Archives

April 2004 (7)
March 2004 (12)
February 2004 (12)
January 2004 (22)
December 2003 (19)
November 2003 (16)
October 2003 (26)
September 2003 (18)
August 2003 (38)
July 2003 (80)
June 2003 (13)
May 2003 (24)
April 2003 (76)
March 2003 (75)
February 2003 (51)
January 2003 (73)

Category

Family (5)
FYI (18)
Games (2)
Geek (88)
Geographic (3)
Hacks (13)
Home (15)
Humor (54)
Ideas (20)
Ideaspace (15)
Local (15)
Metadata (10)
Microsoft (2)
MovableType (5)
Nitwits (66)
PKI (2)
Politics (22)
Quotes (3)
RDF (15)
RSS (4)
Security (3)
Semantic Web (13)
Site Info (13)
Social Networks (1)
Spam (9)
Sysadmin (1)
Tips (2)
Tivo (2)
TMFTOTHD (1)
To Do (1)
Unlisted (1)
Web (3)
Windows (1)

Local

« MetroBlogs »
DC metroblogs
beltway bloggers

Links


Assorted bits

Blogroll Me!
GeoURL
Listed on BlogShares




April 06, 2003

get yer tinfoil hats out!

The weblog community's got itself all a-quiver lately over whether the FBI is watching them. Puh-eeeze people! Gimme a frickin' break.

Web HTTP user agent and referral data is VERY easy to forge. It's possible, with the most trivial of effort, to make a perl script that will visit your site and fake what it sends you in it's referral and user agent fields. What can't be easily forged is the source IP address of the request. THAT'S what's important.

Surprise, surprise, the source IP address isn't from within the government. Of course the conspiracy theorists will undoubtedly find a way to explain that away...

Here's another tip, the browsers surfing out from a secured facility are likely to be proxied. That is, requests from them are likely to have their user-agent and/or referral data stripped off of them. This is the default behavior on most firewalls. This way you see the IP address of the proxy or the firewall, not the actual computer running the browser.

So if someone wanted to make up a referral request that looked like the big-bad-government was out to get you it would be TRIVIAL for them to do it. I'll bet that's the case here. Someone's just fucking with your heads people, wake up from your conspiracy nightmares.

But hey, it's much more fashionable to believe rumor and conspiracy, right? Nevermind truth and realities.

For the morbidly curious:

http://www.mrry.co.uk/index.php?page=1659
http://www.gulker.com/2003/04/04.html
http://inessential.com/?comments=1&postid=2462
http://groups.yahoo.com/group/weblogs-com/message/729

UPDATE: to the overly sensitive types, if I wanted to call people names I'd do so. It's category name so get over yourselves.

Nitwits
Perma  | TrackBack (1) | 04:29 PM  | xml

Navigation

Recent Entries

America and Europe: Vive la différence?
Server changes afoot
Diet behavior mod
Googling for sensitive info
Outlook 2003 and IMAP, a marriage made in Hell
Bike to Work Day, May 7th
Speakeasy rocks
Zippo USB?
When geographic data is nowhere 'near' correct
Local campaign contributions

User comments
Trackbacks

Contact

send me an e-mail E-mail
chat with me using MS messenger MSN Messenger
chat with me via AIM America Online
chat with me on ICQ ICQ
chat with me on Yahoo! Yahoo
Add my vCard to your electronic addressbook vCard
Friend of a Friend FoaF

Syndication

XML  RDF  CDF

Comments

XFML

Extra Stuff

foaf
vCard
pgp info
Linked In
Powered by
Movable Type 2.64