<?xml version="1.0" encoding="UTF-8"?>
<rss 
    version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/" 
    xmlns:content="http://purl.org/rss/1.0/modules/content/" 
    xmlns:atom="http://www.w3.org/2005/Atom" 
    xmlns:media="http://search.yahoo.com/mrss/" 
>
    <channel>
        <title><![CDATA[Olilo {mainframe}]]></title>
        <description><![CDATA[Your ISP is overcharging you and hoping you won&#x27;t notice. Olilo doesn&#x27;t do that. Fast broadband, no hidden fees, no BS - just the internet, sorted.]]></description>
        <link>https://blog.olilo.co.uk</link>
        <image>
            <url>https://blog.olilo.co.uk/favicon.png</url>
            <title>Olilo {mainframe}</title>
            <link>https://blog.olilo.co.uk</link>
        </image>
        <generator>Ghost 6.42</generator>
        <lastBuildDate>Thu, 16 Jul 2026 05:59:36 +0100</lastBuildDate>
        <atom:link href="https://blog.olilo.co.uk" rel="self" type="application/rss+xml"/>
        <ttl>60</ttl>

                <item>
                    <title><![CDATA[Broadband Pricing Is a Casino. Here&#x27;s Our Boring Alternative.]]></title>
                    <description><![CDATA[Quick question: what does your broadband actually cost?

Not what you pay. What it costs. Because in this industry those are two different numbers, and the gap between them depends entirely on how recently you joined, how loudly you complain, and whether you&#39;ve mastered the ancient art of]]></description>
                    <link>https://blog.olilo.co.uk/blog/broadband-pricing-is-a-casino-heres-our-boring-alternative/</link>
                    <guid isPermaLink="false">6a4aa9fbeb50e8abbe3aa6c4</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Sun, 05 Jul 2026 20:22:08 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Quick question: what does your broadband actually cost?</p><p>Not what you <em>pay</em>. What it costs. Because in this industry those are two different numbers, and the gap between them depends entirely on how recently you joined, how loudly you complain, and whether you've mastered the ancient art of Threatening To Leave.</p><p>Broadband pricing in this country isn't a price. It's a casino. And the house always wins - unless you're willing to spend your lunch break gambling on the phone.</p><h2 id="the-haggling-ritual-a-national-embarrassment">The haggling ritual: a national embarrassment</h2><p>You know the drill, because at this point it's basically folklore. Your deal ends. Your bill jumps. So you phone up, sit through the painful hold music, and perform the sacred dance:</p><p>"I'm thinking of leaving."</p><p><em>Click.</em> You're transferred to the mysterious <strong>retentions team</strong> - a department that exists purely because the normal price is a work of fiction. And lo, a discount materialises. A discount that absolutely did not exist ninety seconds ago when you were talking to normal support. A discount that was in a drawer the whole time, waiting to see if you'd ask.</p><p>Stop and actually think about what that means. <strong>The good price existed all along.</strong> They were simply withholding it to see if you'd blink first. Your ISP is running a pricing model where the best rates go to whoever's most willing to bluff, and everyone else - the busy, the trusting, your nan who's been with them since the modem made noises - subsidises the whole operation.</p><p>That's not a loyalty programme. That's a poker game where one side can see your cards and the other side is your nan.</p><h2 id="the-loyalty-penalty-congratulations-youre-the-sucker">The loyalty penalty: congratulations, you're the sucker</h2><p>Because here's the grim engine underneath it all: in broadband, loyalty is a tax.</p><p>Stay for years. Pay every bill on time. Never cause a fuss. Your reward? You quietly roll onto an out-of-contract rate that's often <em>double</em> what the new customers pay, while the person who signed up yesterday gets the discount, the red carpet, and probably a free doorbell camera <strong>(Hi Sky)</strong>.</p><p>The customers who've paid the most, for the longest, get treated the worst. Somewhere in a head office there's a spreadsheet of customers who haven't checked their bills lately, and that spreadsheet is load-bearing. The entire model is a bet that you're too busy living your life to notice you're being farmed.</p><h2 id="the-intro-price-bait-or-the-%C2%A32499-experience">The intro-price bait, or: the £24.99* experience</h2><p>And how does everyone get lured into the casino in the first place? The big glowing "£24.99 a month!" - with an asterisk doing more heavy lifting than a fat guy driving a forklift.</p><p>£24.99 for six months. Then £36. Plus the setup fee. Plus the "activation" fee, which is a fee for the concept of beginning. Plus the router delivery. By the time you've read all the footnotes, the advertised price has roughly the same relationship to your bill as a movie poster has to the actual film. Unless its Project Hail Mary! Amaze Amaze Amaze.</p><h2 id="the-bit-where-were-honest-about-the-awkward-thing">The bit where we're honest about the awkward thing</h2><p>Right. Cards on the table, because we're not going to write a whole post about pricing games and then dodge this bullet.</p><p>Yes, Olilo offers contracts. And yes, if you read ours, there's a clause in there about prices potentially rising. Practically every ISP has one, including us, because running a network in the real world means our own costs - backhaul, power, kit - can move in ways nobody controls <strong>(Hi Telehouse)</strong>.</p><p>Here's the difference, and it's the whole point of this post: <strong>that clause is a seatbelt, not a business model.</strong></p><p>The big players treat the annual price rise as a guaranteed revenue event - pencilled into the forecast before the year's even started, applied to everyone, every April, like clockwork. For us it's a break-glass-in-emergency thing. We're not planning to use it, we don't budget around using it, and if we ever genuinely had to, you'd hear it from us straight - plain English, actual reasons, no burying it in paragraph 47 of an email titled "Some exciting updates to your plan! 🎉"</p><p>We'd rather tell you the uncomfortable truth in a blog post than hide it in the footnotes. That's the deal. Well and an email of course.</p><h2 id="the-boring-alternative">The boring alternative</h2><p>So here's Olilo's entire pricing strategy, and fair warning, it's painfully dull:</p><p><strong>The price is the price.</strong> The rate on the website is the rate you pay - no intro-rate bait, and on our contracts, no activation fee for the privilege of existing. (Rolling monthly does have an activation fee, and we'll tell you exactly why: installing you costs real money, and we can't foot that bill for someone who dips on day 30. That's not a pricing game - that's maths. It's on the website in normal-sized font, like fees should be.) There's no retentions team, because there's no secret second price for them to guard. And there's no loyalty penalty, because the deal doesn't get worse just because you've been around a while. Staying with us shouldn't be a mistake you're punished for. Heck didn't we reduce all our openreach products? Even for those in contracts? Yup, that's us.</p><p>No poker. No drawer full of secret discounts. No spreadsheet of people who haven't noticed yet.</p><p>Boring? Extremely. But you know what's genuinely exciting? Never having to spend 40 minutes on hold negotiating the price of <em>the internet</em> like you're haggling for a rug.</p><p>The casino's fun until you realise you're not the player. You're the chips.....</p><hr><p><em>Olilo - We legit are broadband without the bullshit.</em></p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[We built a public DNS resolver, and you can use it or don&#x27;t]]></title>
                    <description><![CDATA[We now run a free public DNS resolver on AS212683. Two nodes in London, DNSSEC on, no filtering, no logging your queries, and it speaks every modern encrypted transport we could think of. If you&#39;re just here for the addresses, jump to the bottom. If you&#39;re]]></description>
                    <link>https://blog.olilo.co.uk/blog/we-built-a-public-dns-resolver-and-you-can-use-it-or-dont/</link>
                    <guid isPermaLink="false">6a496883eb50e8abbe3aa670</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Sat, 04 Jul 2026 21:57:17 +0100</pubDate>


                    <content:encoded><![CDATA[<p>We now run a free public DNS resolver on AS212683. Two nodes in London, DNSSEC on, no filtering, no logging your queries, and it speaks every modern encrypted transport we could think of. If you're just here for the addresses, jump to the bottom. If you're here for the write-up, put the kettle on or if you are like me grab a redbull.</p><h2 id="the-addresses">The addresses</h2><ul><li><strong>IPv4:</strong> <code>5.182.115.74</code> and <code>5.182.115.75</code></li><li><strong>IPv6:</strong> <code>2a11:2646:1:2::4</code> and <code>2a11:2646:1:2::5</code></li><li><strong>DoT:</strong> <code>dns.as212683.net</code> on port 853</li><li><strong>DoH:</strong> <code>https://dns.as212683.net/dns-query</code></li></ul><p>Setup instructions per platform live at <a href="https://dns.as212683.net/?ref=blog.olilo.co.uk">dns.as212683.net</a>. Yes the landing page is served by dnsdist itself, we'll get to that.</p><h2 id="why">Why</h2><p>The obvious question. There are already excellent public resolvers run by very serious companies with very serious budgets and we are not going to out-Anycast Cloudflare. Fair.</p><p>The less obvious answer: DNS is one of those pieces of the internet where "more distributed" is genuinely better, most public resolvers on offer are three companies in a trenchcoat, and if you're a small ASN with the boxes already spinning it's approximately the same amount of work to serve fifty users or fifty thousand. The customer-facing config we were already running does 90% of what a public service needs. The rest was, in retrospect, an interesting weekend.</p><p>Also we wanted to write a blog post about it, which is arguably the real reason anyone does anything these days.</p><h2 id="the-stack-briefly">The stack, briefly</h2><p>Nothing exotic. Two boxes, both in London:</p><ul><li><strong>dnsdist </strong>out front doing all five transports (Do53, DoT, DoH, DoQ, DoH3), packet caching, rate limiting, dynamic blocking, and - this bit is genuinely funny - the landing page too</li><li><strong>PowerDNS Recursor</strong> loopback-only behind dnsdist, doing actual recursion with DNSSEC validation</li><li><strong>nftables</strong> with <code>notrack</code> on public UDP (more on why in a sec)</li><li>Let's Encrypt via acme.sh for the TLS</li><li>Prometheus + Grafana pointing at both boxes</li></ul><p>The topology is deliberately boring. Boring is a feature.</p><h2 id="the-bit-where-we-tried-not-to-become-a-ddos-weapon">The bit where we tried not to become a DDoS weapon</h2><p>Every open resolver is a potential amplification reflector. This is the biggest reason "just run a public resolver" is a bad idea by default, and the reason most attempts by small networks end up on Shadowserver's problem list within a week.</p><p>You cannot make the risk zero. What you <em>can</em> do is make yourself an unattractive tool compared to the thousands of naked resolvers already floating around:</p><ul><li><strong><code>ANY</code> queries dropped.</strong> The classic amplification vector, gone.</li><li><strong>UDP answers capped at 1232 bytes</strong> (DNS Flag Day 2020). Big answers force clients to TCP, which spoofed sources can't complete. Amplification factor plummets.</li><li><strong>Non-recursive (RD=0) queries dropped.</strong> Real clients set the recursion-desired bit. Scanners often don't.</li><li><strong>Per-IP rate limit</strong> at 200 QPS, dropped past that.</li><li><strong>Dynamic blocking</strong> that watches per-IP QPS, NXDOMAIN rate, SERVFAIL rate, <em>and</em> response bandwidth, and bans offenders for five minutes at a time. Random-subdomain attacks and volumetric abuse get shown the door within seconds.</li><li><strong>DoQ and DoH3</strong> are QUIC-based and QUIC has anti-amplification built into the protocol itself so that's a plus.</li></ul><p>The application-layer stuff above handles abuse patterns. For actual volumetric attacks - the kind that don't care what's listening, they just want to fill your pipe - that's what our DDoS scrubbing is for. Traffic hits our scrubbers upstream of the resolvers, gets cleaned, and only the legit stuff makes it to dnsdist. Between the two layers, the resolvers themselves basically never see an attack in the shape that matters. Which is roughly the goal.</p><h2 id="the-notrack-thing">The <code>notrack</code> thing</h2><p>Enough people asked about this in the review that it's earned its own header.</p><p>Linux tracks every "connection" through nftables' conntrack table so that <code>ct state established,related accept</code> works - that's how return traffic gets in. Fine for customer volumes. Genuinely catastrophic for a public UDP DNS server, because every query looks like a new connection, the table fills, and then the kernel starts dropping packets. On everything. Including the SSH session.... Do not ask me how I know.</p><p>The fix is boring and universal: bypass conntrack entirely for public UDP 53/853/443 via nftables' <code>raw</code> prerouting hook with <code>notrack</code>. TCP stays tracked (it's stateful anyway, and there's dramatically less of it). Every serious public resolver does this. Nobody talks about it. If you're standing up a public UDP-anything and you don't do this, you will find out in production, and it will be at 3am.</p><h2 id="the-nerdy-bits-worth-mentioning">The nerdy bits worth mentioning</h2><p><strong>dnsdist serves the landing page.</strong> It owns port 443 for DoH already, so we told it to also serve <code>/</code> with a small HTML info page. <code>/dns-query</code> is still DoH, <code>/</code> gets a human. This is one fewer service on the box, one fewer thing to keep patched, one fewer reverse proxy to argue with. If it feels wrong, that's because you've been told for years that DNS servers only speak DNS. dnsdist 2.x quietly stopped bitching.</p><p><strong>DDR (RFC 9462) is on.</strong> Clients that speak DDR - Windows 11, increasingly others - will ask us for <code>_dns.resolver.arpa</code> SVCB records, and we hand them back a pointer to our DoT and DoH endpoints. They then auto-upgrade to encrypted transport with zero user configuration. Try it yourself if you're into that sort of thing:</p><pre><code>dig @5.182.115.74 _dns.resolver.arpa TYPE64
</code></pre><p><strong>Two-layer caching.</strong> dnsdist has a 1M-entry packet cache in front, recursor has 2.5M record cache behind it. Popular names never touch the recursor. This is the reason a resolver on modest hardware can sit at very high QPS without breaking a sweat.</p><h2 id="the-grafana">The Grafana</h2><figure class="kg-card kg-image-card"><img src="https://blog.olilo.co.uk/content/images/2026/07/Olilo-DNS--Recursor---dnsdist--1783198193922.png" class="kg-image" alt="" loading="lazy" width="1770" height="3493" srcset="https://blog.olilo.co.uk/content/images/size/w600/2026/07/Olilo-DNS--Recursor---dnsdist--1783198193922.png 600w, https://blog.olilo.co.uk/content/images/size/w1000/2026/07/Olilo-DNS--Recursor---dnsdist--1783198193922.png 1000w, https://blog.olilo.co.uk/content/images/size/w1600/2026/07/Olilo-DNS--Recursor---dnsdist--1783198193922.png 1600w, https://blog.olilo.co.uk/content/images/2026/07/Olilo-DNS--Recursor---dnsdist--1783198193922.png 1770w" sizes="(min-width: 720px) 720px"></figure><p>We monitor the boring stuff (up/down, QPS, cache hit ratio), the interesting stuff (latency percentiles, per-transport response times, dynamic blocks in flight), and the paranoid stuff (kernel UDP drops, response bandwidth vs query bandwidth, DNSSEC bogus rate). If any of those tiles turn red for long enough, Alertmanager tells us before you do. Probably.</p><h2 id="what-we-dont-do">What we don't do</h2><ul><li>No per-client query logging. Aggregate Prometheus counters only.</li><li>No EDNS Client Subnet sent upstream. Authoritative servers see us, not you.</li><li>No filtering. No blocklists. No walled gardens on the public service (this is simply there for the future... AdBlocks anyone?).</li><li>No ads, no upsell, no analytics on the landing page.</li></ul><p>Written down so you can hold us to it.</p><h2 id="how-to-actually-use-it">How to actually use it</h2><p>Easiest: <strong>Android Private DNS</strong>, put <code>dns.as212683.net</code> in the box, done. Everything encrypted.</p><p><strong>Windows 11:</strong> DNS server assignment -&gt; Manual -&gt; the four IPs + DoH template. <br><br><strong>Browsers:</strong> Settings -&gt; Secure DNS -&gt; custom provider -&gt; paste the DoH URL. <br><br><strong>iOS / macOS</strong>: install our configuration profile from <a href="https://olilo.co.uk/as212683-dns.mobileconfig?ref=blog.olilo.co.uk">olilo.co.uk/as212683-dns.mobileconfig</a><br><br><strong>Routers:</strong> point WAN DNS at both IPs.<br><br><strong>Linux:</strong> systemd-resolved with <code>DNSOverTLS=yes</code>.</p><p>Full walkthrough at <a href="https://dns.as212683.net/?ref=blog.olilo.co.uk">dns.as212683.net</a>.</p><h2 id="please-break-it-nicely">Please break it (nicely)</h2><p>If you find something weird, misbehaving, or straight-up broken, tell us: <strong>noc@as212683.net</strong>.</p><p>If you find something we should be doing differently, also tell us. Especially if you've run this kind of thing at bigger scale and have opinions on our thresholds. We can be persuaded.</p><p>Have fun. Tell your mates. Please don't use it to run for-profit DNS-over-DNS-tunnelling schemes.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[What Is CGNAT And Why Should You Care?]]></title>
                    <description><![CDATA[Learn what CGNAT is, why many broadband providers use it, and how it can affect port forwarding, gaming, remote access and self-hosting.]]></description>
                    <link>https://blog.olilo.co.uk/blog/what-is-cgnat/</link>
                    <guid isPermaLink="false">6a1e9aa9eb50e8abbe3aa64c</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Mon, 08 Jun 2026 09:00:59 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Most broadband customers never think about IP addresses. They plug in their router, connect their devices, and expect everything to work.</p><p>However, if you've ever struggled with port forwarding, remote access, self-hosted services, or certain online applications, there's a good chance you've encountered a technology called CGNAT.</p><p>Many internet providers now use it by default, often without customers realising.</p><p>So what exactly is CGNAT, and why does it matter?</p><h2 id="what-is-cgnat">What Is CGNAT?</h2><p>CGNAT stands for Carrier Grade Network Address Translation.</p><p>To understand it, we first need to talk about IPv4 addresses.</p><p>Every device connected to the internet needs an address. Historically, this was provided through IPv4, which uses a pool of approximately 4.3 billion unique addresses.</p><p>That might sound like a lot, but with billions of people, smartphones, computers, servers, and IoT devices online, those addresses have largely been exhausted.</p><p>As a result, many providers now share a single public IPv4 address between multiple customers using CGNAT.</p><p>Instead of your router receiving its own public address, it receives a private address, and the ISP translates your traffic behind a shared public IP.</p><h2 id="why-do-providers-use-cgnat">Why Do Providers Use CGNAT?</h2><p>The answer is simple: IPv4 addresses are expensive.</p><p>As address availability has declined, the market value of IPv4 space has increased significantly.</p><p>Using CGNAT allows providers to serve many customers while using fewer public IPv4 addresses.</p><p>For some providers, this reduces costs and simplifies growth.</p><p>For customers, the experience is often mixed.</p><h2 id="what-problems-can-cgnat-cause">What Problems Can CGNAT Cause?</h2><p>For basic web browsing, streaming, social media, and video calls, CGNAT usually works perfectly fine.</p><p>The problems appear when you want inbound connections from the internet.</p><h3 id="port-forwarding-doesnt-work">Port Forwarding Doesn't Work</h3><p>Port forwarding allows external devices to connect to services running on your network.</p><p>Common examples include:</p><ul><li>Game servers</li><li>CCTV systems</li><li>Home automation platforms</li><li>Self-hosted websites</li><li>Remote desktop access</li><li>VPN servers</li></ul><p>With CGNAT, you typically cannot create working port forwards because the public IP address isn't actually assigned to your connection.</p><h3 id="remote-access-becomes-more-complicated">Remote Access Becomes More Complicated</h3><p>Many homelab enthusiasts use services such as:</p><ul><li>WireGuard</li><li>OpenVPN</li><li>Home Assistant</li><li>Plex</li><li>Nextcloud</li></ul><p>These can require additional workarounds when operating behind CGNAT.</p><h3 id="shared-reputation">Shared Reputation</h3><p>When dozens or even hundreds of customers share a single public IP address, the actions of one user can potentially affect others.</p><p>This is uncommon, but shared IP reputation can occasionally cause issues with certain services or security systems.</p><h3 id="troubleshooting-is-harder">Troubleshooting Is Harder</h3><p>When multiple customers appear under the same public IP, diagnosing network issues can become more complex for both customers and support teams.</p><h2 id="does-cgnat-affect-gaming">Does CGNAT Affect Gaming?</h2><p>This is one of the most common questions.</p><p>For most modern games, CGNAT has little or no impact on latency.</p><p>Your ping is primarily determined by routing and network quality rather than whether you're behind CGNAT.</p><p>However, some games and peer-to-peer applications may report stricter NAT types, which can occasionally affect hosting sessions or direct connections.</p><h2 id="the-long-term-solution-ipv6">The Long-Term Solution: IPv6</h2><p>The internet's long-term answer to IPv4 exhaustion is IPv6.</p><p>IPv6 provides a vastly larger address space, allowing every device to have its own globally routable address.</p><p>With proper IPv6 deployment, the need for technologies like CGNAT is significantly reduced.</p><p>Unfortunately, not every service fully supports IPv6 yet, which means public IPv4 addresses still remain important today.</p><h2 id="how-to-tell-if-youre-behind-cgnat">How To Tell If You're Behind CGNAT</h2><p>One simple check is to compare:</p><ol><li>The WAN IP address shown in your router.</li><li>The public IP address reported by websites such as "What Is My IP".</li></ol><p>If the addresses don't match, there's a good chance you're behind CGNAT.</p><p>Another indicator is if your router receives an address from private ranges such as:</p><ul><li>10.0.0.0/8</li><li>172.16.0.0/12</li><li>192.168.0.0/16</li><li>100.64.0.0/10</li></ul><p>The 100.64.0.0/10 range is commonly used specifically for CGNAT deployments.</p><h2 id="olilos-approach">Olilo's Approach</h2><p>At Olilo, we believe customers should have full control over their internet connection.</p><p>That's why every prosumer broadband service includes:</p><ul><li>A public IPv4 address</li><li>Native IPv6 connectivity</li><li>No CGNAT</li><li>Support from people who understand networking</li></ul><p>Whether you're running a homelab, accessing services remotely, hosting applications, or simply want a more traditional internet connection, you won't find your traffic hidden behind carrier-grade NAT.</p><h2 id="final-thoughts">Final Thoughts</h2><p>CGNAT isn't inherently bad. It allows providers to continue growing despite IPv4 shortages and works perfectly well for many everyday internet activities.</p><p>However, if you value control, remote access, self-hosting, or advanced networking features, it's worth understanding whether your provider uses it.</p><p>Sometimes the difference between something working immediately and spending hours troubleshooting comes down to whether you have your own public IP address.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[ISP vs Broadband Reseller: What&#x27;s the Difference?]]></title>
                    <description><![CDATA[Not all broadband providers are the same. Learn the difference between an ISP and a reseller, and how network ownership can affect performance.]]></description>
                    <link>https://blog.olilo.co.uk/blog/isp-vs-broadband-reseller/</link>
                    <guid isPermaLink="false">6a1e98e2eb50e8abbe3aa637</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Tue, 02 Jun 2026 09:50:14 +0100</pubDate>


                    <content:encoded><![CDATA[<p>When you're shopping for broadband, you'll often see dozens of providers offering services over the same network. At first glance, they can appear almost identical. Similar speeds, similar prices, and often the same underlying infrastructure.</p><p>So what actually separates an Internet Service Provider (ISP) from a broadband reseller?</p><p>The answer can have a bigger impact on your experience than you might think.</p><h2 id="the-network-is-only-part-of-the-story">The Network Is Only Part Of The Story</h2><p>Many broadband providers in the UK use wholesale networks such as CityFibre, Openreach, or other national infrastructure providers. These networks handle the physical connection between your home and the wider internet.</p><p>What happens after your traffic leaves that network is where providers begin to differ.</p><p>Some companies simply purchase a wholesale service, apply their branding, and provide customer support. Others invest heavily in their own network infrastructure, routing, monitoring, and technical expertise.</p><p>Both approaches are valid, but they can deliver very different customer experiences.</p><h2 id="what-is-a-broadband-reseller">What Is A Broadband Reseller?</h2><p>A broadband reseller typically relies on a third party for most aspects of service delivery.</p><p>This often includes:</p><ul><li>Authentication systems</li><li>Routing infrastructure</li><li>Core network services</li><li>Traffic management</li><li>Monitoring platforms</li><li>Technical operations</li></ul><p>In many cases, the reseller has limited control over how traffic is handled once it reaches the wholesale provider's network.</p><p>For customers with basic internet requirements, this may not be an issue. However, when something unusual happens or a more technical requirement arises, the reseller may need to escalate requests through multiple layers of suppliers before changes can be made.</p><h2 id="what-is-an-isp">What Is An ISP?</h2><p>An ISP operates and manages its own network infrastructure.</p><p>This can include:</p><ul><li>Core routers</li><li>Internet transit connections</li><li>Peering relationships</li><li>IPv4 and IPv6 address space</li><li>Authentication platforms</li><li>Monitoring systems</li><li>Customer management systems</li></ul><p>Because the ISP controls these systems directly, it can often diagnose and resolve issues faster, make network changes when required, and provide more flexibility for customers with advanced requirements.</p><h2 id="why-does-this-matter">Why Does This Matter?</h2><p>For many people, broadband is simply expected to work.</p><p>But network design decisions can affect:</p><h3 id="performance">Performance</h3><p>Two providers may use the same fibre connection into your property, but traffic can take very different routes across the internet afterwards.</p><p>Factors such as routing policies, peering arrangements, and transit providers can all influence latency and performance.</p><h3 id="reliability">Reliability</h3><p>Providers operating their own network can often identify and resolve issues more quickly because they have direct visibility of the infrastructure carrying customer traffic.</p><h3 id="technical-features">Technical Features</h3><p>Features that enthusiasts and businesses often value include:</p><ul><li>Static IPv4 addresses</li><li>Native IPv6 connectivity</li><li>Reverse DNS support</li><li>Public IP addressing</li><li>Flexible network configurations</li><li>Advanced troubleshooting</li></ul><p>Not every provider offers these features, even when using the same underlying access network.</p><h3 id="support">Support</h3><p>When a provider owns and operates its own systems, support teams typically have greater access to diagnostic information and more control over resolving issues.</p><p>Rather than passing requests through multiple suppliers, they can often investigate directly.</p><h2 id="bigger-isnt-always-better">Bigger Isn't Always Better</h2><p>It's easy to assume that the largest providers automatically offer the best service.</p><p>In reality, many smaller ISPs have built loyal communities by focusing on technical excellence, transparency, and customer service.</p><p>Smaller providers often have the flexibility to make decisions quickly, listen to customer feedback, and offer features that larger organisations may not prioritise.</p><h2 id="where-does-olilo-fit-in">Where Does Olilo Fit In?</h2><p>At Olilo, we believe broadband should be more than just a connection.</p><p>While we utilise modern fibre infrastructure, we also operate our own network systems and focus on delivering the features that internet enthusiasts, homelabbers, remote workers, and businesses expect.</p><p>That means:</p><ul><li>Static IPv4 addresses included as standard</li><li>Native IPv6 connectivity</li><li>No CGNAT</li><li>Direct access to knowledgeable support</li><li>A network designed with reliability and performance in mind</li></ul><p>We're proud to be part of a growing community that values openness, technical expertise, and a genuinely customer-focused approach.</p><h2 id="final-thoughts">Final Thoughts</h2><p>The fibre entering your home is only one piece of the puzzle.</p><p>When comparing broadband providers, it's worth looking beyond advertised speeds and asking deeper questions about how the service is delivered, who operates the network, and what level of control the provider has over your connection.</p><p>The answers can reveal the difference between a company that simply sells broadband and one that truly delivers internet services.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[What Actually Happens When You Resolve and Load a Website]]></title>
                    <description><![CDATA[Typing a URL and getting a page back feels trivial.
Under the hood, it’s a tightly timed sequence across DNS, transport, TLS, and application layers - and small inefficiencies anywhere show up as “this site feels slow”.

Here’s the clean version of the flow.


1) Name Resolution (DNS)]]></description>
                    <link>https://blog.olilo.co.uk/blog/what-actually-happens-when-you-resolve-and-load-a-website/</link>
                    <guid isPermaLink="false">69fe4c9d850ee26047e9a27f</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Fri, 08 May 2026 21:53:34 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Typing a URL and getting a page back feels trivial.<br>Under the hood, it’s a tightly timed sequence across DNS, transport, TLS, and application layers - and small inefficiencies anywhere show up as “this site feels slow”.</p><p>Here’s the clean version of the flow.</p><hr><h2 id="1-name-resolution-dns">1) Name Resolution (DNS)</h2><p>Your client needs an IP for the hostname.</p><ul><li>Stub resolver -&gt; recursive resolver (often ISP, or public like Cloudflare / Google)</li><li>Cache hit? Return immediately.</li><li>Cache miss? Walk the walk: root -&gt; TLD -&gt; authoritative</li><li>Respect TTLs, possibly DNSSEC validation</li></ul><p><strong>Latency cost:</strong> typically 5-40ms with a warm cache, more on cold paths.</p><p><strong>Gotchas:</strong></p><ul><li>High RTT to resolver</li><li>Poor cache hit rates</li><li>Misconfigured TTLs causing excess lookups</li></ul><hr><h2 id="2-transport-setup-tcp-or-quic">2) Transport Setup (TCP or QUIC)</h2><h3 id="tcp-http11-http2">TCP (HTTP/1.1, HTTP/2)</h3><p>3-way handshake:</p><ul><li>SYN -&gt; SYN-ACK -&gt; ACK</li></ul><p><strong>Cost:</strong> 1 RTT before data.</p><h3 id="quic-http3">QUIC (HTTP/3)</h3><p>Runs over UDP, combines transport + crypto setup.</p><p><strong>Cost:</strong> 0-1 RTT depending on session resumption.</p><p><strong>Why it matters:</strong> Fewer round trips = faster TTFB, especially on high-latency paths.</p><hr><h2 id="3-tls-negotiation">3) TLS Negotiation</h2><p>For HTTPS, you’re doing TLS (usually 1.3 now):</p><ul><li>Cipher suite negotiation</li><li>Key exchange (ECDHE)</li><li>Certificate validation</li><li>Session resumption if available</li></ul><p><strong>Cost:</strong> ~1 RTT (less with resumption/QUIC)</p><p><strong>Gotchas:</strong></p><ul><li>Large cert chains</li><li>OCSP/CRL delays (if not stapled)</li><li>No session reuse</li></ul><hr><h2 id="4-http-request-response">4) HTTP Request / Response</h2><p>Now we actually ask for <code>/</code>.</p><ul><li>Headers go out (cookies, UA, etc.)</li><li>Server responds (status, headers, body)</li></ul><p>With HTTP/2:</p><ul><li>Multiplexed streams over one connection</li><li>Header compression (HPACK)</li></ul><p>With HTTP/3:</p><ul><li>Similar semantics, better under packet loss</li></ul><p><strong>TTFB depends on:</strong></p><ul><li>Server processing time</li><li>Upstream dependencies (DB, APIs)</li><li>Network RTT</li></ul><hr><h2 id="5-rendering-pipeline-client-side">5) Rendering Pipeline (Client-Side)</h2><p>Browser:</p><ul><li>Parses HTML -&gt; builds DOM</li><li>Fetches subresources (CSS, JS, fonts, images)</li><li>Builds CSSOM</li><li>Executes JS (which can block rendering)</li><li>Layout + paint</li></ul><p>This is where a “fast server” can still feel slow.</p><p><strong>Common issues:</strong></p><ul><li>Render-blocking JS/CSS</li><li>Too many round trips for assets</li><li>No prioritisation</li></ul><hr><h2 id="6-edge-caching-cdn">6) Edge Caching / CDN</h2><p>Most production setups sit behind a CDN like Cloudflare.</p><ul><li>Anycast routes you to a nearby POP</li><li>Cached assets served at the edge</li><li>Origin only hit on miss</li></ul><p><strong>Benefits:</strong></p><ul><li>Lower RTT</li><li>Offload origin</li><li>Better resilience</li></ul><hr><h2 id="where-performance-is-actually-wonlost">Where Performance Is Actually Won/Lost</h2><p>If you’re optimising, these are the levers that matter:</p><ul><li><strong>RTT</strong> (physical + routing path)</li><li><strong>Handshake overhead</strong> (TCP + TLS vs QUIC)</li><li><strong>Cache hit ratio</strong> (DNS + CDN)</li><li><strong>Connection reuse</strong> (keep-alive, H2 multiplexing)</li><li><strong>Payload efficiency</strong> (compression, fewer requests)</li></ul><p>Bandwidth matters far less than people think once you’re past a certain point.</p><hr><h2 id="why-this-matters-in-practice">Why This Matters (In Practice)</h2><p>When someone says “the internet is slow”, it’s usually one of:</p><ul><li>Resolver latency or DNS issues</li><li>High RTT / poor routing</li><li>Packet loss impacting retransmissions</li><li>TLS / handshake overhead on fresh connections</li><li>Origin slowness or bad frontend design</li></ul><p>Not “my line speed is too low”.</p><hr><h2 id="takeaway">Takeaway</h2><p>Loading a site is a pipeline of dependent steps:</p><p>DNS -&gt; transport -&gt; TLS -&gt; request -&gt; render</p><p>You don’t feel the individual pieces - you feel the sum.</p><p>And the difference between a “snappy” site and a sluggish one is usually just a few extra round trips in the wrong places.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Why Your WiFi Sucks (And It’s Probably Not Your ISP)]]></title>
                    <description><![CDATA[Slow WiFi? It’s probably not your ISP. Learn what actually causes bad WiFi and how to fix it for faster, more reliable internet at home.]]></description>
                    <link>https://blog.olilo.co.uk/blog/why-your-wifi-sucks-and-its-probably-not-your-isp/</link>
                    <guid isPermaLink="false">69fd0865850ee26047e9a255</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Fri, 08 May 2026 00:00:31 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Be honest.</p><p>When your internet slows down, what’s the first thought?</p><blockquote>My ISP is trash.</blockquote><p>Fair.<br>But also… not always true.</p><p>A <em>lot</em> of the time, your broadband is perfectly fine - it’s your WiFi that’s struggling.</p><p>Let’s break it down.</p><hr><h2 id="wifi-hates-your-house">WiFi Hates Your House</h2><p>WiFi signals aren’t magic. They’re radio waves.</p><p>And your house? Basically the worst enemy.</p><p>Things that absolutely destroy WiFi:</p><ul><li>Thick walls (especially brick or concrete)</li><li>Metal (radiators, appliances, foil insulation)</li><li>Floors (yes, upstairs = pain in the arse)</li></ul><p>That “full fibre gigabit” connection?<br>Yeah… it’s not getting through three walls and a bathroom intact.</p><hr><h2 id="distance-speed-killer">Distance = Speed Killer</h2><p>The further you are from your router, the worse it gets.</p><p>Not just slower speeds - but:</p><ul><li>Higher latency</li><li>More packet loss</li><li>Random dropouts</li></ul><p>WiFi doesn’t fail dramatically… it just slowly becomes unusable.</p><hr><h2 id="24ghz-vs-5ghz-this-actually-matters">2.4GHz vs 5GHz (This Actually Matters)</h2><p>Quick cheat sheet:</p><ul><li><strong>2.4GHz</strong> = longer range, slower speeds</li><li><strong>5GHz</strong> = faster speeds, shorter range</li></ul><p>Most devices switch between them automatically… badly.</p><p>So you end up:</p><ul><li>Stuck on a slow band when you shouldn’t be</li><li>Or clinging to a weak 5GHz signal instead of switching</li></ul><hr><h2 id="your-neighbours-are-fighting-you">Your Neighbours Are Fighting You</h2><p>If you’re in a flat or dense area (hi London 👀), WiFi is chaos.</p><p>Everyone’s router is shouting over each other on the same channels.</p><p>Result:</p><ul><li>Interference</li><li>Congestion</li><li>Random slowdowns at peak times</li></ul><p>Your WiFi isn’t just <em>your</em> WiFi. It’s shared airspace.</p><hr><h2 id="cheap-routers-bad-time">Cheap Routers = Bad Time</h2><p>A lot of ISPs ship… let’s be real… <em>shit</em> routers.</p><p>They:</p><ul><li>Struggle with multiple devices</li><li>Have weak antennas</li><li>Don’t handle congestion well</li></ul><p>So when your house has:</p><ul><li>Phones</li><li>Laptops</li><li>TVs</li><li>Consoles</li><li>Smart home stuff</li></ul><p>…it starts to fall apart.</p><hr><h2 id="your-devices-aren%E2%80%99t-helping">Your Devices Aren’t Helping</h2><p>Some devices just have trash WiFi chips.</p><p>Looking at:</p><ul><li>Older laptops</li><li>Budget phones</li><li>Smart TVs (honestly the worst offenders)</li></ul><p>So even if your network is perfect… that one device will still struggle.</p><hr><h2 id="speed-%E2%89%A0-wifi-performance">Speed ≠ WiFi Performance</h2><p>This is the big one.</p><p>You can have:</p><ul><li>900Mbps fibre</li><li>Perfect line</li><li>Zero issues from your ISP</li></ul><p>…and still get <strong>30Mbps over WiFi in your bedroom</strong>.</p><p>Because WiFi is the bottleneck.</p><hr><h2 id="so-what-actually-fixes-it">So What <em>Actually</em> Fixes It?</h2><p>Here’s what genuinely helps:</p><h3 id="move-your-router-seriously">Move Your Router (seriously)</h3><ul><li>Central location</li><li>Not hidden in a cupboard</li><li>Not behind your TV</li></ul><p>This alone fixes a <em>lot</em>.</p><hr><h3 id="use-ethernet-where-you-can">Use Ethernet Where You Can</h3><p>Gaming PC? Console? Work setup?</p><p>Wire it.</p><p>Instant stability boost.</p><hr><h3 id="get-a-mesh-system">Get a Mesh System</h3><p>If your place isn’t tiny, one router won’t cut it.</p><p>Mesh = multiple access points around your home = consistent coverage everywhere</p><hr><h3 id="upgrade-your-hardware">Upgrade Your Hardware</h3><p>A decent router makes a <em>huge</em> difference.</p><p>Better radios, better handling, less pain.</p><hr><h2 id="real-talk">Real Talk</h2><p>Your ISP delivers internet <strong>to your home</strong>.</p><p>WiFi is how it moves <strong>around your home</strong>.</p><p>Two completely different problems.</p><p>So before blaming your provider…</p><p>Check your setup.</p><hr><h2 id="if-your-wifi-still-sucks%E2%80%A6">If Your WiFi Still Sucks…</h2><p>Then yeah - <em>maybe</em> it is your ISP.</p><p>And that’s where we come in.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[Why UK ISPs Keep Screwing People Over (And Why We Built Olilo)]]></title>
                    <description><![CDATA[Switching broadband in the UK shouldn’t be this hard. Here’s why ISPs keep failing customers - and how Olilo is doing things differently.]]></description>
                    <link>https://blog.olilo.co.uk/blog/why-uk-isps-keep-screwing-people-over-and-why-we-built-olilo/</link>
                    <guid isPermaLink="false">69fcc3b1850ee26047e9a22c</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Thu, 07 May 2026 18:02:03 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Let’s not sugar-coat it - switching broadband in the UK right now can be an absolute fucking nightmare.</p><p>If you’ve tried recently, you’ve probably hit at least one of these:</p><ul><li>You ordered service… and heard nothing for days</li><li>Your internet just <em>stopped working</em> mid-migration</li><li>Support ghosted you when things went wrong</li><li>You got billed… for a service you didn’t even have</li></ul><p>Yeah. It’s a mess.</p><p>And the worst part?<br>This isn’t rare anymore - it’s becoming normal.</p><hr><h2 id="the-problem-no-one-wants-to-admit">The Problem No One Wants to Admit</h2><p>A lot of ISPs aren’t actually built to handle the scale they’re operating at.</p><p>They rely heavily on wholesale networks - which is fine in theory - but when things go wrong, responsibility gets bounced around like a ping pong ball.</p><p>You end up stuck in the middle hearing:</p><blockquote>It’s not us, it’s the network provider.</blockquote><p>Meanwhile… you’ve got no internet.</p><hr><h2 id="the-migration-chaos-yeah-we%E2%80%99re-going-there">The Migration Chaos (Yeah, We’re Going There)</h2><p>Let’s talk about migrations - because this is where things <em>really</em> fall apart.</p><p>We’ve seen situations where:</p><ul><li>Customers are moved between providers with little to no notice</li><li>Services go offline for days</li><li>Billing systems keep running like nothing’s wrong</li><li>Support channels just… stop responding</li></ul><p>It’s not just frustrating - it’s unacceptable.</p><p>Broadband isn’t a luxury anymore.<br>People rely on it for work, healthcare, communication - everything.</p><hr><h2 id="so-why-does-this-keep-happening">So Why Does This Keep Happening?</h2><p>A few reasons, and none of them are great:</p><h3 id="1-overpromising-underbuilding">1. Overpromising, Underbuilding</h3><p>Some providers grow fast… without building the systems to support that growth.</p><h3 id="2-support-is-treated-like-a-cost-not-a-priority">2. Support Is Treated Like a Cost, Not a Priority</h3><p>When things break, there aren’t enough real humans to fix it.</p><h3 id="3-no-transparency">3. No Transparency</h3><p>Customers are left in the dark because companies are too scared to just say:</p><blockquote>Yeah, something’s gone wrong and we fucked up - here’s what we’re doing.</blockquote><hr><h2 id="what-we%E2%80%99re-doing-differently-at-olilo">What We’re Doing Differently at Olilo</h2><p>We didn’t start Olilo to be “just another ISP.”</p><p>We started it because we were genuinely tired of watching this happen.</p><p>So here’s the deal:</p><h3 id="we-tell-you-what%E2%80%99s-actually-going-on">We Tell You What’s Actually Going On</h3><p>If something breaks, we don’t hide it. We explain it - properly.</p><h3 id="real-support-fast">Real Support, Fast</h3><p>No ticket black holes. No scripted nonsense.<br>You talk to actual humans who know what they’re doing.</p><h3 id="built-properly-from-day-one">Built Properly From Day One</h3><p>We’re not duct-taping systems together and hoping for the best.</p><p>Our backend is designed to scale at any given moment.</p><hr><h2 id="the-bottom-line">The Bottom Line</h2><p>The UK broadband industry doesn’t have to be this painful.</p><p>You shouldn’t have to chase support.<br>You shouldn’t lose service without warning.<br>You definitely shouldn’t be billed for nothing.</p><p>We built Olilo to fix that.</p><p>No bullshit. No silence. No messing you around.</p><p>Just broadband that actually works - with people who actually care.</p><hr><h2 id="thinking-of-switching">Thinking of Switching?</h2><p>If you’ve been caught up in a messy migration or just want a provider that won’t you know ghost you…</p><p>We’ve got you.</p>]]></content:encoded>
                </item>
                <item>
                    <title><![CDATA[We’re So Back (the blog, not the broadband)]]></title>
                    <description><![CDATA[Relax - the internet never went anywhere.

Olilo’s been up, running, and doing its thing the whole time.
We’ve just been… a bit quiet on here.

Not because nothing’s happening - quite the opposite.
We’ve been busy building, fixing, scaling, and dealing with all the fun]]></description>
                    <link>https://blog.olilo.co.uk/blog/were-so-back-the-blog-not-the-broadband/</link>
                    <guid isPermaLink="false">69fafe9a850ee26047e9a1c1</guid>


                        <dc:creator><![CDATA[Aydan Abrahams]]></dc:creator>

                    <pubDate>Wed, 06 May 2026 09:42:53 +0100</pubDate>


                    <content:encoded><![CDATA[<p>Relax - the internet never went anywhere.</p><p>Olilo’s been up, running, and doing its thing the whole time.<br>We’ve just been… a bit quiet on here.</p><p>Not because nothing’s happening - quite the opposite.<br>We’ve been busy building, fixing, scaling, and dealing with all the fun chaos that comes with running an ISP.</p><p>The blog? Yeah… that took a back seat.</p><h2 id="so-why-bring-it-back">So why bring it back?</h2><p>Because there’s actually a lot worth sharing.</p><p>We’re doing things differently, and most ISPs don’t exactly open the curtain on how things work behind the scenes.<br>We do.</p><p>This is where you’ll see:</p><ul><li>What we’re building (and sometimes breaking)</li><li>Network updates and improvements</li><li>The reality of running an ISP (the good and the slightly cursed)</li><li>The occasional industry take when things go sideways</li></ul><h2 id="what%E2%80%99s-changed">What’s changed?</h2><p>Honestly? A lot.</p><p>The network’s stronger.<br>Things are faster.<br>We’ve learned a ton.<br>And we’re way more dialled in on what matters - stability, performance, and actually being there when people need help.</p><h2 id="and-yeah%E2%80%A6-the-industry-is-still-a-mess">And yeah… the industry is still a mess</h2><p>You’ve probably seen it.</p><p>Providers overpromising.<br>Support going missing.<br>Migrations turning into chaos.</p><p>We’re not here to pretend we’re perfect - but we <em>are</em> here to do it properly.</p><h2 id="the-plan">The plan</h2><p>Keep building.<br>Keep improving.<br>And actually talk about it this time.</p><p>No corporate bullshit. No pretending everything’s perfect.<br>Just real updates from the people running the network.</p><h2 id="anyway">Anyway</h2><p>The blog’s back.<br>The broadband never left.</p><p>More soon.</p><p>- Aydan</p>]]></content:encoded>
                </item>
    </channel>
</rss>