Who is squatting IPv4 addresses?
blog.benjojo.co.uk
blog.benjojo.co.uk
That's a rather optimistic view of the situation. The next member who will get a block has already been waiting for 2 months and it's unclear when they will get one. It stands to reason that members applying now wold have to wait (potentially significantly) more than 2 months.
Some nice data on the prices of IPv4 addresses: https://auctions.ipv4.global/prior-sales
There is a fee. Your EUR 1,400 annual fee.
For that money you get one IPv4 and one IPv6 (IPv4 subject to availability, obvs!).
Above that they charge per resource assignment, 50EUR per annum per resource assignment ( defined as: "IPv4 and IPv6 PI assignments; Anycast assignments; IPv4 and IPv6 IXP assignments; and Legacy IPv4 resource registrations through a sponsoring LIR. AS Numbers are excluded from this charge")
And yes, I think the 50EUR should be put on a ladder scale so hoarders get charged exponentially more. ;-)
They would just start to put IPV4 blocks behind shell companies.
Several people on the list, including someone who has made quite the sum from collecting allocations and then reselling them, were outraged that this is going on and deem it in violation of the spirit of the waiting list (that spirit being that it is supposed to give small entrants one last method of getting onto the Internet with their own /24). One of the proposed changes is to make transfers of IPv4 space received via the waiting list non-transferable retroactive to January 2021. Of course, transfers that have already happened wouldn't be reversed, since that wouldn't "be fair." Thus, all of the people who got the last "free" /22 blocks around November 2019 and who have gone on to resell those addresses (like the participant on the list who is now advocating that addresses shouldn't be allowed to be transferred) when the 24-month transfer delay expired get to keep their gains. Everyone who comes after who signed up under those rules gets the rules changed out from underneath them.
The whole system of dealing with IPv4 assignments and allocations has gotten completely out of hand. We have these large entities all acting like they are just volunteers doing a charitable thing keeping this polite ad-hoc system going, when that hasn't been true for at least a decade.
I hope they stopped doing that, but I doubt it.
>I hope they stopped doing that, but I doubt it.
Why should they stop? Ideally we'd have had at least 64-bit or better 128-bit from the beginning in a nicer form then IPv6 ended up and then every single one of us could have millions of IPs if we wished. That isn't how it ended up but that doesn't mean those who got them shouldn't use them. I make use of my minuscule bit of public IPv4 for my own stuff.
NAT was developed as essentially a hack, originally more to solve tricky routing situations, but later more to allow broad use of reserved range IPs. But the original intent was always that all hosts would have a unique address, regardless of where they were or were not reachable form (or advertised to). This is a significantly better situation than the modern world of widespread use of reserved ranges and NAT, because it meant that there would not be addressing conflicts even between two private networks. Or, more practically, it meant that setting up tunneled connectivity (VPN, MPLS, whatever) between networks not advertised to the public internet always works properly, because those networks are using IP addressing as intended and thus can simply advertise their routes to each other.
Private IP ranges for "private" hosts are an adaptation to the limitations of IPv4 space, not any kind of design ideal. It's an awkward solution to a bad problem that makes numerous real-world IT situations more difficult, most commonly the case of setting up VPNs between private networks and being forced to introduce NAT because they are both using overlapping private IP space.
A very common but small example of this is the need to choose "unusual" private IP prefixes for VPN networks (like 10.106.41.0/24 or something else sort of randomly selected), because if you use something "simple" like 192.168.1.0/24 or 10.0.0.0/24 you are 100% guaranteed to run into route conflicts because of people's home and small business networks using these ranges internally. If everyone used properly allocated IPs, even on private networks, we simply wouldn't have this problem!
IPv6 offers us a bit of a reset opportunity since it was designed to have enough /64s available to allow use on private networks. Hopefully people understand this and use IPv6 the way it was intended!
Well, no. The word "Internet" is short for "Inter-network exchange".
The original idea of the internet was to allow LANs to talk to each other. Not to give every single device on Earth its own unique key.
For a real-life example of that: according to documentation which can be found at its website, the Brazilian Central Bank has been allocated a full /18 for the national inter-bank network; each financial institution connected to that network receives a /27 or a /28 (or a pair of them) from that range. If you look up that address range on bgp.he.net, you'll find out that it's not announced to the public Internet at all.
And that 9/8 allocation predates RFC1918 by at least four years.
IBM is basically hoarding a bunch of addresses where there's no technical reason to. I get that they aren't required to do anything about it, but it does seem topically relevant.
Because it shows how wasteful these companies operate with resources others are in need of.
There are only ~4 billion IPv4 addresses. There are more than that many humans alive, most of whom have or will have a smartphone. So we're already short on addresses without considering network equipment, servers, IoT, or anything else.
It reminds me of the nouveau urbanists that move into places like SF in droves then instantly start complaining that the little old lady down the street, who has lived in the same house for 50 years, is being greedy and wasteful because she doesn't sell her family home to developers who will build 50 shoebox condos in its place.
I suspect most of the "10/8 ought to be enough for anyone" crowd has never worked on a complex enterprise network. Just because a netblock is in use doesn't mean it has to be routable to the Internet.
The problem isn't with IBM. The problem is all the cloud BS -- the 18,000th food delivery app that no one asked for -- isn't using IPv6. And that's just pure laziness on the developers' part.
If I asked for a class C for my business running a local corner store, I'd be looked at like I was crazy.
IBM gets 16 million public IPs and it's cool?
Yeah, I know you can't perfectly use an IP space, but with 128 offices, IBM could give each office an allocation of around a hundred thousand IP addresses (rounding down by over 20%. But even if it were 10,000 - that's still absurd.)
I worked for a couple of small and mid-sized companies that had /16's and larger. And we barely used a fraction of that space.
I have a /24, personally, registered back in 1993. It's routed to my home network. I know several other folks who were on the early internet, and had the same.
What is bad is ipv4 doesn't have enough space for everyone. Time to move onto ipv6. I don't know how to make that happen.
There is an important difference between "it might be necessary to put them behind NATs" and "shouldn't they be on NATs?".
In any case, /16 should be enough room to prioritize.
IPv6 would be cool.
I asked for a /22 of IPv4 for my home, and was given it, 3 years ago. I also got a /32 of IPv6, and a 32bit ASN to do BGP with.
I paid the signup fees to become an LIR, paid the membership fees, and requested my /22, /32, and ASN allocations. There were no looks, crazy or otherwise. The policies are pretty transparent. Pay money, receive resources.
That said, the policies have since changed (about a year ago?)
If you want to pick on a company for hogging IPv4 space, pick on Apple. They have a /8 and probably aren't using any of it.
Most (if not all) of Apple's infrastructure uses their /8 block. With Apple Park they've moved to using a 10/8 with NAT for talking to the outside. Between iCloud, iTMS/App Store, and iMessage Apple's got a non-trivial amount of global network infrastructure beyond just their corporate network.
So I guess be mad at Apple for using their IP space?
Indeed, both apple.com and icloud.com resolve to 17.253.144.10
But that does definitely seem like an excessive amount for them to own. I would guess the huge swathes the government has reserved are not exactly being used to their potential either.
Neither Apple, not IBM, actually need that many publicly useful set of IPs. IBM would be smart to sell them off. Apple is probably going to sit on them. (I used to work at IBM and that 9 block was very confusing to me, considering that IBM isn't even that big of a DC operator these days)
<citation required>
It's not equipment...it's purely a financial business decision that this hasn't happened yet.
This is a nightmare even inside companies. Two teams set up a default VPC, and one day you go to peer them and find that the IP ranges conflict. At my last job, I ended up using Netbox to manage our private IP ranges alongside our public IP ranges. (In theory, it would be nice if cloud providers offered this feature. "8 other VPCs on this account also use 10.0.0.0/8. Are you sure you want to be the 9th?")
9. addresses only started being used widely inside IBM around 1992 as the internal multi protocol network rolled out (combining RSCS over SNA and TCP/IP). As APPC connected devices gave way to TCP/IP connected devices allocations shot upward, IIRC each major campus was a /16.
Advantis/IBM Global Network ran the 9 network on the same physical and logical circuits as the public networks they managed, leading me to bypass the IBM firewall unintentionally multiple times as the filters they used broke. This may be one of the reasons RFC1918 addresses were discouraged (at least through 12/2001 when I left).
The only real options besides 10/8 are to have been big at the advent of the internet (like IBM or Apple) or misappropriate one of those IP blocks in the hope it never becomes publicly routable.
I'm sure it's a fine option now but that RFC is pretty new.
Ironically, having such addresses was sort of useful when companies got acquired and teams got shifted around. Starting to use an acquired company's network that was never designed with "what if we get acquired and have to play nice with others" in mind causes all sorts of routing pain.
MIT Student Radio WTBS 1964-65.
https://www.youtube.com/watch?v=PI2Xx3XSTFw
WTBS "The Ghetto": Soul-Music Radio Show. Created by Black MIT students in 1970, this radio program gained popularity in the Cambridge/Boston area.
https://www.blackhistory.mit.edu/story/wtbs-ghetto
Promo for MIT BSU's "The Ghetto" (WTBS 88.1 FM)
edit: Just did a quick WHOIS. They still have the /16 even though the university doesn't exist any more (merged with another). Crazy.
Even the article defined it as IP space not owned.
From the parent article "I will define IP address squatting as “using IP addresses that are not RFC1918 defined and not your unicast space issued by a RIR”."
Unless this is meant to construe all legacy assignments as "squatting" which is a pants on head definition.
Using IPs for internal networking doesn't necessarily mean under utilizing though; but might not be enough to justify such an assignment today.
But how do you define 'use' they could easily 'use' them by simply announcing them via BGP and null routing the traffic to the IP's they don't want exposed?
The end answer is still IPv6, where everyone can have as much or as little IP space as they want.
Can they make a plausible spreadsheet showing use. But, clawback of IP allocations is very rare, even for allocations that were made with agreements allowing it. There's some high profile cases relating to fraud, but otherwise nope. Legacy allocations would be nice to clean up, but if it's not voluntary, it's not happening. And at this point, if it happens, it's probably going to be a sale rather than a return.
Like, you have an external entrypoint and a target internal IP that you know will contain a trove of potentially interesting data.
IPv4 is fundamentally too small, period. There are already more people and computers on Earth than possible IPv4 addresses even if it were perfectly optimally used. It leads us further down a path in which everything is behind increasingly starved NATs, making point to point connectivity more and more difficult. Now we are seeing NATs in front of carrier-grade NAT and other madness.
... and no, NAT is not a security feature. You can and almost always do have a firewall in front of IPv6. If you really want NAT there is IPv6 NAT, but it allows you to have all mappings be 1:1 eliminating the need for port starvation madness and making P2P always work. All internal IPs get their own external IP, but those can be random and rotated if you want.
Let's say we claw back /8 networks somehow and let's say we can free up one of those /8 networks per year. Pretty optimistic.
The allocation rate for /8 networks from IANA after conservation measures were put in place was still 5 /8 networks per year. Even if we conserved IP addresses five times better than that, this would still merely freeze the current situation for a few until we run out once again.
There is just no amount of crumb picking that can fix the fact that 32 bits are woefully inadequate.
Something I have observed is that sites that tend to attract DDoS attacks tend not to use IPv6 (note that reddit and HN do not have AAAA records, though I don't know the actual reason for this). I've even seen the heavily attacked sites that I know are using paid Cloudflare or Sucuri services to not have AAAA records, and I wonder if that's a decision or recommendation from the service providers. So, elimination of IPv4 may mean that sites can more easily and cheaply be knocked off the Internet.
I don't think there's anything special about IPv4 in terms of DDOS mitigation. What you're probably seeing is an artifact of focus and investment. IPv4 is still the lowest common denominator standard. Virtually everyone can talk to an IPv4 endpoint. As a result the DDOS protection services still mostly use IPv4 endpoints because it reduces the amount of attack surface they have to protect. If they were dual-stack they would have to deal with BGP black holing on what amounts to two BGP networks instead of just one.
DDOS is something that desperately needs a more comprehensive solution, but it's a hard problem to solve. Right now the solution is for DDOS protection services to run bastions with enough bandwidth to absorb attacks, but that's a solution that constricts innovation tremendously. I feel like a permanent solution would require cryptography to be designed into the entire network so that you could do things like rate limit packets to your host for people who didn't present a certificate. That would require a deep redesign of the entire network though, and that's not going to happen.
In regards to mitigation, what we are talking about is an exclusive network with central controllers in the form of ICANN. Every packet has digital footprints, so what ICANN could do is permit IP address blocks to be seized and transferred when it is demonstrated the owners are consistently using the network for purposes of doing harm, even when it is through negligence. This would work its way through the service level agreements between various ISPs. As in the rest of the business world, you cannot just dump your garbage onto someone's property without eventually being forced to pay for it.
When DDOS black holing is done the recipient will actually look up the BGP advertised prefix from which the attack is coming and black hole the whole thing. Many IPv6 prefixes are /32 and /48.
I am pretty deeply familiar with this stuff. There's nothing about IPv6 that makes current mitigation techniques much harder. The most logical explanation for IPv4-only in the DDOS protection world is just to limit the attack surface by picking the lowest common denominator address. That way you only have to defend in the IPv4 realm instead of in two addressing realms.
IPv6-only would give you the same effect but there are still too many edge devices without IPv6 addresses to use IPv6 alone for anything public facing. IPv6-only systems are sometimes used in private networks, as bastion boxes, etc.
Turn IPv4 off for one minute a day.
Next month, increase it to two minutes, and so on.
IPv6 adoption will _soar_.
Of course it still may make sense to stick to ranges you own in case you need to peer your VPC with someone else, but I don't see much difference between using some random batch of IPs that you don't "own" on the public internet vs any block reserved for internal use. Either can conflict with someone that you want to merge with.
They found a number of AWS users that are treating publicly routable IP space as their own private IP space. If someone were to ever offer a public service in that IP space, the company/network using it as private IPs would not be able to access the public service.
The author is trying to understand how prevalent this is, and to what extent of trouble an owner of these IP spaces would have if they decided to host a public service.
> This is useful since it can remove the need for some servers to have any outbound internet access at all.
My point is that if you are not connected to the public internet at all I don't see why you should be expected to follow the rules of the public internet (who owns what). You can use whatever rules you want for your own private network.
It's hard/impossible to figure out if the VPC in question has been setup this way. But I agree that it would be likely that most of these VPC with the endpoints on don't have internet access.
However if we assume (dangerously I suppose) that the VPC subnet distribution is similar to other VPCs without private link, we can imagine how many other VPCs are squatting on space that do have internet access!
(Assuming any of this makes sense)
Hypothetically if you were dealing with a network that had zero access to the outside world then you are right, it doesn't matter. You can use whatever IPs you want and it wouldn't make a difference.
Its a bit of a moot point though since outside of niche situations like high security air gapped networks you don't really see that scenario anymore. Yes, the network at a nuclear missile silo could do that but everyone else is connected to the internet.
The squatters probably don't intend anything at all evil, but their address use conflicts with access to the general net. If you addresses that aren't yours and you expect to be able to connect to web sites in general, you might by chance use an address that is later allocated to a web site you'll want to use. If you squat on 193.168/16, that's 2¹⁶ addresses and you might block your own access to a few thousand web sites.
I suppose the argument is you're building a house without a door. While you may believe you have everything you will ever need in that house, there's a likelyhood you will eventually need to leave (or something needs to arrive). Now you're stuck. Of course, it's not all or nothihng when it comes to IP space.
If you were going to use 11.x for an air gapped secure enclave, I would have a very difficult time presenting a scenario where that may bite you later. However, I'd vote to use CGNAT reserved space before any 'unused' public IP space.
(FWIW cloudtrail will include source vpc and/or vpc endpoint information when the request is coming through an endpoint. This will help detect those requests)
I wish AWS would offer an all-in-one VPC endpoint that covered all their services. Of course they're not financially incentivized to do that.
Here's the team cymru bogon list, for instance: https://team-cymru.com/community-services/bogon-reference/bo...
My point is about fully private networks that aren't connected to the internet. I would argue that in this case you do own all of the addresses, even if someone else owns them on the public internet.
If you squat as per this definition, can you divert internet traffic designated foe the real IP address to your server?
Or does it only divert it for computers on your network?
https://web.archive.org/web/20080228131639/http://www.renesy...
Sure, some companies have large blocks but that's nothing compared to that.
AMPRnet sold them a quarter of the ip addresses that were allocated for amateur radio. They got a /8 back in the 1980s. A small number of addresses were used for ham radio networks but the AMPRnet addresses were generally not routed between the internet and the radio networks.
Certain popular western european ISP still gives IPv4s cheaper than IPv6s (still a high price, though).
It was "hot" so he couldn't just squat on it or sell it in the open, but he laundered it by trading it to some shady company in exchange for free network services for life.
If I were him, I would have printed out all the addresses on little slips of paper and taken an "IPV4 Address Bath" like Huell's scene in Breaking Bad:
https://www.youtube.com/watch?v=7HrmD_vIMIk
>(sexy lip bite) ... "I gotta do it, man!" ... "Mexico, all's I'm sayin'!"
I have another naughty friend (not the same person) who worked at SRI-NIC implementing and maintaining the ARPANET TACACS database, and as a personal favor, he created our mutual friend Devon his own ARPANET TAC card.
So Devon's free vanity TACACS account was named "DEVON", while most other accounts like mine were something ugly like "DH32", using initials and numbers. One day his boss summoned him to his office and showed him a print-out of the TACACS accounts, with "DEVON" right at the top, and asked him who the hell that was. He sheepishly prevaricated that "DEVON" was actually a control code to turn the printer DEVice ON, which accidentally got printed at the beginning of the list because of a bug in his program missing an escape code, and he would fix it right away. And that's how Devon lost his TAC card. We still tease him about his name as a printer control code, and call him "DEVOFF" when he talks too much. I'm pretty sure his boss knew what was up, but just let it slide.
Network security was a lot different in those days. TAC cards only happened later when they finally put passwords on the dialup TACs/TIPs -- you originally could dial up and connect to any host on the ARPANET without a password, then you could ask nicely for a free tourist account at places like the MIT-AI Lab. It didn't even require any social engineering, just being polite and curious, reading documentation, and following instructions.
I asked BBN nicely about the TIP manual, and they helpfully mailed me a free hardcopy of the "Users Guide for the Terminal IMP", which documented how to take control of other people's sessions and even divert their output by prefixing @ commands by their terminal number! See "Section 5: Unusual uses of the TIP" page 5-7, "Setting Another Terminal's Parameters" and "The DIVERT OUTPUT Command":
https://usermanual.wiki/Document/ADA014398UsersGuidetotheTer...
The guy who originally wrote that TIP manual in 1971 was none other than Will Crowther, who also developed Colossal Cave Adventure with Don Woods! You're in a twisty little maze of IMPs, all different.
https://en.wikipedia.org/wiki/William_Crowther_(programmer)
https://en.wikipedia.org/wiki/Colossal_Cave_Adventure
ARPANET Psiber SPACE (circa 1986): This is the network of IMPs (Interface Message Processors) that comprised the ARPANET in 1986. The ARPANET is history now, but thanks to the magic of Pseudo-Scientific Visualization and the ScriptX language and class library from Kaleida Labs, you can now experience what it was like to be free ranging packet hopping around the ARPANET in 1986!
https://www.donhopkins.com/home/catalog/arpanet/index-large....
MIT AI Lab Tourist Policy
https://medium.com/@donhopkins/mit-ai-lab-tourist-policy-f73...
“The MIT machines were a nerd magnet for kids who had access to the ARPANET,”
https://news.ycombinator.com/item?id=15080221
Keith F. Lynch wrote up a fascinatingly detailed and accurate history of the ARPANET from his perspective:
http://keithlynch.net/history.net.html
Keith mentions that ARPANET TACACS passwords were installed in 1986, and even mentions how Jerry Pournelle got himself kicked off the ARPANET for being obnoxious in 1985, which I can conform with the email messages he mentioned. The first message is about TACACS, and explains how MILNET TACACS was implemented in 1984, before ARPANET TACACS (in 1986). It was addressed to the same DEVON, and HN's own GUMBY chimed in with some salty remarks:
https://www.donhopkins.com/home/catalog/text/pourne-smut.htm...
"then you could even anity TACACS account "
The "Arpanet" episode of The Americans featured a classic scene with an academic computer science professor dude bullshitting about the ARPANET -- I'm sure we both know somebody exactly like that from that period, who made eloquent hand-waving metaphors about Virtual Spaces and Post Offices and God and Disembodied Brains, trying to explain to skeptical people how vast and important the ARPANET was (with its 8 enormous bits of address space). But he kinda had a point, calling the PDP-10 "The Beast".
https://www.youtube.com/watch?v=hVth6T3gMa0
But the thing The Americans "Arpanet" episode got wrong is that you didn't actually have to slap on a Frank Zappa Soul Patch and a Beatnik Wig, dress up like a janitor, and brutally murder an unlucky grad student to get on the ARPANET, you just had to ask the right people nicely! (But it's still one of the best episodes, with the scene about passing a lie detector test by clenching your anus.)
Good old 193.77.212.100, may you rest in peace.
And, let's face it, IPv6 addressing is so fundamentally horked-up that it's practically only usable by propellerheads in the cloud backend: First, the addresses are too damn long and unwieldy to really be used; and second, even most people reading this, tech people in a tech forum, struggle to really grasp the inane IPv6 address shortening rules! Like X.400 mail addresses, they work technically, but are unusable in practice.
(For those of you fortunate enough not to remember, the best way to get and transfer someone's X.400 address, even within the X.400 network, was to have them mail someone through an internet gateway and use whatever it said. Marshall Rose devoted an entire chapter to ranting about this in his Internet Mail book...)
How so? The network-prefix portion of IPv6 is 64 bits, which is a pretty conservative extension of ipv4. Everything after that is under the control of end users, so nothing's stopping them from manually assigning simple ::1, ::2 etc. values for the host identifier part - or whatever addressing scheme happens to be most convenient for any given application.
I have been using IPv6 for at least twelve years and I will agree that at first - maybe the first six months or year - I found these things confusing. But I think your assertion is based on lack of familiarity. Fundamentally, IPv6 works well, and just needs some open-minded people to spend time with it.
Like everyone else on my ISP, I have a publicly routeable v6 subnet at home and v6 addresses on my phones. I couldn't tell you what they are, but they work just fine.
Assuming it's configured correctly. Most devices are not.
> Like everyone else on my ISP, I have a publicly routeable v6 subnet at home and v6 addresses on my phones. I couldn't tell you what they are, but they work just fine.
Why would you ever want publicly routable addresses on devices inside your home?
If Ipv6 was simply a 64-bit quad improvement on IPv4 it would be fine. However, the only valid use cases I can think of are mostly to the benefit of end users.
What possible need could anyone have for more address space than the non-routable private address blocks already afforded by IPv4? Throw in the insecure-by-default and frequent misconfiguration out-of-the-box and you have the current flaming security dumpster fire that is IPv6.
Aren't they? I've never seen a home user fight with IPv6
> Why would you ever want publicly routable addresses on devices inside your home?
Because that's how the internet is supposed to work. It's what protocols are designed for. IPv4's shortcomings have led to many stupid security issues (SIP ALG, FTP ALG, all the other ALGs, all allowing anyone website to punch a hole straight through consumer firewalls). I don't know what insecure-by-default devices you use, but all routers I've seen come with a firewall enabled by default set to deny all incoming traffic.
If you don't want that for some reason, feel free to NAT66 your network into your own chosen ULA.
IPv6 is no more of a flaming security dumpster fire than IPv4.
Ever heard of DNS?
This is the public address space, though, and not really "squatting"
"How I Learned to Stop Worrying and Love IPv6"
https://www.theregister.com/2012/08/21/verity_stob_ipv6/
Choice quote: "'Do you NATter with your Neighbours? Don't squander the nation's resource!'"
That's quite an outperforming asset class if true [0].
For a point of comparison, Microsoft paid $11 per address in 2011[1]. To get to $50 is about 15% appreciation/year, plus the added benefit of being able to rent them out by the minute. This article estimates that Amazon has paid about $25 per address in recent years [2].
[0] https://auctions.ipv4.global/
[1] https://www.marketwatch.com/story/microsoft-buys-nortels-vin...
[2] https://www.techradar.com/news/amazon-has-hoarded-billions-o...
And I honestly don't see why not. This is how the internet was designed to be used, and it works a lot better than most large managed networks in the 10/8 range I've seen. It'll only be a problem once there are more students and services than there is address space.
NAT is a cludge, not a security feature.
The whole migration to IPv6 reminds me of DECnet migration to OSI…which basically never truly happened (because XNS/ITP grew up and became TCP/IP which was then extended to the edge with PPP/RAS, ending the era of store-and-forward email/usenet and destroying X.25/X.PC with its distance-based pricing, heralding the new era of free SPAM and Script Kiddies From Overseas). Same thing will happen to TCP/IP..something else will succeed it before IPv4 is obsolete, probably after somethingBad(TM) happens to create the market imperative for network operators to invest in the alternative.
In fact - DoD should just have it's own internet - that is completely separate. I'd argue that DoD networks should not have any connectivity with broader internet, making their use of the whole 32 bit space completely independent from everyone else.
Doesn't mean that DoD cannot use the global internet, just not use it and their own at the same time. I mean... They could even send traffic over global lines, without taking up IP addresses.
Something I don't quite understand is why IPV6 is better, if anything sticking to IPV4 will lead to more "selective" use. Actually useful things get an IP, the rest, well, better get more useful
We will probably use IPv4 for decades more. It's going to be even slower with constrained semiconductor pipeline.
That's why we have squatters and expensive IPv4 blocks.
But I think we would also be in that situation if it were just IPv4-but-bigger. The main problem is incentives, and they wouldn't change through that.
For example, ipv4 technically has a link-local address space but barely anything will use it and even less will successfully. Many other 80/90s protocols did much better at that (IPX being an example) as well as having distributed name and service locators and such.
IPv6 local networks of IoT devices or whatever can pretty much automagically start communicating with zero configuration to anything else locally. No DHCP or whatever required.
The world didn't stand still between v4 and v6, it'd be weird if the protocol did.
https://cr.yp.to/djbdns/ipv6mess.html
There still hasn't been a coherent answer. The best approximation is that a lot of networking researchers saw their once-in-a-lifetime opportunity to bikeshed the lowest layer of the public network stack, and couldn't resist the urge.
All of this could have been avoided by making NAT64 part of the original IPv6 standard (instead of wasting a decade pretending like it wasn't necessary) and making it a mandatory service provided by every IPv6 router, unless all downstream routers already provide the service. This would have forced an invisible-to-endpoints IPv6 transition, starting at the backbone ("no default route" region). Carriers would have very quickly pushed the NAT requirement downstream (away from the default-free region) in order to offload the burden it creates. Each step of the transition would have been a strictly local change between two peers, one of which is paying the other, and can therefore can be incentivized ("hey, if you run NAT64 for your downstreams so we don't have to, we will charge you less per month"). No global coordination, and the local coordination is always across a commercial relationship where a carrot can be dangled.
But instead we got what is basically a flag day, so "the transition" will never ever happen. We'll still be talking about it in twenty more years.
And the very slow transition hasn't really anything to do with the standard itself, but with the transition technologies (NAT64 like you mentioned). It would have happened with any of the proposed alternatives. Hindsight and all.. NAT itself wasn't even a thing yet (not an RFC anyway) when IPv6 was being developed. Flag days had worked in the past too, so why not again?
All in all you could make the above happen for about the price of a lower end new car in the best case.
There are other ways to get non-legacy IPv4 assignments now but those are leased not owned.
Would stop a lot of squatting on unused space and free it up.
That blog mentioned it but still, the timing of when it happened and who got control of them is odd af.
https://arstechnica.com/information-technology/2021/04/penta...
Something I don't quite understand is why IPV6 is assumed to be better, if anything sticking to IPV4 will lead to more "selective" use. Actually useful things get an IP, the rest, well, better get more useful? Wishful thinking?
Thank you,
That's a scarcity mindset and isn't useful in this case.
Who cares if "low" value things use the internet? Imagine a network in rural Africa. It can't pay market rates for IP addresses but would be extremely valuable for its users.
IP addresses aren't a negative externality like pollution or traffic, they're an artificial construct. So restricting them doesn't actually help people, and making them abundant is a huge benefit to literally everyone.