Live data from Hacker News

AT&T Wireless traffic shaping apparently making some websites unusable

adriano.fyi

171–180 of 305 posts

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#171

Earlier quoted context omitted.

> As for me? ATT has provided the best service of any carrier while traveling, so I will use them. I'm curious about your reasons to say that AT&T provides the best service "while traveling". I'm guessing it would be domestic travel, because AT&T roaming charges are the second highest among the big three (I believe Verizon is actually even more expensive). I was a customer and an employee of AT&T for a while, and I f…

Do you mean international charges? I thought roaming has not been a thing for a decade. Many ATT plans include usage in all of the western hemisphere, excluding the Caribbean islands. And for countries not included, it is $10 per day ($5 for other lines on your plan) up to 10 days in a billing cycle, and after that it is free until the next billing cycle. Not the cheapest (I think T-Mobile has international at $5 per…

Basic international is included on most t-mobile plans.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#172
post #152

Earlier quoted context omitted.

> Since fast.com is a Netflix ip, and the isp can’t distinguish whether it’s video that is being transferred or a file to measure throughout, It is really trivial to do basic traffic snooping and see what people are looking at. I'm surprised it isn't more common. I figured it would be harder, or perform worse, but I easily wrote a little piece of software that filters the TLS ClientHello for arbitrary domains. Maybe…

People drastically overestimate the security properties of TLS. The correct mental model is that it’s good enough to convince 1990’s US internet users to type their credit card into a web page. (Where the downside of a breach is that you have to dispute some charges and change your CC#.) If you need stronger security than that, then many, many caveats start to apply. For instance, by default, anyone that can reliably…

Is there more on this mitm cert spoofing somewhere I can read up on? Sounds intriguing to say the least

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#173

Earlier quoted context omitted.

It definitely looks like testing sites are prioritized. The fastest download speed that I have gotten is maybe 7 MB (bytes) per second; generally it is 2-5 MB per second. The speed test sites generally get 100 Mb per second dowload. In general the best I seem to get is about half the speed of the speed test sites. To me the real speed of the ISP is how fast one can download something one wants, not the result of a te…

I personally like https://speed.cloudflare.com since it just looks like you're doing typical CloudFlare traffic. The results viewer is also quite nice.

My ISP (Telecom) gives me a speed of 250Mbps using fast.com and 40Mbps using Cloudflare's tool.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#174
post #38

When I had AT&T VDSL they had weak peering. Some traffic that should have gone across town would routinely get routed several states away before coming back to town, because they hadn't peered with the local exchanges. Some traffic was ok. When I switched to an ISP with local peering, ping times between my home and my server downtown dropped to a few milliseconds. It's like being on my LAN. If this is still an issue…

Same issue in Canada: our big ISPs historically refuse to peer freely at our domestic IXs like TORIX. So smaller ISP and DCs end up peering with them in the USA and your packets would make circuitous cross-border round trips to go a few km. Some national players do have ports at domestic IXs, but only as backup links or for negotiated (paid?) access. The hazards of ISPs also being backbone providers. (It looks like R…

As far as I can tell, Bell holds its Canadian customers hostage to force peers to pay them for what should be mutually beneficial peering. It does not participate in _ANY_ of the Canadian internet exchanges. Even Rogers connects to TORIX.

https://bgp.he.net/AS577#_ix

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#175
post #35

> I already knew from previous experience that for some reason, AT&T traffic to fast.com is throttled. Why AT&T wants bandwidth to appear lower than reality is a mystery to me, but I digress This I think is because they throttle ip addresses for known video streaming sites. That is one of (the only reliable) ways an ISP can get the streaming provider to drop the stream to a lower quality one by default. Since fast.co…

I recently discovered that T-Mobile does this too, but they actually let you disable it on their site. Ostensibly, it's a feature for your benefit (somehow), and they're doing you a favor by enabling it by default. In reality, of course, it's for their own benefit, and they're banking on people not realizing it can be disabled. I suppose giving you the option lets them advertise things like "no throttling" and "4K st…

T-Mobile gives me full speed when I set my APN to B2B/IPV4.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#176
post #152

Earlier quoted context omitted.

People drastically overestimate the security properties of TLS. The correct mental model is that it’s good enough to convince 1990’s US internet users to type their credit card into a web page. (Where the downside of a breach is that you have to dispute some charges and change your CC#.) If you need stronger security than that, then many, many caveats start to apply. For instance, by default, anyone that can reliably…

Is there more on this mitm cert spoofing somewhere I can read up on? Sounds intriguing to say the least

It probably isn't too different from other access methods: 1) Get access to port 80 for > 60 seconds. Point it at your temporary VM. 2) Use any cert authority, and for verification, choose a file-specific location verification (you can choose amongst DNS records, an email to admin@domain, or a specific file location on your site with many of them) 3) On your VM, Quickly paste the file-specific location into a django GET route. 4) Run the Django site on port 80. 5) The cert authority verifies you, and emails your account the cert, the website author being none the wiser. You can now use it later to fool future visitors for a deeper attack or email-related attacks.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#177
Back in the early 2000's, I worked for a small company that was hired by the law firm representing one of the big cable companies (let's call them Company A).

Company A was suing another big cable company (Company X) b/c A claimed that X was throttling customers without telling them and advertising what were in effect unthrottled bandwidth numbers.

In order to prove this, the company I worked for went out and hired people to get cable modem subscriptions for Company X, install desktop that were locked down so the people couldn't use the desktops themselves and then collected ping and HTTP request data for months.

My job was to take that data and analyze it for throttling patterns.

This was my first job out of grad school and involved lots of:

- data cleaning and organizing using Perl

- analyzing statistics using Excel

- creating charts that could then be shown to the lawyers and in turn could be used in court

I didn't know much about databases or stats packages in Perl which, in hindsight, would have made my life easier.

I still remember being on the call with the lawyers and walking them through the data that proved that Company X was indeed throttling bandwidth at peak usage times. The one lawyer on the conference call said "Wow! This data is amazing. You guys are now basically national experts in this."

I was both:

- flattered that someone would call me a national expert in something

- scared shitless that I would end up being cross examined about how we processed this data

Turns out that the court case never happened and they settled out of court.

The reason I mention this story is that it's FASCINATING to me that this is still occurring today. I guess some things never do change.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#178
post #96

Remember how 5G was supposed to support "the metaverse"?[1] I've been working on a high performance metaverse client. All Rust, all multi-threaded. Designed to max out a gamer PC. Supports Second Life and Open Simulator. Second Life had a reputation for being sluggish. Fixing that. I'm pulling content from the servers at 200Mb/s, sustained. 400Mb/s in tests, but don't need to go that fast. The servers (AWS front-ende…

Unlimited is a term of art that means "limited".

I had to buy a prepaid cell subscription the other day. I went with the one that stated "Truly Unlimited"* as the headline, clearly to differentiate it from all the other "Not Truly Unlimited" plans.

* Truly Limited for heavy users.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#179

Earlier quoted context omitted.

Is there more on this mitm cert spoofing somewhere I can read up on? Sounds intriguing to say the least

It probably isn't too different from other access methods: 1) Get access to port 80 for > 60 seconds. Point it at your temporary VM. 2) Use any cert authority, and for verification, choose a file-specific location verification (you can choose amongst DNS records, an email to admin@domain, or a specific file location on your site with many of them) 3) On your VM, Quickly paste the file-specific location into a django…

This doesn't work unless the attacker happens to be in between your servers and the cert authority. The ISP that's in-between your laptop and the site can't pull this trick.

Also LE actually knows this attack is possible and mitigates it by validating the challenge from multiple sources so the attacker would need to be in the middle of all the LE validators and your servers.

https://portswigger.net/daily-swig/lets-encrypt-deploys-new-...

Post reply on HN