EMZETT.
Login

Hub

Hub Image: Head, Predatorix, CC BY-SA 3.0, Wikimedia Commons

In short: A simple network device that simply passes incoming data at one port on to all other ports, without knowing who it’s intended for.

In more detail: Because a hub blindly duplicates data, all connected devices effectively share the same bandwidth and “hear” all traffic (collision domain). In practice it has been almost completely replaced by switches, which send data specifically only to the right port.

In Depth

A pure signal amplifier without intelligence

A hub works at the physical layer (layer 1) of the OSI model and doesn’t “understand” the content of the data it forwards at all — it’s basically nothing more than an electrical signal amplifier with several connections. If a signal arrives at one port, the hub simply duplicates it electrically on all other ports, regardless of who it’s actually meant for. It reads neither MAC addresses nor any other address information from the header — it only “sees” electrical signal levels, not structured data.

Problem 1: a shared collision domain

This leads to two practical problems. First, all devices connected to a hub form a single shared collision domain — if two devices send at the same time, the electrical signals collide on the shared line, both transmissions become unusable and have to be repeated after a random waiting time (exactly the problem that CSMA/CD — carrier sense multiple access with collision detection — had to solve with classic Ethernet). The more devices are connected to a hub, the more often such collisions occur statistically, which makes the effectively usable bandwidth drop disproportionately as the number of participants rises — with a 10 Mbit/s hub and many active devices, often only a fraction of the nominal bandwidth actually arrived in the end.

Problem 2: lack of security through eavesdropping

Second, a hub is a security risk: since every connected device literally sees all traffic on the line (including traffic actually intended for another device), a single compromised or malicious device in the same segment can use a sniffer tool to read the entire data traffic of all other connected devices — including unencrypted credentials, unless the respective application brings its own encryption.

Replacement by switches

A switch fundamentally solves both problems by actively learning MAC addresses (unlike the blindly duplicating hub — it remembers which device is on which port by observing incoming traffic) and sending traffic specifically only to the right destination port instead of duplicating it to all ports. This creates a separate, collision-free connection per pair of ports, and listening in on other devices’ traffic is no longer possible in normal operation. Modern network hardware is therefore practically exclusively switch-based — real hubs are found today at most in very old infrastructure or deliberately for learning purposes or network diagnostics, when you want to capture the entire data traffic of a segment on purpose (a scenario for which modern switches would otherwise have to be configured specially via “port mirroring”).

See also: Switch, Bridge, Ethernet, MAC addresses