6 ms·
Also to prevent traffic shaping: ISPs throttle traffic that contains netflix.com in the SNI. ESNI (encrypted SNI) comes with TLS 1.3.
by daurnimator 6y ago
Also to prevent traffic shaping: ISPs throttle traffic that contains netflix.com in the SNI. ESNI (encrypted SNI) comes with TLS 1.3.
- cheschire 6y agoAh, the good ol' radar detector reflector. There was a skit I saw a couple decades ago where a person was showing off his radar detector, then in order to combat that, the police had developed a radar detector reflector, so then he had made a radar detector reflector protector or something like that, then they made a protector detector, and so on. It was a couple minutes of explaining his best efforts to counter the police counters to his counters and on and on. But, you know, funny.
- tbrock 6y agoYou’re probably thinking of the movie “the big hit”. It’s trace busters: https://m.youtube.com/watch?v=Iw3G80bplTg https://m.youtube.com/watch?v=Iw3G80bplTg The trace busta busta busta.
- v7p1Qbt1im 6y agoNetworking noob here. Can‘t the ISP see Netflix‘s ASN/commonly used IP‘s and shape that way?
- gsnedders 6y agoYes. The case where it's much more useful is traffic going in/out of major CDNs to shared IP addresses. For Netflix or someone else running their own CDN the gains are much smaller.
- MaxBarraclough 6y agoSo ISPs could still impose traffic shaping on Netflix if they wanted to, I take it? I can't see how Netflix could prevent this. Ultimately, their servers ('OCAs') have easily detectable IP addresses, right?
- throwaway287391 6y agoFast.com probably helps quite a bit. If ISPs throttle Netflix' traffic their fast.com measurements will look bad and customers will complain/sue. (AFAIK there's no way to distinguish between fast.com tests and actual Netflix video consumption since the former's traffic patterns are identical(?) to a Netflix video streaming client's.) Creating fast.com always seemed like a pretty brilliant move by Netflix to me.
- MaxBarraclough 6y agoGood point. Smaller players can't make the same move though.
- Tijdreiziger 6y agoI think that was the whole point of fast.com, right? Speeds to known 'speedtest' servers were manipulated by ISPs, and this was bad for Netflix's business because customers would ostensibly have good speeds yet have slow Netflix, so fast.com was created as a way to measure the 'real' speed to Netflix's servers.
- throwaway287391 6y agoYeah, that's what I was saying (or at least trying to say).
- daurnimator 6y agoIIRC netflix mostly use AWS these days. So checking IPs will just check for anything AWS hosted.
- profmonocle 6y agoFor the web site and UI, yes. But the actual video traffic comes from a private CDN: https://openconnect.netflix.com https://openconnect.netflix.com
- lclarkmichalek 6y agoBoth the replies here miss the fact that the relationship between Netflix and ISPs is often pretty cooperative. Specifically, Netflix will provide ISPs with devices to do caching. The ISPs need to install and run these devices, configure the routes to send traffic to them, etc etc. Details: https://openconnect.netflix.com/en/ https://openconnect.netflix.com/en/. Because of that (and various other things), it's very easy for ISPs to attribute traffic to Netflix.
- georgyo 6y agoESNI was dropped from the TLS1.3 spec. It is currently a draft protocol. Almost nothing supports ESNI yet. Chrome does not have it yet. Firefox does but it very difficult to enable, there is a config flag but it does nothing on its own unless you also enable DNS over HTTP in Firefox. OpenSSL has no support for ESNI yet either. ESNI also never tells the user if it is working or not yet, making downgrades fairly easy. ESNI is a long way from being deployed, let alone useful.
- moduspol 6y agoThey're Netflix, though, so they've got a lot of use cases where they control both ends of the connection (e.g. they've got a native app for the end user). If it's important to them to have ESNI support, they presumably could do it for those use cases.
- middleclick 6y agoCloudFlare has ESNI enabled (and so do websites hosted by it, like medium.com) so it's not as if no one is doing it.
- georgyo 6y agoIf no clients support it, and you can't tell as a user if it is working, then effectively no one is using it.
- middleclick 6y agoFirefox supports it and Chrome has plans to support it in the future. I agree that it's not much right now but it's a start.
- shawnz 6y agoFirefox supports it, although currently only as a configurable. Users can test their ESNI support online here: https://www.cloudflare.com/ssl/encrypted-sni/ https://www.cloudflare.com/ssl/encrypted-sni/