IPv6 support for cloning Git repositories from GitHub
github.com
github.com
2606:4700::6810:686e news.ycombinator.com
Interestingly when I tried to post the above comment over IPv6 I got a Cloudflare "You have been blocked" page. This might be something they do not want you to know! :DDoesn’t CloudFlare have good bot detection? What does HN do that relies on IP addresses that CloudFlare can’t do?
Cloudflare bot detection is more request-by-request. Cloudflares product is more intended to prevent DDoS attacks with millions of bots. I don't think it's sufficiently fine tuned to prevent a handful of spam comments through.
The official solution (and might be why you see the blocked page) is to set up the WAF to block all requests.
Unfortunately all but a handful of their APIs have yet to support IPv6.
I don't need a static IP. I'd be completely fine with a dynamic IPv4 or even dynamic IPv6. But they don't offer that. Just static IPv4 or CGNAT IPv4. Oh well, some day...
I guess the point I was trying to make is that I think IPv6 is a better solution to their problem of not having enough IPv4 addresses.
Bad for at home hosting, good for privacy.
I guess their router stack provides this for free, while the "Zwangstrennung" (disconnect every 24h) was implemented somewhere on their side. So it's actually easier now for them
Others, even Congstar (which is a cheap telekom brand), do 24h disconnects with a new v4 address, and no v6 at all.
The DSL I use gives me a fixed v4 and v6 range, but still needs to do the daily disconnects.
This policy helped move things forward on the networks I worked on. Lately I did setup a business internet with SLA, I specifically told the ISP I would not accept the contract if the SLA did not mention IPv6 as required.
But it is still a lot of battle, where it should be the default.
Github not fully supporting IPv6 is a real shame and they should really move things forward to support it quickly.
Also, systems should not use IP addresses as a mean of security or authentication, it was a bad idea for IPv4, it is even a worst idea for IPv6. To give you an example of bad firewall behavior, I was checking my electric bill from the train, and suddenly my account got blocked, and it took me a lot of time and effort to fix (physical mail...). My IP changed while I was browsing a page and the firewall didn't like it.
Wow, you live in a very different world than me. If I did that, I can 100% guarantee that the answer from the other end of the line would be, "The Internet is working for everyone else just fine, maybe try clearing your cookies. Have a nice day. click"
I have a weather station I run on T-Mobile which is v6only with a ipv4 CGNAT. I just Cloudflare the v6 endpoint and my legacy (v4) users can visit the station.
But even then they often have an ability to get a NAT IPv4 connection out somehow.
pretty lame by hetzner if that's the case
Well, they added the Option, so you can get your server for less then normal. The Servers are cheaper, if you Opt-Out of IPv4. I really liked that move.
[1] https://www.indiatimes.com/technology/news/india-sets-new-de...
[2] http://www.stdaily.com/English/ChinaNews/202208/e154b19bb5b0...
If it ain't broke (and it really isn't quite yet) then I suggest we crack on. IPv4/6 are simply transports, one has a larger address space and quite a lot of attitude! There are translation mechanisms so it is unlikely that anyone will be left behind. As systems move to IPv6, parts of IPv4 space are released and 6to4 n that tunnels can patch up the holes.
You need to learn patience. It took me about two years to persuade a firm with around 6000 employees to deploy DHCP back in the day. I made sure it was everyone else's idea and took my time. That was a tiny thing. This is the entire internet and it requires a massive mindset shift, engineering, purchasing and what not.
I'm going to tentatively put IPv4 -> IPv6 in the "paradigm shift" category. It isn't really technically: the wires (ethernet etc) are the same but the bits are somewhat different!
If you really want to get steamed up then why not debate the semantics of how multi-WAN connections should work with IPv6? Suppose you have two ISP connections for WAN and hence two lots of addresses. How do you deal with an ISP outage? How do your PCs know which set of source addresses to use? Do you use NAT64 or NPT or something else.
Another thing to consider is how do you "bootstrap" your network with IPv6 and how do you deal with a change of ISP? Do you set DNS servers with ULA addresses so they stay static or what? Bear in mind that SLAAC doesn't give out DNS servers. OK, lets do DHCPv6 ... not on Android ...
IPv6 needs some care. It has been messed and muddled around with so many times and it still has some gaping holes. For me the biggest problem is the righteous indignation you find at nearly every turn where stuff gets broken for its own good.
It all starts to go wrong with "everyone should"!
The starry eyed approach that you think that India and China espouse is simply twaddle. No one really thinks that in the real world, despite what is said on TV. Nation policy of that sort is normally a case of "Do as I say and not as I do".
In my opinion we should damn well continue to muddle along as best we can with what we've got. We will patch the flaws and paper over the cracks because that is what engineers do.
If you only get a /64 ie one IPv6 subnet prefix then you are only a tick in a box.
Ideally you also get a separate uplink subnet too along with your shiney prefix for WAN. There is a RFC that will enable a sub-prefix from a prefix allocation to be taken out for WAN and make it all work. Sorry if that sounds like gibberish - I won't explain that lot here!
There are so many things to get sorted with IPv6 - it is not a finished thing. It's only about 40 or so years old.
Now, you could truncate this to eg a /64 or /56 range to identify users, but each ISP has different rules. Mine gives a /56, but I also hear many give only a /64 or less.
As such, it basically means that you can’t really rely easily on IP addresses anymore for spam detection, rate limiting, etc.
Note that I’m not an expert on spam filtering, but I do have quite some networking experience and QoS, and ran into these issues a lot.
Whereas the same in IPv6 isn't feasible. There is no reasonable way to divide the IP space non-sparsely and keep in RAM and still ban without ending up banning a whole ISP.
Even at 128:1 CGNAT ratios a /24 has 32,768 potential users.
By comparison, a /56 has 256 potential users on a /64 each.
With some heuristics of "hey, we saw two /64's from the same /60" you can catch most ISP's that are offering prefix delegation to their customers, and that's only 16 /60's in that /56 before you are fully blocked...
It's not that much harder or difficult.
v6 is more difficult, by design. The lower half of the address is deliberately not subnettable and it is the explicit design intent that machines on a v6 network can just make up new addresses within a /64 as they please. So you have to burn subnets. Except there isn't really a standard for how subnets are issued: most ISPs hand out /48s, Comcast insists on /64s for residential use, etc. In the IPv4 world you could ban one IP at a time, and only move on to banning entire AS allocations if you needed to. On IPv6, banning a /64 is a lot less impactful, so you have to start with the most drastic and customer-hostile option.
It's unfortunately harder to support IPv6 than I think it should be, so many organizations do not. I'd love to see GitHub support IPv6, but they are by no means the only one.
2001:67c:27e4:1064::140.82.121.3 github.com www.github.com
if your curious too, see https://www.rfc-editor.org/rfc/rfc6052#section-2.4edit: yes this is a gateway or "translator" (NAT), you can find a list of other public ones at https://go6lab.si/current-ipv6-tests/nat64dns64-public-test/
I wasn't aware that over half of my internet traffic goes over IPv6 already
A number of high traffic sites (e.g. Youtube and Netflix) have v6, so you might find the percentage of your Internet traffic that goes over v6 is actually much higher than that.
Look for "happy eyeballs"
That being said, looking at real stats (number of packets/bytes through ipv4 and ipv6 firewall on my home router) I have a x1.56 ratio in favor of ipv6. It really depends on what content you consume though.