Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Tuesday, February 19, 2008

Can an IPv4 stock market stave off address depletion, IPv6?

There are many uncertainties surrounding the depletion of the IPv4 address space and the move to IPv6. Currently, five Regional Internet Registries give out address space to anyone who can show a reasonable need for it and pays some administration costs. If nothing changes, that practice will end around 2012 when we run out of unused IPv4 addresses. One possible solution is creating an IP address space market, allowing people who need IPv4 addresses can buy them from those who have a surplus, so that IPv4 address space remains available for a few more years.

Ideally, by the time we run out of IPv4 addresses, we'll all be using IPv6. At the rate IPv6 takeup is happening now, however, a full-scale switch to IPv6 seems highly unlikely. After the IPv4 address space has been depleted, new Internet users will only be able to get IPv6 address space, while existing users are still only connected through IPv4.

Network World has an article speculating about additional delays in rolling out IPv6 if a proposed IPv4 address trading policy is adopted by ARIN. The American Registry for Internet Numbers is responsible for giving out IP addresses in North America. Its policies "are developed in an open and transparent manner by the Internet community," according to the Internet Resource Policy Evaluation Process. An important aspect of that process is that anyone can submit a policy proposal, so the mere existence of a proposal doesn't mean all that much.

The issue of address trading comes up more frequently as we come closer to running out of IPv4 address space. Efforts to reclaim some of the large IPv4 address blocks that have been given out as "legacy assignments" long ago haven't proven all that successful. According to an ICANN blog entry, four blocks of 16.78 million addresses were reclaimed last year: blocks 14, 46, 49, and 50. In reality it was only one: blocks 49 and 50 were marked as "Returned to IANA Mar 98" previously, but is now "Reserved" (unused)—no real change. Block 14 had only some 129 addresses used; nice to have the whole block back, but 129 addresses isn't going to make much of a difference. Even the full 16.78 million addresses in block 46 only give us an extra month's worth of IPv4 address space: we're now using up around 12 of those blocks per year. Did I mention that that was the good news? The not so good news: "Despite this windfall we are unlikely to see any more whole /8s returned to the IANA free pool," notes ICANN. "Our investigations indicate that the other legacy 'Class A' assignments are all at least partially used. Recovering the space in those blocks would require large companies to engage in expensive renumbering exercises."

  
The feasibility of an open IPv4 market

The question is: will a little money make those renumbering exercises more palpable, so that address space that couldn't be recovered for free will enter the market? That's one of the many questions that surrounds a future IP address market. On the one hand, it's possible that organizations that hold large amounts of address space—most notably, the US government with 150 million or so addresses and HP with 33 million—will spend the time and money to free up parts of their address space and put it on the market. The hard part here is that this address space has been around for a long time, which almost guarantees that it's hardcoded in places. As a result, freeing it up probably means extensive system audits. On the other hand, it's entirely possible that such audits prove to be too much trouble or too expensive to bother with, so very little address space would enter the newly created market. Large ISPs need millions of addresses to connect new customers, addresses which they basically get for free today. Even a cost of $1 per address may be prohibitive, pushing those ISPs to implement address conservation techniques—and, ideally, IPv6—instead of buying address space at market prices.

It could be even worse: if demand outstrips supply, the price for IPv4 addresses could skyrocket, where it's attractive for sellers to wait for prices to get even higher before selling. If I were a domain squatter, I would certainly diversify my business in the direction of address squatting while address space is still easy to get.

And what about the rest of the world? The US holds more than half of the currently given out address space, twice as much as the rest of the developed world put together. Of the developing world, only China has a significant amount of address space. So poor countries would have to go to rich, American organizations to buy address space. This isn't likely to be popular in much of the world.

An IPv4 market could work in both directions: a run on the bank could mean that we're effectively out of IPv4 address space one or two years sooner than the currently speculated end date of 2012, or a market with good liquidity could recover, say, 50 percent of the legacy address blocks, more than doubling the still available IPv4 address space and the time that we have. However, the North American Network Operators aren't waiting for that: during their meeting this week, they'll have an IPv6 hour where IPv4 will be turned off temporarily. The Internet Engineering Task Force is planning to do the same during its meeting next month. Time to go either short or long IPv4 addresses in anticipation of the results.

Friday, December 21, 2007

Mozilla Releases Firefox 3 Beta 2; Beefs Up Security

Firefox 3 is shaping up to be a very secure browser thanks to new features

A scathing report on browser security from Microsoft, which claimed in an "unbiased" analysis that Internet Explorer was vastly more secure than Mozilla's Firefox, ignited a recent war of words between the two browser makers. However, Mozilla decided that it was wiser to back up its words with action, rather than just more talk.

The end result is that the company just released the second beta candidate of the third iteration of its increasingly popular Firefox browser, and this release ups the ante on security with many new features.

The new browser has tighter protection against cross-site restrictions on cookies, better malware protection, clearer website identification information in the status bar, stricter SSL error pages, version checking for insecure plugins, a built in antivirus program in the download utility, and improved protection against JSON data leaks.

The feature Mozilla is most proud of is its improved protection from malicious sites. When a user visits a malicious site in Firefox 3, the browser plays sheriff and blocks the site. Even better; it does it with an interface that does not allow click through.

Mozilla's "Chief Security Something-or-Other" (according to his business cards) Window Snyder says that even the utilitarian features in the Firefox browser double as security aids. For example, she stated Firefox's ability to restore tabbing makes patching the browser and easier process, thus helping to safeguard it. She stated, ”I really do believe that every feature is a security feature and should be evaluated as such."

While Microsoft touts that it has fewer vulnerabilities than its competitors, Mozilla measures its browser's security by a different gauge. It judges its performance based on "days of vulnerability", the number of days between when a known exploit code for a vulnerability appears and the publication of the patch for that vulnerability. By this measure Firefox was only vulnerable for 9 days in 2006, versus Internet Explorer, which was vulnerable 286 days of the year.

Mozilla also says that its public bug count is a mark of integrity and the lack of a public IE bug database is a way for Microsoft to hide their vulnerabilities.
Mike Schroepfer, Mozilla's VP of engineering said the lack was, "[a] vivid reminder that there is no way for anyone outside of Microsoft to confirm how many vulnerabilities ever existed in Internet Explorer."

Dave Marcus, security research and communications manager at McAfee Avert Labs, threw out an independent opinion on the issue saying the debate over "days of vulnerability" versus vulnerability counts was pointless and that the only thing that mattered was how quickly patches were made.

Firefox is also working frantically to finish fixes for its identified non-security related bugs in time for the final release of Firefox 3.

Who will win the next generation browser war remains to be seen, but as Mozilla's Firefox 3 Beta 2 release indicates, both companies are going to stake their reputation on providing the most secure solution to the consumer