9 ms·
> We found that HTTPS improved quality of experience on most clients: by ensuring content integrity, we virtually eliminated many types of streaming errors Wow
by coob 10y ago
> We found that HTTPS improved quality of experience on most clients: by ensuring content integrity, we virtually eliminated many types of streaming errors
Wow, what were carriers doing to the streams?!
- JBiserkov 10y agoAttempting to inject adds? Reduce the size by applying JPEG compression? :)
- TD-Linux 10y agoWhen I had Sprint, they did in fact scale down and recompress all images in lower quality JPEG. Some carriers even attempt to realtime transcode video into a lower bitrate. The implementations of this are universally poor and produce rather broken files.
- dublinben 10y agoThe more modern implementation of this (I'm looking at you, T-Mobile) is just to throttle all connections to content providers. They rely on the content providers' own adaptive streaming technology to deliver the appropriate 480p video when presented with a constrained connection.
- ianlevesque 10y agoNot ideal but that's a lot less intrusive.
- mhurron 10y ago> The more modern implementation of this (I'm looking at you, T-Mobile) is just to throttle all connections to content providers. If YouTube can't handle traffic shaping, Youtube is broken.
- dublinben 10y agoIf your ISP applies artificial traffic shaping, your ISP is broken.
- rhino369 10y agoI should be able to turn it off, but I like that tmo throttles my video. I only get 2.5 gb, I don't need 1080p.
- amscanne 10y agoWhat's "artificial" shaping? The average consumer ISP has an over subscription ratio of 70-to-1. Unless you want to pay 70x as much for your "100mbit" connection, there are going to be times when packets get dropped. Isn't it better to drop packets fairly among subscribers? No shaping would result in whoever is using the most dominating everyone else. This basic principle is still neutral; you don't have to shape based on destination / content provider.
- mhurron 10y agoWhat the ISP is doing isn't any different than what any private network could do. If YouTube can not handle that, Youtube is not playing well with standard network practices and is broken at a technical level. Your ISP doing traffic shaping is a question of if they should, not a technical question.
- bisby 10y ago
- chakalakasp 10y agoI used to think it was silly to use a VPN on a cellphone not on WiFi. Not these days, not so much.
- acdha 10y agoThe most common implementation of this appears to be from a company called Bytemobile which also injects some pretty buggy JavaScript into HTML content. The good news is that you can disable all of their degradation by adding "no-transform" to your Cache-Control headers: https://kornel.ski/en/proxies https://kornel.ski/en/proxies “The standard HTTP header Cache-Control: no-transform which tells proxies not to modify responses was respected by all proxies I've encountered. This is amazing! It wins an award in the "Best Supported Obscure Header" category.”
- kbenson 10y agoIt's long been known that some carriers purposefully degraded quality of youtube to keep from saturating their interconnections. That's the reason[1] behind the Google Video Quality Report[2]. Youtube does (did?) redirect you to a comparison of how well your ISP streamed content compared to others when there were streaming problems in some cases to combat this. 1: Well, I'm assuming, but it seems likely this was the main reason. 2: https://www.google.com/get/videoqualityreport/ https://www.google.com/get/videoqualityreport/
- lqdc13 10y agoDegrading video quality is not a bad idea if you have limited bandwidth. This would help in cases such as airplane flights. One person watching HD cat videos is going to consume more bandwidth than 20 people doing work. Now, assuming bandwidth increase is difficult to achieve, they would be forced to keep increasing the price instead. Prioritizing non-video content is challenging if all content is encrypted.
- icebraining 10y agoWhy not limit the bandwidth per user instead? Youtube itself will auto-adjust quality based on connection speed.
- dyladan 10y agoNot sure about other services but at least GoGo was limited to about 500kbps per user last I heard.
- acdha 10y agoExactly – this is both easier to implement and has the advantage of not incentivizing people to use something like a VPN to get more bandwidth at the expense of everyone else.
- mdani 10y agoPer user limits are not easy to implement, maybe easier to visualize - consider that there are a bunch of packet gateways sitting behind a load balancer and each HTTP session may end up on a different server. There is no entity that counts the live bandwidth usage on a per user basis, let alone control it. Billing and metering is done on a session basis through logs. So from T-Mo's point of view it is much easier to detect a HTTP session as video and just throttle that session.
- mholt 10y agoI grew up in rural Iowa with a poor Internet connection (satellite) that dropped packets if there were thick clouds, any snow or rain, even wind sometimes. Integrity checks would have helped a lot.
- mikeash 10y agoTCP already covers that sort of thing. What HTTPS adds is integrity checks against an intelligent attacker, not just random natural interference.
- jasonuhl 10y agoTCP only gives you 16 bits of checksum, which is really not enough. I used to work for a CDN which served downloads over HTTP, and when the object size grew to a few gigabytes a non-negligible percentage of users ended up with corruption. The SSL MAC is valuable even in the absence of enemy action.
- mikeash 10y agoMakes sense. Thanks for the informed correction.
- DanielDent 10y agoThis is a really interesting 'real world' anecdote. Do you know of any related data available publicly? i.e. "on our network, X bits in Y terabytes end up with undetected corruption, meaning that approximately Z% of downloads of a 2GB file will have at least one bit error".
- Dolores12 10y agoFrom http://noahdavids.org/self_published/CRC_and_checksum.html http://noahdavids.org/self_published/CRC_and_checksum.html In "Performance of Checksums and CRCs over Real Data" Stone and Partridge estimated that between 1 in 16 million and 1 in 10 billion TCP segments will have corrupt data and a correct TCP checksum. This estimate is based on their analysis of TCP segments with invalid checksums taken from several very different types of networks. The wide range of the estimate reflects the wide range of traffic patterns and hardware in those networks. One in 10 billion sounds like a lot until you realize that 10 billion maximum length Ethernet frames (1526 bytes including Ethernet Preamble) can be sent in a little over 33.91 hours on a gigabit network (10 * 10^9 * 1526 * 8 / 10^9 / 60 / 60 = 33.91 hours), or about 26 days over a T3.
- drzaiusapelord 10y agoI imagine this was a snarky comment about services like T-mobile's binge. They limit video 720p or 480i at a moderate bitrate for mobile. Its supposed to be opt-in but I wouldn't be surprised if many mobile providers peppered the video stream with errors to knock down costly high-bitrate 1080p streams.
- dawnerd 10y agoOpt in? It was opt out unless it changed very recently. I had a call with their corp office to plea why my plex server should also qualify but they said it wouldn't.
- Thaxll 10y agoRemind me the madness that mobile carrier are doing to the TCP stack.
- mh- 10y agoany links with technical details about this?
- Animats 10y agoIt's turning out that HTTPS is more important for content integrity than for security. It's not surveillance that's the big problem for static content. It's middle boxes designed with the delusion they're entitled to mess with the content.
- abalone 10y ago> It's not surveillance that's the big problem for static content. Why would you say this? Surveilling what URLs someone is accessing / content they are watching / books they're checking out of the library has been a major security issue, historically.
- Animats 10y agoHTTPS doesn't conceal the domain, or the length, or the order of requests. It's less of an issue for Google, because so much stuff comes from one domain. For small sites, figuring out who read what isn't a hard problem. In practice, you can probably buy that info from an ad tracking service.
- abalone 10y agoYou didn't qualify your claim as only pertaining to small sites. You simply said surveillance is not the big problem for static content. Given that most static content is served by large sites and the article is about Youtube, you haven't really supported that claim.
- dredmorbius 10y agoI'd temper that statement significantly. Content integrity is the visible consequence of improved HTTPS compliance and use. The biggest factor about surveillance is that you are rarely aware you're being surveilled. Direct evidence is rarely present. Case in point, Michael Lewis's Flyboys. HFT trades intercepts weren't being overtly signalled, but were only evident when trades were structured such that they bypassed the opportunity to intercept intentions at the first market.