logoalt Hacker News

sedivy94yesterday at 6:14 AM3 repliesview on HN

IPv6, in a way, takes the concept of a MAC address and puts it on steroids. This became evident to me when I learned about EUI-64 addresses. And then my brain melted when I learned that any interface can be assigned an arbitrary number of unique addresses with varying purposes or contexts because the address space is truly *that big*.

When I consider that quality of IPv6’s design, it communicates to me an old and ideal vision of what we thought the internet would and should be - a hyper-connected, shared infrastructure where [Layer 3] identity is universally unique such that connectivity between any two arbitrary nodes is possible (which obviously isn’t true for NAT w/ overload).

I’m just a lowly SysAdmin who finally decided to get his CCNA - so I’m a nobody - but as I worked through the material I felt like I was paging through a history book or biography of how the Internet’s life came to be and all the mistakes made along the way. Most features felt like patches for design considerations that were overlooked. Examples: DHCP Snooping, STP’s various * Guards, and the mere fact that Layer 2 and Layer 3 addresses are distinct concepts.

I don’t think there’s any disagreement that NAT was co-opted as a security feature. I never hear that said in a positive way, either. I think if we were to start over, with IPv6 as the default assumption, the tools we’d develop for network security would look very different, but not at all impossible or any more difficult.

But again - I’m a nobody. Just thinking out loud here.


Replies

tsimionescuyesterday at 8:09 PM

Having actual unique stable IPv6 addresses for every device is the dream of every Ad vendor - no need to bother with the huge array of tracking techniques and the chicken and mouse game of fighting various tracking protection solutions, just log the stable IPv6 of the user's device across any service they use.

So, of course, we then got Privacy Addresses, or whatever the name is. Which now means that you don't actually have a stable unique public IP, it actually changes all the time, and legitimate tracking and logging of your own network activity actually becomes much more complicated on IPv6.

1718627440yesterday at 9:35 AM

> the mere fact that Layer 2 and Layer 3 addresses are distinct concepts.

If it weren't you couldn't have the same IP over several interfaces.

9x39yesterday at 7:45 PM

The 'why' behind all of these protocols and decisions is left out in favor of the cert exams. Being able to implement is usually what gets you paid.

>mere fact that Layer 2 and Layer 3 addresses are distinct concepts.

The logical separation between the ideas allows for a lot of flexibility, and there were some wrong answers on how scalable vs flexible things should be.

Ethernet and IP beat the shit out of everything else: https://en.wikipedia.org/wiki/Protocol_Wars

They emerged with a decent answer: L2 crosses intranetwork, L3 crosses internetwork. Their separation allows L3 addressing to be completely unaware of multiple changing L2 (lower level) intranetwork switches, which is immensely useful.

Trying to solve everything with One Master Protocol to solve it all turned out like this: https://xkcd.com/927/

show 1 reply