2 ms·
The "ip" field used to hold the plain IP address, so it's still called that, even though it now holds a hash. The post() function fills it in like so: $quer
by irvwash 7y ago
The "ip" field used to hold the plain IP address, so it's still called that, even though it now holds a hash.
The post() function fills it in like so:
$query->bindValue(':ip', isset($post['ip']) ? $post['ip'] : $identity);
It's called from https://github.com/OpenIB/OpenIB/blob/master/post.php#L988 https://github.com/OpenIB/OpenIB/blob/master/post.php#L988, but $post never gets an 'ip' key, so it always uses $identity (which was created using getIdentity(), which currently hashes the IP address).
I think the method you describe for checking whether a post could have come from an IP address would work, if they gave up all the relevant salts. secure_trip_salt isn't supposed to change. hashSalt is also needed, because the IDs are generated using the hashed IP addresses, but it's changed infrequently from what I remember (changing it logs out all moderators because sessions are tied to IP addresses, so it's easy to notice).
- molticrystal 7y agoThanks for locating that line. I think between the two of us we've figured out all the relevant parts of the system and assessed what is going on with post ids and ips in the database. At minimum, from my understanding, ipv4 addresses look 100% recoverable with the database and $hashSalt, and 3 upper octets recoverable as long as you have hashSalt, secure_trip_salt and an archive of the thread. Of course this is just from the board software perspective, so the next layer in assessing the privacy of the users with regards to what the FBI can get, is the server, hosting, and upstream providers whether intentional or otherwise may have additional identifying information , for example cache or logs that can be correlated with the posts.