Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting

Details

External ID
46386878
Source
HN
Company
—
Product
Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting
Website domain
github.com
Launched
Dec. 25, 2025
Cohort
—
Upvotes
86
Upvotes percentile
0.8835877862595419
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

TL;DR explanation (go to https://github.com/Sakura-sx/Aroma?tab=readme-ov-file#tldr-e... if you want the formatted version)This is done by measuring the minimum TCP RTT (client.socket.tcpi_min_rtt) seen and the smoothed TCP RTT (client.socket.tcpi_rtt). I am getting this data by using Fastly Custom VCL, they get this data from the Linux kernel (struct tcp_info -> tcpi_min_rtt and tcpi_rtt). I am using Fastly for the Demo since they have PoPs all around the world and they expose TCP socket data to me.The score is calculated by doing tcpi_min_rtt/tcpi_rtt. It's simple but it's what worked best for this with the data Fastly gives me. Based on my testing, 1-0.7 is normal, 0.7-0.3 is normal if the connection is somewhat unstable (WiFi, mobile data, satellite...), 0.3-0.1 is low and may be a proxy, anything lower than 0.1 is flagged as TCP proxy by the current code.

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Security
Function
Observability & eval
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
tcp proxy detection via rtt fingerprinting
Manually corrected
False

Could you build this?

Partial A simple demo script using CDN edge logs or kernel socket metrics is accessible, but building a robust proxy-detection system via TCP RTT fingerprinting requires deep networking research and edge compute infra.

What it would actually take: Built on edge serverless platforms like Fastly VCL or eBPF in the Linux kernel to sample raw socket metrics (`tcp_info` struct, `tcpi_min_rtt`, and smoothed RTT). The difficult piece is developing the statistical heuristics and timing analysis algorithms to reliably distinguish reverse proxies and VPN hops from natural jitter and asymmetric routing without false positives. Requires deep TCP/IP networking expertise and edge observability infrastructure.

Discussion

20 comments analyzed.

Competitors mentioned: XVCL for VCL code writing, sshuttle transparent proxy, CONNECT proxy, SOCKS proxy, BrighData residential proxies

Concerns raised: Detection can be bypassed with VPNs or protocol changes, High false positive rates when blocking legitimate customers, Doesn't work against RDP/VM-based proxies, TCP RTT fingerprinting defeated by quick-ack or QUIC, Scrapers can use 100k residential IPs vs VPN's 5 egress IPs

Feature requests: Support for QUIC/H3 protocol detection, MASQUE proxying support, Fingerprinting detection for tunnels through QUIC, Layer 3 eBPF-based proxy detection, WebSocket RTT comparison detection

Competitors

Other products that read as similar to this one — 101 launches clear the similarity bar, closest 8 shown.

Attention rank: #15 of 102 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 57 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a observability & eval tool for Media & entertainment yet.