用 OONI 觀察行動網路降速 台北市 4G 在演習後仍受限,稍晚恢復可用Measuring Taiwan’s Mobile Slowdown with OONI in Taipei

未簽名
已簽名資訊

豆泥的以太坊地址:mashbean.eth

狀態:未簽名

文章的身分證字號

0x3e626469635aded3f6ceb4aaf3b3b7585ee0f6411168d97fc34a41c36d2215d9

這是什麼?

已簽名表示這篇文章已建立獨特的身分證字號(內容雜湊,contentHash)並且由豆泥簽署認證,簽署是採用以太坊區塊鏈的豆泥專用地址(signer.mashbean.eth)。只要內容一經修改,就會需要重新驗證換發新的身分證字號。但豆泥不是每天都在公所上班,所以偶爾會慢一點認證。

官方降速演習 15:00 結束後,台北市這個台灣大哥大 4G 觀測點在 15:08 仍只有 55 kbit/s,15:10 的串流測試也逾時。17:47 的完整複測顯示下載回升至 30 Mbit/s,串流、Tor 與 Snowflake 均完成。

Taiwan’s announced throttling drill ended at 15:00. At this Taipei observation point, Taiwan Mobile 4G still measured only 55 kbit/s at 15:08 and the streaming test timed out at 15:10. A complete retest at 17:47 measured 30 Mbit/s and completed DASH, Tor, and Snowflake.

閱讀偏好
台北市 4G 在演習前、公告結束後八分鐘與 17 時 47 分的 NDT 下載及上傳速率比較圖

摘要

台灣 2026 年 8 月 13 日的城鎮韌性演習於 15:00 結束行動網路降速。台北市這個台灣大哥大 4G 觀測點在 15:08 仍測得 55.2 kbit/s,15:10 的串流測試也逾時。

17:47 再次完整測試時,下載回升至 30.1 Mbit/s,串流、Tor 與 Snowflake 都能完成。觀測顯示降速影響在公告結束後仍持續一段時間,並在稍晚恢復到可用的傳輸量級。

本文記錄單一 SIM、單一觀測點與數個時間點,無法代表台北市全境,也無法確定精確恢復時間。

台北市 4G 在演習前、公告結束後與稍晚複測的 NDT 下載及上傳速率比較。圖表使用對數尺度並直接標示數值。

三次 NDT 顯示一個明確序列。演習前速度高,公告結束八分鐘後下載仍處於極低速,17:47 已恢復到可正常傳輸的量級。這些測量使用不同的 Measurement Lab(M-Lab)伺服器,訊號強度與基地台狀態也沒有獨立紀錄,圖表適合判讀數量級與可用性變化,無法當成連續的基地台速率曲線。

背景與演習設定

行政院表示,這次演習用來模擬天災、大規模網路攻擊或複合式災害下的有限通訊環境。北部場範圍為基隆、台北、新北、桃園、新竹市、新竹縣與宜蘭。語音、簡訊、文字傳輸、110/119 與細胞廣播預計維持運作,影音串流、視訊通話、行動支付與雲端同步可能受到影響。

行政院公告說明演習時間與範圍。Anoni.net 的社群測量指南整理公開資訊,記載下載上限為 256KB。原始單位沒有明確區分 KB/skbit/s,本文保留原文。

事前公開時間、地理範圍與參與業者,讓公民測量可以比較演習前、事件尾端與事後狀態。本次觀測關注三個問題。

  1. 公告結束後,行動網路何時恢復到可正常完成效能測試的狀態?
  2. 一般吞吐量與串流負載的恢復情形是否一致?
  3. Tor 與 Snowflake 在低頻寬下能否建立連線?

官方資訊曾出現時段差異。少數較早發布的地方政府頁面寫 13:30–14:00,行政院 7 月 23 日公告與較新的地方公告一致寫 14:30–15:00。本報告採用後者。

觀測方法

測量工具

OONI 全名為 Open Observatory of Network Interference,中文可譯為「網路干預開放觀測計畫」,提供開放原始碼的網路測量工具。本次使用 NDT(Network Diagnostic Test,網路診斷測試)測量下載、上傳與延遲,使用 DASH(Dynamic Adaptive Streaming over HTTP,基於 HTTP 的動態自適應串流)模擬影音串流。

Tor 是透過多個中繼節點轉送流量的匿名通訊網路。Snowflake 是 Tor 的可插拔傳輸工具,透過志工提供的臨時代理建立連線。ASN(Autonomous System Number,自治系統編號)用來辨識測量所經過的網路業者。

觀測點與安全條件

  • 觀測地點為台北市,精確位置不公開。
  • 筆電只連同一支手機的 4G 熱點,使用同一張台灣大哥大 SIM。
  • 納入分析的網路為 AS24158 Taiwan Mobile Co., Ltd.。
  • 使用 OONI Probe CLI/miniooni 3.30.0 與 Tor 0.4.9.11。
  • 所有時間使用 Asia/Taipei。
  • NDT、DASH、Tor、Snowflake 全程依序執行,避免互搶頻寬。
  • 每個時段前檢查預設介面、ASN、業者、VPN、Tailscale、active utun、必要指令及 OONI 同意與上傳設定。

OONI 的 Tor 測試會檢查目錄節點與 obfs4 橋接器的可達性。obfs4 是讓 Tor 流量較難被辨認的混淆協定。Snowflake 測試會記錄 bootstrap,也就是 Tor 啟動並連上網路的進度。OONI 的解讀教材提醒,單筆結果需要配合時間、網路與其他測量解讀。

NDT 由 M-Lab 執行。M-Lab 會在公開研究資料中保存測試當下的網際網路服務供應商(ISP)公開 IP 與時間。本文與下載用的安全資料表都不揭露該 IP。M-Lab NDT 說明

實際測量時間軸

台北市有效行動網路測量、官方演習窗口、公告結束後的異常測量與 17 時 47 分完整複測時間軸。

14:35 的 NDT 與 DASH 使用固網出口,已從行動網路分析排除。事件期間可用的行動資料為 14:53 的 Tor 測量。事後測量從 15:08 持續到 15:23,最後一輪完整複測於 17:47–17:49 執行。排定時間、實際時間、測項狀態與排除理由都保留在安全資料表。

觀測結果

15:08 下載仍只有 55 kbit/s

指標14:16 演習前15:08 公告結束後17:47 稍晚複測
下載141,997.8 kbit/s55.2 kbit/s30,131.6 kbit/s
上傳13,981.8 kbit/s1,399.7 kbit/s20,310.0 kbit/s
ping27.6 ms無可用值23.0 ms
average RTT66.0 ms無可用值46.1 ms
測試耗時27 秒94 秒25 秒
測試流量207.9 MB10.3 MB72.4 MB

15:08 的下載約為演習前的 0.039%,上傳約為 10.0%。下載受到的影響遠大於上傳。17:47 下載回升至 30.1 Mbit/s,上傳為 20.3 Mbit/s,NDT 在 25 秒內完成。下載較 15:08 提高 546 倍,上傳提高 14.5 倍。

15:08 的 ping 與 average RTT 在原始結果中都是 0,和測試耗時及其他欄位不一致,本文將兩欄視為缺失值。三次 retransmit rate 都是 0,單獨看這個欄位無法解釋速率差異。

串流測試從逾時轉為完成

時間DASH median bitrateconnect latency測試耗時結果
14:16 演習前75,2830.184 秒18 秒完成
15:10 公告結束後00155 秒generic_timeout_error
17:47 稍晚複測31,6440.033 秒31 秒完成

17:47 的 DASH 成功完成,median bitrate 約為演習前單筆結果的 42%。OONI 原始輸出沒有提供本文可安全確認的 DASH bitrate 顯示單位,因此表格保留原始數值。完成狀態可以支持串流測試恢復可用,數值差異仍受路徑與無線環境影響。

Tor 與 Snowflake 全程可以建立連線

Tor 與 Snowflake 在演習前、事件尾端、公告結束後與稍晚複測的完整測試耗時。

Tor 五次有效測量的目錄埠都是 10/10,目錄權威 OR 埠都是 10/10,obfs4 都是 4/14。測試耗時從演習前 69 秒增加到事件尾端 96 秒,15:15 達到 124 秒,15:21 降至 78 秒,17:48 為 67 秒。可達性成功數維持不變,耗時在事件尾端與剛結束後增加,稍晚回到接近演習前的水準。

Snowflake 三次都啟動至 100%。bootstrap time 從演習前 6.68 秒增加到 15:18 的 17.29 秒,17:49 為 12.78 秒。完整測試耗時依序為 11、25、16 秒。這些結果證明測試當下可以建立 Tor over Snowflake 連線,沒有涵蓋長時間瀏覽、語音或大檔下載。

結果討論

1. 恢復時間應納入韌性演習的成效

官方窗口在 15:00 結束,這個觀測點到 15:12 仍有明確異常,17:47 已恢復到可完成 NDT 與 DASH 的狀態。現有測量把恢復時間界定在 15:12:48 至 17:47:30 之間。這個區間仍然太寬,足以顯示公告結束時間與個別用戶實際恢復可能不同步,也說明後續演習需要公布解除限流的完成標準與長尾恢復情形。

2. 功能恢復與回到基準需要分開判讀

17:47 的下載已遠離 55 kbit/s 的限速級別,DASH 也能完成,代表網路功能恢復。下載只有演習前單筆基準的 21%,DASH median bitrate 約為 42%。單一觀測點、不同伺服器與未記錄的無線條件,使這些比例無法直接歸因於殘留限速。未來若要確認「完全恢復」,需要固定裝置與位置,並連續取得至少兩次接近基準的結果。

3. 匿名網路工具跨過了最低可用門檻

Tor 目錄連線與 Snowflake bootstrap 在事件尾端及事後都成功。這代表本次低頻寬環境仍容許匿名網路建立連線。耗時上升顯示使用者等待變長。實際取得避難資訊或傳送訊息的能力,還需要小型文字頁面成功率、time-to-first-byte、完整載入時間與連線持續性等應用層測量。

限制與不確定性

  • 單一地點、SIM、業者與裝置無法代表台北市、台灣大哥大或北部七縣市整體。
  • 14:30–14:52 沒有有效的行動 NDT/DASH,無法估計演習期間最低值與限速曲線。
  • 15:12–17:47 之間沒有測量,精確恢復時間未知。
  • 訊號強度、頻段、基地台、移動狀態與同基地台負載沒有獨立紀錄。
  • 三次 NDT 使用不同 M-Lab 伺服器,結果同時包含接取網路、路由與伺服器條件。
  • Tor 的 4/14 obfs4 只代表此次抽樣的橋接器,無法涵蓋全部 obfs4 bridge。
  • Tor 與 Snowflake 的成功只證明短時間探測與啟動可行,無法推論長時段應用品質。
  • 本次未測語音、簡訊、細胞廣播、110/119、行動支付或特定即時通訊 App。

下一步

下一次觀測應涵蓋三家行動業者、多個地點與獨立 SIM。事件窗口內需要固定的 NDT、DASH、Tor 與 Snowflake 序列;15:00 之後每五分鐘重複 NDT 與 DASH,直到連續兩組測量回到事前基準的既定比例。每筆資料應同步保存訊號強度、頻段與基地台變化。排程留在本機執行,測試失敗照樣保存。

官方技術說明應使用明確單位,例如 kbit/s 或 kB/s,分別公布下載與上傳目標,定義解除限流的完成期限,並發布三家業者的聚合恢復統計。通訊韌性評估需要同時呈現核心服務持續性、降級幅度與恢復時間。

資料與重現

安全 CSV 保留縣市、排定與實際時間、ASN、業者、測項、狀態、流量與主要結果欄位,不包含公開 IP、OONI UID 或 Measurement URL。OONI 資料依 CC BY-NC-SA 4.0 資料授權引用。

主要背景來源

Executive summary

Taiwan’s mobile-network throttling drill ended at 15:00 on 13 August 2026. At this Taiwan Mobile 4G observation point in Taipei, download still measured 55.2 kbit/s at 15:08, and the streaming test beginning at 15:10 timed out.

A complete retest at 17:47 measured 30.1 Mbit/s down and completed the streaming, Tor, and Snowflake tests. The observation indicates that the slowdown persisted beyond the announced end and that usable transfer capacity returned later.

This report covers one SIM, one observation point, and several measurement times. It cannot represent all of Taipei or establish the exact recovery time.

NDT download and upload throughput on Taipei 4G before the drill, after the announced end, and during the later retest. The chart uses a logarithmic scale with exact values labelled.

The three NDT runs show a clear sequence. Throughput was high before the drill, downstream service remained extremely constrained eight minutes after the announced end, and the 17:47 retest returned to a functional transfer rate. The tests used different Measurement Lab (M-Lab) servers, and signal strength and serving-cell state were not independently recorded. The chart supports order-of-magnitude and usability comparisons, not a continuous cell-throughput curve.

Background and drill design

The Executive Yuan described the exercise as a simulation of constrained communications during natural disasters, large-scale cyberattacks, or compound emergencies. The northern exercise covered Keelung, Taipei, New Taipei, Taoyuan, Hsinchu City, Hsinchu County, and Yilan. Voice, SMS, text transmission, 110/119 emergency calls, and cell broadcasts were expected to remain operational. Video streaming, video calls, mobile payments, and cloud synchronization could be affected.

Taiwan’s Executive Yuan notice confirms the time and area. An Anoni.net community measurement guide records the published download ceiling as 256KB. The source notation does not clearly distinguish KB/s from kbit/s, so this report preserves it as written.

Because the time, geography, and participating operators were announced in advance, the exercise offered an unusual window for community measurement. This observation addressed three questions.

  1. When did the mobile connection recover enough to complete performance tests after the announced end?
  2. Did general throughput and streaming workloads recover in the same direction?
  3. Could Tor and Snowflake establish connections under constrained bandwidth?

Official information contained a schedule discrepancy. A few earlier local-government pages listed 13:30–14:00, while the 23 July Executive Yuan notice and newer local notices consistently listed 14:30–15:00. This report uses the later schedule.

Method

Measurement tools

OONI stands for the Open Observatory of Network Interference, an open-source project for measuring internet performance and interference. NDT, the Network Diagnostic Test, measures download, upload, and latency. DASH, Dynamic Adaptive Streaming over HTTP, simulates adaptive video streaming.

Tor is an anonymity network that routes traffic through multiple relays. Snowflake is a Tor pluggable transport that connects through short-lived proxies run by volunteers. An ASN, or Autonomous System Number, identifies the network operator carrying a measurement.

Vantage point and safety gates

  • The observation took place in Taipei; the exact location is withheld.
  • The laptop connected only to a 4G phone hotspot using the same Taiwan Mobile SIM.
  • Included measurements used AS24158, Taiwan Mobile Co., Ltd.
  • The tools were OONI Probe CLI/miniooni 3.30.0 and Tor 0.4.9.11.
  • All timestamps use Asia/Taipei.
  • NDT, DASH, Tor, and Snowflake ran sequentially to prevent bandwidth contention.
  • Before each slot, the workflow checked the default interface, ASN, operator, VPN, Tailscale, active utun interfaces, required commands, and OONI consent and upload state.

OONI’s Tor test checks reachability of directory authorities and obfs4 bridges. obfs4 is an obfuscation protocol designed to make Tor traffic harder to identify. The Snowflake test records bootstrap progress, meaning how far Tor has progressed in starting and connecting to its network. OONI’s data interpretation guidance recommends reading individual results together with network, time, and repeated-measurement context.

NDT is operated by M-Lab. M-Lab stores the public IP address and time associated with a test in its public research dataset. Neither this report nor the downloadable safe dataset exposes that address. M-Lab NDT documentation

Actual observation timeline

Timeline of valid mobile observations in Taipei, the official drill window, impaired post-window tests, and the complete 17:47 retest.

The NDT and DASH runs at 14:35 used a fixed-line exit and were excluded from the mobile analysis. The valid event-window mobile result is the 14:53 Tor measurement. Post-window tests ran from 15:08 to 15:23, followed by a complete retest from 17:47 to 17:49. The safe dataset retains scheduled time, actual time, status, and exclusion reason.

Results

Download still measured 55 kbit/s at 15:08

Metric14:16 pre-drill15:08 post-window17:47 later retest
Download141,997.8 kbit/s55.2 kbit/s30,131.6 kbit/s
Upload13,981.8 kbit/s1,399.7 kbit/s20,310.0 kbit/s
Ping27.6 msunavailable23.0 ms
Average RTT66.0 msunavailable46.1 ms
Test runtime27 s94 s25 s
Test traffic207.9 MB10.3 MB72.4 MB

At 15:08, download was about 0.039% of the pre-drill result and upload was about 10.0%. Downstream impairment was far stronger. At 17:47, download measured 30.1 Mbit/s and upload measured 20.3 Mbit/s, with NDT completing in 25 seconds. Download had increased 546-fold and upload 14.5-fold from the first post-window result.

The 15:08 record reports both ping and average RTT as zero, conflicting with test runtime and the other fields. This report treats those values as missing. All three runs report zero retransmit rate; that field alone cannot explain the throughput difference.

Streaming changed from timeout to completion

TimeDASH median bitrateConnect latencyTest runtimeResult
14:16 pre-drill75,2830.184 s18 scompleted
15:10 post-window00155 sgeneric_timeout_error
17:47 later retest31,6440.033 s31 scompleted

The 17:47 DASH test completed successfully, with median bitrate at about 42% of the single pre-drill value. The OONI output used here does not expose a display unit that can be safely confirmed for this bitrate field, so the table preserves the raw values. Completion supports restored streaming-test functionality; server path and radio conditions still affect the numeric comparison.

Tor and Snowflake established connections throughout

Total runtime of Tor and Snowflake tests before, during, and after the drill, including the later complete retest.

All five valid Tor measurements reported directory reachability of 10/10, directory-authority OR-port reachability of 10/10, and obfs4 reachability of 4/14. Runtime rose from 69 seconds before the drill to 96 seconds near the end of the event and 124 seconds at 15:15, then fell to 78 seconds at 15:21 and 67 seconds at 17:48. Reachability counts remained stable while runtime increased around the event and returned close to the pre-drill value later.

Snowflake reached 100% bootstrap in all three runs. Bootstrap time was 6.68 seconds before the drill, 17.29 seconds at 15:18, and 12.78 seconds at 17:49. Total runtime was 11, 25, and 16 seconds. These results establish that Tor over Snowflake could connect at those moments. They do not cover sustained browsing, calls, or large transfers.

Discussion

1. Restoration time belongs in resilience criteria

The announced window ended at 15:00. This observation still showed clear impairment through 15:12 and functional NDT and DASH results at 17:47. The measurements bound recovery to 15:12:48–17:47:30. The interval remains wide, yet it demonstrates that an announced end time and an individual subscriber’s experienced recovery can diverge. Future exercises should publish a restoration criterion and report the long tail of subscriber recovery.

2. Functional recovery and baseline equivalence are separate questions

At 17:47, download was far above the 55 kbit/s throttle-level result and DASH completed, supporting functional recovery. Download was 21% of the single pre-drill result and DASH median bitrate was about 42%. One vantage point, different servers, and unrecorded radio conditions prevent direct attribution of those ratios to residual throttling. Confirming full restoration would require a fixed device and position with at least two consecutive results near a defined baseline threshold.

3. Anonymity tools crossed the minimum viability threshold

Tor directory access and Snowflake bootstrap succeeded near the end of the event and afterward. The constrained network still allowed these tools to establish connections, while longer runtimes meant longer waits. Evaluating access to shelter information, message exchange, or practical use of an anonymous channel also requires small text-page success rates, time to first byte, full load time, and connection persistence.

Limitations and uncertainty

  • One location, SIM, operator, and device cannot represent Taipei, Taiwan Mobile, or all seven municipalities.
  • There is no valid mobile NDT/DASH observation from 14:30 to 14:52, so the event-window minimum and throttle curve cannot be estimated.
  • There are no observations between 15:12 and 17:47, leaving the precise recovery time unknown.
  • Signal level, band, serving cell, movement, and cell load were not independently recorded.
  • The three NDT runs used different M-Lab servers, combining access, routing, and server conditions.
  • Tor’s 4/14 obfs4 result covers the sampled bridges and cannot describe every obfs4 bridge.
  • Tor and Snowflake success establishes short probe and bootstrap viability, without measuring sustained application quality.
  • Voice, SMS, cell broadcast, emergency calls, payments, and specific messaging apps were outside the test scope.

What should happen next

A stronger protocol should cover all three mobile operators, multiple locations, and independent SIMs. During the event, each site should use the same NDT, DASH, Tor, and Snowflake sequence. After the announced end, NDT and DASH should repeat every five minutes until two consecutive sets return to a defined share of baseline. Each result should include signal strength, radio band, and serving-cell changes. Local scheduling should continue through connectivity loss, and failed tests should remain in the dataset.

Official technical guidance should use an unambiguous unit such as kbit/s or kB/s, state downlink and uplink targets separately, define a restoration deadline, and publish aggregated recovery statistics for all three operators. Communications resilience reporting should cover service continuity, degradation magnitude, and restoration time.

Data and reproducibility

The safe CSV preserves municipality, scheduled and actual times, ASN, operator, test, status, traffic, and requested result fields. It contains no public IP address, OONI UID, or Measurement URL. OONI data are cited under the project’s CC BY-NC-SA 4.0 data licence.

Principal background sources

← 回文章列表