Summary
- A 24 September Internet Society Pulse guest article explains HERMES, which looks for performance changes in user-triggered M-Lab speed tests against each group's own baseline.
- The project's dashboard labels an attributed segment “Likely source” and expressly calls it an inference, not a finding of fault; event detail requires a signed-in query.
- Different path-direction coverage and grouping regimes limit what a public ranking alone can establish about any particular network.
A network can answer packets and still deliver a markedly worse service. That is the problem Loqman Salamatian set out in a 24 September guest article for Internet Society Pulse. HERMES repurposes measurements that users initiate at M-Lab: it compares a network-and-location group's experience with its own earlier baseline, then examines path evidence to localize a shared change. In the researchers' Chicago/Cogent example, latency rose by more than 200 milliseconds and a route detoured. This is their illustrated diagnosis, not a BTW determination that Cogent committed a fault or owed a remedy.
The scale deserves care. M-Lab's August research account describes about four billion tests over five months and roughly 65,000 detected events. Those are the analyzed corpus and detector output, not a census of every Internet impairment. Users choose when to run tests, so participation is uneven. The project also says a comprehensive ground-truth catalogue of incidents does not exist. Cross-checks can support a method without turning each candidate attribution into an adjudicated fact.
The project's dashboard, currently marked “staging,” makes that distinction unusually visible. Its Overview says “Likely source,” a label changed from “responsible entity,” and explicitly disclaims a finding of fault. Yet deeper guide text still uses responsibility language. A reader seeing only the ranked source may miss the uncertainty. Public population views can be browsed, but event-level detail calls for a Google/M-Lab sign-in because BigQuery work is charged to the viewer's quota. The evidence is not categorically hidden; it has a different access and reproduction path from the overview.
Two further boundaries matter. The guide says reverse traceroute is present for about a quarter of tests; the Pulse article says bidirectional evidence was needed for roughly half of the problematic links its authors examined. The denominators differ. The guide also identifies current metro · ipinfo and older city · maxmind groupings. A discontinuity across those regimes can reflect how observations were bucketed, not a sudden change in network health.
For a public claim to travel safely, its citation should carry the event group, time window and baseline, path-direction coverage, grouping regime, candidate source, and the available correction state. That is Daniel Kade's editorial test, not a HERMES policy or an operator obligation. The dashboard offers a way to flag a wrong inference; that correction route is useful precisely because a statistical lead is capable of changing. The right headline is that a shared degradation may be observable before a network goes down—not that a likely-source field has assigned blame.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

