Workshop

No One Is Driving Your Packet

Published on: 2026-07-15

By: Ian McCutcheon

You read my anycast piece. And if a chunk of it felt slippery — the same address answering from a hundred places at once, packets that never seem to leave town — yeah. Fair. I skipped a step. Before any of that lands, you've got to see how a packet actually moves in the first place. So let's back up. This one's the ground the anycast piece was standing on.

First, let me reach into your head and pull out one bad idea. You picture a packet like a car. You've got the address, you point the car at it, off it goes — and somewhere, something knows the whole way there. Start to finish. A route.

Nope. Nothing knows the whole way there. Let me show you.

My buddy's at the game. Section 118, row 32, seat 15. I want to get a note to him. So I write it, and across the front I write: pass this along until it reaches section 118, row 32, seat 15. Then I hand it to the guy next to me. That's it. That's all I do.

He reads the front. The address. The destination — and that's all he cares about. He glances around, figures 118 is off to his left somewhere, passes it left. Next guy reads the front, figures it's a row down, hands it down and over. Nobody stands up. Nobody plots a route across the whole stadium. Nobody's in charge of this thing. Every single person does exactly one job: read where it's going, figure out roughly which way that is, and shove it that way.

And here's the fun part — before the game's even over, the note reaches my buddy. Thousands of people, each making one tiny local decision, and it just... shows up. That's a packet. That's the whole thing. I'm not simplifying for you — that's actually it.

When he opens it, the first line says: this is from me — section 102, row 23, seat 22. Return address. A packet always carries where it came from, stamped right on it. Does he write back? Whole other story, and we're not going down that road today. We're just watching the trip out.

So throw away the god's-eye view. There's no map floating over the stadium. And — I'll say the quiet part out loud — there's no routing table you need to care about either. Forget it exists. From the packet's own eyes the trip is way simpler, and way weirder, than the car version.

The packet shows up at a door. Call it a gate, a hop, a router — it's a door. Walks up, says one thing: I'm going here. And the brain at that door — the conductor — looks at the address, looks at its doors, and goes: then you want door two. Down that road. Packet walks through door two, down the road, hits the next door. Says the exact same thing. I'm going here. Different conductor, different door.

There are always multiple doors. (Seen the Matrix? The endless hallway, all the doors? There you go.) And not one of these doormen knows where you'll end up. Not one has the map. Each knows one thing: of the doors in front of me, which one points roughly toward there. That's it. That's every router on the planet, all of them, no exceptions.

No driver. Nobody in charge. The whole internet — the entire thing — is just this: strangers at doors, each making one local "that-a-way" call. It doesn't work because someone's steering. It works because everyone's pointing.

Now sit in the hole that leaves you, the engineer, standing in. If nobody has the map — if every door knows only its own next step and nothing past it — then how do you and I ever see the path a packet actually took? You can't ask the network for the route. There is no route to ask for. There's no file anywhere with it written down. And yet — you've traced paths across the internet a thousand times. So what is that tool actually doing?

This is where traceroute stops being magic.

Every packet carries a field called TTL. Time To Live. Worst-named thing in all of networking, because it's got nothing to do with time. It's a number, and it counts doors. Packet's born, gets stamped with a starting value — 64 on a Mac or Linux box, 128 on Windows (Microsoft's gotta be different, always) — and every door it passes through, that conductor subtracts one before handing it on. 64, 63, 62, down with every hop. A normal packet starts at 64 and basically never runs the tank dry. Sixty-four doors is more than most trips on this planet will ever need.

So why bake in a countdown at all? Because of the one nightmare the whole system has to prevent. The loop. Picture three doors screwed up so A points to B, B points to C, and C points right back to A. A packet wanders in and never comes out. A to B to C to A to B to C. Forever. Now picture a million of them. No countdown, and those packets pile up in that loop until the links themselves choke on traffic that can never die. So we don't let packets live forever. TTL is the leash. The instant a conductor goes to subtract one and it'd hit zero — it stops. Does not forward. Drops it — we say the packet expires — and then it does one last, useful, polite thing: it turns around and mails a note back to whoever sent it. Your packet died here. This is me — here's my name, here's where I am. In the trade that note's an ICMP "time exceeded," and the return address on it is the router's own.

Now hold that in one hand — a packet that expires makes the door it died at announce itself — and watch what traceroute does with it. Because traceroute doesn't send normal packets. It cheats. On purpose. And honestly, it's kind of beautiful.

You point it at a destination and it starts asking one question, over and over, of one stranger deeper into the stadium each time: if I were headed all the way to the far end — who are you, and which way would you send me? And it gets each stranger to cough up the answer by handing them a note built to die in their hands.

First probe? Stamped with a TTL of one. One door and it's dead — the very first conductor ticks it to zero, expires it, mails back its "this is me." And just like that, you know stranger number one. Its address, and how long the round trip took. Then a second probe, TTL of two. Clears the first door (two ticks to one, still breathing), reaches the second, ticks to zero, dies there — so the second conductor announces itself. Three for the third. Four for the fourth. One door deeper every time. Each probe a note you know is going to expire in one specific stranger's hands, just to force that stranger to raise a hand and say who they are. (It fires three probes at each step — that's why you get three little timing numbers on every line. Mystery solved.)

And here's the last clever bit — the part that tells traceroute it's finally arrived. On a Unix or Linux box, traceroute doesn't send a normal packet at all. It fires a UDP packet at a deliberately ridiculous, high port number — something like 33434 — a door nobody sane is ever listening behind. Every router along the way treats it like anything else and expires it right on schedule. But when a probe's TTL is finally big enough to go the full distance and land on the real destination — that machine doesn't send back "time exceeded." It's not a hop. It's the endpoint. It looks at that absurd port, finds nobody home, and answers port unreachable. That one different reply is how traceroute knows the trip's over and shuts up. (Windows plays the same game with a different knock — ICMP echoes, plain old pings, instead of UDP — but the engine underneath, the TTL countdown, is dead identical.)

So look at a traceroute one more time. New eyes. Every line is not a step on a route that got written down somewhere — because it wasn't; there's no such file. Every line is a stranger you reached out and interrogated. A conductor you forced to raise its hand. By mailing it a packet you knew would die exactly there. Your gut was right the whole time. That's not a path. It's an interrogation, one door at a time.

And now you can finally put anycast back in its box — because it was never a different animal. Same note, passed hand to hand, exactly like everything else. The only thing that changes is the address on the front. Your note to your buddy said section 118, row 32, seat 15 — one exact guy, one chair. Write a different note. On the front put the popcorn guy. Hand it to your neighbor the same way. He's got no seat to aim for — but he knows popcorn guys work every section, and there's usually one down and to the right, so off it goes. It gets passed toward popcorn, not toward a seat, and it lands in the hands of whichever popcorn vendor's nearest. Same note. Same passing. Same relay of strangers each making one local call. The only difference: the destination isn't a place, it's a role a whole crew answers to — and you get the closest one. That's anycast. Different stitch, another day.

This is the one underneath all of them. No driver. Only the next door. And it quietly rewrites how you'll troubleshoot for the rest of your career. You stop asking "what's the route?" — there isn't one, there never was — and you start asking the only question that was ever real: which stranger pointed the wrong way? Every routing problem you'll ever chase collapses down to that. Go find the door that sent the packet down the wrong road.

No one is driving your packet. It gets there anyway. One stranger, one door, one local call at a time.

Now go trace something.