3 ms·
The challenge with any tool that uses the probe traffic other than the traffic of interest is that the results may be specific to the probe traffic and complete
by ay 2y ago
The challenge with any tool that uses the probe traffic other than the traffic of interest is that the results may be specific to the probe traffic and completely different from the one you care about.
In theory, iOAM (https://datatracker.ietf.org/doc/rfc9326/ https://datatracker.ietf.org/doc/rfc9326/) is a much more robust mechanism.
In practice, internet works on the least common denominator, which means that Traceroute (which is a clever hack on top of the ICMP TTL exceeded behavior, a required internet standard) is often the best one can have, if at all. (And if not, then one has to resort to uglier hacks)
That said - one should not underestimate how much info one can dig out by varying TTL/hop count, changing the 5-tuple (source and destination address and ports + protocol), and tweaking the packet rate.
And the dismissive attitude about “absolutely impossible to do anything with this info unless you are Fortune 500” is wrong. For a counter example of cooperation between the “people of the internet”, here’s a nice presentation:
https://youtu.be/G_Ir_gRlst0?feature=shared https://youtu.be/G_Ir_gRlst0?feature=shared
As one can derive from the above - it’s absolutely possible, just that the level of SNR required to be reacted to is rather high, well above “my Traceroute is not showing what I think it should be showing”. Which, given the population of the internet, isn’t entirely unreasonable.