Report sheet LN-09 · filed 27 Sept 2026
Network Labs: a network bench in a tab — candid, mostly
Probe, sweep, short links and passwords on one page. Our run found one panel timing the wrong server.
- Instrument
- labs.llc/labluxa/
- Shelf on labs.llc
- Live Intelligence · Internet
- Bench
- Local copy of the build-537 files
- Run
- 27 Sept 2026 · 20:10–20:12 UTC
- Controls
- Globalping · who.is
- Evidence
- Source lines in the build; timed reads
Aim
Network Labs puts four instruments on one page: a probe for any domain or IP — your own public address and its reverse DNS, DNS-over-HTTPS resolution, the registry’s RDAP record, five timed round trips, the address block’s owner and a path sketch marked as illustrative; a sweep timing requests to about seventy-five popular sites across six continents; a short-link maker with a moderation queue; and a password generator with seven recipes. Probe and sweep export a PDF report.
It is for curious users and small-site owners who want a no-install look at a domain or their own connection. We tested each panel against what its code actually asks for.
Method
Apparatus: what it reads, and where the work happens
Mostly browser work (labluxa/assets/js/app.js 1–15). The probe gets your address from api.ipify.org, PTR and A records from dns.google, then tries RDAP at rdap.org, rdap.iana.org and rdap.verisign.com in turn, with 7-second timeouts, for registrar, dates and nameservers (208–275), and asks ipapi.co who owns the address block (297–310). The path panel is a fixed list of hops, labelled as illustrative because browsers cannot run a traceroute (312–318). The sweep resolves each site through dns.google and times a no-cors HEAD with a 6-second timeout (358–415).
Only short links touch the server: save.php takes POST only, keeps auto-approval off and allows 20 links per address per hour, because an earlier version was an open redirect; redirect.php answers 302, re-validates the destination and ignores pending links. Passwords come from crypto.getRandomValues with rejection sampling, so there is no modulo bias (29–38).
It reads
- api.ipify.org (your public address)
- Google Public DNS JSON API (A and PTR)
- RDAP: rdap.org, rdap.iana.org, rdap.verisign.com
- ipapi.co (address owner, ASN, place)
- No-cors HEAD requests to about 75 named sites
- labs.llc’s own short-link store (same origin)
Procedure
On 27 September 2026 (20:10–20:11 UTC) we fetched the page, queried the link endpoints without creating a link, repeated the probe’s registry chain for wikipedia.org, timed the probe’s own round-trip request against a direct request to the target, tried the ownership lookup, and read the password recipes in the code.
Result
Fig. 11280 × 800
Fig. 2390 × 844
Table 1 · Run log, 27 September 2026
| No. | Reading | UTC | What came back |
|---|---|---|---|
| 1 | Page and link endpoints | page HTTP 200, 56,512 bytes; check.php: ‘index’ reserved, a test code available; save.php by GET: HTTP 405 | |
| 2 | RDAP chain, wikipedia.org | rdap.org → rdap.publicinterestregistry.org: MarkMonitor Inc., registered 2001-01-13, expires 2027-01-13, ns0–ns2.wikimedia.org | |
| 3 | The probe’s ‘round trips’ | five Google DNS requests: 32, 56, 33, 34, 30 ms; direct HEADs to wikipedia.org for contrast: 49, 38, 41, 43, 38 ms | |
| 4 | Ownership lookup (ipapi.co) | refused as RateLimited — the probe would print ‘Ownership lookup did not answer.’ | |
| 5 | Password recipes, from the code | ‘words’: three from a 26-word list, about 14 bits (about 23 with number and symbol); ‘mnemonic’ about 19 bits; default random at 16 characters: strong |
The registry chain worked and the link service held firm. Two panels did not match their labels: the round trips time a request to Google’s DNS service about the target, not to the target (app.js line 287), and the ‘markov’ recipe’s note promises English-weighted letters that the code draws uniformly (678–684).
Discussion
Two controls: the same job done elsewhere on the web. Each was read on its own page on the date shown, and each is better than Network Labs at something.
Globalping
Checked .
Runs ping, traceroute, MTR, DNS and HTTP measurements from a worldwide network of probes chosen by country, city, ASN, ISP or cloud region, with a REST API, a CLI and chat apps; open source, with free limits.
Where it is better
- Real ping, traceroute and MTR from many places; Network Labs can only time HTTPS from your browser.
- An API and CLI for automation.
Where Network Labs goes further
- Your own address, reverse DNS, DNS, the RDAP record and address ownership in one probe, with a PDF report.
- A CSPRNG password bench and a moderated short-link maker on the same page.
who.is
Checked .
A domain lookup site with tabs for WHOIS, RDAP, DNS records, certificate, uptime, diagnostics and history.
Where it is better
- Certificate, uptime and history views that Network Labs lacks.
- A dedicated RDAP view beside WHOIS.
Where Network Labs goes further
- For wikipedia.org on the test day, the probe’s RDAP chain returned registrar, dates and nameservers; who.is’s WHOIS tab showed only a notice that access was restricted. We did not open its RDAP tab, which may well show the same record.
- It also measures your side: public address, reverse DNS and a six-continent sweep.
Sources of error: where it falls short
- The latency figure is mislabelled: it times Google’s DNS service (30–56 ms whatever the target), not the target.
- Weak word-based passwords (about 14–23 bits) with no strength shown; the ‘markov’ note describes weighting the code does not do.
- Ownership depends on ipapi.co, which refused us; there is no RDAP fallback for addresses.
- No real ping, traceroute or multi-location testing — by necessity, and the page says so.
- RDAP is reduced to five fields, with no raw record view.
Conclusion
FindingThe RDAP chain worked; the ‘round trips’ timed Google’s DNS service, not the target.
Network Labs is at its best where it is frank: RDAP from three endpoints, a path diagram that calls itself a sketch, a link service rebuilt after a real lesson. Our run found that frankness missing in two places — a latency figure measuring the wrong server and a password note overstating its method — plus a lookup that can refuse. For wikipedia.org its RDAP chain returned what who.is’s WHOIS tab would not; for real network paths, use Globalping.