Amazon, Verizon found using IPv4 240/4 addresses
labs.ripe.net
labs.ripe.net
Yeah, so about that:
https://github.com/seligman/aws-ip-ranges/commit/2e0d9d87d4f...
They did briefly list 252.0.0.0/10 in their published list of IP ranges. The people I spoke with about this at the time either claimed it was a mistake, or the state of the world that I should get used to (it broke some surprisingly fragile scripts on my side for silly reasons).
Given they removed it from their list of IPs 27 hours later, I'm guessing I wasn't the only person freaking out. But yeah, they use it internally, and it leaks from time to time in surprising ways.
On the other hand, that’s probably how we ended up with this article. I still don’t understand how this could have been an accident though.
(I'm the first author of a current draft about that, https://datatracker.ietf.org/doc/draft-schoen-intarea-unicas..., and I contributed to this RIPE Labs article but didn't do the underlying research.)
As I think you're pointing out, that's not necessarily interesting because if 240/4 were officially sanctioned as private space, then these people would likely not want to use it, for the same reasons that they aren't already using 10/8.
[1] https://datatracker.ietf.org/doc/html/draft-wilson-class-e-0...
I suspect both AWS and Verizon fall into that category.
It's not necessarily a problem for the general public, but will pose a routing problem for those using them internally.
EDIT: I just realized you said 192.169/16, which is definitely not available for private IPs.
A company I worked for, which is basically a group of a dozen acquisitions, uses practically every RFC1918 block which makes things really annoying. 10./8 used by IT, 192.168/16 used by company X acquired in 2004, 172.17/16 used by company Y acquired in 2011. The list of routes the VPN software installed was impressive.
By the way, I use 172.30/16 for my home net. I have personally seen use of 172.16/16 and 172.31/16 before.
[1] and I mean 'real' VPN that connect machines you own, not glorified proxies/exit nodes.
I wouldn't read too much into it. If they are using it in a way that will break if 240/8 is assigned, I'm sure they will fix it quickly.
* See https://news.ycombinator.com/item?id=29246420 for a discussion of a related proposal.
Yes, obviously that was a terrible choice to make. But it's there. And legal compliance means they can't just let these addresses in as normal unicast.
So while these can work as rfc1918 and similar, nobody will ever want to use these on publicly facing clients or servers. Too many places will never support them.
I'd rather be behind 3 layers of CGNAT.
We've been trying to get people to switch since the late 90s/early 00s. And it's only now making progress because IPv4 address have an actual cost which keeps increasing.
But I think IPv6 is huge example of second system syndrome. Instead of just solving the obvious and most important problem of IP address exhaustion, we piled on a whole bunch of other requirements, greatly expanding the scope, increasing switching cost, and dragging out the migration for literal decades. Here we are 20+ years later with only 40% adoption of IPv6...
And I can see the temptation to bundle in all those other changes, since this might be the big opportunity to get them out there. But seems like we could have come up with a simpler and easier to switch to alternative that would have solved the acute issue much faster.
Instead we're here muddling through.
To get from 40%to 80% just requires a few ISP's to make it the default on their routers, which they have an incentive to do as soon as they run out of IP's and CGNAT starts to get expensive to run. Enabling IPv6 immediately halves the load on the CGNAT boxes because all the CDN traffic immediately uses IPv6.
What you mean? I think what's needed is IPv6 support by ISP and make Happy Eyeballs on client to strongly prefer IPv6, not router.
IPv4 will continue to exist in limited capacity as long as network hardware supports it. With increasingly more network hardware suppliers phasing out IPv4 support for cost reasons, we will see it dying quickly.
Real scenario - developer of Valheim initially released the game on Itch.io but then removed it from there, saying that it now has to rely on Steam services for NAT traversal for its multiplayer, making it tied to Steam in result.
Clearly if IPv6 would have been available there wouldn't have been the need for such services, no? So I'd say end users are bitten by this, just not in obvious ways for them to start complaining about it.
The additional benefit of those services is that they mask clients' IP addresses. This makes doxxing and DDoS attacks much hard to achieve.
Grand Theft Auto 5 Online is notorious for its direct peer to peer connectivity, to the point where it's recommended to play with a VPN. Playing without one exposes you to a very real risk of being hit with a DDoS attack launched by a cheater (or someone with the basic knowledge of Wireshark) who wants to take revenge for one reason or another.
DDoS services are a commodity accessible to anyone with a $5 gift card these days. I don't want to go back to the world of direct peer to peer connections for gaming.
Your device also isn't hidden too much if a NAT router lets it have the ability to make outgoing connections - it's just less convenient to access.
You might see more attacks targeting specific internal IPs if NAT never existed more but it doesn't necessarily follow that NAT is preventing or reducing botnets. Dos/DDoS attacks can be focused a your router with or without NAT.
Problems start with NATs that you can't control.
IPv6 could blow routing tables sky high.
We burn 64 bits of the space (!!) on the "privacy extensions" changing part of ipv6 which is totally insane, and so you have a constant churn for 64 bits of the space. This churn complicates a fair bit of local area network address use.
You can get a static IPv4 block if you need it with business class service as well for that site. Despite claims it's a total pain to get IPv6 static blocks assigned by ISPS.
Your internal network can be subnetted however you like if you do any site to site VPN if using NAT. you are not dependent on uplinks at all.
Now if you have a business with a bunch of sites, not all may have full BGP etc setups. For example, you might do a dual WAN link - one fiber at 1gbps, another at 300mbps for backup. This is seamless with IPv4 in most cases.
With IPv6 - if your routes flap, you have to readdress everything on your entire network (!!!) for that site. And these updates are SLOWER and worse from what I've seen then WAN failover on the NAT. So then you can try to do the workarounds (network prefix stuff). So if you flap around a bit the network is done. This could just be a tech reconfiguring things and pulling a cable and putting it back in seconds later.
And the list goes on. Network prefix stuff is poorly supported. You are basically forced into dual stack mode. Etc.
“Show me how your new system solves problems only the old system has, or I won’t adopt it!”
but you don't have to switch, you can have both at once.
its not even like there is a significant hardware cost; all network gear for the past 15+ years has supported ipv6; you get it for free when you buy hardware that works with ipv4.
Source: Serial Experiments Lain
ISPs are way more eager to move to ipv6, probably due to a higher ip address per customer ratio than companies that offer network services like websites or such.
http://www.delong.com/ipv6_alexa500.html
http://web.archive.org/web/20161019011050/http://www.delong....
So: IPv4 space already pushing $50/address, ~$1bn of unused-but-potentially-routable IPv4 space (240/4) just sitting there, and 25 years to go before it becomes worthless. Any guesses what happens next?
“When will >50% of users access Google over IPv6?”
Community Prediction Dec 21, 2024 at https://www.metaculus.com/questions/9558/when-50-of-users-ac...
“When will global IPv4 traffic account for less than 1% of total internet traffic?”
Community Prediction Sep 23, 2042 at https://www.metaculus.com/questions/4449/when-will-global-ip...
I believe even in 10 or 20 years, we'll see ipv6 only on public traffic, anything else (which is much more both in traffic and ips) will remain on ipv4.
There also seems to be some sort of weekday/weekend pattern going on.
Why does India have such a large adoption rate? Because the got newer hardware to start with I guess?
Instead they've aggressively rolled out IPv6 and carrier grade NAT where needed
1: https://www.businesstoday.in/technology/story/india-to-have-...
The adoption rate in August 2021 was 35.26%, August this year is 39.71% thats a reasonable 12 month growth of 12.6%.
Between August 2020(33.24%) and August 2021(35.26%) there was a 12 month growth of 6%.
Adoption velocity is increasing year on year and for much of the past 25 years there was little reason to roll out IPv6 with gusto and so telcos didn't bother with the investment. With the exhaustion of cheap IPv4 we should see IPv6 adoption velocity only increase.
Other clouds too.
And CGNAT is expensive. No. There are some legacy allocations, but at least my experience is than nobody has enough.
ipv6 is windows me. Skip over it. Wait for ipv8.
edit: Oh! We could make ivp8 just 16bit instead of an octlet!
1...7...7...6...1...8...1...2...1...8...6...5...1...9...1...8...1...9...4...5
And then try to remember and recall this sequence:
1776...1812...1865...1918...1945
Pretty much everyone finds the latter easier even though they are effectively equivalent. This was done as a demonstration of Miller's 7+-2 model of working memory.
I sometimes wonder if the reason IPv4 continues to stick around and IPv6 hasn't gotten the uptake we need is because the former fits into the memory models needed by the end users (developers) whereas a space of 2^128 instead of 2^32 starts pushing the boundary of what a human operator can easily keep in memory.
I agree though that IPv6 has some human factor problems. You can actually use IPv4 addresses in it like ::10.0.0.1 - that's valid IPv6 if you wanted to use it on your own networks at least.
And I’ll probably take the root password to their RADIUS server to my grave.
With ipv6, that's less doable.
So while you may have a similar problem it would be FAR FAR FAR FAR easier for organizations to adopt an addressing system that works EXACTLY the same as ipv4 just with a larger address space
then all the other "improvements" they are forcing down everyone network (unwanted) in with ipv6
ipv6 spec caused all the problems by biting off more than what was needed to solve the problem.
Just start with 1::a: for the first 96 bits and duplicate the entire ipv4 range into the remaining sections (I.e. 8.8.8.8 would become 1::a:8:8:8:8) which would still leave a huge amount of space open from a's-f's being technically available as identifiers (i.e. 1::a:8:8:8:f would be a valid ipv6 address).
Then, as people stop using NAT, let them have access to the 1::b: section, and if that section ever gets filled, 1::c:, etc. Once NAT is sorted, roll out routers that would NAT ipv4 to 1::b: addresses so that they are in both locations at the same time.
It's easy enough to mentally switch to using colons instead of periods, and everyone could also easily memorize their opening "street sign" or whatever it is called.
e.g. ::ffff::192.168.1.1
is an IPv6 representation of 192.168.1.1
Or in more standard v6 notation
0000:0000:0000:0000:0000:ffff:c0a8:0101
Phase one has us use something in tcp headers, maybe something in the reserved area, to set a number. It's OK for that to just be maybe 1 to 4 even, or something small depending upon bit size requirements.
Since old systems won't use that reserved header space to determine anything, they'll ignore it. And new systems will exclusively use unroutable address space, like 240 being discussed here, for routing.
So old systems will drop the 240/ address space, but new systems will route it, as it will be 2.240.x.x.x. So only compliant systems will see the new address space ; the rest won't.
It won't help old systems, but it will mean new systems only using old address space, can speak to old systems, without breaking them.
Everyone loves sensible change, so unlike ipv6, ipv8 will only take 20 years! (What's ipv6 been out for, 25 years and not adopted yet?)
IPv6 is kind of over the major adoption hurdle of rewriting all software to understand it. Nearly all software understands it. I'm not sure anyone really has the appetite for that again.
An example ; when we start throwing smart nano on the grass, to see how each blade of grass is doing on your lawn. Well, each nano is going to need an IP address, and so will all in the neighbourhood. And that's just the grass.
What about when some scientist wants to track sand dispersal patterns, on a beach, after a hurricane? And wants to have each grain of sand tagged with its own nano hitchhiker? Just think of the IP addresses we'll need then!
And even medicine. What if we want to interally tag each cell in our bodies with nano? What if we want to bioengineer our body, so that each cell has its own IP address? And can report health/condition?
No, we need more, more more IP addresses! So many more.
There will need to be multiple addresses for all the nano-services running inside each of those nanobots. Solution: install a k8s cluster with each nano...
https://www.techtarget.com/whatis/feature/IPv6-addresses-how...
"[...] assign an IPV6 address to EVERY ATOM ON THE SURFACE OF THE EARTH, and still have enough addresses left to do another 100+ earths."
The first is, they were working on this before the Internet was widely used. Back in dialup days, pre-2000, the draft presented in 1998, working on it in 1995 and before surely.
Compared to today's scope and size, this was nascent/early style change, in something which was constantly changing.
They didn't see any contention likely at the time. Why not have all the universities, government departments, and research bodies switch? This was an entirely different landscape compared to today.
So in their eyes, why not make change? It wasn't a big deal, hell back in the early 90s, people were using token ring adapters/networking still in many offices!!
The second thing is, NAT wasn't a thing back then. The computational power was a limiter for large scale usage.
An RFC for NAT came out in 98 I think, and Linux had ipmasq, but that was brand new in the early 90s.
Basically, ipv6 was crafted before anyone had any idea we'd be where we are today.
In fact, the worry about address space exhaustion in the early 90s was due to a lack of NAT, or even the idea that it could be deployed everywhere at scale.
Where would all the compute power for NAT at scale come from?!
So basically, it was crafted with a different viewpoint.
That would be a good BS level graduate thesis paper for someone interested.
I really wish cloud providers would just emulate a bare metal network cable that I can send any kind of packets over... Then I could update to IPv7 whenever I damn well please!
you can get IPv6 addresses from Azure for the same cheap price you can get IPv4 addresses for!
not ridiculous at all.
If anything, this is almost a warning from ARIN that this block might be finally repurposed. They find no one using it except for two companies internally ; they're seeking to see if 240/reserved is used or not is seems.
And really, anyone using 240 is to blame if it does get repurposed, so it seems like a good idea.
Blame is not correlated with pain.
I don't know AWS internals, but they may need to do hardware revisions they need to roll out to switch ASICs, not to mention millions of lines of code.
And the addresses will be "kinda broken" everywhere, basically forever. So AWS wouldn't even get the blame. So there's no incentive for them to have a moon landing program costing them many billions, throwing away hardware before they otherwise would.
Of course it is 2022, so I would hope that AWS's current production hardware is IPv6 ready at equal pps, FIB size, and features, but I wouldn't be surprised if not.
But the software should not be underestimated. That IPv4 address in a database, stored as 32bit integer, is not exactly trivial to extend on disk and by every single reader and writer.
Nobody will want these second class addresses, not on the client nor the server, so who are they for?
(on the public Internet, that is. They could be used as 100.64.0.0/10)
Can't migrate to IPv6 without having a real deadline.
That's how it has to be because adoption that's optional never happens: look at the US and metrication.
You can’t just use any IP: some are truly special (e.g. the multicast range) and 240/4 is still treated as invalid by many currently deployed IP stacks in their off-the-shelf configuration. Getting away with this only works at the kind of integration scale where you’re smelting your own copper, so to speak.
The actual probes are tiny consumer grade routers (https://www.google.com/search?q=ripe+atlas+probe&tbm=isch) with a new firmware. RIPE provides these free of charge to volunteers (people and companies) who then run them in their network (e.g. homes and datacenters). (Of course larger form factors are available to volunteers with more in-demand locations.)
In return, volunteers get rewarded for uptime of their probes with credits that can be used to request custom measurements from the Atlas network.
There are probes _everywhere_; not just in terms of geography (https://atlas.ripe.net/results/maps/) but also in network locations that you cannot get access to via any other means; there really is no other service that comes close in terms of reach for global internet status testing.
a. Do linux/windows just take it 240/4 address without special attention?
b. Fun time when 240/4 will be released to public in the future it's gonna be a huge headache for them.
The situation is more complicated for routers, including high-end datacenter routers. (If you have something that's post-2008 Linux under the hood, it probably works although there might be some higher-level software enforcing special cases.) The trend has been toward more router support for 240/4, but the special case was historically enforced in many devices, and older routers sometimes stay in use for quite a while.
Windows is definitely the outlier on endpoints; when I gave some presentations about 240/4 over the past year I pointed out that, if people were watching them on a device running anything other than Windows, that device would most likely interoperate with 240/4 addresses.
This is so tone deaf.
Put it this way, if Verizon, Google, and Facebook weren’t the champions for IPV6 for rolling it out, I’d be on board.
First and foremost: ipv6 is unnecessary for the end user, ipv4 provides the default assumption that a casual anonymizing NAT is in use.
And we can be real: SRV records, SNI, NAT work just fine and solved all the problems IPV6 went to solve _from the consumer perspective _.
I know this comment will be incredibly unpopular on HN, but the points need to be addressed. Your ISP is not your friend and neither are these other companies that sell your information without your explicit consent.
It's sort of tolerable if it happens on your home router which is under your control, but its absolutely a pain in the backside if it's done on the ISP level (CGNAT) and you want to self-host anything from your home network, like multiplayer mode in some games, or whatever…
If everybody was just a consumer all the time, we would have a very different (worse) society overall. There is a reason a subset of technical people do want IPv6 even if it means way more work for them.
ISPs have been deployed for years without IPv4 or bad IPv4 (see this thread). And even not counting those ISPs there are countless more than would completely fall over if the major players stop announcing IPv6.
They just don't have the CGNAT capacity to run the internet without IPv6.
Strictly from the consumer perspective this means buggier, slower, and more expensive internet. Consumers don't care about bits, but their dollars he to buy the CGNAT and other crap.
And it'll only get more and more expensive (for the customers).
Until it breaks something, as was the case with 1.1.1.1