IPv4 address rentals to mint millions of dollars for AWS
- Reference: 1707133510
- News link: https://www.theregister.co.uk/2024/02/05/aws_ipv4_cash/
- Source link:
The cloud computing kingpin [1]signaled last year that it would start charging customers for public IPv4 addresses from February 1, as [2]covered by The Register at the time.
AWS cited increasing scarcity and claimed the cost to acquire a single public IPv4 address for customer use had risen more than 300 percent over the past few years.
[3]
Fortunately, the charge is hardly ruinous – $0.005 (half a cent) per IP address per hour, which equates to a total cost of $43.80 per year for each public IPv4 address you have – excluding any IP addresses that you might own and opt to bring to AWS using Amazon's BYOIP (Bring Your Own IP) service.
[4]
[5]
However a [6]technologist has done the calculations and estimated that across all users, this will add up to a sum of between $400 million and $1 billion a year for AWS. Not bad for something that was being offered completely free just a few days ago (and is still [7]offered for 750 hours a month at no cost in the AWS free tier).
The source of the billion-dollar claim is Andree Toonk, founder and CEO of network services biz Border0, who is presumably trying to generate business for his own company.
[8]
Toonk used Amazon's own IP address range data to estimate that the cloud colossus has at least 131,932,752 IPv4 addresses. Based on the average price for an IPv4 address being about $35 at the time of writing, this means that AWS is sitting on about $4.6 billion, should it wish to divest itself of them.
He also used a script to ping all of the IPv4 addresses in order to gauge how many were "alive" within the AWS network and came up with an answer of about 6 million. But many instances on AWS will have a security policy to not respond to a ping packet, so the actual number of active IPv4 addresses could be double that.
Even with just those six million addresses, that's $262.8 million AWS will earn from charging for IPv4 in a year.
[9]
He forecast the headline $400 million to $1 billion figure by projecting a "conservative" estimate that between 10 percent and 30 percent of the IPv4 addresses (approximately 7.9 million) published in the [10]AWS JSON are used for a year.
We asked AWS if it recognized any of these figures, and what the company itself estimated it would earn from charging customers for public IPv4 addresses, but it declined to answer, instead referring us to its original blog post disclosing the charges.
[11]Zen Internet warns customers of an impending IP address change
[12]Cloudflare dishes up the stats on internet traffic in 2023
[13]China requires any new domestic Wi-Fi kit to support IPv6 and run it by default
[14]APNIC close to completing delegation of its final /8 IPv4 block
The general feeling among industry experts is that this is fair game, and customers should make plans to migrate to IPv6 if they don't like it – assuming their applications allow this, of course.
"While this is a new and additive charge which reduces to a degree the value that a customer receives from AWS services, this is a realistic charge given the expensive and limited nature of an IPv4 address and the fact it is being provided to a customer as a service, similar to the infrastructure hardware," said IDC Senior Research Director Andrew Buss.
"The annual cost is not huge, but is still significant enough to cause companies to make sure they are using their allocation and returning those they don't need, or to consider different approaches," he added, including migrating to IPv6.
"It's likely other providers could follow suit if they feel the IPv4 address crunch," he told The Reg .
Omdia chief analyst Roy Illsley said the motivation is to move people to IPv6 as IPv4 addresses are scarce and the cost to acquire them has increased.
"My view is that AWS has been smart in buying up IPv4 addresses, and this is a way for it to cash in until IPv6 adoption makes IPv4 redundant. It's just that organizations are not rushing to move to IPv6," he said.
This is despite the world [15]officially running out of IPv4 ranges to allocate five years ago. Anyone desiring a new public IPv4 address since then has had to rely on address ranges being recovered from organizations shutting down or surrendering them as they migrate to IPv6.
Corey Quinn, Chief Cloud Economist at The Duckbill Group had initially welcomed the move by AWS as a way of ensuring that other customers were not impacted by the behaviour of the IPv6 laggards.
Duckbill Group is a consultancy that specializes in helping companies to manage their AWS cloud costs.
However, in response to this latest news, he added that Amazon’s glacial pace on adopting IPv6 for its own services made the charges appear somewhat like a cash grab.
“I don't think that's actually true, but when your AWS bill spikes 10 percent due to this change it's really hard to have a charitable interpretation,” he said.
“Customers with huge spend driven by this can't easily bring their own IP addresses; moving everything is a nightmare and requires a lot of work with customers/clients. It likely won't happen and folks will largely have to take it on the chin,” he warned. ®
Get our [16]Tech Resources
[1] https://aws.amazon.com/blogs/aws/new-aws-public-ipv4-address-charge-public-ip-insights/
[2] https://www.theregister.com/2023/07/31/aws_says_ipv4_addresses_cost/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZcEUOi57D8kcoFPQQ6L6EgAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcEUOi57D8kcoFPQQ6L6EgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcEUOi57D8kcoFPQQ6L6EgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.border0.com/blogs/ipv4-surcharge---your-aws-bill-is-going-up-this-february
[7] https://aws.amazon.com/about-aws/whats-new/2024/02/aws-free-tier-750-hours-free-public-ipv4-addresses/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcEUOi57D8kcoFPQQ6L6EgAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcEUOi57D8kcoFPQQ6L6EgAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html
[11] https://www.theregister.com/2024/01/31/zen_internet/
[12] https://www.theregister.com/2023/12/13/cloudflare_internet_traffic_2023/
[13] https://www.theregister.com/2023/10/17/china_networking_hardware/
[14] https://www.theregister.com/2023/10/11/apnic_ipv4_exhaustion_milestone/
[15] https://www.theregister.com/2019/11/25/ipv4_addresses_gone/
[16] https://whitepapers.theregister.com/
Well, they'll be waiting a long time then...
Yep. There are still a large number of currently reserved IPv4 addresses that could be released, but the IETF refuses because it wants everyone on IPv6. IPv4 addresses should be free, or part of the service because the service is pretty useless without them. Sadly though, the Internet powers that be didn't resist the commoditisation of IP addresses and allowed them to be bought & sold.
First they come to charge us for IPv4 addresses.
Then they come to charge us for the air that we breathe.
Finally, they come to charge us ground rent for where we're buried in/scattered on.
The Amazon Business Model. Coming soon.
Stuffed Turkey
I could almost live in a pure IPv6 world - indeed most of my traffic is IPv6. Except there are standouts (looking at you a certain mobile phone provider) who can't provide a universal IPv6 service. Also one of my software providers requires an IPv4 connect to activate.
Until the last IPv4 service is terminated it compels so many others to provide an IPv4 service. Reverse chicken & egg <:-(
Re: Stuffed Turkey
I think consumer-land is moving more and more to IPv4 but providers are using 6to4 gateways for a seamless transition. The avoids the need for expensive and tricky carrier-grade NAT and will allow more parts of the internet to move to IPv6 without anybody noticing. And a smooth transition suits everyone.
Re: providers are using 6to4 gateways
Ah, now that reminds me...
https://www.youtube.com/watch?v=8A3HZvGN0qs
Re: Stuffed Turkey
It's chicken-and-egg in both directions.
1. All content is currently available on IPv4, and will be for the foreseeable future. This is because (a) there is no squeeze on IPv4 availability at the content provider side, and (b) eyeballs are money, and content providers are not going to exclude access from the significant proportion of users who have only IPv4, by creating IPv6-only content. (Bar a few cat-feeders, and loopsofzen.co.uk).
2. However, most of that content is *not* available on IPv6. Large content providers like the BBC (who used to be technical leaders, back in the 20th century) simply can't be arsed to turn on IPv6, even though it would be relatively easy. Ditto for smaller content providers like, erm, The Register. Presumably they are worried about their user tracking and advertising and monetising - they don't want to risk anything which might break - or they simply have higher business priorities.
Therefore: all ISPs must provide IPv4 access to reach all Internet content (or else users will say "your service is broken"); and all content providers must provide content over IPv4, to make it available to all end-users.
Once in this situation, IPv6 becomes irrelevant. Adding it doesn't make any significant content available to users, although it reduces the NAT load on their routers; and adding it on the content provider side doesn't add any new eyeballs, although it may improve performance for some.
Possible ways out:
- government regulation. They legislate for web content to be accessible to disabled people; why not also that content has to be accessible via IPv6?
- something massive happens. There was talk, for example, of the Chinese turning off IPv4. If they do that, and if the Great Firewall of China doesn't do NAT64, then content providers will lose 1/5th of their global audience if they don't make it reachable via IPv6.
- someone builds a bloody great NAT64 gateway from the new Internet to the old, so you can build IPv6-only client networks and still reach all content. Cloudflare or Google would be well placed to do this. Getting hold of the IPv4 resources for the NAT pools is getting harder and harder though.
The Internet "powers that be" didn't really make clear what the legal status of IP addresses was.
There's an interesting snippet [1]here .
However, as in the domain name business, where you create artificial scarcity, someone will find a legal means to secure property rights.
We are just fiddling at the margins now with IPv4 addresses. We rjust need some big service provider to have the guts to turn them off - or at least announce a date.
[1] https://ipv4.global/blog/are-ip-addresses-property/
I don't follow your arguments. It's not the IETF that allocated the IPv4 blocks and the suggestions to move to IPv6 are based on a lot more than just scarce IPv4 addresses. Furthermore, making IPv4 addresses free is what got us to this mess in the first place. It was national regulators, especially the US, that led to an undervaluing of the resource and the incredibly skewed distribution of addresses mainly to US institutions and companies, who are now cashing in on this largesse. There are now more devices than IPv4 addresses so a redistribution, apart from being technically potentially as challenging as moving to IPv6 wouldn't solve the problem.
Re. There are now more devices than IPv4 addresses
Don’t see a problem here, although ivory tower purists might.
Re: Re. There are now more devices than IPv4 addresses
The problem being that, if you want to have two servers but you only have one IPV4 address, you have to put another box in the middle to filter and direct traffic to the right one, and if you want to have twenty, that box ends up having to be a lot bigger to do work you wouldn't need if you could just give each server an address. The problem being that, when someone wants to build a point-to-point network from their own devices, they can't do it without some central server coordinating things because their ISP has multiple layers of NAT in the way. Let me guess, you don't see a problem with it because you either don't run many or any servers on the public internet or because you already have your own IP addresses? A lot of people do not have assigned IP blocks, and many countries were assigned so few that you'll virtually never get them. It's another reason that people start to use cloud providers, because there isn't much work involved getting a new instance publicly available, even though it produces a worse maintenance requirement later.
I don't follow your arguments. It's not the IETF that allocated the IPv4 blocks and the suggestions to move to IPv6 are based on a lot more than just scarce IPv4 addresses.
One has to go back in time to an age where the Internet had class. Specifically the good'ol days of Class A, B, C networks. Those days are long over, and a lot of people forget that Class E still exists, and is 'reserved'. So 2^28 addresses from 240.x through 255.x
There have been frequent suggestions to release this space so it can be allocated and assigned, but those have mostly fallen on deaf ears. Many lunches were consumed to come up with IPv6, so you better damn well learn to start using it. Being a bit more radical, there's also the Class D range, aka 'Multicast', which never really took off. That's another 2^28 addresses. IPv6 does mcasting better (allegedly), so migrate! That's 224.x through 249.x, which had the added advantage of being able to announce the great v4 mcast shutdown in Feb 2024. The general excuse for not doing this is..
..but many computer and router operating systems and firmware do not allow the use of these addresses.
which is an easy problem to fix. And many computer and routers do allow you to unicast using mcast addresses, or configure with 'Class E' addresses. If not, update your bogons filter, and call it good.
Furthermore, making IPv4 addresses free is what got us to this mess in the first place.
They were never really 'free', because they were never really property. It was a case of use'em or lose'em. Then Nortel went titsup.com and the address space it had used was allowed to become property rather than being returned to the RIRs for reassingment. Then speculators dove into the swamp space looking for other address blocks they could acquire and then sell or rent.
Like I said, not enough addresses left to redistribute, even it sounds like a lot. You're also being revisionist. Sure, if we could go back to the 1970s and 1980s, reassignments, at least of company blocks would have been possible. But, by the time, IPv4 addresses scarcity became a thing, the financial possibilities were becoming clear and very few companies were prepared to give adddresses back.
I'm not claiming IPv6 is perfect, but I also don't think it's as bad as many make out, and it wasn't quite the gravy train I think you're suggesting: there have been more egregious examples of that with W3C springing to mind.
It's taken a while, but I think we now have enough people pursuing a pragmatic migration that isn't going to cause obscure and poorly maintained networks in key areas (hospitals are one area with infamously outdated kit) to fail suddenly because IPv4 was switched off. And this should be the blueprint for future changes, though I suspect the lessons about ownership will be some of the first to be forgotten.
Like I said, not enough addresses left to redistribute, even it sounds like a lot.
Class E space is 268,435,456 addresses, double that if mcast is moved to IPv6. Or 2m new 'class C' networks that could be assigned. Or a lot more based on current assignment policies.
You're also being revisionist.
Nope, I'm being a network engineer who's pointing out that the IPv4 address shortage is artificial and due to policy. The result is obviously an artificial scarcity, and an opportunity to inflate prices of something that was never intended to be property in the first place.
I'm not claiming IPv6 is perfect, but I also don't think it's as bad as many make out, and it wasn't quite the gravy train I think you're suggesting:
Having been involved, it was. The bigger problem though is the regulatory capture that happened in the domain name and address space. I also think v6 was the wrong approach and just extending the address field would have been a whole lot easier. Along with allowing routing based on country code. With just a single octet, every country could have the equivalent of the entire current IPv4 address space and make routing it more efficient. Just adding digits is something telcos have been doing for decades, and it works.. But the IETF just had to be different and deliver something that nobody but the mobile operators really wanted anyway. And they can route based on IMEI/IMSI, if they really wanted to.
Sure, they could have made an IPV6 that looks more like IPV4 and has longer address fields, but that would still require people to implement the new protocol, exactly like they do with IPV6. The other changes introduced when they made IPV6 have some problems, but that's not the reason it hasn't been adopted. Most places that haven't implemented it aren't saying that "If only IPV6 didn't have [insert change here], we would just use that". Either way, the change requirement would be the same and the work would only be done when it was almost too late.
> Just adding digits is something telcos have been doing for decades, and it works
It works for telcos because the phone network uses variable-length addresses. It doesn't work for IP because v4 packets have a fixed width for addresses, as does the socket API, as do important protocols like DHCP and DNS. So yes, the IETF did have to be different - because they were extending something that works differently.
Class D and E account for 12.5% of the total available address space. Even if they could be made available, it would have almost hardly any impact on the problem; within months we'd be back where we are now.
But in practice, they wouldn't work anyway, because you can't update the whole Internet to accept them in a reasonable time - it's not much different to updating the whole Internet to accept IPv6.
As a user, if you were assigned a class D or E address, you'd be a second-class citizen unable to access much of the Internet. For a real-world example of this, see my previous post [1]here .
[1] https://forums.theregister.com/forum/all/2022/06/01/ipv4_proposed_changes/#c_4469602
Ip v6
A lot of stuff comes with 6 turned on. Remember guys, this is just another attack surface.
For some of us, one is enough so we stay on 4 until we have to go to 6
We can do both but it is twice the effort.
For the guys that have more that a /21, ARIN charges a yearly fee. For those that are using /24 we just pass on the cost. Nothing like the big guys.
Might be the reason we have had so many move from the cloudy skies.
“ this means that AWS is sitting on about $4.6 billion, should it wish to divest itself of them.”
So whilst a valuable asset that didn’t cost Amazon that much to acquire, it is a really good investment. Based on the math presented in the article, a $400m~$1b Pa income is a really good return on investment.
I suggest the day Amazon, starts disposing of its IPv4 address blocks, is the day IPv4 starts to become history.
Bit rich given they're blocking of IPv6 ISPs
My ISP doesn't support IPv6 and seemingly has no plans to. Hurricane Electric provide a free "tunnel broker" service to you can use IPv6 while waiting for your ISP to either get their act together or for contract renewal to come around.
For the last several weeks it appears AWS, Google and a few others have taken to blackholing the entire /32 address range HE use. Not just a simple deny that would allow browsers and applications to fall back to IPv4, but instead causes them to lock up until eventually timing out, leaving the only option to disable IPv6 completely. And this affects any site who use services provided by this group so the knock-on effects are widespread.
As an end user you cannot even get a response (Google policy is to not discuss this, others likewise) let alone ask for your own subnet to be exempted, so a spectacular own goal in driving adoption.
Re: Bit rich given they're blocking of IPv6 ISPs
For the last several weeks it appears AWS, Google and a few others have taken to blackholing the entire /32 address range HE use.
This is one of the reasons I hate v6. On first parse, I read /32 range and went huh? Maybe too much CIDR over the weekend. But curious what excuse they'd have for doing this given HE's been around almost as long as the Internet, and are generally regarded as one of the good guys.
Re: Bit rich given they're blocking of IPv6 ISPs
It's politics.
* Hurricane Electric does not announce its IPv6 blocks to transit providers, because it considers itself to be a tier 1, and wants to force all other tier 1's to peer with it. But Cogent refuses to. As a result, if you buy your Internet connection from Cogent, you cannot reach IPv6 addresses belonging to Hurricane Electric (and vice versa).
* Google does not announce its IPv6 blocks to its transit providers (i.e. its upstream ISPs) AT ALL. Google want to force all operators to peer with them, so that in the long run, they don't have to pay any transit costs. But tier 1's like Cogent don't want to, as it breaks their business model.
I would have thought HE and Google would be happy to peer, but maybe that relationship has broken down recently too.
In any case, the situation we are in is that the IPv6 Internet is not fully connected - but nobody notices or cares, because IPv4 is what matters, and that works. Dual-stack and happy-eyeballs plaster over the cracks. It's only when you run an IPv6-only network that you find out what things are really broken.
The part that is bullsh*t is that for operations that serve public facing sites, not all clients have IPv6 connectivity -- so we're FORCED to pay for the IPv4 space if clients we have can't support IPv6 (including anonymous users/visitors) or lose their traffic.
It's like when we had to support IE 6-8 for YEARS because of client requirements or lose their traffic.
So they bought up 132 million IP addresses but are estimated to actually have 12 million, or 9%, of those actually in use? No wonder there's a shortage of addresses. Amazon and probably others are hoarding. Even if you consider inefficiencies due to subnetting, and quadruple the number in-use but not pingable, that's an awful fucking lot of addresses that are just being held by greedy corporations for no reason. Either just trying to drive up the price so they can sell them off in a trickle, or planning this rental cost the whole time using "shortage" as an excuse, or just trying to artificially push the world into using IPv6 by manufacturing a need.
That estimate is just wrong. I don't know how many addresses are in use, but there are three categories to consider:
1. Machines that are online now and respond to pings. About 6 million, evidently.
2. Machines that are online and do not respond to pings. This is the default for most machine images and firewalls. You have to take two manual steps to change your configuration to allow pings. I'm not sure why this guy assumed that 50% of users would have done that.
3. Machines that allowlist IPs and won't respond to your script no matter what their ICMP settings are. There are a lot of these out there for private networks that use the public internet to connect them.
I don't know how many are in use, but it's a lot more than 12 million.
Holdout
Pretty much everything has great IPv6 support except Docker. Docker tolerates IPv6 but you're on your own to get the packets routed.
Anyone desiring a new public IPv4 address since then has had to rely on address ranges being recovered from organizations shutting down or surrendering them as they migrate to IPv6.
Well, they'll be waiting a long time then...
Only half joking -->