Talk about putting your money where your mouth is!
You're viewing a single comment thread. View all comments, or full comment thread.
Comments (57)
sorted by:
Wow, I have experience with pcaps files and packet anaylsis, definitely worth a look.
Oh, it's an invite only event. Bugger.
That's too bad. I was going to ask you to report back with your analysis.
If anyone gets wind of a copy of the files being made available, I would definitely perform a proper analysis and create a report. I'd love a chance to do my bit.
Faking pcaps files is almost impossible with any kind of volume. The timings and packet sequences would be easy to spot if they were out of sequence.
In addition, if there are missing 'retries' then that would indicate that the files had been filtered first etc. (i.e. so not raw).
I'm a qualified expert in the field.
In addition to what you stated (which is 100% true; TCP protocol), the fact that they are all TLS packets with origination certificates and fully decrypted... It's virtually impossible to fake this. How they managed to MITM all of this is really an amazing achievement.