all
a
/
b
/
c
/
f
/
h
/
j
/
jp
/
l
/
o
/
q
/
s
/
sw
/
lounge
cgi
up
wiki
Heyuri!
Bulletin Boards
2D Cute
2D Ero
2D Lolikon
3D Girls
Anime/Manga
Flash
Girl Talk
日本語/Japan
Lounge
Oekaki
Off-Topic
Site Discussion
Strange World
Overboard
Heyuri★CGI
Heyuri★CGI
@PartyII
Battle Royale R
Chat
Chinsouki★
Dating
DevChat
Drama Club
Hakoniwa Islands PvE
Hakoniwa Islands PvP
Polls
Slime Breeder
Web Banana
Web Shiritori
Yumemiru Gambler
Kakiko Checker
Other
Anime Nominations
Banners
Cytube
Heyuri Calendar
Heyuri Wiki
MAL Club
Museum
Steam Group
Uploader
[
Settings
]
[
Home
] [
Contact
] [
Catalog
] [
Search
] [
Thread list
] [
Stats
] [
Reports
] [
Watcher
] [
PMs
] [
Admin
]
Off-Topic@Heyuri
it's the place to be!
[
Return
]
Report a post
Preview
Rabbitfield
2025/11/02
(Sun)
19:12:54
No.
160967
[
Report
]
+
▶
Regarding: PACKETS
1. Packets you send over the internet have a beginning at your home network and its outgoing IP
2. Depending on whether your connection is encrypted intermediaries will or will not be able to see the exact contents of data you send and receive - demand encryption whenever possible ("man in the middle" attacks and extensive data collection are severe and urgent threats - refuse unencrypted connections)
3. If you use an encrypted end to end encryption be aware that only your end and the target's end can see the data (if you use a compromised system like MacOS, Windows, Android etc. expect also these corporations to see the contents - use a safe OS!)
4. Depending on whether or not you use proxies, how you many of them, and how you route the packets - it determines whether or not your packets can be read by someone else
4.1. When you use multiple proxies in an integral series (like TOR) - the other party will see your exit proxy only.
4.2. Avoid setting up multiple proxies into a separate series because the separation point will be able to have your decrypted information (unless you absolutely know what you want to achieve and there is no better solutions) - that is how "man in the middle" attacks work.
4.3. If you use proxies in paralel (like one port for proxy A and another port for proxy B) - do not mix up which one connects to what (because you might reveal information about you: mix up your multiple made-up identities, reveal that you are not a tech noob, "cross contaminate" your identities - its best to consider how much you want to reveal about yourself).
5. Packets despite encryption can reveal things:
5.1. Their size - if they are big there is probably file transfer, if they are small there is probably some message or a simple automated ping/response, you can somewhat evade giving out what type of info that was by modifying its size to trick them. Either by artificially making them bigger and rounding them up to a power of 2 or you can compress them to make them artificially small but both are not perfect.
5.2. Their frequency - if they of similar size and appear in regular time gaps - then there is some service going on most likely, if they are irregular then most likely the user is performing some task manually
5.3. What time of the day they go out - when you figure out which packets are those that highly suggest the user actively performing some tasks then timestamps of these packets may indicate what time zone the user is in after a few weeks of observation, or what kind of life they lead, it often correlates to when the user is at home working on the device - it might prove or disprove alibi, and many more
5.4. Unencrypted packet metadata - there are unencrypted bits in some (so research your protocol!), they might sometimes suggest what programs have sent them and it might lead to implications and deanonymization in a long term
Be aware that these are qualities of packets that are intrinsic to them. They are tied to the concept of a packet and cannot be avoided - they only can be laundered and anonymized but even that has its limits - as computing power of corporations and law enforcement grows with AI - assume that all these aspects not only can be considered but definitely will.
Use Wireshark (program) to snoop on your own packets and figure out what is readable, what performs what function and soon you will be able to figure out a lot of things about the object of your investigation. In this case yourself.
About hiding true metadata - you can attempt to "spoof" things. That is to pretend that your machine/program/config is different from the real one. To spoof correctly you need to deeply know the protocol and program that you use so that you do not forget about anything that might be automatically queried that would give you up.
TOR browser for example does spoofing in a way that they declare the same font, same browser, same screen resolution, same language, same timezone and whatever else as everyone else in order to make fingerprinting impossible - because if two things are undistinguishable then which one should be charged for what? Prosecutors do not know it either, good to abuse this fact of reality. It reminds me of one case when two identical twins were charged for murder but only one of them did it. First said it is the second one. Second said it was the first one. They could not tell them apart and eventually let the murderer go because they could not determine which of these two did it.
When you use TOR rememer to ALWAYS use the "safest mode" and use the default "NO JS" extension because these are the two things that make you look identical to other TOR browsers. Do not use onion sites that make you enable java script unless you are a deity. You should leave onion sites that make you use JS and deny to use them so that they die out. They were used to fingerprint, dox and arrest people.
Regarding: IP
1. Your end will see your IP and all intermediaries up until it reaches the IP of the server. Intermediaries like your ISP in particular, but also DNS, and other services in case you use them.
2. Each proxy adds one hop point for the connection where you may try to launder the next hop. It is tiresome for everyone who tries to spy on your but if they are the government - then assume they have the will and resources to force your proxy provider to give up the IP of the next hop, and the next until that finite chain reaches you and the server. (The best you can do is use offline communication like custom radio and decoders on both sides to create a separate chain of proxies where the link is truly broken and cannot be proven unless they analyze internet traffic of the entire earth. Easiest method of achieving it is getting into a random/open router and sending data from LAN level into the internet on their external IP).
3. TOR is only effective because genuine hackers cannot prove a link unless they monitor traffic of the entire earth (unrealistic), and effective from the law enforcement because the police decide not to engage in an investigation (because it is so hard to get the cooperation of the entire earth and they burn more resources to catch one connection than they see appropriate - it is only as effective as the price! If investigations get easier and cheaper then TOR will be pointless!). As of now it is unlikely that the entire earth will ban TOR at the same time and I deem it safe escape into an anarchy.
Additonally regards IP:
There are currently two IP protocol standards, IPv4 and IPv6. In short - always pick IPv4.
IPv4 IP leads to a network from which data originated. IPv6 IP leads not only to the network but a particular device! Set your Wifi to IPv4. Deny IPv6.
When you use IPv4 and leave your Wifi open without a password you can always claim that an alien device connected and posted it. If you use IPv6 they very likely will seize your devices to make sure if it was your device that posted. If you use IPv4 then they don't really have a claim to take your devices - only the router. It will make life much easier. Also if you fear they take your router - you might want to assign your mac address yourself to a new one - perform the deed, and then revert back to your regular mac address. The router might log mac addresses of devices but they are autodeclarative! You can make up any!
Regarding IP and the logging of it there is one more major thing - DNS.
DNS in short is a huge list that converts domains to IPs and IPs to domains, and whenever you type youtube.com into your browser instead of 221.52.65.199:80 or whatever their address is - you will need a DNS lookup! And the DNS checks what IP matches that domain and only then redirects you. The DNS provider can see what domain you typed in and can log it and tie it to your IP and other metadata depending on the protocol. You can run your own DNS if you are extra cautious (akin to running your own node in crypto instead of relying on an alien node that god only knows what they do with your data, you should always run your own node for safety).
https://www.youtube.com/watch?v=1cbMwvuGc6M
Post number
No.
160967
Board
Off-Topic@Heyuri
Reason
Optional. Describe what's wrong with it.
Style: