Re: [v6ops] Fwd: New Version Notification for draft-collink-v6ops-ent64pd-01.txt

Gert Doering <gert@space.net> Wed, 21 December 2022 07:48 UTC

Return-Path: <gert@space.net>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD8DAC14CF19 for <v6ops@ietfa.amsl.com>; Tue, 20 Dec 2022 23:48:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.097
X-Spam-Level:
X-Spam-Status: No, score=-7.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=space.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4k6Wy399M2-o for <v6ops@ietfa.amsl.com>; Tue, 20 Dec 2022 23:48:24 -0800 (PST)
Received: from gatekeeper1-relay.space.net (gatekeeper1-relay.space.net [IPv6:2001:608:3:85::38]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C1F7BC14CE20 for <v6ops@ietf.org>; Tue, 20 Dec 2022 23:48:22 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=space.net; i=@space.net; q=dns/txt; s=esa; t=1671608904; x=1703144904; h=date:from:to:cc:subject:message-id:references: mime-version:in-reply-to; bh=Xuyj+3OT1FP+njoWY089n1V4HP6eS7T9JvVH1zfjhbs=; b=cse/GKikdd0uBlfVZ7O9f9iz5c22LcN1CBrKMGdwb7k7Mby0y2RDV+Bk hIfKy8IQQY4Atba8ER9Pyt3ekudy3w8sqAkxAKqKt+6leVgvzsGlcG9OL gUqMhbdya1HFuhGNBMJCyHU78E3lo0Yvuio0lKdIu3P+a1/uS4xZuYQa0 //KfPseUIvHUSrTO8Lta8afGKdaIxhj0FL2UCAObD5gIF4+dPF9MDvaiI utJaf79gv2295MR8NPuF4rmBsA0aygqP6VnQgcfoQiz38tXSRoWl2NmFY QRa+0MWfCeA4yds/u9QF+ERzyM0TGQPxENuxsjTeHD/kVw0Xi92+TYU/l w==;
X-SpaceNet-SBRS: None
Received: from mobil.space.net ([195.30.115.67]) by gatekeeper1-relay.space.net with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Dec 2022 08:48:19 +0100
X-Original-To: v6ops@ietf.org
Received: from mobil.space.net (localhost [IPv6:::1]) by mobil.space.net (Postfix) with ESMTP id 197914226E for <v6ops@ietf.org>; Wed, 21 Dec 2022 08:48:19 +0100 (CET)
X-SpaceNet-Relay: true
Received: from moebius4.space.net (moebius4.space.net [IPv6:2001:608:2:2::251]) by mobil.space.net (Postfix) with ESMTP id 04DBD40AD0; Wed, 21 Dec 2022 08:48:19 +0100 (CET)
Received: by moebius4.space.net (Postfix, from userid 1007) id EF743F4DD8; Wed, 21 Dec 2022 08:48:18 +0100 (CET)
Date: Wed, 21 Dec 2022 08:48:18 +0100
From: Gert Doering <gert@space.net>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>
Cc: Mark Smith <markzzzsmith@gmail.com>, Vasilenko Eduard <vasilenko.eduard=40huawei.com@dmarc.ietf.org>, V6 Ops List <v6ops@ietf.org>, Lorenzo Colitti <lorenzo=40google.com@dmarc.ietf.org>, xiaom@google.com, draft-collink-v6ops-ent64pd@ietf.org
Message-ID: <Y6K6QtzrEnvqRfd4@Space.Net>
References: <167107554671.48477.568330207202509840@ietfa.amsl.com> <CAFU7BATp=gEB3S8AzhCYDMN3fzLQrYY9pzcWJ=LQnrjC9bRKEA@mail.gmail.com> <Y5sy2ikgQEWSnCsM@Space.Net> <CAKD1Yr0EchmQ11eKCB4AfEJaG7_aFDDv_bavYJY4Zb3iDmhALg@mail.gmail.com> <4277d4e5a962400f8438e8f01c884654@huawei.com> <CAO42Z2y_SWybfLQE3g5a-kVieY05XSxaKTv-UG8kvfbYzJLH6w@mail.gmail.com> <12d95e0b-7264-2fcc-d131-1eca2a72d4e1@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <12d95e0b-7264-2fcc-d131-1eca2a72d4e1@gmail.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/HjQ4WGP3WoexiM3PMcHbHam0lZo>
Subject: Re: [v6ops] Fwd: New Version Notification for draft-collink-v6ops-ent64pd-01.txt
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Dec 2022 07:48:29 -0000

Hi,

On Wed, Dec 21, 2022 at 08:50:10AM +1300, Brian E Carpenter wrote:
> There's a reason that
> https://www.rfc-editor.org/rfc/rfc7421.html#section-4.5 suggests
> /80 as the reasonable limit for privacy purposes. The issue is
> making it highly unlikely (and therefore prohibitively expensive)
> to find an IID by a scanning attack. At /96, the search space is
> about 4 billion. Given the number of Internet users in the world,
> and possible applicability of the birthday paradox, that isn't a
> safe value. (I can't expect to find *your* IID, but I can hope to
> find *somebody's* IID.) At /80, the search space is about 281
> trillion.

What would the benefit be of finding someone's IID, if that IID is only
valid for a specific prefix?

But still, using a /80 permits 65000 host-prefix assignment out of a /64,
which sounds like "big enough" for a layer 2 segment with general purpose
machines attached to it  (for a "sensor network mesh" it might be a bit
tight, but hopefully these would not be requesting prefix delegations
and/or not be in a flat topology).

Gert Doering
        -- NetMaster
-- 
have you enabled IPv6 on something today...?

SpaceNet AG                      Vorstand: Sebastian v. Bomhard, Michael Emmer
Joseph-Dollinger-Bogen 14        Aufsichtsratsvors.: A. Grundner-Culemann
D-80807 Muenchen                 HRB: 136055 (AG Muenchen)
Tel: +49 (0)89/32356-444         USt-IdNr.: DE813185279