India is almost 80% IPv6
apnic.net
apnic.net
There has been a "National IPV6 Plan" in place since 2010, and full coverage has been pushed under that plan in stages. Anyone interested can read all about it in (extensive) detail[2].
0. https://dot.gov.in/ipv6-transition
1. https://dot.gov.in/sites/default/files/Revision%20in%20IPV6%...
2. https://dot.gov.in/sites/default/files/2016_11_18%20IPv6%20N...
Would worry about most average cell phones sitting directly on the public internet.
I think there’s a reason we haven’t heard about mass-owns of mobile phones and it’s because they’re always effectively behind firewalls, not because of their superior security.
From https://www.arin.net/blog/2020/01/16/mobile-edge-of-the-inte...
"80% of smartphones in the US on the major cellular network operators use IPv6 and major mobile networks are driving IPv6 adoption with Verizon Wireless at 84%, Sprint at 70%, T-Mobile USA at 93%, and AT&T Wireless at 57%"
And this were numbers from four years ago.
NAT is not a firewall and it's dangerous to think of it as such, because it causes people to follow a lax approach to security and think they are protected, when they actually aren't.
I hope that IPv6 is rolled out to homes, most ISPs would do the right thing and set up customer routers firewall in "default deny incoming " mode. Otherwise, the number of worms would increase a lot.
What scares me a lot is that lots of folks out there still rely on iptables, and do not realize that they need ip6tables to set IPv6 tables - I dread of the moment some random ISP will push IPv6 routes, SLAAC picks up an IPv6 on a random Linux box and that box gets instantly pwned because it has no ip6tables rule whatsoever blocking inbound traffic.
I've been behind CGNAT since I think 2010, at first with DSL with a small ISP and then with one of the big ones with fiber (bredband2), who introduced CGNAT many years ago to prepare for moving to IPv6, which they have still yet to do.
They even stopped supporting their 6rd tunnel apparently.
I wonder how much all the IPv4's on Earth are worth.
Maybe other places just don’t have a desire to regulate this.
I’ve gotten myself stuck a few times with this assumption. My MacBook Air (and probably any MacBook) will accept a trickle at 5V, but my Dell laptop will not.
Only if you want fast charging. I run my MacBook Air over a USB-A to USB-C cable and it slowly charges under light use at around 2.5A and 5V. And tops off to 100% while not in operation. If you want more voltage, then yeah, you’ll need a more specialized charger, whether USB-C or proprietary.
1. Corporations are exactly the tool we use to work out what trade offs of cost v. standardisation are best. Everyone is going to claim victory for a bureaucratic committee then a few years down the track we'll discover technology moves on and the regulation is force people to make stupid choices. Removing the flexibility to adapt at the forefront of technology is going to turn out to be foolish in hindsight. These devices aren't even 20 years old and the EU has already decided to start fossilising the tech.
2. There is a decent chance that this will corrupt the USB standard itself. We're already seeing the bizarre profusion of naming [0]. If there is an incentive for corporations to create incompatible things that are all named "USB-C" they may well manage it. Calls to mind the OOXML vs ODF format wars.
3. This is a total waste of political attention. I suppose now we know how the EU ended up in such a catastrophic posture with their energy policy. Their best and brightest were back-seat-driving iPhone design. Thank goodness for the Europeans, they may not have reliable power but if they did they won't have to search around for the right cable. And if we need to send phones into the land war, we know what adaptors to send with them!
The USB standard is messy, but I think there's been ample evidence that this is not because of the EU. Bluetooth is also very messy.
Point three is just nonsense, I got nothing to add to that.
yeah... about that.... we in fact have electricity in the outlets, we have countries where the grid has lower chance of a power outage than the chances of a UPS failing. We dont have people rushing to buy gasoline for their generators as soon as a wee bit of bad weather hits..
hows it going in california right now? Babylon bee had a pretty funny, atleast from an outsiders perspective, "news" article:
https://babylonbee.com/news/california-man-takes-his-fiance-...
What you're referring to is a very recent law (months old) that will take effect in 2024.
And it could limit future newer ports that are technologically superior (like lightning was when the standard was micro USB)
IPv4 930k -> 515k aggregated https://www.cidr-report.org/as2.0/
IPv6 161k -> 86k aggregated https://www.cidr-report.org/v6/as2.0/
Both of those are nothing compared to the requirements for CGNAT, tracking each individual TCP session.
Savings are pretty much capped at one month of internet service, as that’s roughly what an IPv4 address costs.
World ranking: https://stats.labs.apnic.net/ipv6/
I understand why v6 is necessary for the internet but I can’t reconcile it with my home network.
I tried a few times migrating over and it’s just an insane amount of work for essentially nothing… all the firewall rules, containers to subdomain mappings, all the wifi clients would get a completely new numbering scheme. And it changes when you change ISP if I understand correctly because your prefix changes.
It just seems insanely complex to me for no benefit. I have nginx as a proxy on ports 80 and 443 which dispatches the request to the right application based on the subdomain, and that’s it. I don’t understand what ipv6 would do for me in that context.
And most (all?) games or VoIP or other network applications all know how to deal with NAT by now.
With v4, I can have subnets and firewall rules so that my printer can only talk to local computers, or my tv only to my home assistant instance. Now idea how I’d move this all over to v6.
Edit: Reading your post again it sounds like you have mental model of either IPv4 or IPv6, when in practice it is often mixed. Each client can have an IPv4 and IPv6 address - even multiple ones! When you enable IPv6 on your router it gets a subnet from your provider and announces the prefix on your network. The clients then generate their public IPv6 address based on this announcement. Note: Even though they now have a public IPv6 address, the router's firewall should block incoming connections to it by default. That's the case for my router, but to be sure you should check it yourself for yours.
This is why I won't enable IPv6 unless ISPs dramatically change how their hardware works. My ISP-issued modem+router doesn't even have a way to disable routing or automatic updates. I can test the firewall today, but what guarantee is there it'll just keep working?
Also, I doubt ISPs will ever change their home routers to default to IPv6 because of the complexity it'll add to customer support with no extra benefits.
It could be with UPnP, which as a security conscious person you likely have disabled. Do you trust it staying disabled or none of your many devices trying to use it to poke holes in the NAT?
Even if you have to use your ISPs modem/router device, it might have a bridge mode where it just becomes a modem, enabling you to use your own router. It might be worth checking this option if you didn't already.
If you don't trust the ISP device to firewall, then you can't trust it even for v4. You need to run your own router.
Now if I also let internal devices get both a v4 and a v6, they essentially all become directly exposed to the internet through v6 don’t they? That’s the part that really confuses me. And if they aren’t publicly accessible from the internet then I’m back to v4 NAT where I was all along which kinda makes v6 pointless doesn’t it?
If you enable IPv6 on your router it will likely advertise an IPv6 prefix on your internal network, which in turn will lead to your clients getting IPv6 addresses - unless you disable IPv6 on their interfaces. Clients will then make use of IPv6 to connect to any service that has an IPv6 address, as they prioritize IPv6 higher than IPv4.
> Now if I also let internal devices get both a v4 and a v6, they essentially all become directly exposed to the internet through v6 don’t they? That’s the part that really confuses me.
They won't become directly exposed - the router's firewall should block incoming IPv6 traffic by default. This is the case for my router and should also be the case for others. To be 100% sure you could do a quick check and try to ping your device from the internet using its IPv6 address. You will likely see a message saying: "Destination unreachable: Administratively prohibited" or get a timeout.
> And if they aren’t publicly accessible from the internet then I’m back to v4 NAT where I was all along which kinda makes v6 pointless doesn’t it?
You can open ports in the router's firewall for IPv6 addresses. However, the main advantage for you would be that your clients can access public IPv6 addresses - which they currently can't. This might not be a big deal yet, but as IPv6 slowly gains some traction it will be noticeable in the future. Some hosters already charge extra for IPv4 addresses.
Most consumer routers have a stateful firewall [0] for IPv6 that basically behaves like NAT. But it's less of a problem than on IPv4 anyway. It's possible to scan the whole IPv4 Internet in less than 5 minutes. [1] And this is done constantly by many people. The IPv6 address space is way to big to do this and you have to harvest addresses. [2] It's always a good idea to have a firewall but unlike IPv4 you don't get port and vulnerability scans seconds after you expose a host to the internet.
>which kinda makes v6 pointless doesn’t it?
IPv6 is mostly useful for ISPs. There are just not enough IPv4 addresses for everyone.
[0] https://en.wikipedia.org/wiki/Stateful_firewall [1] https://en.wikipedia.org/wiki/ZMap_(software) [2] https://isc.sans.edu/diary/Targeted+IPv6+Scans+Using+pool.nt...
Your home network is part of the Internet, by definition. There is no difference between one part and another.
It’s useful for certain corporations to try to crush the end-to-end principle but there is no benefit in going along with their plans.
Why didn't "ipv6" simply get implemented as:
"Well, our ipv4 addresses of 4x8bit, well, we'll just switch those to 4x64bit or whatever."
Then it becomes like a gradual y2k migration. Old servers could be addressed by the new ones, and if the old ones didn't want to address the new ones, well, that was their problem. You didn't need new infra, addresses, etc, you simply upgraded the software.
Or, using NAT, the 4x64s would provide some NAT port with an 4x8bit address to respond with. As the internet switched over to 4x64 in the DNS and freed up 4x8bit addresses, they could be dedicated to the translation.
I know the ship sailed long ago, but what am I missing here? Can this still be done with some "IPv8" movement where everyone gets fed up with IPv6 hassle, and also just wrap in ipv6 addresses somehow? Why didn't the original group simply expand the size of the numbers in the address quads?
Yeah the current holders of IPV4 ranges would have gotten large segments of address space, but if there are 4x64bit, that's still several universes of per-atom addressing.
As for India, it's unsurprising a nation with a billion people and on the outside looking in of ip address governance is more gung-ho about ipv6 adoption. Plus, India is probably mostly mobile phones in terms of computing, and ipv6 was the basis of mobile phone internet infrastructure from the ground up.
Almost all fields in IP header have fixed size - so it doesn't really matter that you just change address size - it is already a new and incompatible protocol.
And adoption of IPv6 wasn’t so slow due to its design or any technical properties. Simply no one wanted to do additional work as long as supporting only IPv4 worked fine.
As in they didn't even seem to consider that maybe you adapt the existing IPV4 code to some form that can handle both protocols. It seemed like they wanted to force total software rewrites and hardware purchases all over the stack.
I mean look, one if-then to identify the packet type is not that bad. Or simply have the ipv4 as the first part and the wrapped packet has another 128-256 addressing bytes.
Almost all existing code that was written to handle v4 was written to handle addresses of exactly 32 bits, not addresses of arbitrary length. Longer addresses therefore required writing new code to handle them. v6 is close enough to v4 that you can write code that can handle both families, but neither the existing code or the new code was under the control of the people designing v6.
You use dual stack because it's maximally compatible with existing devices and code. There are plenty of ways to run single-stack v6 if you want to, but they all have some compatibility issue or another (and the compatibility issues stem from the way v4 was designed, not the way v6 was designed).
v6 addresses use : rather than . because they could otherwise be confused with DNS. For example, a string ending in ".be" could have been a v6 address or a subdomain of the .be ccTLD.
IP packets do start out with a version field, so your "one if-then to identify the packet type" requirement is exactly what v6 already does.
> Or simply have the ipv4 as the first part and the wrapped packet has another 128-256 addressing bytes.
You've invented 6to4. It already exists, but people seem to prefer native.
A /8, an example being "~rel" (one syllable names based out of a bank of 256 memorable 3-letter syllables)-- these are galaxies and are extremely rare (128 galaxies total). Then you have /16 stars which are like "~tabrel", combining two of these syllables -- their are 64,000 stars. And then finally, you have /32 planets like "~sampel-tabrel", which are 4b illion and enough to be valuable and stop spam, but are somewhat disposable kind of like a phone number.
Each one of those planets can spawn billions of /64 moons (sampel-tabrel^dambel-gabnel) which can be used for IoT or family members.This naming scheme draws a good delineation has both human understandable names and memorable addresses you can use for a lifetime -- as well as tremendous scalability to support routing between trillions of addresses.
TIM had a very poorly functioning technical trial of native IPv6 12 years ago, and while it still exists (and sucks) it only works on ADSL (not VDSL, 20Mbps ADSL).
I guess that carriers have just too many IPv4 to throw around, mobile connections are all NATted with no sign of any future roll-out of IPv6 in sight.
I use Tunnelbroker to provision IPv6 to some services I run on a VPS provider that hands out a /128 for some obscure reason. It works great if you can configure the tunnel in your router.
The biggest difficulty for home use is to set up DNS in such a way that streaming services don't resolve over IPv6 so you don't get blocked (or, as I did for a while, to just pirate content when they refuse access to the services I pay for; my Jellyfin + *arr setup is often easier to manage than finding the right service to watch my shows on).
ISPs don't want to spend money exchanging routers.
There's a per-country map here: https://www.google.com/intl/en/ipv6/statistics.html#tab=per-...
PTS is starting to show some interest[1], we'll see what leads to.
[0] https://en.wikipedia.org/wiki/Municipal_broadband
[1] https://www.pts.se/sv/dokument/rapporter/internet/2022/ipv6-...
Slightly off-topic, but what should you be ashamed by something that is totally independent from you, that you can't control in any way? Personally I'm ashamed only if I do something wrong myself.
Ok, maybe I should exclude clubs...
I don't really miss it anyway. There is nothing I can't do without it.
Edit: According to the link Spain is at 3% which seems about accurate :)
Source: My current Internet connections.
Other RIRs will have the information on their website, or your sponsoring LIR will be able to answer any questions :)
[0] https://www.ripe.net/publications/docs/ripe-738 section 7
Solved it googling "lir ripe"
This was the first time I felt like being on the ipv6 network. I also wonder why I was not able to access to ipv4 servers, I assume that in India people have no problem accessing ipv4 only networks.
Anyway - this was the first time I had to deal with ipv6 :)
On the business side. One ipv4 costs us $3/mo. We never had any problem with this, didn't feel any business reason to upgrade and in particular we (as most of the companies) do not have any permanent test of ipv6 connectivity going on. So even if this had been setup at some point, we would never notice a regression here.
So - unless our customers started asking for ipv6, government pushed some regulation or the address' prise would go up - I do not think we will do anything about ipv6, like most other companies.
The $3 are an early warning signal. You can start upgrading slowly on the cheap when you have all the time in the world, or you can do it for much more money and higher risks come crunch time, when you "see a business reason."
I don't have an axe to grind with IPv6 in particular, but I wish managers who consistently make short-sighted management decisions when the writing is so obviously on the wall, would face unemployment.
I don't know why a tornado would only knock out IPv4, seems to me that the prefix administration for IPv6 should run on the same location as the DHCP administration for IPv4.
I would've switched most of my systems over to IPv6 by now if it wasn't for my workplace using Ubiquity hardware that still lacks IPv6 hardware acceleration, forcing the admins to disable it or face unnecessary network slowdowns. I like to be able to use my password manager and such on their WiFi just in case.
Indian regulation forcing IPv6 availability may lead to limited IPv4 availability in one of the biggest developing economies in the world, which may lead to business reasons for switching over. I can only hope, we've been stuck with IPv4 for way too long.
Apparently this is now common. It’ll hold back adoption even more since most people do not change defaults.
Can anyone from India comment? I imagine a lot of this is mobile, what is the v6 like on fixed broadband?
But maybe variable SLAAC will be the solution here
https://datatracker.ietf.org/doc/draft-mishra-6man-variable-...
https://whatismyipaddress.com/ reports an ipv6 and ipv4 address for each connection.
I had to do nothing on my routers, it just started working a few months ago.
Edit:fixed bad URL