [ Edited: My previous explanation here was just wrong. Sorry. Go read up on 464XLAT if you care, the phone needs to know what's going on here, so this is easier to deliver for a phone network than to home computers... ]
Case 2 isn't much better than CG-NAT for IPv4 services - your smartphone still doesn't have a "real" IPv4 address. BUT the ISP only needs to spend on it in proportion to continued use of IPv4. As sites big or small offer IPv6, their users automatically stop relying on 464XLAT for those sites and cut the costs of the equipment, whereas people who choose CG-NAT are stuck paying for that forever.
It's probably uncommon, but I wonder what happens if a T-mobile customer has an older 3G-capable device that doesn't support CLAT.
Whirlpool still exists also.
It seems that there has been a bit more adoption of it since I last checked which must have been a while ago, I'm surprised to see Telstra on the list!
I see lots of comments here about the merits of IPv4 v IPv6 v CG-NAT. That's all irrelevant. Aussie Broadband, like all Australian ISP's, provide their customers with a router configured to do NAT. If like me you don't want that your on your own you are better off purchasing your own gear. They won't support you, but at least you will be familiar with it. For some ISP's like Optus you have no choice - they've crippled the firmware in their routers so you can't change it.
Given the router is doing NAT they can use any carrier. And indeed, some Australian NBN ISP's use IPv4/DHCP, some use PPPoE and others were at one point doing QinQ and of course for pre-NBN ADSL connections it was ATM. Whatever, if your router is doing NAT it doesn't doesn't effect the customer one way or the other. IPv6 is a perfectly reasonable choice for a carrier in those circumstances, and for bonus points it means you can give your customer routeable IP addresses. (It would simplify my home setup considerably.) And it doesn't use a single paid for IPv4 for internal routing!
As for the hand wringing about the price - we've known this was coming for decades. We've figured out the solution and it's been available for purchase for years. They've almost certainly replaced their gear at least once in those years. They definitely replaced the routers they've handed out to customers because of the NBN rollout. If they didn't replace it with something IPv6 capable that's piss poor planning - particularly so because unlike most countries the NBN roll out gave Australian ISP's the perfect opportunity to do it.
Over a year ago, I decided to check out if I could do IPv6. And indeed I could! I am now getting a dynamically-allocated /64 block, which is used to make allocations to my desktop and my phone. From my perspective, IPv6 just works!
I hope, in two or so years, they come back to the same conference with a report of how much traffic has moved to IPv6.
At my employer we typically find IPv6 is 25-30% of our traffic. It’s better than I thought it would be but still not great. Much of that percentage is BT and Sky.
I do run an IPv6 tunnel out of my network to get access to the IPv6 internet and add my tiny bit of traffic to things and try and increase adoption, but I'd much prefer it if VMB just gave me IPv6 native. Not even sure they're working on it.
I have a BT Openreach fibre, and A&A give IPV6, and several v4s
I get patchy v6 connectivity. v4 is stable.