Live data from Hacker News

AT&T Wireless traffic shaping apparently making some websites unusable

adriano.fyi

251–260 of 305 posts

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#251
post #35

> I already knew from previous experience that for some reason, AT&T traffic to fast.com is throttled. Why AT&T wants bandwidth to appear lower than reality is a mystery to me, but I digress This I think is because they throttle ip addresses for known video streaming sites. That is one of (the only reliable) ways an ISP can get the streaming provider to drop the stream to a lower quality one by default. Since fast.co…

On my ISP (Three UK), a DNS lookup to fast.com gives you faster internet for the next minute or so.

Therefore, I have a background bash loop just looking up fast.com every 30 seconds all day long.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#253
post #63

Earlier quoted context omitted.

> Placing a device in passthrough mode will remove firewall protection provided by the AT&T gateway Did... did they seriously turn the router into a DMZ*, without your consent? Where every port of your computer is just open to the internet? That's scary. *that's what it was called on my router, the "forward every single port to one device" mode. Not sure if that is the correct term for it.

Passthrough mode turns ~90% of the (DSL modem / ONT) + router + DHCP + NAT + WiFi AP + whatever functionality off, allowing you to add another home router after it which is completely under your control and let the ISP-provided one only do the most necessary, eg. (DSL modem / ONT) parts.

I might end up getting another router next time I move because of this.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#254
post #41

Fun story: I work remotely for an org located in the Bay area. Few months ago I get a call early morning from the IT security person. Apparently someone had been trying to RDP into my work laptop, over a thousand attempts per day for last couple of days. What changed before the last couple of days? My laptop was frequently dropping WiFi connection- a lot of times in the middle of zoom meetings. We use a router provid…

finally, after switching to 5GHz WiFi was the Zoom problem resolved? asking because: Your comment reminded me of one article / discussion about Apple Devices causing huge network load , and hence delays, due to some map ping thingy. [Apple Maps location scan spikes WiFi latency every 60 seconds. 677 points, 172 comments] https://news.ycombinator.com/item?id=31356730 (I hate the '5G WiFI' that most ISPs seem to be cal…

We don't have any apple products actually. Three Lenovos and a Razer. My wife is still on WiFi most of the time and she hasn't experienced much issues. But my impression is that we always has 5G WiFi enabled. Still not sure actually what AT&T support did, but if there was an issue it was most likely fixed by the router reset.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#255

Earlier quoted context omitted.

Is there more on this mitm cert spoofing somewhere I can read up on? Sounds intriguing to say the least

It probably isn't too different from other access methods: 1) Get access to port 80 for > 60 seconds. Point it at your temporary VM. 2) Use any cert authority, and for verification, choose a file-specific location verification (you can choose amongst DNS records, an email to admin@domain, or a specific file location on your site with many of them) 3) On your VM, Quickly paste the file-specific location into a django…

> The cert authority verifies you, and emails your account the cert, the website author being none the wiser.

It’s not hard to monitor cert transparency logs, which will show this new cert.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#256
post #152

Earlier quoted context omitted.

> Since fast.com is a Netflix ip, and the isp can’t distinguish whether it’s video that is being transferred or a file to measure throughout, It is really trivial to do basic traffic snooping and see what people are looking at. I'm surprised it isn't more common. I figured it would be harder, or perform worse, but I easily wrote a little piece of software that filters the TLS ClientHello for arbitrary domains. Maybe…

People drastically overestimate the security properties of TLS. The correct mental model is that it’s good enough to convince 1990’s US internet users to type their credit card into a web page. (Where the downside of a breach is that you have to dispute some charges and change your CC#.) If you need stronger security than that, then many, many caveats start to apply. For instance, by default, anyone that can reliably…

If by “people,” you mean “people who rely on HTTPS for security,” then it seems like you’re saying that every hosted software company is getting it wrong. HTTPS is the foundation of the “zero trust” security model as implemented by Google, MS365, Facebook, AWS, etc.

I think it’s more likely you are not considering the full picture of the TLS ecosystem, or are making arbitrary distinctions like “cert transparency logging isn’t actually part of HTTPS” or something.

Consider that Symantec basically did what you suggest (mis-issue some certs) and not only was it detected and mitigated, they lost their CA business entirely over it.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#257

Earlier quoted context omitted.

Many of their plans downscale video, or at least they used to

I've never experienced this. How would this even work for encrypted (HTTPS) streams? Even if this were technically feasible, it sounds like a massive infrastructure investment with little to no value. T-Mobile would need to have enough compute and network horsepower to DPI all outbound traffic, intercept every video stream, detect if it's over some resolution threshold, and re-encode it at a lower resolution or bit r…

"Downscale" is not quite the right term to use, they just throttle the video CDNs so the streaming platform chooses a lower bandwidth version

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#258

Earlier quoted context omitted.

Plus you can rewatch without downloading again. And use sneakernets for sharing with your friends.

I've always disliked how wasteful streaming is in respect bandwidth consumption. However, the "efficiency be damned, just make it fasterer" attitude towards bandwidth is, if not the biggest, then definitely among the biggest, drivers behind the ever increasing internet throughput. Thinking about it, it seems like watching habits could make streaming be more or less "efficient" compared to downloading once and storing…

With music it's quite different though, I often have the same albums on rotation and it's great to be able to cache them all locally.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#259
post #102

Earlier quoted context omitted.

Early in the pandemic, I spent a while without wired internet using a wireless hotspot from the library which would not connect to Netflix but any other streaming video service was fine. I forget who the wireless vendor behind the hotspot was—I think it might have been Verizon.

So there's a bit of a weird fact about public libraries, which is that it probably wasn't on the normal internet (Internet1) but was in fact on Internet2 (see [1]). Internet2 is used by hospitals, among other things, and as such has higher robustness requirements than Internet1. The pandemic created much higher demand for bandwidth from hospitals, forcing Internet2 providers to scramble to keep up in areas. As such,…

I've worked at two hospitals. Both of them "had" Internet2. I was excited, as I had not heard about it in ~20 years.

Neither of them actually ran any traffic over it.

Re: AT&T Wireless traffic shaping apparently making some websites unusable

#260

Earlier quoted context omitted.

Yeah, except they leak customer data regularly and have offshored tons of customer service to India -- including onboarding. When I tried to sign up, they didn't know what an esim was and wanted my SSN, along with other data that could easily be used to steal my identity. I don't want to spend my days arguing with people, definitely not about the existence of esim; but I did that day. It went all the way up their cus…

ATT has provided the best service of any carrier while traveling, so I will use them. Really? My experience with AT&T while traveling has been pretty awful. In the US, in rural areas, Verizon is better. And outside the US, Google Fi gives you international data roaming as part of the base package. One of the reasons I switched to Google Fi is because it's so much better when traveling.

I've been to every state in the contingent US, most many more times than once, and spent most of my time in rural areas / wilderness. Verizon was poor during the time I had it. I forgot what triggered switching from them but I didn't last long, had to switch to ATT. I switched to ATT because my Tesla uses them and I noticed it almost always had service in remote areas when I did not. Haven't needed to switch since.

ATT has a great plan for the Americas, south America is all covered, Canada is covered, and many other places. It worked really well for me in Brazil.

That said, when I start traveling to Europe and Asia more, I may switch back to Google Fi.

For domestic use, while traveling / on the road a lot? I would rate as follows:

ATT > Google Fi > T-Mobile > Verizon

Keep in mind, if you are mostly stationary it is better to use the carrier known for good service in your fixed location.

Post reply on HN