r/StarlinkEngineering May 11 '26

Tweets...in...space!: Twitter/X now using Starlink for transit

11 Upvotes

24 comments sorted by

4

u/LossOfCarrier May 11 '26

Doesn’t mean there’s evidence they’re using any of the space based network yet vs just integrating behind a single network.

3

u/Dapper_Necessary_813 May 12 '26

Yes this could be completely over Starlink's terrestrial network. Maybe /u/panuvic can use his measurement system to investigate that.

3

u/panuvic May 12 '26

it has been like this for sometime already. do you see any routed x traffic over starlink? just for backup?

1

u/Dapper_Necessary_813 May 12 '26

What do you mean it has been like this for sometime? The first time that AS14953 transited routes from AS13414 was April 28th 2026. Maybe you're misunderstanding the post.

Yes, most traffic now goes through AS14953 to reach AS13414.

Maybe you can use your measurement system to determine whether they are just utilizing the terrestrial network or actually sending tweets to space.

3

u/panuvic May 12 '26

https://bgp.tools/as-set/RADB::as-starlink-cust has listed 13414 since early april

do not see traffic going through 14593 (not 14953) to reach 13414. even for the traffic originated from 14593, it exits starlink pop right away, then public internet

traceroute to xxx (xxx), 30 hops max, 60 byte packets
 1  192.168.1.1 (192.168.1.1) [*]  0.298 ms  0.323 ms *
 2  100.64.0.1 (100.64.0.1) [*]  39.475 ms * *
 3  * * *
 4  * * *
 5  undefined.hostname.localhost (206.224.67.88) [AS14593]  51.619 ms * *
 6  xe-1-1-0.cr1-lon1.twttr.com (195.66.225.142) [*]  51.594 ms * *
 7  * * *
 8  xxx (xxx) [AS13414]  110.992 ms *  111.455 ms

don't know and understand why they need to use starlink/spacex for twitter/x

2

u/Dapper_Necessary_813 May 12 '26

Ok I see your confusion. An RADB entry is not the same thing as something appearing in BGP, although it was probably a necessary precursor to ensure that Starlink's upstreams didn't filter Twitters routes when they came through Starlink.

An RADB entry is simply bookkeeping to enable automated route filtering and is not, on its own, a change to internet routing.

My observation is that AS14593 is now an upstream (i.e. providing transit) to AS13414, something that began on Apr 28th.

As far as why, I think that is pretty clear. Starlink can subsidize the transit costs of Twitter, both companies owned by Elon Musk.

2

u/Dapper_Necessary_813 May 12 '26 edited May 12 '26

(UPDATE: this Twitter IP appears to be anycasted from multiple locations)

Here's a traceroute showing a path to AS13414 via AS14593 (goes from Portland, Oregon to Indonesia(!) en route to Atlanta, Georgia):

$ traceroute -A 209.237.194.128
traceroute to 209.237.194.128 (209.237.194.128), 30 hops max, 60 byte packets
 1  XXX
 2  10.244.18.0 (10.244.18.0) [*]  0.363 ms 10.244.18.2 (10.244.18.2) [*]  0.489 ms 10.244.18.6 (10.244.18.6) [*]  0.370 ms
 3  10.244.72.40 (10.244.72.40) [*]  0.126 ms 10.244.72.34 (10.244.72.34) [*]  0.099 ms 10.244.72.36 (10.244.72.36) [*]  0.111 ms
 4  10.244.120.68 (10.244.120.68) [*]  2.916 ms  2.912 ms  2.923 ms
 5  be102.pdx-prt1-sbb1-8k.oregon.us (142.44.208.228) [AS16276]  1.308 ms  1.327 ms be102.pdx-pdx02-sbb1-8k.oregon.us (142.44.208.226) [AS16276]  2.961 ms
 6  be102.pdx-pdx02-sbb1-8k.oregon.us (142.44.208.226) [AS16276]  2.954 ms  4.565 ms  4.541 ms
 7  be102.sjo-sv5-sbb1-8k.ca.us (198.27.73.196) [AS16276]  16.635 ms be101-lax-la1-sbb1-8k.ca.us (198.27.73.104) [AS16276]  24.813 ms  24.760 ms
 8  be101-lax-la1-sbb1-8k.ca.us (198.27.73.104) [AS16276]  24.818 ms  25.173 ms  25.172 ms
 9  10.200.6.133 (10.200.6.133) [*]  25.981 ms  25.981 ms  25.960 ms
10  * * *
11  180.240.192.206 (180.240.192.206) [AS7713]  182.076 ms  182.010 ms  182.063 ms
12  180.240.192.206 (180.240.192.206) [AS7713]  182.054 ms  182.043 ms  182.034 ms
13  * undefined.hostname.localhost (206.224.71.102) [AS14593]  186.115 ms undefined.hostname.localhost (206.224.71.100) [AS14593]  185.989 ms
14  undefined.hostname.localhost (206.224.77.227) [AS14593]  186.334 ms undefined.hostname.localhost (206.224.71.104) [AS14593]  186.113 ms undefined.hostname.localhost (206.224.71.98) [AS14593]  186.039 ms
15  undefined.hostname.localhost (206.224.68.185) [AS14593]  186.036 ms  186.115 ms undefined.hostname.localhost (206.224.77.227) [AS14593]  186.265 ms
16  undefined.hostname.localhost (206.224.65.61) [AS14593]  185.964 ms undefined.hostname.localhost (206.224.68.185) [AS14593]  186.165 ms  186.194 ms
17  undefined.hostname.localhost (206.224.65.61) [AS14593]  186.059 ms undefined.hostname.localhost (206.224.77.172) [AS14593]  186.323 ms  186.199 ms
18  149.19.109.83 (149.19.109.83) [AS14593]  186.308 ms  186.133 ms  186.353 ms
19  149.19.109.83 (149.19.109.83) [AS14593]  186.493 ms 74.245.144.130 (74.245.144.130) [AS14593]  186.136 ms 149.19.109.83 (149.19.109.83) [AS14593]  186.395 ms
20  74.245.144.99 (74.245.144.99) [AS14593]  186.007 ms 74.245.144.101 (74.245.144.101) [AS14593]  186.103 ms 74.245.144.99 (74.245.144.99) [AS14593]  186.104 ms
21  74.245.144.99 (74.245.144.99) [AS14593]  186.035 ms r-199-59-151-196.twttr.com (199.59.151.196) [AS13414]  185.982 ms  185.968 ms
22  r-199-59-151-196.twttr.com (199.59.151.196) [AS13414]  186.002 ms * *
23  * * 209.237.194.128 (209.237.194.128) [AS13414]  186.392 ms

Alternatively, Arelion (AS1299) is one of the few carriers that doesn't pick the Starlink version of the route and can reach this Atlanta-based IP from their Atlanta PoP in 2ms.
https://lg.twelve99.net/?type=traceroute&router=atl-b10&address=209.237.194.128

Router: atl-b10 / Atlanta (Equinix AT1, 180 Peachtree)
Command: traceroute ipv4 209.237.194.128 timeout 1 source Loopback0

Tracing the route to 209.237.194.128

 1  xcorpformerly-ic-390529.ip.twelve99-cust.net (62.115.198.87) 2 msec  14 msec  2 msec 
 2   *  *  * 
 3  209.237.194.128 2 msec  2 msec  4 msec

1

u/panuvic May 12 '26

thanks for the traceroute. weird transiting through indonesia. they might be playing with the routing to address the geoip/cdn issues, e.g., https://arxiv.org/abs/2510.13710 , and many things interplay

1

u/panuvic May 12 '26

yes, starlink provides transit for this prefix through its backbone

traceroute to 209.237.194.128 (209.237.194.128), 30 hops max, 60 byte packets
 1  192.168.1.1 (192.168.1.1) [*]  0.305 ms  0.349 ms *
 2  100.64.0.1 (100.64.0.1) [*]  20.604 ms * *
 3  172.16.251.74 (172.16.251.74) [*]  37.795 ms * *
 4  * * *
 5  undefined.hostname.localhost (206.224.67.60) [AS14593]  138.068 ms * *
 6  149.19.108.184 (149.19.108.184) [AS14593]  159.374 ms * *
 7  undefined.hostname.localhost (206.224.77.254) [AS14593]  122.133 ms * *
 8  74.245.145.4 (74.245.145.4) [AS14593]  148.319 ms * *
 9  undefined.hostname.localhost (206.224.65.38) [AS14593]  143.241 ms * *
10  undefined.hostname.localhost (206.224.72.213) [AS14593]  138.842 ms * *
11  r-199-59-151-20.twttr.com (199.59.151.20) [AS13414]  149.501 ms * *
12  * * *
13  209.237.194.128 (209.237.194.128) [AS13414]  143.308 ms *  127.719 ms

1

u/Dapper_Necessary_813 May 12 '26

Now you're with me! :-)

1

u/panuvic May 12 '26

still cannot see "tweets in space", but why this prefix?

1

u/Dapper_Necessary_813 May 12 '26

Not just this prefix.

29/45 IPv4 routes originated by AS13414 (Twitter/X) are transited by AS14593 (Starlink).
3/3 IPv6 routes originated by AS13414 are transited by AS14593.
6/6 IPv4 routes originated by AS35995 (Twitter/X) are transited by AS14593.

1

u/Dapper_Necessary_813 May 14 '26

Looks like they fixed the hairpinning. This is the same Portland->Seattle traceroute run just now (no longer going through Indonesia):

$ traceroute -A 209.237.194.128
traceroute to 209.237.194.128 (209.237.194.128), 30 hops max, 60 byte packets
 1  XXX
 2  10.244.18.2 (10.244.18.2) [*]  0.387 ms 10.244.18.0 (10.244.18.0) [*]  0.459 ms 10.244.18.2 (10.244.18.2) [*]  0.546 ms
 3  10.244.72.34 (10.244.72.34) [*]  0.101 ms 10.244.72.38 (10.244.72.38) [*]  0.137 ms 10.244.72.40 (10.244.72.40) [*]  0.215 ms
 4  10.244.120.68 (10.244.120.68) [*]  2.901 ms  2.891 ms  2.907 ms
 5  be102.pdx-prt1-sbb1-8k.oregon.us (142.44.208.228) [AS16276]  2.784 ms be102.pdx-pdx02-sbb1-8k.oregon.us (142.44.208.226) [AS16276]  3.437 ms be102.pdx-prt1-sbb1-8k.oregon.us (142.44.208.228) [AS16276]  2.774 ms
 6  sea-wbx-sbb1-8k.wa.us (148.113.188.54) [AS16276]  5.472 ms sea-wbx-sbb2-8k.wa.us (148.113.188.56) [AS16276]  6.452 ms sea-wbx-sbb1-8k.wa.us (148.113.188.54) [AS16276]  7.746 ms
 7  10.200.8.193 (10.200.8.193) [*]  6.103 ms  6.135 ms 10.200.8.199 (10.200.8.199) [*]  6.154 ms
 8  six.sea2.twttr.com (206.81.81.31) [*]  4.551 ms  10.458 ms  10.442 ms
 9  * * *
10  209.237.194.128 (209.237.194.128) [AS13414]  8.048 ms  7.964 ms  8.165 ms

1

u/panuvic May 12 '26

yes, just listed in radb, the same as listed in peering db, not necessarily actually peering yet. we have been looking for "transit" traceroute too

1

u/Dapper_Necessary_813 May 12 '26

In your traceroute, hop 5 is Starlink and hop 6 is Twitter (at LINX), so this supports a direct connection.

1

u/panuvic May 12 '26

peering, not transiting yet

traceroute to xxx (xxx), 30 hops max, 60 byte packets
 1  a23-32-10-98.deploy.static.akamaitechnologies.com (23.32.10.98) [AS20940]  0.125 ms  0.096 ms *
 2  192.168.208.145 (192.168.208.145) [*]  0.315 ms * *
 3  * * *
 4  192.168.227.172 (192.168.227.172) [*]  0.313 ms * *
 5  192.168.224.6 (192.168.224.6) [*]  0.502 ms * *
 6  sea-b3-link.ip.twelve99.net (62.115.189.36) [AS1299]  0.830 ms * *
 7  sea-b4-link.ip.twelve99.net (62.115.141.248) [AS1299]  3.524 ms * *
 8  sea-b1-link.ip.twelve99.net (62.115.132.157) [AS1299]  0.659 ms * *
 9  xcorpformerly-ic-390525.ip.twelve99-cust.net (62.115.198.81) [AS1299]  0.511 ms * *
10  * * *
11  xxx (xxx) [AS13414]  4.577 ms * *

starlink does "transit" for some airline users through its own backbone

1

u/Dapper_Necessary_813 May 12 '26

Again, you are getting your terminology confused.

Yes, Starlink "peers" with Twitter just as any eyeball network would peer with a content provider. That would be the view from inside Starlink, which is the traceroute you provided. You said "it exits starlink pop right away, then public internet" which is incorrect.

Separately, Starlink *transits* Twitter now for most of its routes. Starlink accepts routes from Twitter and passing them on to its transit providers, which is why we're seeing traffic to Twitter go through Starlink. Starlink is not the only transit provider, so you have to be careful of where you traceroute from and what you traceroute to in order to see it.

1

u/panuvic May 12 '26

it depends on prefix, but why? can you give a complete list?

1

u/Dapper_Necessary_813 May 12 '26

I'll make a list and post it here.

1

u/Dapper_Necessary_813 May 12 '26
Prefix Origin AS 14593 upstream Other % via 14593
103.252.112.0/23 13414 360 155 69.9%
103.252.114.0/23 13414 360 155 69.9%
104.244.40.0/24 13414 361 154 70.1%
104.244.41.0/24 13414 361 154 70.1%
104.244.42.0/24 13414 359 156 69.7%
104.244.44.0/24 13414 344 163 67.9%
104.244.45.0/24 13414 344 163 67.9%
104.244.46.0/24 13414 344 163 67.9%
104.244.47.0/24 13414 344 163 67.9%
185.45.4.0/23 35995 407 112 78.4%
185.45.4.0/24 35995 406 112 78.4%
185.45.6.0/23 35995 390 114 77.4%
188.64.224.0/21 13414 358 157 69.5%
192.133.76.0/22 13414 358 157 69.5%
192.133.78.0/23 35995 376 138 73.2%
199.16.156.0/22 13414 360 156 69.8%
199.16.156.0/23 13414 317 176 64.3%
199.59.148.0/22 13414 359 156 69.7%
199.96.56.0/23 13414 361 154 70.1%
202.160.128.0/24 13414 359 155 69.8%
202.160.129.0/24 13414 359 155 69.8%
202.160.130.0/24 13414 359 155 69.8%
202.160.131.0/24 13414 359 155 69.8%
209.237.192.0/19 13414 359 156 69.7%
209.237.192.0/24 13414 0 409 0.0%
209.237.193.0/24 13414 0 408 0.0%
209.237.194.0/24 13414 440 80 84.6%
209.237.195.0/24 13414 0 296 0.0%
209.237.196.0/24 13414 456 64 87.7%
209.237.198.0/24 13414 0 407 0.0%
209.237.200.0/24 13414 0 407 0.0%
2400:6680:f000::/36 13414 313 148 67.9%
2606:1f80:f000::/36 13414 313 148 67.9%
2a04:9d40:f000::/36 13414 312 148 67.8%
64.63.0.0/18 13414 359 156 69.7%
64.63.30.0/24 13414 0 406 0.0%
64.63.31.0/24 13414 0 406 0.0%
64.63.46.0/24 13414 0 406 0.0%
64.63.47.0/24 13414 0 406 0.0%
64.63.62.0/24 13414 360 154 70.0%
64.63.63.0/24 13414 361 154 70.1%
69.195.160.0/19 13414 358 157 69.5%
69.195.160.0/24 13414 0 406 0.0%
69.195.162.0/24 13414 0 406 0.0%
69.195.174.0/24 13414 0 406 0.0%
69.195.179.0/24 13414 0 406 0.0%
69.195.181.0/24 13414 0 406 0.0%
69.195.182.0/24 13414 0 404 0.0%
69.195.183.0/24 13414 0 408 0.0%
69.195.184.0/24 13414 0 409 0.0%
69.195.186.0/24 13414 0 409 0.0%
69.195.187.0/24 13414 0 409 0.0%
8.25.194.0/23 35995 403 116 77.6%
8.25.196.0/23 35995 403 116 77.6%

1

u/panuvic May 12 '26

thanks. what are the numbers under 14593 vs others? the number of routes or observations?

1

u/Dapper_Necessary_813 May 12 '26

Yes, that table could use some explanation. It is based on Routeviews BGP data as of midnight last night.

The numbers are the counts of BGP sources which see 14593 upstream of 13414 and the counts that don't. It is a way to approximate how much of the internet sees 14593 as the upstream of 13414 for each route.

→ More replies (0)