Hacker News new | ask | show | jobs
by cpncrunch 2022 days ago
>This is a pretty bad article.

The main problem I have with the article is that it's factually incorrect about it being easy to spoof an ip address in a situation like this. It's easy to send off a fake ip address if [1] your ISP permits spoofed ips (which it shouldn't) and [2] you don't care about a response. But in this case the user had to actually log into the system, which is pretty tricky to do with ip spoofing. (There is some debate about it potentially just requiring an email to be sent to a mailing list, but even SMTP requires various responses).

Given the level of technical difficulty to do this, it seems extremely implausible that someone would go to all that effort just to send out this message.

3 comments

> Given the level of technical difficulty to do this, it seems extremely implausible that someone would go to all that effort just to send out this message.

I agree. I think the two most plausible scenarios are that she too technologically illiterate to know that IP addresses are logged by ISPs and login systems, or the Governor has it out for her and hired someone to do it. I think both scenarios are totally feasible, though it's really hard to imagine she'd never heard of IP addresses before...

The original text from the parent post is "Butler, at the University of Florida, said making an IP address that appears to come from elsewhere isn't that complicated."

There is no specific mention of IP Spoofing, so I wouldn't assume that. By far the easiest method of making an IP address appear to come from somewhere else would be a proxy, but it's never precisely claimed, because that's not how rules of evidence work. The burden of proof is on the prosecutor, and we don't know exactly what is being alleged, nor how it will be defended. I assume that the search warrant is somewhere on the Internet, but without at least the warrant to add context, we fart into the wind.

But a proxy would have the proxy server ip, unless Rebekah was hosting a tor node or some other proxy at her home. Even in that case the ip is still at her home.
The state may well have had her wifi password from her work laptop she may have used at home at one time. The technical difficulty would be driving to her home then. If it is still possible I would try to secure logs from that device.