Summary

  • A 24 September Internet Society Pulse guest article explains HERMES, which looks for performance changes in user-triggered M-Lab speed tests against each group's own baseline.
  • The project's dashboard labels an attributed segment “Likely source” and expressly calls it an inference, not a finding of fault; event detail requires a signed-in query.
  • Different path-direction coverage and grouping regimes limit what a public ranking alone can establish about any particular network.

A network can answer packets and still deliver a markedly worse service. That is the problem Loqman Salamatian set out in a 24 September guest article for Internet Society Pulse. HERMES repurposes measurements that users initiate at M-Lab: it compares a network-and-location group's experience with its own earlier baseline, then examines path evidence to localize a shared change. In the researchers' Chicago/Cogent example, latency rose by more than 200 milliseconds and a route detoured. This is their illustrated diagnosis, not a BTW determination that Cogent committed a fault or owed a remedy.

The scale deserves care. M-Lab's August research account describes about four billion tests over five months and roughly 65,000 detected events. Those are the analyzed corpus and detector output, not a census of every Internet impairment. Users choose when to run tests, so participation is uneven. The project also says a comprehensive ground-truth catalogue of incidents does not exist. Cross-checks can support a method without turning each candidate attribution into an adjudicated fact.

The project's dashboard, currently marked “staging,” makes that distinction unusually visible. Its Overview says “Likely source,” a label changed from “responsible entity,” and explicitly disclaims a finding of fault. Yet deeper guide text still uses responsibility language. A reader seeing only the ranked source may miss the uncertainty. Public population views can be browsed, but event-level detail calls for a Google/M-Lab sign-in because BigQuery work is charged to the viewer's quota. The evidence is not categorically hidden; it has a different access and reproduction path from the overview.

Two further boundaries matter. The guide says reverse traceroute is present for about a quarter of tests; the Pulse article says bidirectional evidence was needed for roughly half of the problematic links its authors examined. The denominators differ. The guide also identifies current metro · ipinfo and older city · maxmind groupings. A discontinuity across those regimes can reflect how observations were bucketed, not a sudden change in network health.

For a public claim to travel safely, its citation should carry the event group, time window and baseline, path-direction coverage, grouping regime, candidate source, and the available correction state. That is Daniel Kade's editorial test, not a HERMES policy or an operator obligation. The dashboard offers a way to flag a wrong inference; that correction route is useful precisely because a statistical lead is capable of changing. The right headline is that a shared degradation may be observable before a network goes down—not that a likely-source field has assigned blame.

Sources