Amazon owns more than $2B worth of IPv4 addresses
dangoldin.com
dangoldin.com
If you want to see some sketchy shit, look deeply into what the VPN companies are doing.
When you “geolocate” an IP, you’re really just looking up the registered info for that IP’s ASN in the ARIN/RIPE database.
To comfort me, the CEO told me that they would go ahead and vest my 4% shares immediately for the new entity. The checks were still cashing and I didn't think much of it at the time. The company started making decent money about 1M annual revenue, but when profit sharing season came, I was not given anything but a 2k bonus. Then one day when nobody was in the office, I happened to see some documents on a desk that dissolved the company I supposedly owned 4% of and described a 3 tier ownership scheme (dreamt up by a creative lawyer on retainer)
There are many people that will prey on young talent, get them to build their startup infrastructure by promising them 250k+ salaries plus profit sharing. After you build the thing and server your use, be warry of the people suddenly wanting to "help" or "co-administer" the system. It's code for they are trying to learn how to run things without you because you are too expensive now that the system is online. Additionally, in more conventional contracts vesting options can cost you a lot financially if you don't calculate the taxes right.
In the end the CEO and VP got sued by both their former employer and the state of california. The CEO's wife then divorced him and took half of his money after he lost nearly 500k. Karma was a little mean in my opinion on that one haha
For those reading along, States like Wyoming (and New Mexico IIRC) are attractive for these kind of LLC fillings b/c they don't have a public Company Databases.
That, and cheap taxes/fees.
Looks like the data will only be available at the Federal level and not open to the public.
> In another transparency setback, the law also exempts some entities from the disclosure requirements, including domestic investment funds that are advised and operated by a registered investment adviser.
Sounds like the practice of using Registered Agents will still be allowed to continue.
So it's a new law that will change how the Feds can access and prosecute organized crime, which is a good thing, but won't help much in allowing us to learn who really owns that new shinny LLC.
Maybe there's some similar avenue here.
AFAIU, typical reason is to compartmentalize liabilities, but aren't you doing something sketchy if you have reasons to compartmentalize?
That's pretty much the whole business model of VPNs.
That, and secure encrypted traffic.
HolaVPN unapologetically does this too [2].
All of this is discounting the new-age dVPNs like Orchid (not quite the Tor replacement that was promised? [3]) and Mysterium [4].
[1] https://news.ycombinator.com/item?id=21664692
[2] https://news.ycombinator.com/item?id=9614993
It seems, however, that at least some VPN providers use their customers' bandwidth without their knowledge to route other customers through it. I'd say that qualifies as sketchy.
Although on an entirely personal level, I'm not a fan of stuff like going through VPN to use Disney+. I think people should ideally either not watch or pirate geoblocked content. Consuming geoblocked content through VPNs is basically letting such companies get away with discrimination and still get your money.
The internet made them largely redundant, but they still had their contracts and pushed to have things like geo-blocking to maintain their "local monopoly" arrangement.
When legal options are not readily available to me due to geo-blocking, I have no qualms about pirating instead.
Just because this type of licensing contract is common in the media industry doesn't make it acceptable. People should just pirate whenever they hit a wall like that.
I pay a significant amount of money for MLB streaming, only to have many games blacked out. Due to various factors, I cannot legally get access to those games.
I just route my entire connection through it on one of my SSIDs/VLANs.
Firstly, you really want to engineer your systems as much as possible so that you can't look at any PII -- and that includes things like usernames that aren't displayed to the public, and maybe even ones that are! -- as an administrator of your system, without going through some sort of "break glass in case of emergency" process that leaves an audit trail with a clear policy of when it is acceptable.
Second, even if you have access for job-related tasks, you shouldn't spontaneously try to tie user accounts to outside identities; that should be like line 4 or 5 in your data access policy. The right way to do the above would be something like saying "Thanks for vouching for us! If you message me your username @XYZ, I'll add some extra bandwidth credits to your account. :)"; that turns the interaction/demasking into something voluntary on the user's behalf, rather than you creepily stalking them through your user DB.
My second thought was hoping traffic actually does get proxied through your network, and isn’t pure P2P, to provide anonymity between users.
My third thought was that I should sign up regardless, as this could be useful!
Agreed it's a little scummy to not factor your operating expenses into the price of the product, especially if that's not blatantly obvious from the outset.
edit: The information on how it's secured for packeteers seems a bit limited. (how do you prevent people spraying 192.168.1.1 into all endpoints?).
But it's interesting enough to hit up in a seperate docker network. I'm looking forward to seeing if it'll actually use GBs.
1. Check your ISP contract. If it is a residential connection, it probably says you are not allowed to share your connection with people outside your home (and it could be argued that you are doing so by running this).
2. Check your laws. In Spain, if your connection is used to conduct illegal activities and you willingly gave access to the attackers (which is what you are doing here) then you are a "necessary collaborator" and would be found guilty of these crimes.
In other countries, “not technically illegal” may apply. In Spain, it does not.
Or to give another analogy, it’s not technically illegal to sit in a car. It’s a different matter if you’re sitting in the car as a lookout while a crime is occurring. While there’s “intent” that matters in that particular example, when it comes to internet crime in Spain, intent doesn’t matter, facilitation is all that does.
How confident can I be that the Feds wont pay me a visit at 4am?
One nitpick: I'm seeing occasional timeouts (probably because the residential endpoint went down recently). Do you have a best practice on how to work around that?
Is being a packeter safer than running a tor exit node? I'd worry that the people willing to run this risk for a small income couldn't afford adequate legal defense if necessary.
Lord man, what kind of bills were these?
And I shut it down because the support requests became unmanageable, there was rampant fraud, chargeback rates were through the roof. I had more important things to do / opportunities to focus on.
You mean selling use of residential IP addresses of people who have no idea? I assumed that was the case when I saw companies selling proxies that route through residential IPs
My point is, if 20k/month motivates you, Silicon Valley has hundreds of thousands of people in that category. And by many perspectives, they are underpaid. Really, I'm just saddened by how out of touch the rest of the world is on the subject.
What I wonder, is it a competitive advantage for Amazon at this point that they have so many? Phrased differently, would it benefit Amazon if the current status quo of IPv4 vs IPv6 adoption is maintained?
I own 2048 IPv4’s myself and their value is ever increasing. Like digital real estate, without the fluctuation of crypto. But I would prefer it if IPv6 would take over IPv4, and fast, because it will become a problem that will stifle competitors at some point. If most IPv4’s are owned by big corporations, that’s essentially.. them owning the current internet.
IPv6 is practically free.
I would love to see a breakdown of IPv4 FAANG ownership!
Looking at something like https://bgp.he.net/AS32934#_prefixes will tell you what IPs Facebook announces. Rinse and repeat for whoever else. Maybe a bit tricky if you need to track down subsidiary ASes.
Disclosure: I worked for WhatsApp including while it was part of Facebook, and was involved in getting AS11917 setup for WhatsApp.
Source: also worked at FB/WA.
Source: helped a customer with WA Business architecture (and worked at SL/IBM in the past)
The AS number is used to let others know that a given IP range is reachable via your router.
I'd like to give a better explanation, but I think it would be wrong. BGP is really hard for me to grasp, even if my networking colleagues claims it's not really that complicated.
You need public addresses if you want to be publicly reachable. If you're small you might find an ISP — let's say ISP Inc — that will give you an internet connection and allocate some part of the address space it in turn has been allocated. There's no need for BGP or dedicated IPs here — the rest of the internet already knows how to reach the range(s) of addresses assigned to ISP Inc, and from there ISP Inc's own network takes care of sending the traffic down the pipe to you.
If you need a lot more addresses, or you want to use more than one ISP (either of which could apply to WhatsApp's case), you probably need to get a dedicated assignment and an ASN. The ASN means you're an "autonomous system" — not a carved out bit of someone else's network. You go to your local registrar and convince them you need some addresses, and then you go to your ISP(s) and ask them for "transit", which means they'll connect you to their network and route to and from the rest of the internet for you. But since you're now using your own addresses it's not as simple as above, where your IPs were part of your ISP's range and everyone else just sent their traffic to your ISP for them to route to you. Your IPs are yours now, and until you tell the rest of the internet how to find you nothing will work. To make this work you have to get your ISP(s) to tell the internet "hey, y'all want to send traffic to Mr Weasel LLC? I can handle it for you". This is called "announcing" a prefix (IP range) and BGP is the mechanism through which all the routers on the internet propagate announcements detailing who is providing connectivity to who.
Conceptually this stuff is quite straightforward but in practice it can be mindbending. As well as transit there are peering arrangements (where Mr Weasel can arrange with Netflix to swap traffic over a dedicated physical connection, rather than their respective ISPs) and hella complicated traffic engineering schemes linking the big content providers to the internet. For instance, Facebook has thousands of transit and peering connections with other ISPs and providers and deciding which path is optimal for any given situation requires very complicated policies and management.
Any halfway serious company that wanted to run a global application on their own infra is gonna need their own ASN and internet presence with their own IP space.
A) justify an AS and pay the fee B) find someone to buy IPv4 addresses and pay them (probably a deposit) C) justify IPv4 address space to the RIR and pay the fee to transfer from your seller D) pay annual dues
If your RIR actually has space available, you might be able to skip step B. And you can get IPv6 addresses without finding a seller, because all the RIRs have IPv6 space.
RIR processes are generally human driven, so you might get more questions if you're filing as an individual.
The whole RIR and IP ownership process is so antiquated it’s almost hilarious. It’s on par with BGP, with is fully trust based as well :)
A fascinating field, that I’m glad not to be a part of any more!
As a legacy address holder, how do you feel about RPKI?
Until the day when ipv6-only connectivity becomes practical/commonplace. At some point ipv4 market is going to crash when they are simply not needed anymore. Of course that inflection point might still be quite far away, but I wouldn't count on ipv4 stock being a retirement fund
If 90% of content is on IPv6, you as a user are unlikely to need an IPv4 address.
Some people are unable to get ipv6 from their cloud hosted servers outbound right now too. Even if they tried.
So what happens is that beyond a certain point it stops making commercial sense to route IPv4 globally. That's probably before your 10% mark. So by then there's no point bothering with IPv4 for your systems unless you specifically serve that deprived market and will spend money to connect to them specially.
For IPv4 users the Internet still mostly works, when their system asks "A? some.website.example" and there is no A record because the IPv4 Internet isn't really a thing any more, it gets an answer like "10.20.30.40" where that address was arbitrarily picked as a temporary local assignment for some.website.example. When they connect to 10.20.30.40 a Network Address Translation module behind the scenes does an IPv6 connection to some.website.example and hooks them up.
So their copy of Internet Explorer still "works" although some more advanced features are flaky or missing but hey, they know they have crappy 20th century Internet and ought to upgrade.
Inside some larger companies there already is no IPv4, and that will spread, inconsistently but it will spread, because IPv4 is a pain in the backside, it's easier without it. Translation gateways keep things mostly working enough for people who have IPv4 only, today that's the majority, a decade from now it's a minority, and eventually it's too few people to care about.
Eventually (probably much below 10%) the translation gateways are thinly used enough that "nobody" proactively notices if they're broken, that'll happen in some places faster than others, but the effect is to push those final people to upgrade because it's just annoying to always be the person calling your ISP to complain when it breaks.
IIRC, this has already occurred for mobile phones.
* https://blogs.akamai.com/2016/06/preparing-for-ipv6-only-mob...
It's (one off?) the reasons why Apple mandates that apps work with IPv6-only networks:
And a lot of Indian providers as far as I know.
Most still doing either v4 only with CG-NAT or dual stack.
I own several /22's, and are renting them out through a broker. So far, 1 months rent (easily) covers the yearly RIR costs, so quite a good margin, and I still own them.
So when time comes, I can sell them, but before that, rent keeps coming in. Just need to make sure they are sold before the market value of an IPv4 crashes to zero.
IPv6 penetration is growing, but Akamai reports that even the most IPv6 networks only go to ~ 92% IPv6. So if you want to have full reach, you need IPv4, but you don't really need IPv6 (although, you may want it, some of the CGNAT systems that users are behind are pretty bad, avoiding that is nice)
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-... https://aws.amazon.com/premiumsupport/knowledge-center/elast...
* They'll provide a free dynamic IPv4 address attached to any interface/VM for the life of that VM.
* They'll provide static IPv4 addresses. These are generally free, but you'll be charged if they're not attached to a VM (i.e., sitting unused). Only one IP per instance is free.
Charge is a half cent an hour, so works out to about $3.65/mo to camp on an IP address.
EC2 prices are pretty high compared to other offerings if you run the machine permanently. The "free" IPv4 address is certainly a part of the price. (There are other parts like good maintenance, which you don't necessarily get from cheaper competitors)
Scaleway charges you 1 € / month for such address whether you use it or not. That's a 25% premium on the cheapest machine when in use. Much cheaper than AWS whether in use or not.
Not sure how many customers could perfectly live without the IPv4, but AWS seems to be in the market position to (covertly) charge them, too.
It's much more typical to either have cgnat IPv4 and public IPv6, or just cgnat IPv4 and no IPv6 than to have cgnat both.
I don't even see what possible rational there could be for such a change. Most native v6 consumer already have firewalls for IPv6 in the CPE which block any incoming connections per default, so not even the misusing NAT as firewall argument applies here.
NAT is expensive.
One of the few examples of “the more of them you have for sale, the more they’re worth”
Once you get bigger than what can be easily justified, the prices go down a bit. If you need a /18, you can probably use either an /18 or two /19s or ... You can make it work, and there's not enough benefit for contiguous to pay more. Of course, if you can justify an /8, there is a premium for contiguous. Otoh, not too many /8's for sale.
Just a data point.
I'm on a cellular network in the UK for both my phone and my phone network (via 4G router).
My phone get an IPv6 address only, no IPv4.
But my home network gets an IPv4 address only, no IPv6. I can't obtain IPv6 on the home network even though it's the same cellular service (down to the same kind of SIM and same contract) as the phone.
>My phone get an IPv6 address only, no IPv4
Please tell me which network so I can immediately switch.
Three unfortunately still don't use IPv6, and I'd prefer if my phone were IPv6-only than IPv4-only since everything else in my life is IPv6 capable -- all my servers, my home Internet, my email provider, etc...
EDIT: So it seems some people have gotten IPv6 addresses from Three last year - e.g. https://twitter.com/Mythic_Beasts/status/1195292901191892992 - so perhaps I just need to wait for Three to enable it for everyone? Not going to wait forever though...
The phone Settings > About > Status shows an IPv6 and no IPv4.
However it's not really IPv6-only. It is able to make IPv4 connections, which rather than going over the IPv6 route, are instead tunnelled to the network separately via the modem and the network applies CGNAT and assigned an ephemeral source IPv4.
I've described some of the NAT behaviour here: https://news.ycombinator.com/item?id=25399780
I also I also use Three for my 4G+Wifi home router. That doesn't get an IPv4 at the moment, just an IPv6. None of my home devices can make IPv6 connections over the LAN to my internet services. They resolve ok, but then have no route.
Same applies when using my phone as a Wifi hotspot. The hotspot is IPv4 only, even though the phone itself has an IPv6 uplink.
Now I know it's an experimental partial rollout by Three, I wonder if I'd see the opposite if I swapped the two SIMs.
No IPv6 support though :(
https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addre...
[1]: https://tools.ietf.org/html/rfc790 "RFC 790"
We also have a single /22 block of addresses from RIPE (we were one of the last companies to get such a block in 2019), so far we haven't made use of it though as it's still a bit tricky to find providers that will announce your addresses (without asking a hefty amount of money for it).
Vultr can do so https://www.vultr.com/features/bgp/ for no additional cost.
BGP itself doesn’t care at all. Announce the entire block from one “region” in Vultr, or split it out with a /24 in four different ones. It’ll work just fine.
$ wget https://ip-ranges.amazonaws.com/ip-ranges.json
$ grep ip_prefix ip-ranges.json |
sed -re 's|.*(/[0-9]+).*|\1|' |
sort | uniq -c
4 /11
16 /12
30 /13
82 /14
188 /15
278 /16
70 /17
63 /18
30 /19
47 /20
111 /21
248 /22
204 /23
839 /24
68 /25
235 /26
142 /27
124 /28
50 /29
42 /30
362 /31
370 /32> jq is like sed for JSON data - you can use it to slice and filter and map and transform structured data with the same ease that sed, awk, grep and friends let you play with text.
curl -s https://ip-ranges.amazonaws.com/ip-ranges.json | jq '.prefixes | .[].ip_prefix | .[-3:]' | sort | uniq -cNetmasks might not always be three characters.
Perhaps something like this:
curl -sf https://ip-ranges.amazonaws.com/ip-ranges.json | jq -r '.prefixes[].ip_prefix' | grep -o '/.*' | sort | uniq -c
If you really wanted to, you could even do the splitting and counting in jq: curl -sf https://ip-ranges.amazonaws.com/ip-ranges.json | jq 'reduce (.prefixes[].ip_prefix | split("/")[1]) as $mask ({}; .[$mask] += 1)'
It's a super handy tool with a real language in there!> …a bunch of lazy network admins in NA and the EU that don't want to learn the new tech…
That’s a cheap shot, and it’s not called for.
Network admins are paid to make the networks run. Anything else is less important. If your IPv6 network experiences some small problems, well, you’re going to hold on to IPv4 because small network problems can mean big inefficiencies or lost sales.
Just a few weeks ago I was on the phone with my WiFi router’s vendor for a couple hours or more because IPv6 traffic wasn’t working through it. I had narrowed the problem down to the router itself. It’s not necessarily that IPv6 is poorly tested or has technical problems, it’s that there’s a long tail of devices/configurations/software out there which screw it up, and it’s often cheaper to just use IPv4 rather than suffer even the minor inconveniences and troubleshooting sessions necessary to run IPv6.
It’s moving forward but it’s slow progress, and it’s not because network admins are lazy or stupid. It’s because there’s a lot of work to be done and not everyone has much of an incentive to do it at all.
We had to return stacks of Cisco equipment, because despite being brand new it had no IPv6 support. We should have checked of cause, but we just didn't imagine that you could buy IPv4 only equipment in 2020.
Software is even worse, we have had software that advertised IPv6 support, so we build an IPv6 only solution, only to find out that the manufacturer has NEVER had a customer using their software on IPv6. They tested it six years ago and never followed up, meaning that IPv6 does actually work in the latest versions.
Docker is another example, who in their right mind designed Docker to be a IPv4 only solution and then attempts to bolt on IPv6 later. It should have been IPv6 and then if you really needed it you could add an IPv4 ingress. Most of the issues we have experience using Docker could have been avoided by using IPv6 and dropping IPv4 all together.
Indeed. Even stuff like pfSense has only rudimentary IPv6 support.
And I guess software support is poor because they're still figuring out how to actually deploy IPv6, churning out new RFC's[1].
[1]: https://tools.ietf.org/html/draft-gont-v6ops-ipv6-addressing... (random example)
We discovered this due to operating an IPv6-only network and having to deploy NAT64/DNS64* on the edge specifically for reaching hub.docker.com
* NAT64/DNS64 was trivial to set up (Tayga + bind9) - took 2 hours for a networking apprentice
[1] https://www.datacenterknowledge.com/sites/datacenterknowledg...
Google is seeing 43% IPv6 traffic in the US, 50% in Germany, 35% in Japan, and 17% in Gabon (the most of any African country).
The data seems to support the exact opposite of your assessment.
Not one of our enterprise customers has IPv6 enabled.
Not one of the public clouds we manage have IPv6 addresses on their virtual networks.
Meanwhile, putting a CDN in front of an otherwise 100% IPv4 web server will add an IPv6 address whether you like it or not, and that traffic will contribute to those stats you mentioned.
This article is about public cloud providers hoarding IPv4, which applies to things like the PaaS and SaaS services, internal APIs, etc... which are nearly 100% IPv4 in all three of the big public cloud providers.
It hasn’t even been that long that Amazon EC2 has had v6 support, which is where a huge chunk of the Internet is hosted.
The network admins at ISPs are just providing connectivity the customers demand. It’s hosting providers and sys admins that don’t bother setting up anything interesting on v6 in the first place.
Second: Ever since IPv6 has been a thing, I've offered to customers the option to turn it on for free. No added charge. We'll just flip the switches and it's there. Not one customer, ever, has said "yes". They've all actively refused to turn it on, for any purpose.
Third: The few times IPv6 has been forced upon our customers, mostly due to Microsoft Windows DirectAccess, it was the network administrators frothing at the mouth, ranting and raving about how they don't want to do it, that DirectAccess should use IPv4 (I'll call Redmond and I'm sure they'll get right on it!), etc...
Fourth: As you've mentioned, AWS, Azure, and GCP had practically zero IPv6 support until very recently. Now, they have broken IPv6 support which is worse than useless, because it gives the impression that the problem is with IPv6, not with the people holding on to an appreciating asset of IPv4 addresses that they intend to use to lock out the competition.
TL;DR: IPv6 is held back by a combination of bad ISPs, lazy network admins, and monopoly seeking public cloud providers.
As such a customer, I’m worried that my ISP would eventually bait-and-switch me from routable IPv4 + optional IPv6 to CGNAT IPv4 + IPv6 when convenient to them. Sorry, but I’m not risking going behind a 1:n NAT layer that I don’t manage.
Does this strategy work? Maybe, when I upgraded my plan they wanted to switch modems, the new one didn’t have working bridge support, and I said to them it was a requirement for me. No bridging, revert everything. The field tech escalated to engineering and they approved a business-class modem. I expect the same with IPv4, even if I have to pay extra.
For example Aussie Broadband had a nice writup of their CGNAT setup: https://www.aussiebroadband.com.au/wp-content/uploads/2019/0...
It's extremely hyperbolic to call an ugly syntax a bad "design". But IMO it would have been much nicer if they just reused '.' as in IPv4. ':' seemingly came out of their pie in the sky desire to replace MACs.
Speaking of MACs, every time every time I see some cheap trash gizmo come with its own MAC I'm surprised there isn't address space pressure. I guess that's due to having 16 more bits as well as being non-aggregable.
It’s funny, there is an interview with Vint Cerf where he mentions the choice of 32 bit address space for ipv4 was essentially pulled out of a hat and it could just as easily have been 48/64/24.
On the other hand, most devs / technical staff type IPs into the browser and terminal daily.
No they don’t. Configure a DNS server and type these in once. Any time I see IP addresses passed around it’s a sign of broken infrastructure. (It also means you aren’t using tls or you’re training people to accept cert errors)
Oh yes they do.
> Any time I see IP addresses passed around it’s a sign of broken infrastructure
Nope.
> It also means you aren’t using tls or you’re training people to accept cert errors
So, let me get this straight. You have a server that's behind CloudFlare, and you're claiming we should use DNS and TLS to SSH into it?
Every server/VM I control (~200) has a DNS entry. Every active IP has a reverse (PTR) entry.
I have a monitoring task to check for missing DNS entries, as it usually suggests a problem (i.e. we've deployed or undeployed something incompletely).
You said devs and technical staff were typing IPs into their browsers. Presumably this means the address bar, which breaks TLS.
SSH derives a big chunk of security from key caching. If you’re using IPs you now can’t have an IP change without triggering key warnings on the SSH clients for a new key at a minimum or (worst case) a breach.
What alternative do you propose, that gives us more addresses but isn't longer? (IPv4 has fewer addresses than people)
I've been in networking for 30 years, worked for multiple multinational ISPs, and the answer is basically never.
1990s, Quake.
I let about 10 family and friends connect directly to my home server. My firewall blocks everything except for these 10 IP addresses.
I did get tired of having them figure out their IP address so now I just tell them to access a dummy page page on my external VPS and I check the web server log to see their IP to add to my firewall config.
And also it seems like a lot to sacrifice in order to make something marginally more helpful about once or twice a year.
Also why would you say it over the phone? Would you not ask them to email or IM it? I can't count the number of times passwords and names have been misunderstood over the phone. Numbers? Basically always at least one number is misheard.
As I see it, IPv6 can't come fast enough. NAT really needs to die a death so people can actually use the internet fully, not only as a client or using hack-y work-arounds.
-IPv6 is fundamentally much more secure than IPv4 (no scanning, etc.)
-opt-out is bad for innovation, especially since the cheap default ISP router firewall software is likely to not even allow opt-out for any other protocols than TCP and UDP. (Heck, these days on IPv4 even anything different than HTTPS can be problematic...)
-reliance on router firewalls is bad because they incentivize sloppy device security - the manufacturers should be instead liable when they are at fault for screwing it up (also, how many of these "insecure IoT devices running ancient software" are even able to run IPv6 ?)
source : https://lafibre.info/ipv6/ipv6-le-firewall/msg704095/#msg704... (fr)
Incidentally, one of the "big 4" French ISPs "Free" didn't even have an IPv6 firewall on its customers routers between 2008 and 2019, and it's probably still opt-in : 4 months ago : https://fr.answers.yahoo.com/question/index?qid=202008121107... (fr)
So I guess that we're going to see in practice the problems that having no IPv6 firewall causes (most customers not having any idea about what even is a firewall) as it gets more popular... and since Free this summer boasted about reaching 99% IPv6 coverage, and is enabled by default, and can NOT be disabled...
The same was true for ipv4 until about a decade ago.
> opt-out is bad for innovation, especially since the cheap default ISP router firewall software is likely to not even allow opt-out for any other protocols than TCP and UDP. (Heck, these days on IPv4 even anything different than HTTPS can be problematic...)
I can't wait for conficker6 to innovate it's way around the ipv6 net.
> reliance on router firewalls is bad because they incentivize sloppy device security - the manufacturers should be instead liable when they are at fault for screwing it up (also, how many of these "insecure IoT devices running ancient software" are even able to run IPv6 ?)
Sounds like an excellent reason for an opt-out by standard. 99% of the world's internet users wouldn't have a clue how to manage a firewall. Directly connecting all their devices to the internet is an awful idea for 99% of the world.
Your 50/50 example is hugely biased, first it's on a Telco discussion forum so that clearly selects for technical users, then it's on ipv6 which is going to further select for technical people.
Go canvas 100 random people outside a supermarket if they want to have to manually manage a firewall for every device they connect to their network. If they don't give you a blank stare at that question remind them that includes everything from lightbulbs, washing machines, "smart" speakers, to their computers/phones (likely the only thing they think of as being connected to the internet). If you find more than 1 I'll eat my hat.
I don't own a hat.
As you can see I'm aware of that, they are also aware of that, and the discussion is not so much about themselves (since they know how to configure a firewall or even to install their own router), but about what your "average grandma" should get.
Especially interesting is this RFC : https://www.rfc-editor.org/rfc/rfc6092.html "Recommended Simple Security Capabilities in Customer Premises Equipment (CPE) for Providing Residential IPv6 Internet Service"
It shows that there are lots of different filterings involved, so it looks like that these millions of residential users connected to the IPv6 Internet without router firewalls might still have some router filtering going on ?
Also, it confirms that "The IPv6 stateful filtering behavior described in this document is intended to be similar in function to the filtering behavior of commonly used IPv4/NAT gateways, which have been widely sold as a security tool for residential and small-office/home-office networks.
As noted in the Security Considerations section of [RFC2993], the true impact of these tools may be a reduction in security. It may be generally assumed that the impacts discussed in that document related to filtering (and not translation) are to be expected with the simple IPv6 security mechanisms described here.
In particular, it is worth noting that stateful filters create the illusion of a security barrier, but without the managed intent of a firewall. Appropriate security mechanisms implemented in the end nodes, in conjunction with the [RFC4864] local network protection methods, function without reliance on network layer hacks and transport filters that may change over time. Also, defined security barriers assume that threats originate in the exterior, which may lead to practices that result in applications being fully exposed to interior attack and which therefore make breaches much easier."
So now I'm kind of confused as for the different meanings of 'filtering' and 'firewall' that might be used... The RFC seems to use 'firewall' in the sense of 'customizable firewall', while ISPs still often don't provide other options on their IPv6 'firewall' than 'ON/OFF'...
Yes, everyone should have a hardware firewall, but we both know most people just buy the cheapest thing, and by bad large, real firewall features are mostly targeted toward higher end devices.
More seriously; for 99% of people their ISP router handles NAT and firewall duties. Adding DENY ALL inbound and ALLOW ALL outbound isn't a great stretch for them on ipv6.
Only servers that need to be publicly accessed directly like a web server actually need a public IP.
Speed is so much better with new ISP though so he just set up Wireguard to the VPS server he rents to get "his own" IP.
Despite this, it's able to connect to IPv4 web servers just fine.
All connections from the IPv6-only phone to IPv4-only web are automatically NAT'd to IPv4 by the cell service provider. I've tested this recently and it uses a different ephemeral source IPv4 after a few minutes when doing this. Tested with HTTP, HTTPS and ICMP ECHO. It is definitely NAT.
At the same time, my connections from the phone to IPv6-only web are not using NAT. The server sees the same source IPv6 as the phone reports as its own.
When I enable tethering on my phone, it creates a local IPv4 wireless LAN. Devices on that LAN such as my laptop access the web using IPv4, which is NAT'd twice: Once on the phone when crossing from the WLAN to the cell network, then by the cell service provider to get an ephemeral source IPv4. This is double NAT.
When the Linux VM on my laptop connects to an internet service and I'm using the Wifi hotspot on my phone, there's yet another NAT in the way, on the laptop itself. This is triple NAT.
All this NAT means it doesn't matter so much that we are out of IPv4 addresses for phones. They can connect to both IPv4-only and IPv6-only services while assigned only a public IPv6.
In fact phones don't need a public IPv6 either. They don't need any public address.
Those NAT'd IPv4 connections don't go over the IPv6 link. They are not being translated to IPv6 and back. Rather, they go over what is effectively a private IPv4 tunnel to the cell provider. Just as IPv4 connections can work like that, so could IPv6 so there's no real need for the phone to report that it has any public IPv6 or IPv4 address at all.
However, mine is currently reporting a public IPv6 and no IPv4, while able to make connections to both.
It's as much of a mental shift as replacing street addresses with Latitude/Longitude coordinates.
So I've avoided IPv6 as much as possible.
Can you elaborate a bit? Where do you find frustration with IPv6? I've been using IPv6 for probably close to 10 years now, and I can't say it's been frustrating
At this point, though, you may be able to find an IPv6 capable ISP and just switch to them. Your phone might also have IPv6 too, especially if it's 4G/LTE.
Any amount of exposure is better than none. If you're using AWS, I can help you setup IPv6 in your VPC and use it with EC2 which can let you get some first hand experience. My email is in my profile if you want to take me up on that offer.
Lat/lon is a data set primarily used by applications. IP addresses are much the same way aside from private networks and experimentation. If you need to describe a private space in IPv6 you have link local addresses that begin with fe80.
Modern routing tables are primarily defined by dynamic protocols, such as OSPF. If you really need to express a static IP address directly, such as for remote access to a switch, the IP address will be provided to you. This is why Cisco now requires Python for the CCNP.
aspmx.l.google.com. 293 IN AAAA 2a00:1450:400c:c07::1b
aspmx1.migadu.com. 600 IN AAAA 2001:41d0:2:4a6f::
IP blacklists are possible for IPv6 based email. I have heard many work by blacklisting the /64 or bigger subnet. Sometimes also adjacent subnets.Perhaps with SPF+DKIM and other measures we will be able to rely less and less on IP reputation anyway?
That doesn't make "You can't run an email server on ipv6" correct.
At best it’s broken at worst it’s not an email server
There's nothing that prevents email from working over IPv6. The sender and receiver just need to have IPv6 connectivity.
Every email provider that supports IPv6 will also support IPv4 (for the time being). To use Gmail as an example:
aspmx.l.google.com. 293 IN AAAA 2a00:1450:400c:c0b::1a
aspmx.l.google.com. 293 IN A 173.194.76.27
There is both an A and AAAA record. You can send emails over IPv6 or IPv4 to Gmail addresses.Did you mean you can't exclusively use IPv6? Because that is also true for browsing the web - because so few websites support IPv6, a lot of links will just not work.
For example, approximately nobody has IPv6 in Spain. It's one of the countries furthest behind in dual-stack adoption. This is entirely the fault of Spanish ISPs.
ISPs won't be forced to deploy dual stack IPv6 until IPv6 only servers are commonplace, and IPv6 only servers won't exist until that wouldn't lose them a significant fraction of users. And thus progress is glacial.
Or, another certainly plausible explanation is that your router either doesn't support IPv6 or it is disabled
Detectives and other governments rely on IPv4 addresses as part of 'evidence', and storing V6 uses more storage and is much more complicated generally due to the much longer address space.
We won't see the internet migrate to IPv6 entirely for another 20/30 years from now.
The other reasons are all about the difficulty of the change. IPv6 is not an incremental update to IPv4. There's a ton of changes that are just totally different. Arp is replaced by ICMPv6, dhcp is mostly replaced by slaac, but dhcpv6 was added later, header processing is different. All that means, it's a good bit of work to get IPv6 to run as well as IPv4, and chicken and egg issues made it hard to justify doing the work, and hard to verify the performance.
Finally, work towards making transition easier was only started much later than the protocol design. Making it easy to use, and easy to switch to should have happened during design. Things like continuing to use ARP for IPv6 would have been simple (arp is extensible), and reduced implementation work, and gotten things moving quicker. OTOH, you would be stuck with ARP forever, instead of ICMPv6, but it doesn't seem like a big difference to me.
> "try to buy them all"
buy all of AWS's? Then: no, it would cost less.
buy from open market? Then: yes, It would cost more
If you go into a market and try to buy lots of something, it drives the price up because you're increasing demand and removing supply.
If you go into a market and try to sell lots of something, it drives the price down because you're increasing supply and removing demand.
AWS don't obviously have an incentive to sell IP addresses for substantially below market value, so I don't see why buying them from AWS versus someone else would make much difference.
You just invalided yourself. What do you think my point is?
The point I was trying to make is that just because the IPv4 addresses are valued at $2B doesn't mean you'd be able to buy them for $2B.
A) we all know, we're not 6 years old.
B) it doesn't really matter, the value is still $2B. It's not the total dump sale value we care for but the actual value of these addresses in the hands of Amazon.
Edit: apply this same exact comment also to any discussion about Bezos' net worth
Regardless of how you calculate the %, it's doubled in a few years.
I still would love to know what they were thinking when they added 252.0.0.0/10 to their list.
It's listed as reserved here: https://www.iana.org/assignments/ipv4-address-space/ipv4-add...
I got the impression it was meant for some internal to AWS use and was pushed to their list of IP addresses erroneously, but I barely speak to AWS, much less speak for them.
Some jurisdictions have laws regarding real estate that, if it not be used for about a decade, it becomes legal to squat.
This is primarily in densely populated jurisdictions where real estate is a scarcity and the government doesn't want it to go unused.
A similar structure could actually be made for IPv4 addresses.
I.P. addresses, unlike real estate, are a matter that's hard to bind to any specific jurisdiction.
2,344,576 IPs, so ~47mm on the same math.
7,580,928
So ~151mm, on the same math.
While the auction receipts go into the public coffers, it’s not like we get annual cheques.
https://www.icann.org/resources/pages/allocation-ipv4-rirs-2...
https://afrinic.net/policy/manual
https://www.arin.net/participate/policy/nrpm/
https://www.apnic.net/community/policy/
I know RIPE now want members to charge customers for IPs, but..
I see that RIPE is currently only giving out a /24 for free to those who haven't received an allocation before, so my bad.
Now they are limited to handing out /24's that are returned to them to hand out to new ISPs (since going IPv6-only is still not quite possible..).
Generally, you get a /64. Of course, when using IPv6 there is no NATting, each of your device has its own IPv6 address of the /64 range allocated to you.
Right now blocking a bunch of home servers is easy - just don’t give people addresses. With IPv6 you’ll need to thread that needle some other way or give people access to something that will actually test your advertised bandwidth commitments.
Edit: instead of downvoting how about having a conversation? That’s the great thing about this place, lots of diverse perspectives.
Besides, why shouldn’t users be allowed to connect to machines on each other’s network without a central gatekeeper in the way?