However if your a normal consumer with a single network visible IP (if that), it's REALLY useful. I've got a /60 (16 /64s'), and I have one per port on my router and it's quite nice to be able to get to anything inside my home network from anywhere on the internet. Filesharing, monitoring home automation, opening/closing my garage door, etc.
When you put it like that, it sounds kind of scary.
Hell if you have a firewall exploit then exposing stuff to the internet doesn't matter.
Sadly, this is very far from the truth. Most routers do not filter IPv6 by default, mainly because IPv6's design assumes a per-device firewall. This means that literally you need to ensure that every device supports a firewall or otherwise operates in such a way that it is safe for public access.
This isn't my experience. If you are correct however, that is a failure of the ISP/CPE provider, not a flaw of IPv6.
> mainly because IPv6's design assumes a per-device firewall
I don't see a single mention of firewalls in the RFC[1]. But then neither did the ipv4 spec. Why would we suddenly stop using firewalls though? They have been standard on networks for decades.
First, I'm excluding enterprise firewall here.
I've verified this with multiple non-CPE routers, and except for the router itself (for obvious reasons), no, IPv6 traffic isn't really filtered. The "firewall" is laughable on some routers (including some assuming /64 filters which isn't necessarily true for some servers like OVH's). The only non-enterprise one that's working as much as an IPv4 system is Asus'.
Some routers tries to filter out DoS attacks. Those are rather confusingly called a "Firewall", but it's not really a controllable firewall per se, allowing "normal" but otherwise a malicious-if-DPIed traffic. A tell-tale sign that this is the "firewall" you have is that you cannot set IPv6 whitelists on your router.
> I don't see a single mention of firewalls in the RFC[1]. But then neither did the ipv4 spec. Why would we suddenly stop using firewalls though? They have been standard on networks for decades.
The RFC? Yeah, both IPv6 and IPv4 have evolved in the years so that there's multiple RFCs about them. For example, IPv4 don't promote ICMP firewalls but details what ICMP messages must you allow if you deploy one (unless you wholesale block that IP). IPv6 instead never allows you to block any ICMP messages except if you wholesale block an IPv6 address.
https://www.anvilsecure.com/blog/dhcp-games-with-smart-route...
In other words, if you have internet and you're using NAT then unless you have done some complicated stuff (port forwarding) you're probably safe.
If you have internet and you're using IPv6 then unless you have done some complicated stuff (enabling a firewall) then you're probably not safe.
I guess eventually IPv6 enabled routers will come with a firewall enabled by default but let's not hold out breaths!
I wouldn't trust the horrible default passwords and lax security built into most devices for home use to be exposed directly to the Internet even with a firewall.
Again, people are depending on something that isn't really designed to provide security to provide security. Devices that have horrible default passwords aren't secure in any environment. We need to a) do better in picking what we run on our networks and b) hold manufacturers accountable for setting sane defaults.
Some people just want their lightswitches to work.
It's super annoying, tbh. A subset of technologists only seem comfortable with the technology that was available when they were 18-24, regardless of how old they get.
"What's this? I never needed it before, what's the sysctl to turn it off?"
It's super annoying, tbh. A subset of developers only seem comfortable with technology invented in the past 18-24 months, regardless of how untested and unstable it is.
“What's this? It was written 2 years ago? It must be old and useless. I’m going to require my app to use the latest version and I don’t care what kind of headaches it makes for the people who actually need to make sure it’s up an running when users try to use it.”
It's already possible to connect from v6 to v4, and using 48-bit addresses wouldn't make doing so any easier. 48 bits would also be way too small; there'd be no point in going to this amount of effort to update IP only to then have to do it a second time straight afterwards.
Trying to keep jumping to the new hotness is simply a survival strategy.
IPv6 has been a draft standard since 1998. Get a better argument.
I’m not interested in another argument but calling my position “pitchforks” is a bit disengenuous and irritating (which is why I’m replying, off-topic, to you).
While I think it has something to offer I would like potentially better alternatives to be able to exist in future, this is not “pitchforks”.
systemd is the choice of basically everyone who builds distros, so of course it's going to be hard to avoid unless you volunteer to do all of that work yourself. When you take work from someone else, that comes with taking on the choices that they make.
What you state is absolutely true, but denying there’s more nuance is not helpful. That’s all I’ll say because this is not a worthwhile conversation to have here.
Even if we ignore the fact that systemd made it artificially difficult* for distros to support other init systems (so it wasn't a freely made "choice"), have you never encountered a situation where the popular choice turned out to be the wrong one? Think, for example, of people throwing their trash into nearby rivers, or developers using 2 digits to store year values.
(* Imagine being a volunteer for a distro and having to deal with bugs like "I installed my new printer and it changed my init system[0] / my system no longer boots").
[0] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863974
IP6 requires a bunch of new tooling and configuration, and if running dual stack provides plenty of new opportunities for failure.
When ever I enabled ipv6 I got 10/10 from test-ipv6.com and randomly few ours later it would go down for no reason. I used few hours to understand wtf was happening. Then I just gave up and disabled ipv6. I got peace of mind and lost nothing. Maybe someday I am bored enough to try again that sorcery and black magic.
Of course, turning off IPv6 fixed a lot of connectivity issues, at least back in the day. Maybe it's better now, but I see no benefit in re-enabling it. What's the value-add?
Horace Odes, III 65BCE
In anticipation, where can I catch up on ipv6 routing? Does the number of route entries explode?
I do need a "business reason" to adopt it, since the Center for Internet Security benchmark dings your system if it is turned on.
That's also your business reason. The price for IPv4 connectivity will go up. At some point a startup will not use IPv4 anymore because it will be too expensive. If you don't have IPv6 access you will not be able to use the services of that startup.
Price of an IPv4 address has doubled last year and gone from about $7.50 in 2016 to about $40 now. https://ipv4marketgroup.com/ipv4-pricing/ https://ipv4.global/reports/