5 ms·
Seems like few people really read the stuff. One sentence made me choke : > "The network needs to provide specific QoS and security policies based on user ide
by jojo2000 7y ago
Seems like few people really read the stuff.
One sentence made me choke :
> "The network needs to provide specific QoS and security policies based on user identity, rather than mapping to something instead"
Well, no, sorry. It's an orwellian design proposal.
- jusssi 7y agoStill it might be an improvement over "whoever yells the loudest", which is the current situation. And even though it has multiple interpretations, I only mean that at the technical implementation level. Edit: downvotes because you hate QoS? Edit2: Yes, I get the irony.
- temac 7y agoIt depends, but I agree that this is a crazy hard problem to address correctly and not create dystopian side effects or even just risk that. Imagine you need some QoS on a few streams for serious and useful purposes (telesurgery comes to mind). Core networks are able to provide that, but this is not usually mapped to user extensible protocols on general purpose/public access points. Now there are indirect advantages in just not providing those, because: - you also reduce the risk of dystopian usage / restriction of usage / etc. - in some cases, you make mass-applications being developed for non-QoS networks instead, so you eventually end-up (maybe a few years behind, but this is a cost I'm willing to pay) with basically the same service on a simpler and less dependent to political context tech. But: - in the context of a benevolent legislation, this could be actually more useful and fair than the current situation, where network neutrality has became half a myth both in theory and in practice (there is no practical neutrality anymore when you can just put your own private datacenters all over the world plus high bandwidth links to supposed neutral providers, then use that to push your proprietary services/applications without emerging/low capital competition able to do the same) - so you actually depend on private parties to be benevolent with the supposedly "best effort" but actually not anymore approach - and then it is a matter of taste, but in some part of the world I'm more inclined to trust elected politics (even if they sometimes do some bullshit) defining regulation than private soulless multinationals with the often stated theory that they must optimize shareholder outcome and nothing else. That being said, given both the current state of the world (and even if it was better, the always persistant risk of it degrading) and the practical difficulty to cleverly and benevolently regulate fast moving technical fields, I'm willing to stick to basically the current situation, which seems less prone to extreme situation. But it would be a mistake to view authenticated QoS as inevitably and purely evil.
- salawat 7y agoI beg to differ. It's the authenticated part that's the problem. That assumes you're tracking every connection to perfect granularity. Are you going to change the QoS for each host? Are you going to enforce every host to authenticate to determine which tier of service they are provided? You want QoS? Fine. Provision your network for it, let everyone enjoy it. As soon as you start putting levers in place to pick who gets the better service tier, you get crap like Verizon throttling essential services right when they're needed the most because someone decided that their bloody contract wasn't looking like they were getting fleeced enough while said service is trying to ensure the damn countryside isn't completely burnt down. Once the mechanism is in place it'll get abused, because their is always a buck to be made by doing so, or an ideological ambition to be realized. Sometimes it's just better not to even open that damn door. DPI and traffic shaping be damned.
- betterunix2 7y agoPerhaps so, but there is plenty of precedent and quite a few networks operate in this manner (or something close to it). The real problem from an engineering perspective is that doing such a thing makes it much harder to deploy new devices and applications, since identities must be managed by some authority. Sometimes that is what you want (think of a corporate network where access is limited to provisioned devices) but it is not what we want for the public Internet (which is meant to be as general purpose and open-ended as possible).