i think the first step to start a revolution against these cronies is to talk about net neutrality in your hoa if you are part of one and find ways to ensure comcast does not have a monopoly.
If we're going back to the past, let's go back to the 1996 Telecom act, and get unbundled last mile; but apply it to all mediums this time, instead of only telephone.
I don't care if Comcast blocks BitTorrent for its direct customers, as long as it doesn't touch it for wholesale customers, and as long as wholesale prices are lower than retail prices (learning from Telco dsl pricing shenanigans)
Oh boy, all the market forces are lined up against the consumers on this one. BT implies content holders have a teensy bit of interest: around $2 trillion annually[1]. That dwarfs by 20x the $1B cable industry[2]. Maybe we've been looking for for Ajit's daddy in the wrong place.
It's hard but possible. China manages to detect VPN's with their great firewall and cut a VPN connection to outside countries fairly fast.
You basically need to look at traffic patterns. A TLS handshake (HTTPS) is very distinct from a typical VPN handshake (except maybe OpenVPN since it uses TLS)
Or they can just block/throttle IP's of VPN providers. Not a lot of people can set up their own VPN server.
Ports are not enough, they can inspect packets. I believe most VPN protocols can be detected, although you could probably adapt one (possibly OpenVPN, which can already use TLS) to look like a regular HTTPS or IMAPS connection (assuming they don't analyze the patterns of traffic).
There's still the possibility of blocking commercial VPN services by their IP addresses, making it harder for anyone who can't host one themselves on a VPS or something.
VPNs can and will adapt, they're only detectable if they behave a certain way, last article i read a while ago openvpn was generally being detected by the way it did the handshake.
but yeah, the only permanent way to block VPNs is to get rid of encrypted traffic, otherwise they're going to be in a running battle of updating their detection methods and vpn providers obfuscating their protocol
Yeah, I wasn't clear. I meant running the VPN on a TLS connection to those ports, so that it looks like an HTTPS or IMAPS or whatever connection.
I suspect that the direction the web has been moving for the last few years is making traffic analysis harder. More and more things that used to only done locally with desktop applications are now also being done over the web, and so we now have many more traffic patterns that are not unusual for an HTTPS connection. That means more and more chance that some non-web traffic pattern will be similar to a web traffic pattern.
The problem ISPs face if they try to block things is that what they want to block will be specific sites, not specific protocols or specific types of use. For example, an ISP might want to block or slow subscription video streaming services other than one that it owns, but it probably does not want to block video from news sites, sports sites, company tech support sites, and many others.
If they just go by detecting that a site has video, perhaps by traffic analysis, they won't be able to tell which are the ones they want to block and which they don't.
As far as IP addresses go, perhaps IPv6 could help. Most of the major sites that support net neutrality have way more IPv6 addresses than they will ever use. Perhaps some of them could get together and offer a service where they run a VPN forwarding service on some of those IP addresses. So when Alice signs up for VPN service from Bob's Budget VPNs, she also goes to her Google account configuration, and enables Google's VPN forwarder and points it to Bob's Budget VPNs. Google dedicates an IPv6 address to this and tells it to Alice.
Actually, if major sites like Google wanted to provide a VPN forwarding service, they could just run it on the same addresses as their other services and provide a way for clients to signal they want to use the connection for VPN forwarding instead of whatever it is normally used for. For example, make it so you can start the VPN forwarder via HTTPS by having their HTTP server recognize "GET /vpn_forward HTTP/1.0" as meaning the client wants to use the VPN forwarding service, not the web service.
China could get away with blocking all of Google (and any other major site that might also do this) because China is an authoritarian government that takes a hands on approach to censoring and restricting what people there can see, and can bring its major propaganda machine to bear to trying to convince people that its approved alternatives are better.
I don't think that would work for private ISPs in the US.
I mean if legally they can block bittorrent or other protocols, does it mean that one could create a new protocol each time it's legal to block it, rince and repeat, and force the legislator to create a new law forbidding each nez appearing protocol?
Also one might implement ways to prevent protocol detection into a BEP, but if comcast ends up shutting down any traffic that is peer to peer... I wonder if legally they could forbid any traffic that is "too much peer to peer" and argue that it's illegal downloading. Hard to say if comcast could win in court, because if you do the stats, most of peer to peer traffic is indeed illegal.
The internet could end up without any peer to peer traffic, and only works with servers, most users would not really complain, things would still work like they already are. It would really create pressure from users to change ISP.
Some ISPs might not block peer to peer, and I wonder if subscribers would end up moving out of neighborhoods where comcast has a monopoly.
AFAICT it's not about making bittorrent illegal, but to make it legal for ISPs to block any specific protocol.
I'm assuming you're thinking in terms of designer drug legislation? Comcast in this case would simply need to match the new protocols to block, no new legislation needed.
Obvious first-line defense is to make the peer-to-peer traffic indistinguishable from use of important services: eg, Google App Engine for peer discovery, and VoIP for data transmission.
I have a choice between Time warner (now spectrum) or ATT. I have zero confidence in either and my choices are slim. I'd rather have net neutrality enforced so I'm not left having to choose which of those two I'd rather use.
Sounds like you are a prime customer for a 3rd option. Market forces are real. BTW, since you have 2, competition is still there. Zero confidence or not, one will take advantage of the other's mistake. Do you also have telco DSL avail?
i guess you could quantify that as the real problem if you like, it's a much harder problem however.
the incumbents are currently successfully shutting out big competition from putting in their own infrastructure (google has been successfully blocked from areas by lawsuits, along with municipal ISPs).
edit: and even if competition was unfettered, it would still take many years and a lot of investment to provide real alternatives
giving a shit about what the "right" way to deal with these assholes is probably not that productive.
Na. Giving a shit is the only thing that actually changes stuff.
And it's not harder since NN is dead. It's gone and by 2020 people will understand the opposition to axing it's short existence was pointless. We should focus on what you appear to agree matters more; more competition.
ultimately the issue is laws in favor of the incumbents, while more competition would absolutely be a better solution long term if laws aren't being made to ensure net neutrality laws are definitely not going to be made to allow more competition.
Three years + voting + a number of more years for execution is a long time to wait to possibly get back to an open internet (with real competition for web services as you seem to like).
Open? Like the ~25 years before 'NN'? I was there. Competition works. NN is just a typical BS branding for "More Rules". It's step 0 in the standard manual on mission creep.
Well I'm arguing against it so of course I have no idea. Please elaborate. Maybe also expand on the difference between oldschool "utility" dialup and pre-NN broadband (as if the upstream ISP couldn't legally traffic shape "utility" dialup).
I'm all ears on how mission creep with regards to regulation is not a "conspiracy". Maybe you understand that power expansion is a law of nature and hence does not require overt "evil" conspiracy, if so, we agree.
What people like you[1] are missing is that Internet providers all benefit massively from regulation that PREVENTS competitors from threatening them. NN rules are just a counterweight to all that mess.
There is no way in hell that we are going to see real competition between ISPs in Amarica this year, next year, or five years from now.
We all want it, but it’s not going to happen (obvious, even to a casual observer).
So tell you what: let’s get competition first, and then talk about eliminating net neutrality rules. Because doing the latter certainly won’t accomplish the former.
Your argument is exactly like “We don’t need laws regulating guns, we just need people to stop shooting people with them.” True and helpful, as long as we live in a fantasy world instead of this actual one.
[1] That is, people who keep trotting out this “competition is better than regulation” trope, in the context of net neutrality, where it has relevance only in fantasy scenarios (e.g. a superhero named MarketMan appears to blast everybody with his Competition Ray, and somehow open up an industry that is more protected from competition by regulation than almost any other that exists).
CORRECT. Ditto for cars. Lock me out of the HSCAN bus and I guarantee I wont buy it. So far, I can hack my way in, and similarly I can disable ME, but yes, I will _happily_ pay extra to wadge the war for general purpose computing.
Where I used to live, in a major American city, my choice was Comcast for broadband. Or dialup at 56k. Or DSL at maybe less than 1mbit/sec. a lot of Americans don’t have any true choice of ISP. This is why we want regulation. The free market idea didn’t provide the choice that a free market needs in order to be fair.
Stop the panic, the internet existed for years without those regulations that he wants to cancel which were applied only in 2015. I prefer the government will not touch it, it will just ruin everything, if you are worried about US becoming China you have to remember that it is government regulation in China which cause the problems, not the ISPs.
ISP is a pretty competitive landscape and I am sure if one of them block something there will be other ones which will be happy to offer unlimited services, the way it was until 2015 without those regulations. If something really bad actually happen I will want to see the government interfere but to call the government to interfere with no reason and no real problem is just going to do more harm than good.
The problem is you can't tell bittorrent or any other protocol from SSL if its encrypted. The only way to stop it is slow all random ip to random ip connections, basically if one of the endpoints isn't a major, known company its in the slow lane. Count on AWS creating a few Canadian regions.
The government does not understand that, the more they restrict, people will find alternatives. Privacy of movies/songs is still on in-spite of all laws
50 comments
[ 6.1 ms ] story [ 127 ms ] threadI don't care if Comcast blocks BitTorrent for its direct customers, as long as it doesn't touch it for wholesale customers, and as long as wholesale prices are lower than retail prices (learning from Telco dsl pricing shenanigans)
1. https://www.billboard.com/biz/articles/news/global/1565728/s...
2. https://www.ibisworld.com/industry-trends/market-research-re...
This is a great way for ISPs to milk legitimate VPN traffic _and_ tax downloaders.
You basically need to look at traffic patterns. A TLS handshake (HTTPS) is very distinct from a typical VPN handshake (except maybe OpenVPN since it uses TLS)
Or they can just block/throttle IP's of VPN providers. Not a lot of people can set up their own VPN server.
[1] https://airvpn.org/ssl/
There's still the possibility of blocking commercial VPN services by their IP addresses, making it harder for anyone who can't host one themselves on a VPS or something.
but yeah, the only permanent way to block VPNs is to get rid of encrypted traffic, otherwise they're going to be in a running battle of updating their detection methods and vpn providers obfuscating their protocol
I suspect that the direction the web has been moving for the last few years is making traffic analysis harder. More and more things that used to only done locally with desktop applications are now also being done over the web, and so we now have many more traffic patterns that are not unusual for an HTTPS connection. That means more and more chance that some non-web traffic pattern will be similar to a web traffic pattern.
The problem ISPs face if they try to block things is that what they want to block will be specific sites, not specific protocols or specific types of use. For example, an ISP might want to block or slow subscription video streaming services other than one that it owns, but it probably does not want to block video from news sites, sports sites, company tech support sites, and many others.
If they just go by detecting that a site has video, perhaps by traffic analysis, they won't be able to tell which are the ones they want to block and which they don't.
As far as IP addresses go, perhaps IPv6 could help. Most of the major sites that support net neutrality have way more IPv6 addresses than they will ever use. Perhaps some of them could get together and offer a service where they run a VPN forwarding service on some of those IP addresses. So when Alice signs up for VPN service from Bob's Budget VPNs, she also goes to her Google account configuration, and enables Google's VPN forwarder and points it to Bob's Budget VPNs. Google dedicates an IPv6 address to this and tells it to Alice.
Actually, if major sites like Google wanted to provide a VPN forwarding service, they could just run it on the same addresses as their other services and provide a way for clients to signal they want to use the connection for VPN forwarding instead of whatever it is normally used for. For example, make it so you can start the VPN forwarder via HTTPS by having their HTTP server recognize "GET /vpn_forward HTTP/1.0" as meaning the client wants to use the VPN forwarding service, not the web service.
China could get away with blocking all of Google (and any other major site that might also do this) because China is an authoritarian government that takes a hands on approach to censoring and restricting what people there can see, and can bring its major propaganda machine to bear to trying to convince people that its approved alternatives are better.
I don't think that would work for private ISPs in the US.
https://github.com/cjdelisle/cjdns/blob/master/README.md
https://www.open-mesh.org/projects/open-mesh/wiki
I mean if legally they can block bittorrent or other protocols, does it mean that one could create a new protocol each time it's legal to block it, rince and repeat, and force the legislator to create a new law forbidding each nez appearing protocol?
Also one might implement ways to prevent protocol detection into a BEP, but if comcast ends up shutting down any traffic that is peer to peer... I wonder if legally they could forbid any traffic that is "too much peer to peer" and argue that it's illegal downloading. Hard to say if comcast could win in court, because if you do the stats, most of peer to peer traffic is indeed illegal.
The internet could end up without any peer to peer traffic, and only works with servers, most users would not really complain, things would still work like they already are. It would really create pressure from users to change ISP.
Some ISPs might not block peer to peer, and I wonder if subscribers would end up moving out of neighborhoods where comcast has a monopoly.
I'm assuming you're thinking in terms of designer drug legislation? Comcast in this case would simply need to match the new protocols to block, no new legislation needed.
It should be standard to:
1. Cancel your acct.
2. (nd amendment) use protocol 6 port 443; emulate SSL
Why ignore one's ability to apply market forces? Is acting too hard?
Extra LOL on the thought of filtering BT. Who pay's who?
the incumbents are currently successfully shutting out big competition from putting in their own infrastructure (google has been successfully blocked from areas by lawsuits, along with municipal ISPs).
edit: and even if competition was unfettered, it would still take many years and a lot of investment to provide real alternatives
giving a shit about what the "right" way to deal with these assholes is probably not that productive.
And it's not harder since NN is dead. It's gone and by 2020 people will understand the opposition to axing it's short existence was pointless. We should focus on what you appear to agree matters more; more competition.
The 25 years when internet was accessed over telephone wire which was regulated as a utility?
Do you even know why NN came to be?
> NN is just a typical BS branding for "More Rules". It's step 0 in the standard manual on mission creep.
In this evil governmental overreach conspiracy, who do you think benefits from these "More Rules"? What's their motive?
I'm all ears on how mission creep with regards to regulation is not a "conspiracy". Maybe you understand that power expansion is a law of nature and hence does not require overt "evil" conspiracy, if so, we agree.
Definitely don't mention competition.
There is no way in hell that we are going to see real competition between ISPs in Amarica this year, next year, or five years from now.
We all want it, but it’s not going to happen (obvious, even to a casual observer).
So tell you what: let’s get competition first, and then talk about eliminating net neutrality rules. Because doing the latter certainly won’t accomplish the former.
Your argument is exactly like “We don’t need laws regulating guns, we just need people to stop shooting people with them.” True and helpful, as long as we live in a fantasy world instead of this actual one.
[1] That is, people who keep trotting out this “competition is better than regulation” trope, in the context of net neutrality, where it has relevance only in fantasy scenarios (e.g. a superhero named MarketMan appears to blast everybody with his Competition Ray, and somehow open up an industry that is more protected from competition by regulation than almost any other that exists).
Trump admires china, and promised a wall.. we just had the wrong context.
But seriously this sucks... But I am sure evolution of the protocol to thwart detection will happen.
Vps/seedbox usage would go up as a quick bypass... But who knows, this could allow them to block whole network segments in worst case scenario.
I can see this play out like long distance plans