11 ms·
Show HN: How did your computer reach my server?
- luckman212 3y ago> "Hi! I'm Lexi. I'm 17..." Holy shit. This girl's going places. I just skimmed https://kognise.dev https://kognise.dev and saw that in addition to the deep understanding of TCP/IP and all 7 layers of the OSI model she appears to posses, she also does front- and back-end development, embedded hardware, mobile apps, and compilers. She also rock climbs, can pilot a Cessna (all by herself), build robots, plays (and composes music for) the cello (since she was 5 years old apparently). Do I need to keep going? This is nothing short of incredible. If I did 1/10 of the things this kid's already done by the time I kick the bucket I would have lived a full life.
- Alifatisk 3y agoWow! Impressive is an understatement, she has achieved so much at that her age.
- jcrawfordor 3y agoVery cool way to present this. Obviously there's a lot of legwork here, but for major ISPs you could probably use some heuristics to give a little more detail on internal network structure. Comcast, for example, has their core network under ibone.comcast.net, but their HFC infrastructure directly under comcast.net. So you can tell when traffic makes the jump from their HFC consumer ISP network to their backbone. At one point I had some notes on patterns like this for a number of the majors but I think I've lost it. :(
- deadbabe 3y agoYou can even use traceroute to send short hidden messages! :D
- deleted 3y ago[deleted]
- zharknado 3y agoGreat write up, thank you for making this! From a learning design perspective, the blend of static and dynamic prose based on my own packet’s journey was super cool, not something I’ve seen done quite that way before. Makes me imagine an online programming textbook that could to walk you through what your own custom code is doing. Very cool!
- collsni 3y agoAkami blocks the return trace which is no fun. But regarless a cool project. 9 a23-203-147-39.deploy.static.akamaitechnologies.com (23.203.147.39) 36.707 ms 36.783 ms 40.110 ms 10 * * * 11 * * * 12 * * * 13 * * * 14 * * * 15 * * * 16 * * * 17 * * * 18 * * * 19 * * * 20 * * * 21 * * * 22 * * * 23 * * * 24 * * * 25 * * * 26 * * * 27 * * * 28 * * * 29 * * *
- spondylosaurus 3y agoLove the looooong furret in your header image! :D
- aizyuval 3y agoI might not now an y better, but this implementation seems so cool. Can I trace the location of an AS?
- xfish1 3y ago[dead]
- averageRoyalty 3y ago> My claim that this website’s traceroute was the path your packets took to reach my server was a bit of a white lie. To calculate that, I would’ve had to be able to run a traceroute to my server from your computer. Instead, I ran the traceroute from my server to your computer and just reversed it. That’s also why the traceroute at the top seemingly loads in reverse order. I was wondering if we'd address this. That was my first thought - how can you do this without initiating ICMP from my side? > Does running a “reverse traceroute” sacrifice accuracy? A little, actually. > As I said when describing Internet routing, each device a packet traverses makes a decision about where to send the packet next until it reaches its final destination. If you send a packet in the other direction, the devices might make different routing decisions… and if one device makes one different decision, the rest of the path will certainly be different. > This reverse traceroute is still helpful. The paths will be roughly the same, likely differing only in terms of which specific routers see your packet. Sure... But it's pretty common for multi pathed AS' to traverse in all sorts of different ways. My experience (non residential) is that more often than not, the trace and reverse trace were different. Your upstreams and my upstreams have very different commercial agreements, and both peer and transit in multiple places. Still cool though, well done!
- sgjohnson 3y agoIPv6 support would be great for this. I run my own AS (AS200676) and one of my prefixes is actually announced at my home. I'm really curious as to what would the auto-generated green text say about that route. I announce only IPv6, because I don't currently have access to any v4 blocks, they are expensive and I have little need for one.
- keep_reading 3y agoThere's no possible way to guarantee that traceroute is accurate. The same route is not taken both directions. A Practical Guide to (Correctly) Troubleshooting with Traceroute by Richard A Steenbergen explains it well
- archmaster 3y agoHi! I'm Lexi. I'm 17, and one of the things I'm interested in right now is gaining a deeper understanding of how computers work and showing that in new ways. A few months ago I published https://cpu.land https://cpu.land (discussion: https://news.ycombinator.com/item?id=37062422 https://news.ycombinator.com/item?id=37062422). After cpu.land, I felt a lot of pressure to make another Big Giant Thing but didn't really have anything compelling. So I just hacked away on personal projects and, through some coincidental learning on how the Internet works, ended up hacking together a traceroute program that could live stream to a website from scratch! I realized I had never seen this sort of thing on the web before, and it was actually a kind of cool and novel way of visualizing the structure of the Internet, so I polished it up and built a pretty site around it. In the process, I learned some really interesting things about how BGP and the structure of The Internet, so I melted the traceroute tool with an article sharing that knowledge. I'm still hacking on this and I'm sure my code will manage to break somehow, so please let me know if you have any suggestions! :) (Side note: why Rust? I don’t think programming language choice matters that much, but I wanted to quickly write a very dependable low-level program, and I really like Rust’s error handling primitives. Why do you care about this?)
- glandium 3y ago> I felt a lot of pressure to make another Big Giant Thing but didn't really have anything compelling. Easier said than done, but don't feel like you have to provide a constant flux of interesting things. That kind of pressure ends up being toxic pretty quickly. Do what you enjoy, if it hits an audience, great, but don't feel like you have to make it happen.
- r3trohack3r 3y agoThis is absolutely amazing <3 The narrative based traceroute in green is something I’ve never seen before. How many providers, like CDNs, did you take the time to map into a narrative? This feels targeted towards folks who kind of already understand computers. It be cool to repackage this in a way that can show non-technical people the stuff they take for granted. The mountains that move on a user’s behalf under every keystroke is humbling. One of my favorite books on this topic is Interconnections: Bridges, Routers, Switches, and Interconnections by Radia Perlman if you haven’t come across it.
- monkeyjoe 3y agoOn my device, there are no intermediate steps shown between my device and the server. Just FYI.
- themoonisachees 3y agoWell maybe if you'd not browse HN from inside linode data centers it'd work better :P
- archmaster 3y agoYeah, sorry, Hacker News has successfully made my server chug a lot :) I'm working on it right now and hopefully will be working better soon! In the meantime I've increased timeouts so loading will be longer but it should work better.
- macksd 3y agoSame here! But I'm gonna bookmark this and try it another day. Kudos for sharing this - love to see younger folks hacking. This is a cool idea.
- archmaster 3y agoShould work a little better now! It's still chugging, but I made the rest of the article load (although now it's a bit janky when you have JS disabled, but not much I can do)
- noort 3y agoDoesn't work at all with Enhanced Tracking Protection enabled in Firefox, and times out when it is disabled. I guess it's supposed to do something like this: https://dnschecker.org/online-traceroute.php https://dnschecker.org/online-traceroute.php
- archmaster 3y agoShouldn't have anything to do with Enhanced Tracking Protection, but my server is buckling under the traffic pressure! I'm working on it, maybe check back in 40m or so (SORRY!)
- Rastonbury 3y agoDo you have a VPN on as well? It works for me on FF mobile with Enhanced protection
- noort 3y agoNo I think I just tested it while his server was intermittently failing and it happened to correspond to switching this setting off and on.
- ibejoeb 3y agoHere's some earlier work on reverse traceroute: https://research.cs.washington.edu/networking/astronomy/reverse-traceroute.html https://research.cs.washington.edu/networking/astronomy/reve... paper: http://www.cs.washington.edu/homes/ethan/papers/reverse_traceroute-nsdi10.pdf http://www.cs.washington.edu/homes/ethan/papers/reverse_trac... video: http://www.usenix.org/multimedia/nsdi10katz-bassett http://www.usenix.org/multimedia/nsdi10katz-bassett
- c0pium 3y agoYou might be interested to know that many times, packets in a TCP session take asymmetric routes across the internet. In my experience, the most common reasons for this are business rules related to cost and human error. If you think about how IP works, you’ll see that this doesn’t particularly matter but that it can make understanding the routing more difficult.
- liquidgecka 3y agoFun story time! Boise State University, and the University of Idaho are two schools at opposite ends of the state of Idaho. UIdaho in the north is close to Spokane, and almost all of its connectivity comes from Seattle. Boise is closer to Salt Lake so most of its connectivity comes via Portland or Salt Lake City. The middle of the state between the two schools is mountains and very, very little large scale connectivity at all, except there was a small line way bad in the day because the UofIdaho had remote classrooms in the southern part of the state. Sometime in the late 90's a network engineer from BSU and one from UofI realized that they both had switches and routing kit in the same building so they ran an ethernet cable between them. The effect was catastrophic. It turns out that both networks happily started announcing BPG to each other, which in turn announced the connection to the internet as a whole. Suddenly there was a very short jump between networks in Seattle and networks in Salt Lake City. That poor little t1 (iirc) was absolutely getting saturated. But, interestingly only in one direction. See Boise announced the route, but Idaho didn't so the traffic was effectively only failing in one direction. Needless to say the cable as disconnected and years later when I worked at the UofIdaho it was still well known that the two networks shouldn't ever be connected again! (Which was ironic because I was working on a program to setup I2 at both universities)
- supermatt 3y agoThis is "how your server reaches my computer but reversed" rather than "how my computer reaches your server". The routing in each direction will most likely be very different.
- archmaster 3y agoYeah, there is actually a whole section about this in the article! Called "Front to Back, Back to Front". tl;dr in my experience the networks traversed are usually very similar, and the content is relevant and interesting either way around
- Mountain_Skies 3y agoBack in the days of bang paths, it was interesting to see how different a sender's bang path might be to the bang path for your reply and try to figure out what network connection differences caused the asymmetry.
- nullindividual 3y agoHere's a paper you might be interested in with regards to how traceroute works. One thing that many (non-network) folks miss is that traceroute is not necessarily symmetrical -- the return path may differ. https://archive.nanog.org/sites/default/files/traceroute-2014.pdf https://archive.nanog.org/sites/default/files/traceroute-201...
- archmaster 3y agoTY, will read! I touched on this duality in the article actually :)
- justsomehnguy 3y agoIt's extremely rare but the data paths can be asymmetrical too. Eg satellite with a ground based uplink.
- ta1243 3y agoDue to internet problems in Egypt earlier today with Telecom Egypt, I had a traceroute to the same destination going via _8_ different paths. Have to say that's twice the higher number of ECMPs I've seen on the internet in the past. And yes, traffic is routing different ways from my Cairo office to my UK core --London ->Cairo is direct and still suffering massive loss, Cairo->London is now routing via ntt and seems fine. If they haven't fixed it by tomorrow might have to change some local prefs.
- yieldcrv 3y ago[flagged]
- intelVISA 3y agoremember the avg person presses colorful squares on a screen to "operate a machine" this type of self-directed exploration is still in the hacker spirit imo even if it's not the Next Big Thing according to greybeards I enjoyed using it and i'm sure many others too, though i do agree we're in interesting times with how regressed the modern understanding of computing truly is
- ericmcer 3y agoIf you had a non-traditional computer education (I definitely did) there will be huge holes because your skillset is going to be hyper practical. All of these concepts are just somewhat arbitrary rules nerdy white guys came up with 30+ years ago, there is no way someone would understand them unless they were specifically taught them. Programming isn't like music or math where there is a natural order underlying the man-made rules.
- OrderlyTiamat 3y ago> Programming isn't like music or math where there is a natural order underlying the man-made rules. I'd like to reinforce your point by disagreeing on two counts: programming (in so far as it's related to computer science) is like music and math in that there is loads of underlying natural order that can be independently derived (think about the lambda calculus vs Turing machines which are proven to be identical, for one example). That underlying beauty is there, and I think it's there because computer science is a part of (or at the very least akin to) mathematics. Secondly, both math and music are, like programming, not really that devoid from arbitrary rules nerdy white guys came up with 30(0)+ years ago. When you're tuning an instrument, you'll likely tune it to the western chromatic scale- but that's just a convention, there are more scales! Just as much of a convention is to tune that scale to concert pitch, where A is tuned to 440 Hz. But that's not required- concerts will tune to 422.5 Hz when playing Handel. There are all kinds of conventions all around us which are invisible because we're accepting them as a given of the world, more so if we have a traditional education in that field. That's why it's enjoyable to see stuff like this, what intel-VISA called self-directed exploration, it deepens your understanding and is just fun!
- Hasz 3y agoI think it's also worth mentioning mtr, which is what I use much more frequently than traceroute. It can help diagnose intermittent packet loss, and gives you an averaged sense of how things flow. This article from APNIC explains more about mtr and how to read it (plus some interesting details about how MPLS can obscure true paths) https://blog.apnic.net/2022/03/28/how-to-properly-interpret-a-traceroute-or-mtr/#:~:text=Traceroute%20is%20a%20one%2Dshot,is%20the%20tool%20to%20use https://blog.apnic.net/2022/03/28/how-to-properly-interpret-.... Also worth noting: It's also sometimes useful to trace with UDP, and many routers will drop ICMP selectively under strain. Nice article, and excellent presentation!
- magnat 3y agoYou can go one step further and instead of separate ICMP ECHO trace, use existing HTTP TCP connection between client's browser and your web server. That way you can traverse client-side NAT and/or stateful firewall.
- archmaster 3y agoOoh, that's compelling. I wonder how that would work for an actual traceroute.
- ryan-c 3y agocalled a "parasitic traceroute"
- mikewarot 3y agoSQUIRREL!!! How did you manage to tilt the section header text? I've not seen that done before.
- archmaster 3y agoCSS transforms! transform: rotate(-2deg) skew(-2deg); transform-origin: bottom left;
- tonetheman 3y ago[dead]
- kazinator 3y agoThere should be a traceroute protocol whereby a "specially marked packet" is understood to be traceroute, and generates an ICMP response even though its TTL is still positive. The ICMP response will carry the observed TTL value. Then one packet will get all the echoes in one go instead of having to send a tirade of packets with increasing TTL values.
- plingbang 3y agoCombined with IP source address spoofing, it would probably help greatly with DDoS amplification attacks while only saving up <50% packets for good users. If you care about time rather than packet count, you can send packets with all reasonable TTL values at once.
- kazinator 3y agoOh no question; the amplification is concerning. Send one packet, get 19 responses, versus having to send 19 packets to get 19 responses: it's a "gain" of 19 to 1.
- ta1243 3y agoHave enough problems with routers not sending normal ttl expired messages Just use a better client. Takes about 3 seconds to do an mtr -b over 15 responding hops from a server in London to something like 43.249.179.0 in the south pacific.
- netfortius 3y agoNANOG relevant talk (PDF): https://archive.nanog.org/sites/default/files/10_Roisman_Traceroute.pdf https://archive.nanog.org/sites/default/files/10_Roisman_Tra...
- Kinrany 3y agoDo the h3 heading tags look like they're tilted a little bit? CSS/font trickery? Just me?
- WaffleIronMaker 3y agoYes, they are tilted: .text h3 { margin-top: 60px; margin-bottom: -4px; transform: rotate(-2deg) skew(-2deg); transform-origin: bottom left; }
- denton-scratch 3y ago> WHOIS is actually an... interesting protocol to make a parser for. It's actually impossible. Responses are essentially free-form (if the server responds at all). I tried my hand at this; you can make an ad-hoc "parser" that works for 90% of addresses/domains (or you could, ten years ago when I tried). But the remainder are intractable. Nowadays it's much worse; nearly everything is hidden behind privacy shields, which purport to protect PII. But WHOIS records aren't supposed to contain personal information; they're supposed to contain contact information for network operators. This is ICANN's doing, I'm afraid. ICANN had a rule that networks should provide public WHOIS servers. They never enforced the rule, and now they've scrapped it.
- deathanatos 3y agoRDAP contains some of the WHOIS information in a machine-readable format. (JSON) Not everything, but I think it's better. Not everything runs an RDAP server, though; I do wish ICANN/IANA or whoever would enforce that. > Nowadays it's much worse; nearly everything is hidden behind privacy shields, which purport to protect PII. But WHOIS records aren't supposed to contain personal information; they're supposed to contain contact information for network operators. Network operator info can also be PII. My info is PII, but I have a domain name, so putting my info into WHOIS is putting PII into WHOIS. The privacy guard just forwards everything to me, minus spam. (If it's a corporation, I don't think there's a good reason to permit privacy guards. But not all domains are owned by BigCos, yet.)
- thiht 3y agoRegarding RDAP, it actually is enforced by ICANN, it’s been mandatory for a few years for gTLDs (not sure if it is, or can be made mandatory for ccTLDs). All registrars handling gTLDs should now have an RDAP, otherwise they’re in breach of ICANN rules. RDAP has the benefit of being JSON, but even then it’s a reaaally crappy format. For example, contacts are represented by the jCard pseudo-standard, which is a JSON version of vCard, and it’s completely awful and hard to deal with. Basically instead of a nice JSON object, it’s arrays in arrays in arrays… RDAP should get better in the future versions, but I’m not sure registrars will follow in good faith because the initial specs were a bit of a shit show.
- quantum5 3y ago> BGP is the protocol that gives the Internet its shape, and you can’t directly speak it yourself. It's actually surprisingly easy to get an ASN for yourself and speak BGP. If you find building something like this tool interesting, you should give it a try. I wrote an introduction of sorts earlier (https://qt.ax/asn https://qt.ax/asn) if that interests you.
- at0mic22 3y agoAs it was mentioned above, you are not measuring connection from the client to the server, but from the server to the client. It can be a completely different route, and internal routing behind the IP is hidden. You should try 0trace to get the real route
- senectus1 3y agoNote, I geo-block IP's not from Australia for my home network. This is why it failed for me.
- sltkr 3y agoWhy?
- elwebmaster 3y agoIt would be cool to add a map of the hops.