Pages

Wednesday, March 20, 2013

IPv6 happy eyeballs breaks connection to secure sites

OSX / Safari seems to choose protocol IPv4 or IPv6 based on best network performance (syn-ack roundtrip time ?). What is even worse, the browser toggles protocol within a secure SSL session (e.g. banking). Most sites that contain sensitive information will break the connection for security reasons if the IP address changes.

In my opinion, Safari should give IPv6 a preference, and should only fallback to IPv4 if the connection is really bad. Moreover, the number of switchovers should be limited since it is almost impossible to finish a secure transaction sequence.

 

As most Internet providers do not yet support IPv6, IPv6 enabled networks do so by tunneling, which makes the IPv6 network slightly slower than the IPv4 network. Still I believe we should give IPv6 a preference.

 

Please Apple, dont discourage early IPv6 adopters and correct this behavior. By the way: Chrome on OSX suffers from the same problem.

 

Jan C.

 

One additional note: the IPv6 tunnel is not terminated on my Macs, but on the network vdsl2 gateway device


View the original article here

0 comments:

Post a Comment