Live data from Hacker News

AT&T Wireless traffic shaping apparently making some websites unusable

adriano.fyi

221–230 of 305 posts

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#221
post #41

Fun story: I work remotely for an org located in the Bay area. Few months ago I get a call early morning from the IT security person. Apparently someone had been trying to RDP into my work laptop, over a thousand attempts per day for last couple of days. What changed before the last couple of days? My laptop was frequently dropping WiFi connection- a lot of times in the middle of zoom meetings. We use a router provid…

finally, after switching to 5GHz WiFi was the Zoom problem resolved?

asking because: Your comment reminded me of one article / discussion about Apple Devices causing huge network load , and hence delays, due to some map ping thingy.

[Apple Maps location scan spikes WiFi latency every 60 seconds. 677 points, 172 comments]

https://news.ycombinator.com/item?id=31356730

(I hate the '5G WiFI' that most ISPs seem to be calling it everywhere. )

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#223

Taking a quick 5 minute look at the packet capture attached to the post, it looks to me like this is likely traffic shaping. While it's always difficult to be 100% sure from just the client side capture, the capture looks relatively clean of errors, and the amount of data in flight doesn't appear to even approach the advertised window. We're getting some merging of segments likely from a segment offload, but I doubt…

Could it not also be the problematic traffic getting routed to a Cloudfront node that's overloaded or otherwise misbehaving? Years ago, I had to troubleshoot a very mysterious issue where sometimes a huge percentage of the PCs in the company I worked for would have trouble loading the company's e-commerce site. Everyone was going through the same array of 2-3 proxy servers, and the e-commerce site had Akamai caching…

> Could it not also be the problematic traffic getting routed to a Cloudfront node that's overloaded or otherwise misbehaving?

This is plausible. Nothing I saw in the packet capture specifically pointed in this direction, but I don't really have the information I'd want to rule this out totally.

I've seen issues like this when the TCP stack on the server effectively runs out of allocated memory. This can cause the server not to use all of the available tcp window.

The only reason I think this is less likely, is I'd expect a company like AWS to monitor and tune the memory on their CDN, and notice something like a kernel bug here or block an attack exploiting the kernel memory.

Some network providers, especially wireless providers also deploy TCP acceleration equipment, so that network speeds are faster. On a wireless carrier if you've got temporary bad signal and drop some packets, if the carrier can retransmit them instead of going to the internet, this makes for a faster connection. Crappier implementations of these TCP accelerators, do a sort of transparent redirect to the kernel TCP stack. So if the ATT proxy has run out of kernel memory, it could be providing a slow connection. It wouldn't surprise me for a telecom carrier to miss and not tune or monitor kernel memory.

If the issue was caused by a proxy, I'd expect more to be broken then a single server, and other customers to also be complaining.

If ATT is using these accelerators, it also means the proxy could be hiding packet loss and delays between the proxy and upstream server or network. Because the client TCP connection is only to the proxy, we only get to see what happened between the client and proxy. So this precluded drawing strong conclusions from the client side capture only.

There is one thing about the packet capture that suggests a shaper to me. And that's how even the traffic is from server to client. While I didn't spend a bunch of time timing out all the packets, it looked a bit like I'd expect to see for packets getting released by a token bucket algorithm. This isn't necessarily safe to conclude, because the client has an offload that is buffering and merging packets using a receive segment offload, which causes us to miss some timing information in the capture.

So based on the above, shaping looks a little bit more likely to me, but I don't have the right information to rule out a broken or miss-configured server. An overloaded or otherwise broken network link like errors on a link doesn't appear likely to me at all.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#224

Earlier quoted context omitted.

MB = megabyte Mb = megabits 1 byte = 8-bit

For years, AT&T sales reps would refer to MB when they meant Mb. Soon after I started service with them, I called to ask about the promised speed, and the tech insisted they sold Mb/s. He conferenced in a salesperson and was embarrassed to discover that the salesperson talked exclusively in terms of MB/s.

Did they just spell it with the abbreviations? Or did they pronounce 'megabytes' deliberately?

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#225
post #41

Fun story: I work remotely for an org located in the Bay area. Few months ago I get a call early morning from the IT security person. Apparently someone had been trying to RDP into my work laptop, over a thousand attempts per day for last couple of days. What changed before the last couple of days? My laptop was frequently dropping WiFi connection- a lot of times in the middle of zoom meetings. We use a router provid…

> Placing a device in passthrough mode will remove firewall protection provided by the AT&T gateway Did... did they seriously turn the router into a DMZ*, without your consent? Where every port of your computer is just open to the internet? That's scary. *that's what it was called on my router, the "forward every single port to one device" mode. Not sure if that is the correct term for it.

That's why a firewall I own is in-between my ISP provided equipment and my computer.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#226

Earlier quoted context omitted.

For years, AT&T sales reps would refer to MB when they meant Mb. Soon after I started service with them, I called to ask about the promised speed, and the tech insisted they sold Mb/s. He conferenced in a salesperson and was embarrassed to discover that the salesperson talked exclusively in terms of MB/s.

Did they just spell it with the abbreviations? Or did they pronounce 'megabytes' deliberately?

They literally said it out loud. I had spent the last 7 years on a fast university network, and had never paid for internet before that. I honestly believed that they were going to deliver the speeds they claimed.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#227

Earlier quoted context omitted.

So there's a bit of a weird fact about public libraries, which is that it probably wasn't on the normal internet (Internet1) but was in fact on Internet2 (see [1]). Internet2 is used by hospitals, among other things, and as such has higher robustness requirements than Internet1. The pandemic created much higher demand for bandwidth from hospitals, forcing Internet2 providers to scramble to keep up in areas. As such,…

Not quite sure I understand - what do hospitals need a ton of bandwidth for? Why would those bandwidth requirements rise significantly during the pandemic. Sure there were a bunch of people on vents in the MICU, but pretty much every elective procedural service plummeted.

Other than telehealth, we also use the bandwidth for remote desktops/apps and lossless high-resolution radiographic images. While one might expect this traffic to occur over local networks, many hospitals have multiple sites and partnerships that are connected over the internet. So, for example, one might operate the hospital's apps while sitting in the library at the affiliated university.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#228

Earlier quoted context omitted.

Yup. Buffets have been that way forever. No one is actually allowed to eat unlimited.

I'm not sure what you mean. Most buffets won't limit you.

Buffets have inherent limits in the way they do things. It's just transparent to you unless you know what to look for.

Limited buffet hours. Most Indian buffets are lunchtime only, and the restaurant is open, say, 11am-1pm, and then closes until dinner. Indian buffets are often leftovers from last night's dinner, too, so there's a limit to the amount of food that they won't cook more.

Size of plates, bowls, glasses. This is an easy one, and you can use it to go on a diet. If you have large plates or bowls, throw them out and get small-capacity dishes. Buffets will make you use a certain size plate, and so each trip you can only pick up so much food, and this helps you notice that you feel full before taking more.

You may also be required to use a clean plate each time you dip into the buffet. This might have various effects on how you regard the food you took originally.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#229

Earlier quoted context omitted.

Did they just spell it with the abbreviations? Or did they pronounce 'megabytes' deliberately?

They literally said it out loud. I had spent the last 7 years on a fast university network, and had never paid for internet before that. I honestly believed that they were going to deliver the speeds they claimed.

I wouldn't have believed "megabytes" was an Internet speed, because it never is. It's literally impossible for that to be a signaling rate on any known Layer 2 technology. ISPs use Gibibytes or Tebibytes (which they misname as Gigabytes/Terabytes) for transfer caps, but that's apples and oranges.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#230

AT&T uses different APNs for regular phone plans and data-only hotspot plans. It's very possible that the phone traffic is being routed completely differently than the hotspot traffic, with congestion at a peering point occurring on the hotspot. AT&T tends to be known for having poor/congested peering. You could try changing the DNS server on your hotspot to a different public resolver like 1.1.1.1 or 8.8.8.8. If Clo…

Good tip. I just tried with both and wasn't routed to a faster point of presence with either. I'll add a traceroute from the phone and one from a device connected to the LTE router to the updates section next. [update] Traceroutes added

On chrome-based mobile browsers your traceroutes are getting stuck in a small non scrollable iframe-type-thing.
Post reply on HN