Over 25% of Verizon Wireless Traffic Is Now Over IPv6
internetsociety.org
internetsociety.org
[0]: http://en.wikipedia.org/wiki/Space_and_Naval_Warfare_Systems...
[1]: http://www.usipv6.com/ppt/IPv6SummitPresentationFinalCaptDix...
[0]:http://fcw.com/articles/2010/08/17/navy-shares-ipv6-lessons....
Related, from links in the article: Google has a graph showing that over 1% of their users now have IPv6 available. http://www.google.com/ipv6/statistics.html
This is actually not as strange as it might seem. Google/Bing/Facebook/Youtube/Netflix/Wikipedia and the iTunes store are all available over IPv6. These properties represent a significant portion of typical mobile device traffic. That 11% of the remaining Alexa top 1000 properties are IPv6 enabled doesn't hurt either. Lastly, practically 100% of VZW's LTE customers are using handsets and operating systems that support IPv6 so they don't have the issues Comcast has with ancient home routers and modems stopping people from using the v6 service that is provided.
For mobile networks IPv6 has a better business case than most networks. Mobile networks are new enough that they don't typically have large blocks of addresses ready to use so every IPv6 packet is one that doesn't take resources on your expensive CGN gear. T-mobile's wireless network is also fully IPv6 enabled.
Yes. All LTE devices on Verizon are given real, globally routable IPv6 addresses. You can test this here: http://test-ipv6.com.
This presentation [1] is pretty interesting, showing how aggressive Verizon was with IPv6 on their LTE network.
> At first read I thought the headline meant that 25% of consumer traffic was going to IPv6 sites, which seems impossibly high.
Keep in mind that many popular websites--Yahoo, Facebook and Google among them--now publish AAAA records in DNS. With that in mind, this statistic isn't that unreasonable. If you have a Verizon iPhone, you're probably reaching Google via IPv6 without realizing it.
[1] http://conference.apnic.net/__data/assets/pdf_file/0017/5081...
With globally routable addresses, where is the protection for attached devices from global attacks? Does VZW firewall their network, or are they relying on their supported devices not having open, vulnerable ports?
My phone is battery powered. My cell phone link uses a lot of power when active compared to when inactive. I don't want some random ass killing my battery life by packet spamming me.
My cell phone provider charges me for data. Would that include random UDP packets spammed at my device?
The abuse potential is high enough that it concerns me. Having some sort of firewalling on the provider side seems straight up useful.
http://security.stackexchange.com/questions/8772/how-importa...
How ISP level firewalls should be configured is an interesting and open question for consumer level connections. For mobile connections default deny seems like an OK place to start, given that mobile connections tend to be shared and metered. I hope that this doesn't stifle the innovation that could come from true peer to peer mobile connectivity though.
Presumably VZW's IPv6 configuration is similar, though I'd be interested to hear exactly what connections are allowed between devices at different locations within their own network. Wouldn't be surprised if they're completely forbidden.
Of course the network should not be trusted to protect you. But in the real world, everyday consumers are connecting insecure devices, and I'm curious how VZW is going about saving them from themselves.
You do realize just how many IPv6 addresses there are? The good old days of randomly scanning the interwebs in the hopes of finding an IP are gone, at least, for IPv6.
The minimum assignment form RIPE/ARIN etc to an ISP is a /32. Meaning Verizon on it's own has at least the same number of /64's as the entire IPv4 internet has IPs..
That's 4,294,967,296 /64's.
A single /64 is 4 billion times the entire IPv4 address space.
Which is the only way it should ever be.