Re: [v6ops] How to make an elegant IPv4 outage
Phillip Hallam-Baker <[email protected]> Sun, 14 Jun 2026 14:13:30 -0400
| Newsgroups | gmane.ietf.general,gmane.ietf.tsv-area,gmane.ietf.v6ops |
|---|---|
| Message-ID | <CAMm+LwhpT-M+LVEkwzERK1Qd0sMwbZ4G6-swQrkFz+xofRVr8g@mail.gmail.com> |
--00000000000079e8c406543aab70 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Sun, Jun 14, 2026 at 12:45=E2=80=AFPM Franck Martin <franck@peachymango.= org> wrote: > My internal network is segmented into a series of VLANs so that the IoT > devices cannot touch the production network. Each VLAN has a separate > prefix 10.x.*.*. If a device has IPv6 service, the IPv6 address will be i= n > a /24 with the lower 32 bits being its net 10 suffix. > > And this isn't just some scheme PHB thunk up, it is pretty much the way > people deploy the hardware just as named.config.local is the place most > people list out the zone files for their local domains. > > > And the security of those devices is questionable at best. Like you I > don=E2=80=99t see it changing soon. When you are in the shop, there is no= way to > figure out if any device has IPv6 support, but I know they will want me t= o > open a cloud account, to manage this device. Nothing can work locally > (because they sell time on those device for scrapping the Internet for ou= r > AI overlords?). > As an applications guy, I recognize the fact that there are many situations where it is simply impossible to make the system work unless there is a part of it rooted on a service that is available 24/365 with a static IPv4 address. I do not expect that to change and so I work within that constraint and instead look at ways to eliminate the switching costs that give the service provider pricing power in that situation. I am building out a service so other people don't need to do that. But if you choose to use my prototype service and decide you don't like my SLA, you can switch at any time you choose without any switching cost provided only that you have your own DNS name registration. As an application provider, I need a place that is separate from the device where my code runs that can provide at minimum discovery and presence services and it is handy to have some storage. But as a user, I do not need to have those services from Microsoft, Apple and Google, all three of which I am using today because the cost of not doing so is much higher than paying for them. And I might even be prepared to tolerate that indefinitely if two of the providers I bought over $1500 worth of IoT gear had decided on a forced obsolescence strategy in the hope of forcing me to pay for upgrades. So my architecture consists of: 1) A brand which tells people 'this application/device will work with the open service' 2) An application that manages public AND PRIVATE keys for the end user so they have 100% control over the trust endpoints of their communications. 3) An open cloud service that provides a dead drop allowing applications to exchange messages with other users/devices even if the other endpoint is currently offline that the user chooses and can change at any time they choose without switching costs. 4) An open cloud service that provides the DNS layer management for the internal and external networks. I am fully aware that this approach conflicts with the commercial ambitions of some parties. But I am also aware of many other commercial parties which will do better under my approach. And remember that when we built the Web, we knew full well that it conflicted directly with the 'Interactive TV' proposed by Time Warner. --00000000000079e8c406543aab70 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><div class=3D"gmail_default" style=3D"fon= t-size:small">On Sun, Jun 14, 2026 at 12:45=E2=80=AFPM Franck Martin <<a= href=3D"mailto:[email protected]">[email protected]</a>> wrot= e:</div></div><div class=3D"gmail_quote gmail_quote_container"><blockquote = class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px sol= id rgb(204,204,204);padding-left:1ex"><div><div><blockquote type=3D"cite"><= div><div dir=3D"ltr"><div class=3D"gmail_quote"><div style=3D"font-size:sma= ll">My internal network is segmented into a series of VLANs so that the IoT= devices cannot touch the production network. Each VLAN has a separate pref= ix 10.x.*.*. If a device has IPv6 service, the IPv6 address will be in a /2= 4 with the lower 32 bits being its net 10 suffix.<br></div><div style=3D"fo= nt-size:small"><br></div><div style=3D"font-size:small">And this isn't = just some scheme PHB thunk up, it is pretty much the way people deploy the = hardware just as named.config.local=C2=A0is the place most people list out = the zone files for their local domains.<br></div></div></div></div></blockq= uote><div><br></div>And the security of those devices is questionable at be= st. Like you I don=E2=80=99t see it changing soon. When you are in the shop= , there is no way to figure out if any device has IPv6 support, but I know = they will want me to open a cloud account, to manage this device. Nothing c= an work locally (because they sell time on those device for scrapping the I= nternet for our AI overlords?).</div></div></blockquote><div><br></div><div= class=3D"gmail_default" style=3D"font-size:small">As an applications guy, = I recognize the fact that there are many situations where it is simply impo= ssible to make the system work unless there is a part of it rooted on a ser= vice that is available 24/365 with a static IPv4 address. I do not expect t= hat to change and so I work within that constraint and instead look at ways= to eliminate the switching costs that give the service provider pricing po= wer in that situation.</div><div class=3D"gmail_default" style=3D"font-size= :small"><br></div><div class=3D"gmail_default" style=3D"font-size:small">I = am building out a service so other people don't need to do that. But if= you choose to use my prototype service and decide you don't like my SL= A, you can switch at any time you choose without any switching cost provide= d only that you have your own DNS name registration.</div><div class=3D"gma= il_default" style=3D"font-size:small"><br></div><div class=3D"gmail_default= " style=3D"font-size:small">As an application provider, I need a place that= is separate from the device where my code runs that can provide at minimum= discovery and presence services and it is handy to have some storage. But = as a user, I do not need to have those services from Microsoft, Apple and G= oogle, all three of which I am using today because the cost of not doing so= is much higher than paying for them. And I might even be prepared to toler= ate=C2=A0that indefinitely if two of the providers I bought over $1500 wort= h of IoT gear had decided on a forced obsolescence strategy in the hope of = forcing me to pay for upgrades.</div><div class=3D"gmail_default" style=3D"= font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size:= small">So my architecture consists of:</div><div class=3D"gmail_default" st= yle=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"fon= t-size:small">1) A brand which tells people 'this application/device wi= ll work with the open service'</div><div><br></div><div><div class=3D"g= mail_default" style=3D"font-size:small">2) An application that manages publ= ic AND PRIVATE keys for the end user so they have 100% control over the tru= st endpoints of their communications.</div><div class=3D"gmail_default" sty= le=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font= -size:small">3) An open cloud service that provides a dead drop allowing ap= plications to exchange messages with other users/devices even if the other = endpoint is currently offline that the user chooses and can change at any t= ime they choose without switching costs.</div><div class=3D"gmail_default" = style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"f= ont-size:small">4) An open cloud service that provides the DNS layer manage= ment for the internal and external networks.<br><br>I am fully aware that t= his approach conflicts with the commercial ambitions of some parties. But I= am also aware of many other commercial parties which will do better under = my approach. And remember that when we built the Web, we knew full well tha= t it conflicted directly with the 'Interactive TV' proposed by Time= Warner.</div><br></div><div><br></div><div>=C2=A0</div></div></div> --00000000000079e8c406543aab70--