CGNAT frustrates all IP address-based technologies (2019)
sidn.nl
sidn.nl
> Our [American Indian] tribal network started out IPv6, but soon learned we had to somehow support IPv4 only traffic. It took almost 11 months in order to get a small amount of IPv4 addresses allocated for this use. In fact there were only enough addresses to cover maybe 1% of population. So we were forced to create a very expensive proxy/translation server in order to support this traffic.
> We learned a very expensive lesson. 71% of the IPv4 traffic we were supporting was from ROKU devices. 9% coming from DishNetwork & DirectTV satellite tuners, 11% from HomeSecurity cameras and systems, and remaining 9% we replaced extremely outdated Point of Sale(POS) equipment. So we cut ROKU some slack three years ago by spending a little over $300k just to support their devices.
* https://community.roku.com/t5/Features-settings-updates/It-s...
* Discussion: https://news.ycombinator.com/item?id=35047624
* https://en.wikipedia.org/wiki/Native_Americans_in_the_United...
Even nailing it down to XYZ country in Europe is a bit of a stretch, as the European genepool isn't the most diverse thing in the world.
I guess an American-British would be somebody who immigrated to GB from the US in that convention, but actually I’m not sure what convention they use over there.
Anyway in this case they aren’t talking about anybody who’s immigrated at all so it is pretty much unrelated.
People with multiple nationalities or who grew up in a different country than their nationality very often describe themselves in terms of a single nationality, often the place they spent most of their childhood. "I'm Argentinian" "Oh, was it difficult to get a visa to come here?" "Well, I have an Italian passport because of my mother."
Americans describing themselves as British-American or whatever seems strange to us, since we can recognize typical British people but aren't seeing any of it in the American.
The 71% is almost certainly because Roku consumes a lot more bandwidth doing video streaming than the other services. Even if Roku did support it I'm sure the users wouldn't be happy that xx% of the web was unreachable.
If you're trying to do an ISP on a budget, IPv4 makes things harder.
Or it was people who weren't going to be served by commercial companies tried to help their community as best they could on a shoestring budget, with minimal funding, in a non-profit fashion.
The fact that they did try to go ipv6-only (ie. "cutting corners") shows that the people involved were blamed were incompetent.
That explains why cellular ISP are progressively adopting 464XLAT, a IPv6-only technology. /s
Sounds like the legal department didn't want them to get sued for "negligence" or whatever when some customer exposes their windows server 2008 installation to the internet and promptly gets hacked.
Which is a perfect incentive for incumbent ISPs to delay and stall IPv6 rollout as much as possible to ruin the day of any would-be competitor.
My personal benchmark: hotels. I have not seen a _single_ hotel that provides IPv6 on their WiFi. And I made a habit of checking this every time I check in.
And I've seen a hotel that was giving out public IPv4 addresses (in Mountain View, CA).
Depends on the country. US>50%; FR>80%:
* https://www.google.com/intl/en/ipv6/statistics.html#tab=per-...
Currently staying at a Hilton hotel in Tucson, Arizona that has IPv6. I only checked because of the submission about ipv6.me yesterday [0].
[0] https://news.ycombinator.com/item?id=43256298
I'm not there at the moment, but I definitely took note of having an ipv6 address displayed on https://ip6.me/home.cgi
I bought this laptop at an electronics recycler. It came with a verizon SIM card, with service that's still working. So this ipv6 address is from Verizon, not the hotel.
Google's numbers for IPv6 connections used are significantly (about 40%) lower than the percentage of homes and other locations that have IPv6 enabled by their ISP to their location.
>>One practical outcome is that government agencies find it harder to identify criminals behind particular IPv4 addresses.
lol, lmao even.
>>As a result, the agency says, investigations often involve examining and tapping the connections of many more people than really necessary.
just incompetence abound, the police should suffer if they don't know how to do their job more effectively
I'll be boycotting IPv6 for as long as it's possible.
The control is in _your_ hands. Unlike CGNAT, where the NAT owner is the one making decisions.
1. setting it to short intervals eventually causes issues, because it fills up your router's routing tables and eventually causes it to crash.
2. Having a short rotation period doesn't help because people typically don't time their incognito tab usages to when the privacy IP rotates. Moreover if you have any apps/tabs in the background that are logged in (eg. gmail), it can track your new privacy addresses as they're being rotated. The only way to fix this is to somehow integrate privacy addresses into the browser itself (ie. having separate privacy addresses for regular/incognito browsing), but that doesn't seem like it's going to happen any time soon.
>The control is in _your_ hands. Unlike CGNAT, where the NAT owner is the one making decisions.
You're trying to imply this is a bad thing but it's unclear how the CGNAT owner can sabotage anonymity in this case. You're mixing your browsing with tens or hundreds of other customers. That provides strictly better anonymity compared to privacy addresses that rotate but are shared by every app/tab on a given system.
I don't buy this argument at all. The router knows about the /64 prefix only, unless are you talking about the ND cache?
Furthermore, let's say you can fill up your route table somehow. What prevents the same thing from happening to the NAT state tracker?
>Moreover if you have any apps/tabs in the background that are logged in (eg. gmail), it can track your new privacy addresses as they're being rotated.
HTTP cookies are enough for that (tracking sessions). No amount of Layer 3 tricks like CGNAT or IPv6 privacy extension will fix it.
>You're trying to imply this is a bad thing but it's unclear how the CGNAT owner can sabotage anonymity in this case.
I assume you understand CGNAT sessions are logged?
How does your router know which device to route a specific address? It can't possibly be broadcasting any incoming packet to all devices.
>Furthermore, let's say you can fill up your route table somehow. What prevents the same thing from happening to the NAT state tracker?
NAT has specific logic to handle dead connections. UDP connections typically time out if there's no activity within 2 minutes, and TCP within 10-60 minutes. Under typical usage situations you're unlikely to hit those limits, however consumer routers were known to choke on too many connections, eg. from torrenting. There's no similar mechanism for ipv6 privacy addressees. The closest is a dumb expiration timer (ie. temp_valid_lft), but that means it can only drop addresses without regard for whether it's active or not, causing issues for long lived connections (eg. ssh).
None of these are impossible problems to solve. There's clearly enough computing power on routers to track each and every connection, so it should be possible to implement better tracking of privacy addresses, but that doesn't mean it's happening today. The same applies to browsers using a different address for private browsing. However "it can theoretically be fixed" isn't a valid response to the sad state of ipv6 privacy today. It's entirely reasonable for ivp4 holdouts to refuse ivp6 until these issues are fixed.
>HTTP cookies are enough for that (tracking sessions). No amount of Layer 3 tricks like CGNAT or IPv6 privacy extension will fix it.
This is false. Third party cookie tracking doesn't work on Firefox anymore because they enabled first party isolation by default a few years ago. Chrome is planning to do the same, but regardless users can already opt into it.
>I assume you understand CGNAT sessions are logged?
Irrelevant. If ISPs wants to log your CGNAT sessions, they can also log your ipv6 traffic.
Well, that only applies if you think ISPs don't log your CGNAT sessions.
But personally I don't think IPv6 is ever going to happen. There's simply too little monetary incentive for supporting it. For outbound connections NAT/CGNAT works fine. For inbound connections you can use SNI routing with a tunnel[0].
If you own a mobile phone you use it every day. IPv6 has already happened.
> There's simply too little monetary incentive for supporting it.
IPv6 allocations are orders of magnitude cheaper and wider than v4 allocations, which are already exhausted.
> For outbound connections NAT/CGNAT works fine. For inbound connections you can use SNI routing with a tunnel[0].
All of these add latency, IPv6 reduces latency (particularly the more widely it is deployed).
Which is of no consequence to the incumbents who have enough existing stock to last them forever (with tricks like CGNAT/etc). The cost of IPv4s mostly impacts smaller players and/or new entrants, which works in favor of the incumbent ISPs.
And yet, Comcast was one of the first nationwide ISPs to enable residential IPv6 service. Comcast is a Very Large ISP. They also happen to have switched ages ago to an all-IPv6 internal network because they ran out of non-routable IPv4 addresses many times over. I suspect (but do not know) that Comcast's experience with how much easier switching over made operations for them to have been a significant factor in providing IPv6 service to residential (and eventually business) users.
CGNAT still causes issues for long lived connections though. Things like SSH will get cut off.
Weird. I've had "native" IPv6 service continuously since... 2004? 2006? and IPv6 via a 6to4 tunnel that terminated in Hurricane Electric's network since two years before that.
Bonus: I discovered recently that the Zoom teleconferencing software works just fine if you have only IPv6 connectivity.
Is there stuff that's IPv4-only? Sure. But IPv4 doesn't need to be shut down for IPv6 to have happened (and have been happening for a long time now).
As for incorrect? How so? Perhaps "web service providers" is a bit glib and incomplete too, but it gets to the core of the issue here: ISP not providing internet service and only providing a limited subset. if the 'web' works that's all that really matters for advertising and getting people to pay them. Meanwhile most people aren't even aware of what they're missing and their inability to participate in the internet; but they, and especially their kids', educations are stunted by the lack of being able to participate, etc. And all of society is worse for it.