Summary
- The September 2 individual draft's 100/50 figures concern two different, narrowly defined quantities—not a measured halving of organisational risk.
- IPv6-only transport can coexist with IPv4 processing at endpoints. A retirement claim must identify which components it includes.
A network team can finish its migration while an application still needs the old protocol. That is the useful operational tension in Charles C. Sun's current individual Internet-Draft, revision -01, dated September 2. The author, affiliated with Alliance for Universal Computing, formalises what removing an IPv4 processing path means. The draft is not an IETF-endorsed standard or evidence of a completed deployment.
Its arithmetic needs its nouns. The 100% figure concerns the defined class of executable attacks that necessarily require the removed IPv4 Layer 3 path. The 50% figure counts concurrently exposed protocol-stack surfaces falling from two to one. The text expressly rules out interpreting either as an observed reduction in attack traffic, incidents, financial loss or total organisational risk. Reading it as a promise of safer IPv6 would misstate the proposal.
A narrow claim can be correct
The consequential condition is the chosen host or network boundary. If a translator, tunnel endpoint or compatibility component still performs IPv4 Layer 3 processing inside that boundary, the draft's retirement premise is not met there. Removing that component from a diagram does not disable it.
This is not an exotic distinction. RFC 9099, the 2021 operational-security guidance, describes 464XLAT: translation from IPv4 to IPv6 at the host and back to IPv4 at the provider can connect an IPv4-only application to an IPv4-only server across an IPv6-only network. The transport can genuinely be IPv6-only without the larger system ceasing to process IPv4.
The implication is analytical, not a finding about a particular operator. A transport-only acceptance test may be adequate for the transport team's contract. It cannot by itself certify retirement across endpoints and compatibility services. Expanding the scope changes the proposition being tested, not merely the wording of the certificate.
What the number leaves open
Stack count assigns each protocol one unit; it does not weigh the loss associated with a surviving failure. The draft also does not deny shared code or resources, and preserving IPv6's own mechanics does not guarantee access to destinations requiring IPv4. Those exclusions are explicit limits, not concealed defects discovered by this report.
There may be real operational value in maintaining fewer protocol paths. Whether that value exceeds migration and compatibility costs requires evidence from the affected system. The draft supplies a bounded vocabulary for removal; it does not supply that business case.
This distinction follows Lu Heng's account of BTW's editorial purpose: describe the operating structure without turning it into advocacy. That note guides the analysis; it is not technical corroboration.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

