I discovered caching CDNs were throttling my everyday browsing
blog.abctaylor.com
blog.abctaylor.com
They try to limit bandwidth to video sites, but since most video traffic is transferred by HTTPS these days they end up just making a massive list of IP's which look like they might be sending video data and dropping some percentage of traffic to those IP's. Most CDN's are probably on the list.
End result is most video sites drop back to SD rather than HD.
If you do a speedtest, it will come out as fast. If you VPN, that will also be fast.
The IP range has nothing todo with it - it is the route the packets traverse and what the packets look like when they pass the shaper device that matters.
You could theoretically find out which device on the path is doing the dropping by manipulating the TTL of packets in a live TCP session and seeing when you get back TTL exceeded messages.
*Technically some ISPs can (and probably do) look at the ServerNameIndication to determine hostname and therefore whether they’re video flows or not, but I’ve not heard any real world examples of this being done.
IIRC, it's now called ECH, because AFAIK the focus changed from "encrypt the SNI" to "encrypt the whole Client Hello".
By doing that, they can get a good estimate of your connections available bandwidth, which is needed for the decision whether to automatically switch to a higher/lower quality feed.
It also means they can use 'dumb' servers which don't do any application-specific logic for throttling.
(The issue is not the router, though - this doesn't happen on my laptop. I think my phone is just more aggressive in assuming the Wi-Fi is down and it's better to switch to cellular. But couple that with my phone's policy to use VPN on cellular, and the switch becomes much higher friction. I tried simply disabling cellular data, but then it's even worse because every time the phone disconnects from Wi-Fi it pops an alert telling me to enable cellular data.)
Snooping like this is EXACTLY why we still have unencrypted ServerNameIndication, even to this day in ECH (which still leaves the outer SNI in the clear).
You really don't when every modern browser sends SNI, which exposes the full domain name it's trying to connect to.
Many browsers these days support using DoH without changing any OS settings.
And ECH will still reveal the outer SNI, apparently.
This is a pretty standard feature of DOCSIS, I believe. It allows bursting above the provisioned connection speed for a few seconds when there's capacity on the shared network segment.
Anyway, annoying… at least http supports resuming, so it is possible to kill and restart manually, or use aria2c to circumvent it.
The trick is just to do your own rate limiting without burst at the right limit, that bypasses whatever shitty burst implementation your ISP modem has and weird shit won't happen anymore.
The burst mechanism of your provider possibly squeezes below your normal speed to compensate for the burst, but ends up confusing TCP flow.
Those burst and squeeze cycles can cause some undesirable bandwidth oscillations.
Say you're bursting 1gbps on a connection with 100ms latency. That connection squeezes to 20mbps suddenly. In the best case in those 100ms that the sender cannot even react to the change, we receive 10mbytes. Those 10mbytes that now have to be throttled away either get dropped or end up in a buffer. Now you either have a 5 second backlog latency or massive packet loss for 100ms while this resolves. And things overcompensate. And worst case, you end up in a oscillation pattern, the throttle goes off, and you burst again.
This happens and is measurable.
Most ISPs don't have one fat pipe to this magical "internet" place, they have multiple pipes going different places and not all of them are even listed in peeringdb, so their route to a particular CDN might be over private peering which is limited in size (e.g. 1-10Gb). Sure, then excess traffic might go over public peering but that might also then get saturated, or the ISP might force traffic over the private peering to keep the public peering clear for general traffic.
If you use a VPN then the traffic will come from a different route and different peering, thus be subject to the capacity of that route. What the OP probably wants is for Zen to have better peering with Akamai (they already have some announced routes).
Zen used to be decent, now pretty much only the only residential ISP left that offers quality support is AAISP. They also have all sorts of stats monitoring[2] on all customer lines by default, which they expose to customers on the portal.
AAISP will also, unlike many ISPs, not shy away from giving Openscreech a strong poke with a very sharp stick if the underlying issue with your line is due to Openreach. They know how to play the BT game.
No affiliation with AAISP other than knowing a number of their customers, not a customer myself due to completely unrelated reasons which are entirely beyond their control.
They are not the cheapest ISP in town, but it very much is a case of you get what you pay for.
[1]https://www.aa.net.uk/ [2]https://support.aa.net.uk/Category:Diagnostic_Tools
I figure the only way this is economic is because they have a technical customer base who phone support maybe twice a decade.
Years back I had a conversation with someone who had done a couple of ISP mergers, and his opinion was that techie-focused ISPs look fantastic on paper because their support costs are really low. Then someone buys them, tries to expand their userbase to "regular" people, and their support costs fall in line with the rest of the industry (eg Demon -> Thus -> Vodafone).
So far, A&A have avoided that fate.
Isn't a stable connection more important?
Oh, and on the subject of stability, they send me an SMS every time my line goes up/down. Even if it happens at 4AM. They don't have to, other ISPs hope you won't notice, it's just a nice feature.
Support is for the times where the connection isn't stable, and it appears AAISP handles these situations better.
Support is not important, until you need it.
There are alt-net providers out there (who shall remain nameless) whose engineers are trained to practically breathe down the necks of their customer just after installation in order to get them to post a 5-star review on Trustpilot. However the reality is when the customer has an issue down the line, they discover to their horror that the post-sales support is shit.
I don't think I've ever seen that before, they usually don't share their infrastructure like this.
I can't get Openreach-based FTTC ISPs though.
Sort of.
Certainly when it comes to home internet connections, there is a little bit of smoke and mirrors because BT have their horrid sticky fingers in many pies.
So the reality for many home internet connections in the UK its more a case of finding an ISP who's on your side and that is willing to pick a fight with BT when needed. This also remains the fact with the alt-net home fibre providers, because they will typically just aggregate your building onto a BT connection back to their PoP.
Well, that's slightly unfair, because ISPs clearly also vary on their own commercial decisions such as how "hot" they run their network, whether or not you can get static IPs and whether or not they run CGNAT. And there are some very noticeable quality differences on this level.
The absolute independent choice is only there for businesses in (some parts of) major cities where you have genuinely independent operators running their own fibre end-to-end, never touching the BT network.
Wavelength services are very different to a "network" though.
Having lived in ~5 apartments over the past ten years, I've only ever had a single broadband provider available as well.
Different providers cover different parts of the city, and even if you're lucky enough to be in a neighborhood that gets two, your landlord will only have wired the building for one of them.
Have also seen the openreach situation play out. I tried to get one of the other providers initially and they said that it would take almost a month for openreach to do the install. Contacted AA and they had it done in a couple of days. They actually show the logs of their comms with openreach in your online account so you can follow along.
Wow.
What's the point of having gigabit download speed if you have to constantly worry about using up your cap? And paying an extra £5 for every 250GB extra seems like some arbitrary punishment for power users.
They don't pay for infrastructure based on bytes transferred so why should I as a customer pay this random made up number?
> The second reason, which mainly makes sense with our terabyte services, is to have a high limit but one that deters the really heavy users, i.e. the people that literally use hundreds of times the typical usage. By excluding such customers from these services we can provide a faster and better services to our customers
What is ridiculous to me is that in 2023 we have someone on a techie forum who actually believes in the unlimited fairy.
Go read the small-print of your "unlimited" contract. Especially any sections entitled "acceptable use policy","fair use policy" or similar.
"unlimited" only means two things : traffic shaping and rate limiting.
I regularly use well over 10TB a month and have never had any issues from multiple ISPs. We have a regulation-enforced split between ISPs and the line owners, meaning anyone can set up an ISP for a relatively low capital cost by leasing access to the last mile fibre lines to customers. As such, there are plenty of nation-wide ISPs here.
I'm quite fond of NZ and I've heard good things about the quality of your telecoms regulation, but ....
We manage traffic which may influence your broadband performance. This means we might have to pause, restrict, end or slow the performance of your service if it’s necessary for us to protect our networks or manage traffic over our networks. See clause 6.6 of our General Terms for more details.
and You need to use our services fairly – we’ve set out our rules on this at clause 2.6 of our General Terms.
and Fair use by you: You must use our services fairly. This means you agree to use them in a way that’s not overly excessive or unreasonable. This policy is based on how most people use the service and helps us make sure everyone using it gets to enjoy it. If we, acting reasonably and in good faith, believe your use is excessive and unreasonable, we might need to restrict the service or stop providing it to you.
All from Spark NZ's conditions[1][2] for their "unlimited data" fibre product[3].[1]https://www.spark.co.nz/help/other/terms/personal-terms/esse... [2]https://www.spark.co.nz/help/other/terms/personal-terms/gene... [3]https://www.spark.co.nz/online/broadband/buy-plan?category=f...
There's rarely any benefit to using them compared to the competition - they are more expensive and refuse to join free internet exchanges, so Spark users frequently experience bad routing to services which refuse to pay money to Spark to peer.
What I can tell you, though, is that I have never once heard of Spark warning/booting a user for excessive usage, and I have my ears to the ground at various NZ tech forums.
Other ISPs, however:
https://www.orcon.net.nz/terms/broadband
If you are on an Uncapped or Unlimited Plan, the total amount of data you can upload or download is unlimited. We may use traffic prioritisation policies for these Plans to protect our Network and improve the overall performance amongst our customers.
(This is the Vocus group, including 2degrees, Slingshot, Flip, 2talk and Stuff brands)https://main.prod.vodafonenz.psdops.com/_document?id=0000018...
Our policy is to provide you with the best broadband experience possible, so we won’t slow down or throttle your connection.
One New Zealand does not have a fair use policy for One New Zealand Fibre, HFC, VDSL or ADSL broadband
(One NZ, old Vodafone)https://care.zeronet.co.nz/hc/en-us/articles/7436185566863-N...
Zeronet does not enforce a fair use policy when your connection is used for standard home use.Once a few ISPs started offering "truly unlimited broadband" where they couldn't hide anything, (the big) ISPs that did shape traffic speed limit where now fighting on their back foot, so most of them stepped up and started offering "truly unlimited broadband" too.
Some networks/ISPs may lower speeds in an area due to capacity on a backhaul, but if your speed drops below the minimum outlined at the beginning of your contract for longer than 30 days you can exit your contract early.
So most of the ISPs (in the UK) who offer unlimited contracts these days will have a FUP but they mainly focus on a) no reselling their services b) not running open proxies c) not sending solicited bulk emails, spam emails, calls, sms, etc (because the FUP also covers the landline bundled in with the internet connection it covers things like 118,0871/2/3 service limits and mass calling). They tend not to fret about download caps in their FUPs. Heck I was on a unlimited 4G connection for a while and easily used over 1TB per month and didn't even get a text message asking me to "tone it down".
EDIT: Just checked and my providers FUP is 3 (well 2 and a third) pages long, written in easy to understand language (no legalese), and hasn't even been updated in the past 5 years.
Like I can't understand why so many people get butthurt about the word unlimited when I can play hours and hours of video games, have multiple 4k streams constantly going, casual piracy and two adult fully remote workers in video calls all day for like $80/mo and not a penny more.
Compared to some residential ISPs where I've seen caps as low as 15GB/month..
How much does it cost to upgrade from 1TB to 10TB?
I don't care how common a cap like that is, or what abominable caps some other service might have. 1TB for a whole month is only 3 megabits per second average, and that is not a good amount. And it should definitely be possible to buy more than 30 megabits per second average for a residence. For a business, 20TB in a month is good for a few employees but breaks down very fast if they start working remotely.
£10/month
Ever since the introduction of the "Automatic Compensation Scheme" the larger ISPs (zen being one of them, the scheme covers about 80% of UK customers) have had a bigger stick to whack Openreach with as Openreach have to contribute to the payments to end customers. (Some altnets such as CityFibre have also started signing up to the scheme, but iirc CityFibre don't pay per day for faults, only missed appointments and delays to connecting a new line)
One thing ISPs can do (but increases their costs) is increase the service level on your line, standard service is iirc end of 2 full business days, which most residential lines are on. Next level is end of the next working day, next level is end of same day (if reported before 1PM and next day if not) including Sundays/Bank holidays. And the next is 6Hr fix around the clock. But the higher the service level the more the ISP has to pay OR for the line. I can see "more specialised" ISPs such as A&A increasing the service level of the lines but passing that cost on the customer (one of the reasons of their increased cost, but as you said you get what you pay for, though this is just speculation as I have no idea if they actually do, just seems like something they would do - A&A are known not to be fobbed off by Openreach).
However the "Automatic Compensation Scheme" and increased service levels still doesn't stop Openreach taking their time. Recently had an FTTP outage which took a week to clear, Blinking PON, first tech who turned up determined there wasn't an issue between the pole and the premises but as he was "first level support tech" there wasn't much else he could do, he did however call someone at the exchange to poke around which a few things (which he told me was "above that persons pay-grade", so he shouldn't really be doing it but it was worth a shot as its fixed issues in the past) but no dice and the call would have to be escalated (They said it was a one-way light issue).
Next call was a missed appointment, Booked the callout, waited in until an hour after the time, called the number I got on the text and it was the same person as the callout before, OR had screwed up and put it back on his job list instead of escalating it, not the end of the world, just wish they had told me so I didn't waste most of the day waiting for someone who wasn't going to turn up.
3rd call out and this tech re-splices every splice between my house and the exchange, tech told me it was four splices (not including the splice in the "customer service point"). Still no dice. At which point they believe its a problem with a fibre card in the exchange, it will need resetting which they don't want to do in the middle of the day because it will knock everyone connected to it offline while it resets. Fair enough, he tells me they will get it done overnight, next morning still flashing PON, call the number for the 3rd tech and they confirm that the card wasn't reset and they will get it done that night.
Next day, Still Blinking PON, I'm just about to call the tech again (this is about 8am) but as I'm pulling out my phone PON goes static green, I start rebooting and reconfiguring kit (I was using my own 4G back up, I hadn't config'ed auto failback, so was killing one connection and restarting the other) when my phone rings, its the 3rd tech to tell me that they hadn't reset the card overnight again so he did it himself, something he wasn't supposed to do but heck it was getting silly at this point as it had been a week and from his end it was looking like my ONT had connected and was calling to make sure I was connected (which I was).
So even Openreach have to take the advice of the The IT Crowd every once and a while, because it turns out my week long outage was cleared by turning it off and on again.
I remember they were often referred as one of the best on ADSLguide.uk. At least in the late or early 00s.
It is sad to see the state of UK ISP not improved much after 20 years.
Internet connectivity is not transitive, throwing a VPN into the mix changes the A <-> B scenario to A <-> C <-> B, which can have very different properties, since the paths may have very little in common. For multihomed A and B, the paths may in fact have nothing in common at all.
Same applies to IPv4 vs. IPv6, the routing may be entirely different, especially with a CDN you might even straight up get a different CDN instance.
But a link between an ISP and a CDP provider being overloaded is quite common. The ISP is trying to get away with the minimal infrastructure investments possible, and good interconnect is expensive.
The EU has a consultation on it, although I think it'll fail to get traction.
Thank god it'll fail to get traction.
Many ISPs have been receiving boatloads of government subsidies to build out infrastructure, and they have very little to show for it. There is no reason to believe this would be any different.
My ISP has a strong presence on a local forum where I posted my issue.
Long story short, despite my ISP actually having an Akamai cluster on their own network, Akamai’s DNS was resolving my ISP’s customers to a cluster on a different ISP’s network.
That different ISP either had terrible peering, or the theory is they were throttling their Akamai cluster’s IPs to other ISPs.
Fortunately my ISP managed to convince Akamai to fix the DNS resolution.
Needless to say, I’m super impressed I can actually get the attention of the right people at my ISP to resolve this kind of issue.
In the 2 different Wireshark dumps, a relevant difference is MSS=1460 and MSS=1380 in the second one.
I'd recommend setting the local NIC MTU to a low value just to see if it has an impact. However, the Wireshark dump doesn't show packet fragmentation, so perhaps this isn't a problem at all?
A better idea would be to reduce the MSS inside the tunnel.
I have a browser based mtu test http://pmtud.enslaves.us/
Currently IPv4 only, requires a somewhat recent browser, and client to server testing is iffy, but if you start the test and get OK in the notes field for both directions, your MTU settings are probably fine (or something is doing proper mss clamping between your client and my server, my server is limited to 1500 MTU so problems with jumbograms can't be detected)
Set MTU on affected systems to 1400 or implement MSS clamping via firewall, etc.
Strategy might be different for a free-tier/cheap CDN.
The idea of paying for premium access and it negatively affecting the competition is looking at the challenge wrong. It also presumes that ISPs have one fat pipe that gets divided up, which is not usually the case unless you're a tiny ISP.
What actually affects performance and is probably the case with this user is that ISPs and CDNs need to come to an agreement over what connectivity they peer with. At scale they don't do that over public peering, it's private peering either through a third party (like Equinix or Digital Realty) or directly patching fibres within the major data centres and linking their networks together. New and unusual services will likely use public peering instead of private peering, or they won't use an tier 1 CDN like Akamai who an ISP would peer with, instead using someone like Bunny CDN, a fine CDN but not peering on the same scale.
The fairness risk comes not from the CDN or content provider 'paying' for priority, but comes from the ISP not investing in public peering. That's not the content providers fault, it's just bad operational practice. You could say it's the content providers fault for subsidising the route that gets their traffic through, but its really the ISPs poor infrastructure investments playing out. There's a small risk from content providers doing deals with ISPs to "zero rate" traffic where that ISP (or more usually cellular provider) charges users for bandwidth (or caps it), where the big content provider can use their leverage to make their service cheaper to the consumer. But the reality is that zero rating isn't particularly commercially popular, I've seen it once or twice in my career.
https://web.archive.org/web/20231123142332/https://blog.abct...
Funny thing is the author apparently doesn't use the caching CDN, thus users are not getting throttled but having 503...
In case anyone else wants to read it while it's hugged to death.
Except farnell.com which is shit everywhere because their entire platform is a turd.
They are. The name only comes up here because the blog post used their website as a test target.
Farnell the company is also a turd, another example of a once great company that has gone to the dogs.
You can't even trust the stock numbers on the Farnell wesbite anymore.
At least it's not CPC. They sent me an empty box once.
Hopped on IRC and nobody was talking slowness, so I was assuming it was my end still, but then somebody mentioned sluggishness, so I spoke up.
Quick traceroute later and within 5 minutes I had a new pppoe user to try, which moved my routing to a different router in docklands, and all was good. 10 minutes later they've shifted everyone to that and taken the router out for investigation.
I wouldn't be surprised if this is related to that someway!
I had symmetrical 1gbps up and down. When wired, I could get nearly the full amount on the WAN. When wireless, I could only get 300mbps to the WAN.
However, when wireless, I could get ~800mbps to another device on the LAN. I could also get 800mbps to the internet if I proxied from my wireless devices to my wired device before going to the WAN.
My router company sent me two additional routers, one with a similar chipset and one with a chipset from a different vendor and this persisted. I checked it with a competing router and it persisted.
It did not matter what the wireless device was, Mac, windows, phones, or tablets, and it persisted.
Moved somewhere else with a different ISP and it immediately stopped. I still don’t know how an ISP would identify and throttle a wireless device, but that was pretty much the only explanation I could come up with.
No modem within 15 floors.
Interesting guess though, wouldn’t have thought of that.
- Did you make sure to compare results for non-concurrent speedtest? Ie maybe those ~800 were actually 4x~200 - many speedtests open parallel connections by default.
- The speed test difference was consistent no matter the measurement tool - speedtest.net, fast, actual file transfers, etc.
We got pretty far down the rabbit hole with diagnostics. TP-Link actually spent a significant amount of effort supporting me - had a debug firmware doing packet captures, testing different hardware acceleration settings, sent me multiple routers with different chipsets, etc.
I brought the hardware with me when I moved and I do not have the issue.
Pinging abctaylor.com [82.71.78.1] with 32 bytes of data:
Request timed out.
Reply from 82.71.78.1: bytes=32 time=186ms TTL=55
Reply from 82.71.78.1: bytes=32 time=208ms TTL=55
Request timed out.
Reply from 82.71.78.1: bytes=32 time=200ms TTL=55
The ironic thing was I was blacklisted from loading Akamai's help pages about what to do if you are blacklisted. I never did find their tool, I wonder if it would have been blocked too. https://www.akamai.com/us/en/clientrep-lookup/
The ban expired after about 3 days.
On the other hand, I think any ISP at the mercy of openreach is doomed to have limited support.
I have fibre to the property, and was having periods of 1hr-2hr day of my gigabit speeds dropping to 4-5MB. openreach themselves were blindly sending engineers to look for an issue that couldn’t physically be at my house.
Not much you can do there either as an ISP or as a customer besides wait for openreach to figure out they’re wasting their own time
BBC, Farnell, everything else - just works, and works fast.
Please note, pinging public DNS servers is a useless metric, because you would never know if your provider hijacks your DNS packets or even all traffic to those public servers.
Yes.
> what's the alternative
a) some ISP targets, eg mailcluster.zen.co.uk
b) lg.he.net and bgp.he.net
You also seem to know your way around networking as well, genuinely curious.
Judging by https://unixism.net/2020/05/what-kind-of-traffic-does-hacker... and https://news.ycombinator.com/item?id=30481230, surviving a couple loads per second up to 25 will get you through many slashdottings, and with a solid symmetrical home connection you have a very good chance.
If you have video, you're not going to survive a slashdotting, but 5Mbps will let you have about one viewer with a smooth experience, while 20-30 viewers could watch the same content on 100Mbps. Or maybe you want to deliver 4k and it's zero versus several peak viewers.
This isn't about getting tons of nines of uptime, this is about people enjoying the page a strong majority of the time they're visiting. That needs a certain amount of speed unless it's a super lightweight page.
Oh the irony