8,337 karma · joined January 1, 2023
* https://datatracker.ietf.org/doc/html/draft-ietf-v6ops-6mops
Fewer IPv4 deployed subnets means those addresses can be used where they're 'really' needed instead of being 'wasted'.
Is there a 'break glass' workflow in case you are not available (e.g., health incident)?
* https://www.youtube.com/watch?v=UTRsi6mbAWM
Even in organizations where IT cannot control devices, like universities which are largely student-BYOD, IPv6 take-up can reach 80%:
* https://www.youtube.com/watch?v=2B-liebzcOMmkm&t=10m
"Obviously" in what way?
Sure they could: if your ISP owns 1.2.0.0/16, it could advertise 2002:1.2::/24 via BGP. So if someone on the other side of the planet wants to send something to 2002:1.2.3.4::/48 they would know where to send it.
And just like how something sent to 1.2.0.0/16 globally is then handled internally via IS-IS/OSPF/etc so your ISP knows how to send something for 1.2.3.4 to your CPE, your ISP would know how to handle 2002:1.2.3.4::/48 to get it to your CPE.
Routers are told to map traffic for (::ffff:)a.b.c.d to 2002:a.b.c.d::/48. If you're sending from w.x.y.z, you can put the source address as from something in 2002:w.x.y.z::/48.
It has nothing to do with "clean slate" or not. There are two immovable facts:
"""
IPv4 implementations, in 1994 and still today, have the 32-bit address format built into their code. Whether you expand the address size to 33, 64 or 128 bits, all IPv4 implementations will discard the packets. So it's a matter of mathematical and physical fact that to expand the address size, you must change the protocol, and that means two things immediately:
1. You have to change the version number.
2. You have to add new code to handle the new version.
""
* https://github.com/becarpenter/book6/blob/main/01.%20Introdu...
And this also includes 'accessory protocols': DNS A records are fixed at 32-bits, so if you want to use hostname with IPng you needed to upgrade the DNS infrastructure, including APIs to say "give me A and Ang", and then you perhaps need fallback mechanisms, in which case you're at:
* https://en.wikipedia.org/wiki/Happy_Eyeballs
Any IPng protocol, including 'just' adding bits, regardless of how you want to hand wave it as being 'just' an extension of IPv4 will be in same situation because you can't fit >32-bits in the 32-bits of the original code. You're rolling out new code in a rolling fashion, just like had to be done with IPv6.
You've obviously never been part of an SAP/ERP implementation. /s
* https://www.journalofdemocracy.org/articles/the-future-of-no...
* https://global.oup.com/academic/product/civil-resistance-978...
At least per historical surveys (600 movements since 1900).
* https://en.wikipedia.org/wiki/United_States_Government_Accou...
May be worth noting/reminding of the 17 inspectors general that were fired on the first Friday (2025-01-24) of Trump 2.0 administration:
* https://en.wikipedia.org/wiki/2025_dismissals_of_U.S._inspec...
::ffff:1.2.3.4
* https://en.wikipedia.org/wiki/IPv6#IPv4-mapped_IPv6_addresse...
By having 1.2.3.4 you also got 2002:1.2.3.4::/48 'for free' (per 6to4). So if you want to send things to 1.2.3.4 / ::ffff:1.2.3.4, you tell your router that it's available via 2002:1.2.3.4::/48.
Any idea that you think is clever and to 'just' do X and/or Y for IPng, and would work, has probably already been thought of and attempted in the last 20-30.
How is this sustainable for a for-profit entity? How do they pay the bills/developers?
6to4 is exactly ownership:
> For any 32-bit global IPv4 address that is assigned to a host, a 48-bit 6to4 IPv6 prefix can be constructed for use by that host (and if applicable the network behind it) by appending the IPv4 address to 2002::/16.
> For example, the global IPv4 address 192.0.2.4 has the corresponding 6to4 prefix 2002:c000:0204::/48. This gives a prefix length of 48 bits, which leaves room for a 16-bit subnet field and 64 bit host addresses within the subnets.
* https://en.wikipedia.org/wiki/6to4
The relaying is a necessity:
OLD DUAL NEW
----------------------
OLD | 32 | 32 | XX |
|------|------|------|
DUAL | 32 | 64 | 64 |
|------|------|------|
NEW | XX | 64 | 64 |
----------------------
* https://github.com/becarpenter/book6/blob/main/01.%20Introdu...There's no way around it: a non-IPng-having node will have to go through a translation box of some kind.
See "The Recommendation for the IP Next Generation Protocol", §8.3 TUBA Reviews:
* https://datatracker.ietf.org/doc/html/rfc1752
The document explains why SIPP was chosen (with the tweak of 128-bit addresses instead of 64).
> By 2028, three reactors could be restarted, adding 4 GW of capacity. If decommissioning stops now and rehiring begins, Brokdorf could resume operation as early as the end of 2025. With swift legislative action and proper planning, Emsland and Grohnde can be operational by the end of 2028. Six additional reactors could all be restarted by the end of 2032.
* https://www.radiantenergygroup.com/reports/restarting-german...
This has been approved:
* https://ca.pcmag.com/networking/16760/fcc-approves-reflect-o...
That won't prevent me from getting a ticket saying "the network is down".
Lots of folks were using "dev" as a sub-domain which was fine until ICANN decide to give Google a TLD:
* https://en.wikipedia.org/wiki/.dev
So if you generally had "search example.com" in you resolv.conf, and were in the habit of having "web01.dev" in places, behaviour may have changed if you were suddenly on a machine that had the "search" line missing (or something else).
Library/CLI that speaks the API of several dozen DNS providers so you don't have to re-invent the wheel:
You now also have to build infrastructure to distribute the wildcard from (presumably) central place where you generate it to all the different places where it is desired.
And hope the wildcard's private key does not leak from one of myriad of places it now lives.
See also perhaps DNS aliasing in case you are not able to dynamically update your 'primary' domain, but can update a secondary or sub-domain:
* https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mo...
So if "example.com" is control by Corporate IT, and they don't want 'random' folks fiddling with it, then you can create a "dnsauth.example.com" and point the dns-1 challenge record from "…foo.example.com" to "foo.dnsauth.example.com" (or a completely different domain, like "…example.net").
There are DNS servers written strictly focused on this use case:
* https://github.com/acme-dns/acme-dns
Also code that handles a bunch of DNS provider APIs so you don't have to roll your own for ACME client hooks:
Which could (maybe) be fine if they could be permanently turned off (and not reset-to-on on every startup). Heck, even if it was a dealership-only change it would be something.
See recent driving 4 answers video on the silliness of some of these features:
* https://www.youtube.com/watch?v=f-S76WEl25k
An alert that causes you to look down every time to enter an intersection/roundabout when you most need to be looking up? Warnings when you put on sunglasses?
"Probably not, but then my job is to celebrate and defend the wonders of British democracy. And look at this: the fact that you're interviewing me, on the Today program, because all the other parties are not standing [up candidates] says more about them than it does about me."
I don't have a garage/drive way, and so have to park on the street, which makes me leans towards another short [1] vehicle: currently thinking about VW Golf, Mazda 3, Mazda CX-30, Kia Niro.
From what I've seen from almost all cars, lots more screens and lots fewer buttons.
* https://datatracker.ietf.org/doc/html/rfc6296
When I pointed out that the NAT(44) RFC (1631/3022) was 'only' "Informational" I got radio silence:
The GOST cipher, which is Russia's AES equivalent, is also in an RFC:
* https://datatracker.ietf.org/doc/html/rfc9189
* https://en.wikipedia.org/wiki/GOST_(block_cipher)
Is the IETF validating its use?
The GOST document is categorized in the same way as the one currently being debated/discussed: Informational. It also has "N" under the "Recommended" column (like ML-KEM-only will have):
* https://www.iana.org/assignments/tls-parameters/tls-paramete...
Further the draft that this is all about does not make a recommendation for its use. The currently IETF-recommended TLS algorithms are: X25519MLKEM768, x448, x25519, secp384r1, secp256r1.
As noted by someone on the IETF list [1] there are already ML-KEM-only implementations in various libraries, so if we want interoperability then it's best to have a standard document. No one is forcing anyone to use this algorithm, and it's not even 'officially' recommended (per above).
[1] https://mailarchive.ietf.org/arch/msg/tls/SXo4iVmp0ng_vi57ce...
> Trump averaged 85 trades per market day, an analysis of the report shows. Just 10 days accounted for about a quarter of all trades executed in 2025. Many of those came during heightened volatility on Wall Street after Trump had already announced policy changes.