Live data from Hacker News

AT&T Wireless traffic shaping apparently making some websites unusable

adriano.fyi

291–300 of 305 posts

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#291

Earlier quoted context omitted.

They literally said it out loud. I had spent the last 7 years on a fast university network, and had never paid for internet before that. I honestly believed that they were going to deliver the speeds they claimed.

I wouldn't have believed "megabytes" was an Internet speed, because it never is. It's literally impossible for that to be a signaling rate on any known Layer 2 technology. ISPs use Gibibytes or Tebibytes (which they misname as Gigabytes/Terabytes) for transfer caps, but that's apples and oranges.

> I wouldn't have believed "megabytes" was an Internet speed

Perhaps HNers know better, but among lay people, pretty much no one talks about megabits. For example, people know that an MP3 is about 5MB. They know that they can email attachments up to 20MB (or sometimes 10). But I've literally never heard a lay person talk about bits, or bits per second.

And the fact that ISP's transfer caps are denominated in bytes makes things all the more confusing.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#292
post #282

Earlier quoted context omitted.

I recently discovered that T-Mobile does this too, but they actually let you disable it on their site. Ostensibly, it's a feature for your benefit (somehow), and they're doing you a favor by enabling it by default. In reality, of course, it's for their own benefit, and they're banking on people not realizing it can be disabled. I suppose giving you the option lets them advertise things like "no throttling" and "4K st…

> Ostensibly, it's a feature for your benefit (somehow), and they're doing you a favor by enabling it by default. Some throttling by default for video actually is sort of for your benefit, at least indirectly, although I don't know if carriers are throttling more than that amount. A surprisingly large number of people nowadays watch movies on their phones or small tablets. On screens that size at the distances they t…

Speak for yourself. 1080p is noticeably worse if I'm paying attention; 720p is noticeably worse at a glance; and 480p (which is effectively T-Mobile's limit by default, even though they advertise my plan as supporting "4K streaming") looks like hot garbage.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#293
post #112
post #89

Earlier quoted context omitted.

Couldn't ISPs just sniff the SNI hostname to differentiate fast.com vs actual Netflix video streaming?

You can think of the requests to fast.com as just loading the speed test control scripts and user interface. The actual speed test loads files from the same servers (with the same SNI hostname) used by actual Netflix video streaming. It wouldn't surprise me at all if the fast.com speed test loads real streaming video segments from these servers, the only difference being that it doesn't have the decryption key for th…

It does. You're loading segments of real movies on Netflix that are not encumbered by copyright.

But they're intentionally otherwise indistinguishable from any other real movie on Netflix.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#294
post #35

> I already knew from previous experience that for some reason, AT&T traffic to fast.com is throttled. Why AT&T wants bandwidth to appear lower than reality is a mystery to me, but I digress This I think is because they throttle ip addresses for known video streaming sites. That is one of (the only reliable) ways an ISP can get the streaming provider to drop the stream to a lower quality one by default. Since fast.co…

> Since fast.com is a Netflix ip, and the isp can’t distinguish whether it’s video that is being transferred or a file to measure throughout, It is really trivial to do basic traffic snooping and see what people are looking at. I'm surprised it isn't more common. I figured it would be harder, or perform worse, but I easily wrote a little piece of software that filters the TLS ClientHello for arbitrary domains. Maybe…

AT&T is well know for doing deep packet inspection so that they can properly throttle NetFlix. They are always at the top of the list of Net Neutrality violators that Netflix complains about.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#295
post #203

Earlier quoted context omitted.

As I learned the hard way once, when AT&T say “unlimited” they mean up to a certain amount for data. Y’know. Like how Olive Garden offers unlimited breadsticks but then when you get your bill they charge you $40 for each breadstick over the unlimited amount of 2.

This is actually good analogy. OG will definitely throttle your breadsticks if you eat too many by taking their sweet time bringing another basket.

Not the way I ask for breadsticks they won’t.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#296

Earlier quoted context omitted.

As I learned the hard way once, when AT&T say “unlimited” they mean up to a certain amount for data. Y’know. Like how Olive Garden offers unlimited breadsticks but then when you get your bill they charge you $40 for each breadstick over the unlimited amount of 2.

A literal case of there being no such thing as free lunch.

Especially since given the ultimate horrifying finiteness of both the material and time in the universe, the dream of truly unlimited breadsticks will forever be outside of our reach.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#297

Earlier quoted context omitted.

They literally said it out loud. I had spent the last 7 years on a fast university network, and had never paid for internet before that. I honestly believed that they were going to deliver the speeds they claimed.

I wouldn't have believed "megabytes" was an Internet speed, because it never is. It's literally impossible for that to be a signaling rate on any known Layer 2 technology. ISPs use Gibibytes or Tebibytes (which they misname as Gigabytes/Terabytes) for transfer caps, but that's apples and oranges.

There was a time when everyone considered a kilobyte to be 1024 bytes, a megabyte to be 1024 kilobytes, and so forth. The main reason this changed is because disk manufacturers advertised e.g. 1 billion byte hard disks as having “1 GB” of capacity and, to pretend they weren’t ripping us all off, proceeded to claim that the definitions were ambiguous. But even today, if you go out and buy an 8 GB DIMM, you are getting 8 * 1024 * 1024 * 1024 bytes.

(As a historical side note, there was even a weird transitional period where a “1.44 MB 3.5 floppy” held 1.44 * 1000 * 1024 bytes, or what everyone at the time would have called 1440 kilobytes.)

Personally I think it’s unfortunate that standards bodies and even courts have sided with the disk manufacturers. I also find the SI binary prefixes utterly revolting on an aesthetic level, so I’d much rather join whatever parts of the tech industry are still holding out.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#298

Earlier quoted context omitted.

With music it's quite different though, I often have the same albums on rotation and it's great to be able to cache them all locally.

Couldn't agree more. I've stopped paying to stream music entirely and now pay to own FLAC files which I store and use on my PC and phone. Almost like regressing back to having an iPod, and I personally love it.

I never gave up my music files, and never will trust service providers enough to do so.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#299
post #179

Earlier quoted context omitted.

It probably isn't too different from other access methods: 1) Get access to port 80 for > 60 seconds. Point it at your temporary VM. 2) Use any cert authority, and for verification, choose a file-specific location verification (you can choose amongst DNS records, an email to admin@domain, or a specific file location on your site with many of them) 3) On your VM, Quickly paste the file-specific location into a django…

This doesn't work unless the attacker happens to be in between your servers and the cert authority. The ISP that's in-between your laptop and the site can't pull this trick. Also LE actually knows this attack is possible and mitigates it by validating the challenge from multiple sources so the attacker would need to be in the middle of all the LE validators and your servers. https://portswigger.net/daily-swig/lets-en…

Yes that's true, but I was just talking about the scenario of having access to port 80 of a server DNS pointed at by some domain.

You might have access through editing a proxy rewrite rule, for example.

In the attack above you use your own SSL provider for a cert (LE not involved) and you overwrite the cert in a sense that existed before. You choose a provider that just validates with a file location. It's an attack which already requires compromise.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#300
post #41

Fun story: I work remotely for an org located in the Bay area. Few months ago I get a call early morning from the IT security person. Apparently someone had been trying to RDP into my work laptop, over a thousand attempts per day for last couple of days. What changed before the last couple of days? My laptop was frequently dropping WiFi connection- a lot of times in the middle of zoom meetings. We use a router provid…

I prefer to treat my ISP-supplied equipment as foreign territory, so their modem is in passthrough mode on purpose. Its only client is my own standalone firewall, since I have its Wi-Fi turned off.

As long as I'm not messing with the network, it's all great, and I know where to start looking if there is odd traffic going on.

Post reply on HN