4 ms·
He states that there is no way that a public IP would show up in a packet capture over a Tor network. No, he does not. He says that there's no way a public IP
by michael_storm 12y ago
He states that there is no way that a public IP would show up in a packet capture over a Tor network.
No, he does not. He says that there's no way a public IP would show up at layers 3 or 4 of the OSI model. The author takes the position that the IP leak must have come from layer 7 (quoting from the article):
[...] and it is at the application layer that the FBI uncovered the IP address.
Depending on how one interprets the FBI's wording, this impossibility contradicts their accounting of how they discovered the IP. Let's look at what the FBI said:
Upon examining the individual packets of data being sent back from the website,3 [sic] we noticed that the headers of some of the packets reflected a certain IP address not associated with any known Tor node as the source of the packets.
Note that they're talking about headers of the packets, not HTTP headers. This is the FBI, though, so it's possible they confused "packets" with "HTTP requests". Taking their words at face value, though, the FBI seem to say that they got the IP address from the IP headers on packets received from Silk Road, or at least traffic generated by their browser on behalf of Silk Road. That's what the author argues is impossible.
Nobody, least of all the author, disputes that Silk Road could have leaked its IP in HTTP headers, or via some other misconfiguration. But if they did, why didn't the FBI just say that? Why claim that they leaked it in the IP layer?
Two possibilities come to mind. The first is that the FBI got the IP from the application layer, as everyone believes is possible, and misattributed the leak to the IP layer due to terminology confusion. The second is that they got the IP from another source, attempted to deceptively misattribute the source, and accidentally picked a fake source the leak could not have come from. If the second option is the case, we're looking at an example of parallel construction.
Edit: Grammar. Gotta keep up appearances.
- MaulingMonkey 12y agoNote that they're talking about headers of the packets, not HTTP headers. HTTP headers are in the packets, and I could see myself very very very easily writing "of the packets" in lieu of "in the packets". When proofreading, I'd be much more likely to catch the extra "3" in that same sentence, than to catch the s/in/of/ as introducing confusion.
- ssmoot 12y agoMy gut reaction to that is skepticism. I've done basic switch configuration, looked at packets, had to troubleshoot MTU and MRU misconfiguration in commercial switches, etc. Conceptually stuff at that layer is a long ways from the actual content. It's like pointing to a guy walking his dog at the park after noticing a parked car with it's lights on, and saying "there's the owner in the car" vs "there's the owner of the car". It feels, to me, like those sorts of linguistic mistakes must be exceedingly rare? Or maybe the person writing up the statement wasn't the person who generated the notes and they just had a transcription error. I'd buy that I guess.
- diminoten 12y agoYour gut reaction is to lean towards conspiracy rather than a simple typo/transposition in the mind of the FBI agent who wrote the report?
- ssmoot 12y agoThat's awful snarky, and misses the point entirely. My gut reaction is that if I, as a civilian, were to ask an FBI agent for details about a case, I'm as likely to receive half-truths and lies by omission as anything at all though. So if you want to be pedantic I guess so. I did point out that I'd believe it could just be a transcription error by someone unfamiliar with the subject matter though.
- diminoten 12y agoThe point here is that this is nothing more than a simple writing mistake on the part of the FBI. Pretending like there's some conspiracy or parallel construction taking place here is just nonsense and the folks suggesting it are doing so out of irrational fear more so than any actual evidence. Your gut reaction seems to place you in the camp of the conspiracy theorists. That should raise alarm bells for you.
- ssmoot 12y ago
- donavanm 12y agoIts entirely possible to leak addresses at layer 3, ICMP. Redirect and Type 3 unreachables intentionally encode additional IP headers inside the data segment. Additionally ICMP processing goes up to the control plane, not just a data/routing/forwarding plane. Its incredibly common to get back valid ICMP responses sources from RFC1918/3330 space on the internet. The router (or whatever) responds with the "private" management address as the source. I would not be surpised in the least to have a box leak "private" or unintential data via ICMP.