Depends on where you live, I haven't exactly counted them but I have at least 20 options. Worst-case you can start your own ISP.
Source? I do not think most of the ISPs in my area are particularly scummy. They provide reliable plain internet service with no data caps (and also TV/phone service if you so desire) for a reasonable monthly fee, and in my experience, most of them hire enough customer service workers on their support phone. All of them also resisted internet filtering until the legal system forced them to do so. What more is there to ask of an ISP?
In my area none of them provide reliable internet service, most of them enforce some censorship and have poor customer service, and all of them perform the legally-mandated surveillance.
Taking care of insecure IoT devices would be a start: https://news.ycombinator.com/item?id=15946095
Where I live the nationwide fiber network has around 100 ISPs available of varying reputation.
Wikipedia says that PPPoE "offers encryption" but now I'm curious if this is effective, and actually used by anyone...
That said, if you set up your own vpn on a digital ocean node, moving your network boundary to the datacentre, then the cloud hosting companies network that you end up trusting is less likely to be set up to spy on you then a consumer isp.
I get bad speed though when I do this. The processibg speed required to encrypt a connection at 300mbps just isn't there in my router.
That's probably the issue. A general purpose machine (with AES-NI), slap OpenBSD on it, disable DHCP server on your ISP router, let OpenBSD handle that... and done! (not for the faint of heart though)
You might even add a NIC to it, and act as another physical hop for firewalling, etc.
The problem here is not that the ISP can not be trusted, you should never trust them anyway. The problem is that the ISP is using their router to force their way into what is supposed to be the trusted part of your network, your LAN.
This is exactly why I don't use the ISP provided router, and every piece of equipment of theirs I have to use (mainly the IPTV box) is in a separate, untrusted, VLAN.
Also, I dont rely on just the one VPN service. I use nested chains of VPNs, and so distribute trust among multiple providers. Doing business from different jurisdictions. Just as Tor does with three-relay circuits. Sometimes I use private VPNs running on anonymously leased VPS.
Finally, each of my personas uses a different nested VPN chain, or Tor (Whonix) through other nested VPN chains. So linking my various personas would be nontrivial.
Fundamentally a VPN service allows you greater control over who you trust with your traffic. You always have to trust someone[1]. For example I trust F-Secure and the Finnish court system much more than I trust Virgin Media, GHCQ and the British court system which is why I run Freedome and route my traffic through Finland. As pointed out in another subthread here UK ISP are required to collect a bunch of data by the Snooper's Charter, the same is not true in Finland.
0: https://news.ycombinator.com/item?id=16371030
1: The default for many people is their local ISP which might or might not be a good entity to trust based on where you are. In many place you also have very few choice when it comes to your ISP.