Speaking Engagements & Private Workshops - Get Dean Bubley to present or chair your event

Need an experienced, provocative & influential telecoms keynote speaker, moderator/chair or workshop facilitator?
To see recent presentations, and discuss Dean Bubley's appearance at a specific event, click here

Showing posts with label DPI. Show all posts
Showing posts with label DPI. Show all posts

Monday, July 18, 2016

My comments on BEREC's Net Neutrality guidelines consultation

I've been meaning to submit a response to the BEREC consultation on its draft implementation guidelines for the new EU Net Neutrality guidelines for some time. However, a combination of project-work and vacation has meant I've had to do just a fairly rapid set of comments at the last moment. 

I'm posting them here as a reference and further discussion-point. 

As a background, I think the guidelines are quite comprehensive - but have shifted the needle somewhat from the final EU regulation back towards the Internet-centric view of the world. However, the permissiveness around both zero-rating and (in certain circumstances) so-called "specialised services" seems a pragmatic compromise position. I tend to think that zero-rating is fine "in moderation" - it's basically the Internet equivalent of promotions and coupons. "Sponsored data" is an almost-unworkable concept anyway, so the regulatory aspect is largely irrelevant.

Specialised services are OK as long as they are genuinely "special" - something I've been saying for a long time (see post here). It should also be possible to watch for genuine innovation being catalysed / inhibited by the new rules - and then regulators and policymakers can take a more-educated view to revising them in a few years, based on hard evidence.

Anyway - the contents of my submission (reformatted slightly) are below:



Preamble

I am an independent telecom industry analyst and futurist, representing my own advisory company Disruptive Analysis. I advise a broad variety of telecom operators, network and software vendors, investors, NRAs, IT/Internet firms and others on technology evolution paths, business models and applications, and regulatory issues. I look at the issue of Net Neutrality particularly through the lens of what is, or what is not, possible – and also how the Internet value-chain, applications and user-behaviour are likely to evolve in future.

In the past, I have published research studies examining the possible roles and scale of “non-neutral” broadband & IAS business models. My primary conclusions have been that, irrespective of regulation, most proposed commercial models such as “paid prioritisation”, application-based charging or “sponsored data” are broadly unworkable, for many different technical and business reasons – such as growing use of encryption, plus the risks of false positives/negatives.

Overall, I see the guidelines as broadly positive, as they help clarify some of the many grey areas around implementing NN, and clearly try to close off future potential loopholes. Some aspects will likely be difficult to implement technically – notably the precise definitions and measurements of QoS / and “quality” – but the guidelines are good in setting the “spirit” of the law, even though in some cases the “letter” may be harder to achieve.

Listed below are comments that I feel could help to:

  • Clarify the guidelines further 
  •  Help future-proof them against changes in technology 
  •  Raise questions about possible evolution of the guidelines in response to those changes 
  •  Lock down a few additional possible loopholes
                                                                                                                       
Specific points on individual paragraphs: (reference to the guidelines doc here)

#10 – in locations where “WiFi guest access” is made available (eg visitors to a company’s offices), there is sometimes a sign-up or registration required, either via a splash-page, or simply via obtaining a password. Does this count as “publicly available”?

#11 – it should be clarified that there is a difference between corporate VPNs for connecting to a central site, and personal VPNs that are designed to secure/encrypt normal users’ access to the Internet. There is also a growing trend for corporate VPNs to be replaced by a new technology, software-defined WAN, which may itself use Internet access or even multiple accesses as transport.

#12 – Consideration of WiFi hotspots needs to distinguish between voluntary access (eg if a user obtains the cafĂ© password & registers independently) vs. automated “WiFi offload” by ISPs as an integral part of their IAS offering. The latter is a form of “public access”. Also, there are growing examples of ISPs using WiFi in public places, including outdoors, sometimes as part of “WiFi-Primary” public IAS.

#14 - It is worth distinguishing between capital-I “The Internet” (ie public Internet, addressable via the DNS system & IAS) and lower-case-I “internets” (internetworks) that are private domains.

#23-25 – This needs to reference what happens when “terminal equipment” becomes virtualised, through the imminent release of NFV (network function virtualisation) architectures. This could mean that either the “terminal” become a software-function in the ISPs’ data-centre, or could be (in part) pushed down as a “virtual network function” (VNF) to a general-purpose box at the customer site. Some providers are already discussing the concept of a “VNF AppStore” where the user can choose between different software “terminal” functions. It is unclear if this is permissible – or even mandatory.

#39 & #45 – the nature of software and Internet applications makes its increasingly hard to define categories. There are many blurred boundaries, overlapping categories, “mashups” and differentiated offers. How is the categorisation achieved, for example where a social network includes a large amount of video-streaming in its timelines? Is that equivalent to a “pure” video application? What about streaming of games? Is there a distinction between video-on-demand and live-streaming? This is particularly difficult where some functions such as voice communication are being included as “secondary features” embedded in many other applications, often via the use of 3rd-party platforms and APIs (application programming interfaces). There needs to be stronger guidance on how “categories” are defined and how disputed or ambiguous categorisation can be addressed.

#40 & #45 – a possible implementation option is to require ISPs to report the % of overall traffic (or % of particular user-classes) that is zero-rated.  If the total amount provided “for free” is less than (say) 10% of the total, it can a-priori be considered acceptable as it is unlikely to materially affect users’ choices. However, if it is higher this could trigger closely investigation by the NRA.

#43 – this section seems to focus more on established CAPs or possible new-entrants. It is unclear if this explicitly covers the needs open-source initiatives and general software-developers

#56 – There is a possible implementation option for NRAs to collect and hold configuration details for ISPs’ network equipment or software-equivalent VNFs, to allow retrospective analysis of network setup if disputes occur. This could be done on an encrypted / escrowed basis to maintain normal commercial confidentiality

#57 – the reference to encryption needs to explicitly include both app-level encryption (eg HTTPS / HTTP2) and more general “all-traffic” encryption using corporate or personal VPN “tunnels”

#57 & 58 – an implementation option for NRAs could be provision of a contact-point for internal ISP whistle-blowers to report infringement, or 3rd-party monitoring organisations (eg that use pattern-recognition to detect abuses)

#60 & #61 & #63 – categorisation is extremely hard, owing to application differentiation, complex hybrid and “mashup” applications, different levels of fault-tolerance built into applications by developers etc. For example, different VoIP applications use different approaches to error-correction, or are used differently (eg ordinary telephony vs. karaoke). In future there will also be a difference based on whether the application (at either end) is a machine rather than a person. Implied QoS when speaking to “Siri” or “Alexa” may have very different characteristics to speaking to a friend, despite being carried over VoIP. There may also be other dependencies – eg if network conditions have worse impact on badly-designed applications, or devices with other constraints (memory, CPU power, processing chips etc)

#64 – does “network management traffic” also include other types of operational (internal) ISP traffic such as billing records, customer-service inquiries & apps and so forth?

#71 – does “alteration” cover so-called “optimisation”, whereby various content such as a video or image can be paused, down-rated, reformatted etc.? Does it also cover “insertion” of additional data such as tracking codes / “supercookies”, or additional overlay advertising? Are “splash pages” (eg for WiFi registration) allowed?

#89 – Dimensioning may well be affected by other constraints, such as spectrum availability, location, economics of network coverage/capacity, or “emergent” unexpected trends in demand

#98 & #123 – this appears to define specialised services as “actually being special” rather than those capabilities that are normally delivered over IAS. How are hybrid specialised/non-specialised services to be treated?

#101 & #104 – technologies such as SD-WAN (software-defined WAN) allow improved QoS by linking together multiple IAS connections, which in aggregate can perform as well (or even better/cheaper) than one QoS-optimised connection. Should NRAs consider this option when determining if specialised services are valid? See http://disruptivewireless.blogspot.co.uk/2016/06/arbitrage-everywhere-inevitable.html  and http://disruptivewireless.blogspot.co.uk/2016/03/is-sd-wan-quasi-qos-overlay-for.html for more detailed discussion of this point

#111 – It is important to recognise that VPNs are increasingly used by consumers as well as businesses, often to provide a secure & privacy-protected path to the Internet over both public IAS and localised WiFi hotspots. The guidelines should specifically reference consumer VPNs.

#113 to #115 & #117 & #119 – It may be difficult to guarantee coexistence of IAS and specialised services over cellular/other radio networks, where factors such as location in a cell, mobility, density of users, coverage/interference etc are non-deterministic. Potentially the guidelines could advise use of different spectrum bands for IAS and specialised services, to mitigate these problems.

#113 & #116 – in future 5G architectures, we may see a concept called “network slicing”, where the radio and core networks are logically divided into “slices” suitable for different application classes – either broadly between Internet & specialised services of different types, or resold more granularly a bit like “super-MVNOs” to particular 3rd-parties on a wholesale basis. Where those parties are themselves CAPs, this could make interpretation of this section very difficult. If Netflix or Google or even a rival ISP/telco buy rights to a “slice”, how do the guidelines apply?

#131 – This guideline should potentially also include information/transparent guidance for application developers, who may be creating applications intended to run over the IAS provided

#152 – should coverage maps be 2-dimensional, or also include z-axis detail (eg speed in a basement / on the 50th floor of a tower block)? How can such maps cope with the trend towards self-optimising / self-reconfiguring networks of various types?

#167 & #180 – NRAs should potentially seek to maintain records of network configuration status (which may change abruptly with the advent of NFV & SDN). This could perhaps be stored securely & reliably using technologies such as Blockchain.

#172 & #179 – monitoring of aggregate volumes of traffic subject to price-discrimination (eg % of IAS traffic that is zero-rated) would be useful


General comments:
  • There needs to be consideration of meshed, relayed or shared connections which run directly between users’ devices. In device-to-device scenarios, does the owner/operator of an intermediate device become responsible for the neutrality of the “onward” link to 3rd parties? (which could be via any technology such as WiFi, Bluetooth, wired USB port etc) 
  •  There needs to be consideration that some of the more invasive mechanisms for traffic discrimination and control will in future move from “the network” to becoming virtualised software (provided by an ISP) that reside in edge-nodes at the customer premise, or even in customers’ mobile devices. It is unclear how the implementation guidelines deal with predictable near/mid-term trends in NFV/SDN technology, especially where there is no clear “demarcation point” in ownership between ISP and end-user. 
  • Equally, in future there may well be CAP companies that offer their services “in the network” itself, also with NFV/SDN. There needs to be careful thought given to how this intersects with Net Neutrality guidelines 
  • The evolution of artificial intelligence & machine-learning means that workarounds or infringements may become automated, and perhaps even invisible to ISPs, in future. This may also impact the nature of QoS as used for different applications. See http://disruptivewireless.blogspot.co.uk/2016/04/telcofuturism-will-ai-machine-learning.html for more details 
  •  Where wholesale relationships occur – eg MNO/MVNO, “neutral host” networks using unlicenced-band LTE, or secondary ID on the same WiFi hotspot – and the traffic-management / IAS functions are co-managed, how do the guidelines apply? Which party/parties is responsible?

Tuesday, February 23, 2016

Mobile adblocking is overhyped & mostly unworkable

There's been a lot of fuss in recent weeks about the possibility of mobile operators blocking ads transiting cellular networks - or perhaps even charging advertisers for their delivery. I've written before that I think the idea is a non-starter (link), and I still believe that to to be the case

Three has announced a deal (link) with Shine that will (at a future date) implement network-level ad-blocking. The PR talks a good game about privacy and control, but is unfortunately divorced from reality in several important ways.

(Incidentally - I apologise. Mea culpa. I was the one who originally suggested that mobile ads' data-traffic could be charged to the advertisers - see this link. But that was 5 years ago, and the mobile world has moved on rather far since then)

Now to be fair, some mobile ads are very annoying and intrusive. I hate the ones that pop-up while scrolling through a website (or in-app) and take you straight to the appstore download page, as you swipe on the wrong bit of the screen. And yes, if I was limited to a very small data allowance, I'd be annoyed by the big chunks of data from the ads themselves, cookies and assorted other background marketing eating up my quota. There's a bunch of dodgy privacy-invading practices too, which I despise.

But.

There are multiple reasons why trying to fix these issues in the cellular network is the wrong answer:
  • 50-90% of smartphone use, and probably 90-95% of tablet use, is over WiFi - and almost exclusively WiFi not provided by cellular operators, or transiting their core networks. Therefore people will still get ads on their phones most of the time. (And no, they won't "onload" to cellular just for the ad-free experience).
  • The most fast-growing part of mobile advertising is in-app. And while some in-app traffic (eg rendered in browser-style webview pages) might be blockable, the "native" ads such as Facebook's in-timeline ads won't be. Facebook blends them in at the server, and encrypts it all. That's not going to change, apart from becoming ever more-sophisticated.
  • Encryption is also being more widely used elsewhere. HTTPS, encrypted video streams, full-VPN clients and so forth. Some of this might be block-able, eg if it comes from easily-identified servers or IP addresses, but it's naive to think that isn't subject to a million workarounds
  • People who really want ad-blocking are likely to do it themselves, either with an app or browser-capability, or perhaps even in the OS. That way they can block ads on WiFi too
  • Any network-level solution is held hostage to future modifications in Android and iOS which offer work-around options for advertisers. That might not be a bad thing, in that it could cut down on some of the worse pop-up offenders or most-egregious "cookie monsters", but it won't reduce the overall amount of ads.
  • Advertising and B2C engagement is changing anyway. Some is moving to apps, some is moving to ads/interactions in messaging (conversational commerce - see link here from my friends at STL Partners)
  • It risks all manner of embarassing or legally-questionable side-effects. There will be false positives (eg blocking things that aren't ads) and false negatives (failing to blocks ads). What happens when Operator A blocks an ad from Operator B, and the competition authorities take a dim view? Or blocks a government ad for submitting tax returns on time, or a charity's disaster appeal? Put your PR and legal teams on danger-money....

The bottom line is that screaming headlines in stories like those from ZeroHedge (link) about "the risk to Internet companies' business models" are nonsense. Ironically, it's Google and Facebook's approach to advertising that is safe. Small online publications using other advertising channels may not be so lucky. I noticed this tweet referencing mobile advertising growth forecasts from Goldman Sachs (link) which seems to suggest that Wall St is sanguine about the adblocking "threat" and that rapid growth in revenues will continue.

Yes, there are some possible upsides here. Network-level cookie blocking is a possibility, and could help preserve privacy. (I already use a VPN service from F-Secure that anonymises my traffic, on mobile and WiFi). We could also see a proportion of the nastiest pop-up ads being squashed, which is also a good thing in most users' eyes. But that will just shift mobile advertising to other inventory types or channels. And maybe for some very low-end users, in markets with low-end data plans and a preponderance of web vs. app traffic, it could make a worthwhile difference.

But for everyone else, I think it's hugely overhyped. It's unlikely to stop more than single-digit % of overall data traffic per user. There's a huge set of "gotchas" for the idea that mobile network operators can make a meaningful difference, given WiFI and in-app ads. And the idea of actually charging advertisers for some sort of curated "personal advertising preference" system isn't going to come through this route either. (There's a whole separate post's worth of problems about that side of things, but it won't even get to that stage).

Yes, it makes for fun controversial headlines and might allow telcos to stick another metaphorical finger up at net-neutrality rules ("See? We're protecting consumers by fiddling with traffic non-consensually!"). But it's a sideshow, not something that will give Google sleepless nights.

Incidentally if you're reading this on a phone, here's a mobile advert: I do workshops, consulting projects and speaking engagements for operators, vendors and investors, on a variety of topics such as mobile networks, voice/video/UCaaS, and broader telecom futurism (link). I think of concepts like this, 5 years ahead, when they're stilll plausible. Drop me a line via information AT disruptive-analysis dot com, or via Twitter or LinkedIn. And good luck blocking this paragraph in the network without some really good AI and contextual analysis (I cover those technologies too).

Thursday, January 29, 2015

Mobile Data Monetisation Report Update: Still no upside from sponsored data or paid prioritisation models

Disruptive Analysis has recently published an update of its June 2014 report on "Non-Neutral Mobile Broadband: New Models for Monetisation"

It updates and extends the model for mobile data revenues worldwide, for both traditional and new forms of charging. It also analyses the impact of the Apple SIM, mobile data encryption (including SPDY), zero-rating, paid-peering, new vendors and other recent developments in regulation.

The baseline forecast for global mobile Internet access is $354bn by 2019. New business models such as "sponsored data" or "paid priority QoS" might add another $19bn incremental revenue - but may well cost more than that to enable, deploy and market. The report analyses more than 15 different policy use-cases, such as sponsored advertising, single-app dataplans, enhanced MVNOs, and IoT-related QoS.





Despite developing markets having more lax rules on neutrality, the bulk of the "enhanced monetisation" opportunity (2/3rd) is in North America and Europe.

In other words, for mobile, all the arguments about Net Neutrality (or Non-Neutrality) are largely a waste of time and effort in terms of new revenues, justification of 4G/5G investments and so on. The telco industry's voluminous research papers and theoretical models, from assorted academics, economists and consultants, fail to understand the practicalities involved - technical, commercial alike. It's a set of straw-man arguments.

The concept of two-sided markets applied to mobile data traffic - whether "sponsored" by content companies, or "prioritised" using QoS, simply doesn't fly in the real world. The academics ignore the realities of mobile application development, behaviour & perception of users, role of WiFi, encryption (see below), recalcitrance by smartphone platform providers, lack of willingness-to-pay and ability-to-bill, and about a dozen other issues.

In a nutshell: If mobile operators can't justify investing in 4G and 5G on their current trajectories, then changing the law (or preventing Internet regulation) isn't going to help. There is very limited money in "application-based" business models - except (ironically) zero-rating of certain apps' traffic, which seems to encourage new sign-ups or switching, albeit without any extra revenue from the Internet companies. Some very low-end users are adopting restricted plans for single applications or a curated selection, but as a general rule "anybody who can afford the whole Internet will not be satisfied with just half of it".



Mobile operators would be better off switching money away from lawyers and lobbyists, and towards genuine service innovation - or (as is actually happening) either consolidation, or just getting on with building networks and selling access with decent pricing and tiering, differentiating on coverage, speed, customer service, devices, bundled content and maybe time-of-day or location-specific plans.

The obsession with application-based charging models is mostly driven by DPI and policy vendors - there is very little (if any) demand from application and content players for prioritised QoS or sponsored data. This is critically important, as attempts to "non-consensually" filter or modify Internet traffic by application (blocking or "negative discrimination") are leading to a huge rise in encryption, also catalysed by surveillance fears. 

Some mobile networks now have >50% encrypted data traffic, and that is inexorably rising as websites switch to HTTPS or (in future) SPDY or similar variants in default-encrypted HTTP2. The industry's attempts to halt the spread of crypto are likely to fail - the "Open Web Alliance" seems to be too little, too late, and over-focused on proxies which are intended to optimise telco intervention opportunities, rather than fix specific problems. The new report update gives a full analysis of where the encryption debate is likely to end up. 

Report purchasers will get both the original full 150+ page 2014 report [details here] and also the new 35-page update document. Those buying the Corporate licence will also get a free one-hour conference call with Dean Bubley, the report's author, to discuss the findings in detail.

Payment is either with the links below (Paypal / Credit Card) or via bank transfer & invoice (contact information AT disruptive-analysis dot com)


For online purchasers, the PDF document will be sent by email, typically within 24hrs of receipt of payment, although sometimes travel schedules may mean a small delay. Please include company name for licence purposes, and VAT number for EU purchasers. 

NOTE: PAYPAL's CARD PAYMENT SYSTEM CAN BE TEMPERAMENTAL, IF USED IN A BROWSER ALREADY ASSOCIATED WITH PERSONAL PAYPAL ACCOUNTS, OR WITH SOME CORPORATE CARDS THAT CANNOT BE USED FOR OVERSEAS PURCHASES. PLEASE EMAIL INFORMATION at DISRUPTIVE-ANALYSIS dot COM IF YOU HAVE PROBLEMS




Mobile Broadband report (PDF) 1-3 users




2014 MBB report (PDF) Corporate Licence