Slashdot Mirror


New RFC Adds "Evil Bit"

Nashirak writes "This is new RFC that introduces new security measures into IPv4 header. The measures include an "evil bit" that can be set an unset according to wether the packet is evil or not."

160 comments

  1. Intentional? by dracvl · · Score: 5, Funny

    What's this, a meta-dupe?

    1. Re:Intentional? by Anonymous Coward · · Score: 2, Insightful

      Of course it is. And the joke is on all those people too ready to whine about dupes (and the unceasing amount of aprils fools stories - no matter that they do this /every/ year), rather than thinking just a bit further. (It never ceases to amaze me how so many people here can forget that the editors are geeks just like us, and thus almost per definition should be assumed to have at least a moderate amount of intelligence.)

    2. Re:Intentional? by Anonymous Coward · · Score: 0

      Naaaah a super-dope-dupe.

    3. Re:Intentional? by wheany · · Score: 1

      I'm pretty sure it's intentional.

      People have probably submitted copy-pasted april fool's articles from the front page as is.

    4. Re:Intentional? by wheany · · Score: 0

      I just hope CmdrTaco doesn't update the story with some lame "April fools!" -comment. Let the story be.

    5. Re:Intentional? by JWhitlock · · Score: 1, Funny
      Nah - yesterday it was news, today it's an April Fools joke.

      When timothy posts it again tommorow, then it will be a dupe.

    6. Re:Intentional? by druske · · Score: 1
    7. Re:Intentional? by nomadic · · Score: 1

      I just hope CmdrTaco doesn't update the story with some lame "April fools!" -comment. Let the story be.

      Yep, last year was kind of sad. "Ha ha, we got you!" "No you didn't. Every April Fools post was immediately recognized as a ham-handed, completely unsubtle hoax."

      I mean, how can you react to like 200 messages recognizing the hoax and criticizing you for making it so obvious with "ha ha we got you"?

    8. Re:Intentional? by CySurflex · · Score: 1
      rather than thinking just a bit further.

      Is that a pun?

    9. Re:Intentional? by Anonymous Coward · · Score: 0

      No, but I wish it had been. Drat! :)

  2. First 1st April Joke Dupe! by edgrale · · Score: 4, Informative

    Yay!
    http://slashdot.org/article.pl?sid=03/04/01/ 021822 6&mode=thread&tid=172&tid=156

    --
    09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
    1. Re:First 1st April Joke Dupe! by muffen · · Score: 0, Funny

      Incase it gets /.'ed, here's another link: http://slashdot.org/article.pl?sid=03/04/01/133217 &mode=thread&tid=95

    2. Re:First 1st April Joke Dupe! by madprof · · Score: 0

      Perhaps the dupe is the April Fool itserlf? Perhaps we'll see this story repeated about 17 times later today?
      Maybe we'll get 'RMS hired by Microsoft' and it'll be a link to this RFC?
      I'm in paroxyms of laughter already.

    3. Re:First 1st April Joke Dupe! by Enigma2175 · · Score: 1

      In case those two sites become unavailable, here are some mirrors:

      http://slashdot.org/article.pl?sid=03/04/01/0218 22 6&mode=thread&tid=172&tid=156

      http://slashdot.org/article.pl?sid=03/04/01/1332 17 &mode=thread&tid=95

      --

      Enigma

    4. Re:First 1st April Joke Dupe! by Enigma2175 · · Score: 1

      Ok, now some actual information. Since the ftp isn't allowing users in anymore, here is an http link for the same page:

      http://ftp.rfc-editor.org/in-notes/rfc3514.txt

      It works, and you don't run into the FTP user limit.

      --

      Enigma

  3. Dupe. by nmg196 · · Score: 4, Funny

    Looks like CmdrTaco *is* the April Fool!

  4. Retarded. by Anonymous Coward · · Score: 1, Funny

    God, I fucking hate April first.

    1. Re:Retarded. by Anonymous Coward · · Score: 0
      (read it again, it's kinda subtle)
      Ok, I did. For much the same reason that when I see a train wreck, I look at it again.
  5. Oh, nice by gazbo · · Score: 1

    Oh, very nice indeed. No really, I'd normally rip a new one for your lame April fools, but seriously, kudos!

  6. April Fools? No - just Slashdot fools. by buzzsport · · Score: 1

    Once again -- people just don't read before they post.

  7. All together now.... by threeturn · · Score: 1

    All together now .... "its a dupe"

    1. Re:All together now.... by MikeDX · · Score: 1

      and after 3, everybody re-submit ALL the homepage news stores and see if we can get an April 1st TRIAD OF CRAP

      1..2..3...

  8. New bit for Slashdot by mseeger · · Score: 4, Funny
    Hi,

    I just heard they have a new bit at Slashdot. It's called "DupeBit" and this is the first article which got it.

    Yours, Martin

    1. Re:New bit for Slashdot by mark_lybarger · · Score: 1

      sorry. this bit isn't new and the /. comedy crew (read: editors) have been using it for quite some time now. it even helped save my job once thursday afternoon. i was about to snooze off after having a huge bowl of pasta for lunch and reading /. when all the sudden right there in the middle of the page was this blatant dup article. well, that woke me right up and got me into posting mode, which after 20 minutes or so usually turns into coding mode which helped me get my project complete only 3 weeks behind schedule which helped me keep my job. thanks /. for keeping some of us employed just a tad bit longer!

    2. Re:New bit for Slashdot by Alien+Being · · Score: 1

      "this is the first article..."

      1st article, 2nd posting -> DupDupe

    3. Re:New bit for Slashdot by j-pimp · · Score: 0, Offtopic

      Well it would appear in your case the problem threating you employment is your personal performance. Not that I'm getting all holier than though. Programming is a creative task probally not meant to be done on a 9-5 schedule. We've all had our lack of performance issues. However, that don't mean every time you lose a job in thie market its the fault of "the economy"

      --
      --- Justin Dearing http://www.justaprogrammer.net/ We're just programmers.
    4. Re:New bit for Slashdot by mark_lybarger · · Score: 1

      repeat after me:

      s a r c a s m
      s a r c a s m
      s a r c a s m

    5. Re:New bit for Slashdot by worf_mo · · Score: 1

      I just heard they have a new bit at Slashdot. It's called "DupeBit" and this is the first article which got it.

      They actually use a NewBit for articles that are supposed to slip through without a dupe.

  9. bleh by Vampyre_Dark · · Score: 1

    I'll set that bit on every post i see today

  10. Repost? by RyanFenton · · Score: 1


    http://slashdot.org/article.pl?sid=03/04/01/021822 6&mode=thread&tid=172&tid=156

    Likely, this is already a repost ABOUT the repost. Still, it's always fun to pile on!

    Ryan Fenton

  11. This might be funny if... by StringBlade · · Score: 1

    The article it was clearly based on wasn't four topic below this.

    --
    ...and that's the way the cookie crumbles.
  12. Staggering by GothChip · · Score: 0

    They even manage to dupe their April Fools jokes.

  13. FTP??? by TopShelf · · Score: 1

    My workplace's firewall blocks FTP, you insensitive clod!

    --
    Stop by my site where I write about ERP systems & more
  14. CmdrTaco adds new bit to story submissions by blowdart · · Score: 4, Funny

    Now users can tick if their stories are duplicates or not.

  15. Grrr! by Jellybob · · Score: 1

    Ok. This is getting silly now... I'd really rather not have to try and guess which articles are the real ones.

    1. Re:Grrr! by AKnightCowboy · · Score: 1
      Ok. This is getting silly now... I'd really rather not have to try and guess which articles are the real ones.

      You must be new here. They're all jokes on April 1st... or are they? ;-) Yes, it gets tired and annoying throughout the day after about 3 hours of these stories, but hey, it's only one day a year. Just think of it as reading the Weekly World News for a day.

    2. Re:Grrr! by Anonymous Coward · · Score: 0

      It's easy... until tomorrow all are fake.

    3. Re:Grrr! by Anonymous Coward · · Score: 0

      You must be new here...

      You _don't_ have to guess. All stories posted today will be about jokes posted on other sites. They did exactly the same last year. And the joke is on all the people whining about it... :)

    4. Re:Grrr! by Jellybob · · Score: 1

      Well... it is my first April 1st.

      Oh well, I'll cut them some slack I guess, I'm just in a grouchy mood today.

    5. Re:Grrr! by Anonymous Coward · · Score: 0

      typing at less than 1 year old?

      what are you, some kind of frickin' genius?

  16. Hey by Anonymous Coward · · Score: 0

    maybe we can have two april the firsts now.

  17. You fail english? by fadeaway · · Score: 1

    Slashdot - Security updates in broken english, or we'll double your karma back! ;)

  18. Hmm... by chrisbro · · Score: 1

    So not only is it an April Fool's joke, but it's a dupe?

    Punchlines are never as great the second time around.

    -chris

  19. I suppose this bit will be set on.... by dochood · · Score: 1

    .... all packets originating from Microsoft Windows machines?

    dochood

    1. Re:I suppose this bit will be set on.... by GammaTau · · Score: 2, Funny

      .... all packets originating from Microsoft Windows machines?

      I doubt that. After all, Microsoft Windows-based products have a bad habit of not following the Internet standards.

      On another news, the Mozilla project has announced that it will introduce the EVIL bit on all HTTP requests originating from users clicking links on duplicate Slashdot news items. The announcement has received good response from the Internet community. An anonymous system administrator was heard stating: "I am very pleased of this late development. I wish more hardware could learn to drop all packets with EVIL bit before it consumes all the bandwidth of the victim."

    2. Re:I suppose this bit will be set on.... by Anonymous Coward · · Score: 0

      You're a bit like the kid on the outside of the circle trying to join in, aren't you? There's all these Microsoft jokes, so you give it a go, and even mimic the popular subject/body sentence split. The thing is, dochood, you've forgotten to make it funny. You've created a facsimile of a small, witty comment, but you've missed the wit.

      Keep practicing though.

    3. Re:I suppose this bit will be set on.... by EvilAlien · · Score: 1
      No, all MP3s and P2P traffic will have the evil bit set. What could be more evil than stealing the hard work of musicians by distributing digital copies of their music? Look at what MP3s have done to Metalica?! Once upstanding members of the musical community... now washed-up has-beens.

      Please note that .ogg will be an exception, because software released under the BSD license can never be evil.

      --
      perl -e 'print $i=pack(c5, (41*2), sqrt(7056), (unpack(c,H)-2), oct(115), 10)'
    4. Re:I suppose this bit will be set on.... by TheCrackRat · · Score: 1

      Please note that .ogg will be an exception, because software released under the BSD license can never be evil.

      Umm, songs in the .ogg format aren't under the BSD license. Just the format itself.

      --
      Ignorance is not linguistic drift.
  20. Dup by dcs · · Score: 1

    So, how many times are you going to repeat this story today?

    --
    (8-DCS)
  21. Same page duplicate for goodness sake by rusty+spoon · · Score: 3, Funny

    Yeah, but this time the bit is real evil and the entire story is even more menacing ;-)

  22. It would appear by tdvaughan · · Score: 1

    The that waistband of the 'Daddy pants' needs to be adjusted slightly. It's obviously restricting bloodflow to the primary dupe-avoiding cortex.

  23. Jokes on us? by autocracy · · Score: 1

    I know it's been said. It shouldn't have to be said. It shouldn't have to be said again. I'm saying it again. That's because this story is here, again.

    --
    SIG: HUP
  24. Cmdr. Xerox! by opti6600 · · Score: 5, Funny

    The best post duplicator around!

  25. Actual Implementation by rf0 · · Score: 2, Funny
    Yeah this a dupe but since the first article someone has actually implemented this on FreeBSD. See ftp://ftp.jurai.net/users/winter/patches/IFF_EVIL. patch for the patch. From the freebsd mailing list..


    From: Matthew N. Dodd (mdodd at freebsd dot org)
    To: freebsd-current at freebsd dot org
    Subject: IFF_EVIL patch available.

    Leveraging our new RFC3514 support I've implemented a new network
    interface flag 'IFF_EVIL' which causes all IP packets crossing the
    interface to have the IP_EVIL bit set.



    Cool

    Rus
    1. Re:Actual Implementation by Koyaanisqatsi · · Score: 1

      Now those guys on open source are quick to fix things up aren't they? Way to go!

      OTOH, M$ will only implement this in the next XP service pack, and I heard rummours they won't bother to fix it in Win2K, since it is too near it's end of life anyway.

    2. Re:Actual Implementation by REBloomfield · · Score: 1

      this is why i love geeks :)

    3. Re:Actual Implementation by thogard · · Score: 1

      The problem is finding the right bit. I figure that if you logical or every bit, then you the the IFF_EVIL bit. This works great execpt on one machine that has mac address of 0:0:0:0:0:0.

    4. Re:Actual Implementation by Gerald · · Score: 1

      Patches have been submitted for Ethereal and Nmap as well.

  26. Oh my, a dupe by virve · · Score: 1

    Christ almighty. An april's dupe. This is beyond me. By the way, the Risks list does this RFC thing really well.

    virve
    --

    1. Re:Oh my, a dupe by Anonymous Coward · · Score: 0

      p.s. the risks list administered by the great and good Lindsey (male) Marshall

      a brilliant lecturer and an even more interesting blogger

      AndyboyH
      [2nd year at ncl.ac.uk ;) ]

  27. Off Topic (-1) by gowen · · Score: 1

    I don't mean to interrupt this thread, but has anyone seen this. Its an RFC that adds an new bit field to TCP/IP headers for packets that have malicious intent.

    I haven't seen it at /. , and its hilarious.

    --
    Athletic Scholarships to universities make as much sense as academic scholarships to sports teams.
    1. Re:Off Topic (-1) by Anonymous Coward · · Score: 0

      You could try submitting it? Maybe it'd even make the front page!

  28. To Quote Mermaid man from Sponge Bob... by bjb · · Score: 1
    To Quote Mermaid man from Sponge Bob...

    "Evil! EEEEEEEEEEEvvviiiilll!!!!"

    (or whatever the heck that character's name was...)

    --
    Never hit your grandmother with a shovel, for it leaves a bad impression on her mind...
  29. Slashdot adds dupe bit in posting protocol... by TheOrquithVagrant · · Score: 1

    Oh, if only.

    I used to wonder why people heaped so much derision on CmdrTaco. He's like that annoying bastard who keeps setting the network printer to make two copies of everything as the default. Gah.

  30. I'm confused by WARM3CH · · Score: 1

    Is there anyone to explain me if it's finally April's dupe or IP's fool??

  31. Re:I'd just like to point out that by StringBlade · · Score: 1

    How do I know it's not both?

    --
    ...and that's the way the cookie crumbles.
  32. Lawmakers love the idea by Ost99 · · Score: 1

    A new bill requiring all pornographic material and terrorist communication to be transmitted with the "evil bit" set was proposed only hours later by a Texas representative.

    This just in:
    RIAA will propose a bill later this week requiring all p2p apps to use the "evil bit" as well.

    - Ost

    --
    ---- Sig. gone.
    1. Re:Lawmakers love the idea by Anonymous Coward · · Score: 0

      very cute... RIAA people finally have someone on the inside helping them.

  33. How about an "unfunny" bit? by Anonymous Coward · · Score: 0

    unfunny.

    dupe.

    blah blah blah.

  34. Of course it's a dupe ... by binaryDigit · · Score: 1

    ... It's April Fools isn't it? How disappointed we all would have been it there wasn't at least one dupe today. Hell, I wouldn't be surprised to see this article pop up with several different variants ALL DAY LONG. I wouldn't be surprised if they had a dupe of every April Fools articles posted today.I find it amusing that people are getting soooo worked up about it on this of all days :)

  35. THREADJACK: Google IPO by Boss,+Pointy+Haired · · Score: 1

    Well sod it; it's a dupe _and_ April 1st so this thread is not worth anything anyway; so:

    Am I alone in the world, or is there anybody else out there that COULDN'T GIVE A FLYING F*** whether Google go for an IPO or not?

    Seriously, the BB's and media are making a meal out if this AND IT HASN'T EVEN HAPPENED YET. If they do, i'm gonna have to cut myself off from society until the media bullshit has calmed down.

    I trust the management will do what's right/needed for the company; and i'll leave it at that.

    Any journalists reading? Please, I beg you; let's not blow this one out of all proportion.

    Thanks.

    1. Re:THREADJACK: Google IPO by muffen · · Score: 1, Funny

      ...i'm gonna have to cut myself off from society

      Dude, you're posting on a site called "slashdot, news for nerds, stuff that matters". The decision to cut yourself from the real world (the thing that you see outside the window, where that bright annoying light that reflects on the monitor comes from) was taken a long time ago ;)

  36. Evil indeed by deadgoon42 · · Score: 1

    I was checking out this dupe post and the advertisement was for Microsoft Visual Studio .Net. That's pretty evil. Then I got to thinking about advertising and it seems that I rarely notice those in-article advertisements. I usually only notice the top-of-page advertising. So there is something for the advertising department.

    --

    Smeghead every day of the week.
  37. This is a good thing by kinnell · · Score: 3, Funny

    The latest version of IPv6 incorporates an evil bit, and adding one to IPv4 will allow existing IPv4 networks to become forward compatible with the new IPv6 networks. Without this, the mere existence of an "evil" bit in IPv6 may suggest to the poular imagination that IPv6 is more evil than IPv4. This would be catastrophic, as it would stall the uptake of IPv6, possibly forcing us to use IPv4 forever and preventing us from giving every molecule on the planet it's own IP address. This is a good day for mankind.

    --
    If I seem short sighted, it is because I stand on the shoulders of midgets
    1. Re:This is a good thing by b0bd0bbs · · Score: 1

      The bit is not so much evil as just generally disagreeable.

  38. Slashdot and dupes by the+uNF+cola · · Score: 1

    Slashdot cleaning up their act and NOT having a dupe today would be a great april fools joke.

    --

    --
    "I'm not bright. Big words confuse me. But Wanda loves me and that should be enough for you." - Cosmo

  39. original post must have had its evil bit set by calethix · · Score: 1

    How else could it have been reposted so quickly?

  40. I got it... by Steelwings · · Score: 1

    It was the evil mime that gave it away.

  41. Plausible cause for dududuplicate by fbernard · · Score: 1

    I guess CmdrTaco was so stunned by Whitespace that he started rewriting his automatic dupe-removal routine with it!

    Must be busy looking for a WhiteSpace debugger by now, time to sneak another dupe!

    --
    Fabien BERNARD.
  42. Re:Dup by muffen · · Score: 3, Insightful

    Actually, if they posted it again, it would be kinda funny again. I think the odd number of times something is posted, it's funny. Even number of times, it's just not as good to read.

    Check the download.com april first joke.

  43. Microsoft Implementation by elliotj · · Score: 1

    I read recently that Microsoft will set the bit to binary 1 on all new versions of Windows 2003 and XP. After embracing the new protocol, they then plan to extend the bit to two bits so that in subsequent versions it will be set to 11 or "most evil".

  44. Awww... by EvilFrog · · Score: 1

    I know this is an April Fools day joke... but I really wish it wasn't...

  45. Reaching new audiences by SlashdotMakesMeKool · · Score: 1, Insightful

    Slashdot April 1st jokes used to be a lot more subtle than this.

    --

  46. Well for crissake people! by 91degrees · · Score: 1

    If you have problems with dupes, simply change your setting to disable display of duplicate stories! It's hardly rocket science.

  47. don't blame /. editors... by 5prite · · Score: 1

    in fact dups on /. is sent with the evil bit on and is intended as a test for you guys, if you have the appropriate support for evil bit, you should not be able to see dups! ugh... it seems that i should file a bug to report this to my OS vender and tell them to have this feature properly supported so I won't receive any dup again...

  48. Jesus christ by Anonymous Coward · · Score: 0

    Not even 10 hours later and a dupe? Even if it is April Fool's day... most people run a minimal 1600x1200 resolution if not higher so why can't the editors notice them ?

    Its official. I'm never coming back to Slashdot. Goodbye dupes, goodbye DMCA bulls**t, goodbye NEW/Lunix talk.

  49. How bad can this really get...? by Mr.+Smoove · · Score: 1

    Posted after 12pm and it's a duplicate! Maybe /. should consult the AprilFools man page...!

    --
    Mr. Smoove
  50. People! by Anonymous Coward · · Score: 0

    You need to give Cmdr. Taco a break! He's got work to do and can't be expected to just break from his tasks to read /. like the rest of us!

    Man...with all the bitchin' you'd think his job was to read this site on a regular basis!

    Sheesh!

  51. This is not a joke... by QwkHyenA · · Score: 1
    Taco...

    PLEASE! Drink MORE Coffee!

    --
    LFS. Have you built your system today?
  52. I smell microsoft... by Swift(void) · · Score: 1

    Previous story: Can You Trust Microsoft On Security?

    I KNEW they had their finger in evey pie! (and some things not even pie related).

    At least its not April Trolls day...or does that happen everyday?

    I like apirl 1 =)
  53. Nigger Please by Beatlebum · · Score: 1

    nm

  54. uuhh...thanks god... by scheuri · · Score: 1

    ...I already implemented the "evil bit" feature of IPv4 on my firewall, that's the reason I don't see this arti......*doh*

  55. Stop it already by Capt.+Mubbers · · Score: 1

    Our sides cannot take anymore of these hilarious gapes!

    --
    "Watch the skies, keep watching the skies"
  56. Talk about speaking too soon... by briqui · · Score: 1

    There are times you just wish you could mod a post up past 5...
  57. How long until... by Whispers_in_the_dark · · Score: 1

    ... someone actually USES this bit in their hacks. That would definitely make news... >:)

    1. Re:How long until... by Boss,+Pointy+Haired · · Score: 1

      That was what I thought. It is effectively a published RFC (well it's on FAQs.org - that's good enough).

      Script kiddies could set this bit in their next DoS attack and use it in defence if they wind up in court :)

  58. Stop that pigeon! by eyeball · · Score: 1

    I wonder how an evil bit would affect the pigeon.

    --

    _______
    2B1ASK1
  59. It's not a dupe by Anonymous Coward · · Score: 0

    They're just adding two evil bits. It helps to seperate script kiddies and terrorists (although it's not neccessary). The other reason is to make the bitsize divisible by 2.

  60. Slashdot! The only place where . . . by div_2n · · Score: 5, Funny

    1) A first exclusive interview gets posted twice.

    2) New scientific discoveries sound familiar.

    3) 10 questions turn into 20.

    4) Last interviews turn into next to last.

    5) Congress is considering the first ever digital cloning ban.

    6) Duplicate replies to duplicate posts get duplicate moderation.

    7) The only thing not duplicated is polls (not even sure about that).

    8) 1000/1 = The ratio of time it takes for moderators to discover a dupe vs. the readers.

    9) 0 = The number of dupes deleted.

    10) The post (God forbid) announcing its closing will probably be posted twice.

  61. And thats not all... by Mysund · · Score: 1

    A friend of mine that works for a big sw company told me, that roumors was that the networkcoders in that company is making some additions to the api, to not only set the "evil-bit", but also make an undocumented apicall, that can toggle the evil bit to minus 1 (-1). That would allow pakages avoid being caught in intrusion detection sw, firewalls etc. This is to allow authorities to monitor evrything more effectively. I believe the concept of evilbit manipulation is good, for security resons, but...

  62. And in other news.... by slayer99 · · Score: 1
    Some chap has come up with an idea for tagging specific packets types.

    --
    Martin Brooks / Slayer99 #linux / UIN 2178117
  63. wow by PhrostyMcByte · · Score: 1

    wow, now we are even duping the jokes. must be a slow day for news eh?

  64. Slashdot must follow the standard!! by borgdows · · Score: 0

    We should add a "Evil" moderation option!

    +5, Evil

  65. the evil bit is meet and right!! by fortunatus · · Score: 0
    now wait a second, it's not a dupe!

    really, i think evil-doers will set the evil bit with pride, and that will be a real help!!

    MPEG2 has one of these on the Transport Stream level called "transport_error_indicator", which you set when there's no point in transmitting a packet but you transmit it anyway.

  66. Re:Question about RFC by wheany · · Score: 1

    Does anyone care to guess how many more messages will be posted that somehow mention duplicates and the evil bit?

  67. Duplicate by 1s44c · · Score: 0

    Not just bad april fool postings, but duplicate bad april fool postings.

    This april fool stuff is a stupid tradition, can we have an end to it now?

  68. Square Packets by depechemodem · · Score: 1

    Reminds me of the joke we played on a coworker - told her that the square packets from her application were congesting the network causing the round packets not to flow as well. We suggested using a packet analyzer to see if her team could recode the application.

  69. ARGH! by awx · · Score: 1

    I don't know if this is meant to be funny or not! *screams*

    --
    Feel that power? That's mah MOUSING FINGER
  70. AP: Bush seeks to root out "Evil Bit" by Marijuana+al-Shehi · · Score: 0, Funny
    Washington -

    President George Bush is meeting this meeting with high-level Cabinet members, Pentagon advisors, and the corpse of Dick Cheney to develop a battle plan against the so-called "Evil Bit" developed by the nefarious organization known as "IETF", White House spokesman Ari Fleischer said today.

    Fleischer said "We know this IETF has RFC's, and they plan to use the RFC's against the American people". When a reporter from the New York Times (free registration all day 4/1!!) stated that the IETF was the Internet Engineering Task Force, a standards body for the Internet, Fleischer gave a slideshow depicting the IETF's True Secret Agenda: a plot against Freedom and Democracy.

    When the Times reporter asked CIA director George Tenet about the slideshow, Tenet exclaimed

    "What the fuck is wrong with those idiots? The CIA is the organization from which the President receives his intelligence information, and we have never heard of such a ridiculous plot. [Bush] pulled this same shit two months ago with the 'proof' that Iraqi had nukes, which turned out to be something scrawled by a 10th-grader. Fuck this bullshit! I quit!"

    The President will address the nation this evening at 8:00 p.m. on all major networks.

    --
    "I think all foreigners should stop interfering in the internal affairs of Iraq"
    -- Paul Wolfowitz, 7/21/2003
  71. Desering of a Dope Slap by cpfeifer · · Score: 1

    Click and Clack demonstrate the proper technique. Arms at the ready!

    --
    it's not going to stop until you wise up, no it's not going to stop. so just give up.
  72. Favorite sections were by dooguls · · Score: 1

    "Multi-level insecure operating systems may have special levels for attack programs; the evil bit MUST be set by default on packets emanating from programs running at such levels. However, the system MAY provide an API to allow it to be cleared for non-malicious activity by users who normally engage in attack behavior."
    A slight against M$ perhaps...

    And my other fav was: "In networks protected by firewalls, it is axiomatic that all attackers are on the outside of the firewall. Therefore, hosts inside the firewall MUST NOT set the evil bit on any packets."
    Esp considering how many people actually believe the second quote.

    --
    Sig 'em boy!
  73. Dupe? by stevenp · · Score: 1

    Yes, it is a dupe - no doubt. But why so fast, the old story is still on the FRONT page. In fact it is ONLY 3 stories below this one.

    Ahem, long live the slashdot editors that provide us constantly with interesting stuff to read! The latest trend is to post old stories as often as possible so that we do not need to scroll down the front page. Long live!!!

  74. How exciting by stinky+wizzleteats · · Score: 1

    I was all set to add a new traffic definition in my COPS server, but then it occurred to me - it is impractical to implement a QoS recognition for evil without also taking into account evil's opposite. Therefore, I feel I must postpone network reconfiguration until someone invents a stupid bit.

  75. A bit of Opportunity by Frightened_Turtle · · Score: 2, Funny

    What people need to realize is the sheer opportunity presented by the evil bit! Particularly when used in conjunction with the new Whitespace Programming Language ! Sending an html-based email to your boss laced with WPL and the evil bit set will cause his computer to download all your pr0n for you, as well as send the memo to the finance office to process your raise with haste.

    However, the only problem I've come across with setting the evil bit deals with products from a certain Redmond, Washington software development company. Apparently, when the evil bit is set, it negates all the security holes inherent in the OS from this company, and it becomes rock solid secure.

    Go figure...

    --


    Whew! This water sure is cold!
  76. In other news by niall2 · · Score: 0, Funny

    Cisco plans to introduce their new "evil router". This new fiber channel router will give special priority to packets known to be truely evil. Special discounts for those installing new networks for thier "death star" or "hollowed out volcanos".

    --
    Today is a gift. Save the receipt.
  77. Obligatory Simpsons Quote by Anonymous Coward · · Score: 0

    "Here's your problem: Someone set this thing to Evil!"

  78. The bit defines READ by enigmacole · · Score: 1

    Learn to read first.... www.eteckonline.com

  79. From the redundant duplicate depatrment.... by petepac · · Score: 2, Funny

    Yo Taco,
    Since this article was posted twice, does it make it a sticky bit?

    --
    >> Practice Safe Hex
  80. This dupe is okay.. by jetmarc · · Score: 3, Funny

    ... because it has the evil bit set. Had you installed
    the RFC update already, you wouldn't even have seen it!

  81. Re:Dup by datadictator · · Score: 1

    That download.com story should have include this program the best program ever written in that category.

  82. WARNING!!!! Evil Bit and Apples! by Frightened_Turtle · · Score: 1

    Young women should avoid setting this bit to evil if they are using an Apple computer!

    One young teenager apparently set this bit and immediately fell into a coma. Her family's only warning that this had happened was when seven dwarves burst into the house and carried her off in a glass coffin.

    Her parents were visibly upset.

    "They seemed quite chipper while they carried our daughter off," cried the teen's mother. "They were whistling quite enthusiastically while they worked."

    Police are investigating the incident. Representatives from Disney have already contacted the family for the movie rights.

    --


    Whew! This water sure is cold!
    1. Re:WARNING!!!! Evil Bit and Apples! by AndroidCat · · Score: 1

      That's been a problem with Apples from almost the begining. Some snake sent this woman a packet with the evil bit set, and it snowballed from there.

      --
      One line blog. I hear that they're called Twitters now.
  83. Evil bit MUST be set on duplicate posts by Anonymous Coward · · Score: 0

    A section was inadvertantly left out of the RFC.

    The Evil bit MUST be set on duplicate slashdot posts.

  84. When will we get the Crazy Bit that we deserve!! by Montgomery+Burns+III · · Score: 1
    Please don't mis-interpret this post, I am very grateful for the good work that is conducted by the IETF, IEEE, DHS, NBC, and CNN.
    But, IMHO, we have a desparate need for a standard concerning "The Crazy Bit."
    Once this bit is detected, the remaining packets, message, media, disk drive, computer, Flame-email, etc can be discarded without risk to humanity.
    --

    'ta
  85. That's all fine and good, by bplipschitz · · Score: 4, Funny

    however, I'm going to sit back and wait for the 'Naughty Bit'.

    1. Re:That's all fine and good, by lindsayt · · Score: 1

      I think most PFYs on /. these days would miss the obvious Flying Circus reference.

      --
      I did not design this game/I did not name the stakes/I just happen to like apples/And I am not afraid of snakes-AniD
  86. @PR1l ph0ol5, 5UXXOr5 by IIRCAFAIKIANAL · · Score: 1

    "There's your problem. Somebody set this doll to evil!"

    --
    Robots are everywhere, and they eat old people's medicine for fuel.
  87. C Strings patented April Fool's joke from early 90 by minton · · Score: 1

    In the early 90s, an April fools joke was passed through Usenet from a guy claiming to have patented null terminated strings. Anyone still have a copy of this or know where to find it?

  88. consistent, but not particularly funny by endoboy · · Score: 2, Insightful

    Ok, so it's april fool's day... but 2 spelling mistakes in a 2 sentence joke?

  89. Massive flaw in this RFC by ellem · · Score: 1

    It seems not all packes that pass through ports:

    137
    138
    139

    are marked as "evil". How can that be correct?

    --
    This .sig is fake but accurate.
  90. 3x by pr0nbot · · Score: 1

    Has there ever been a triple post on slashdot?

  91. Dr. Evil Packet? by sporkboy · · Score: 1

    I've been a fricken Evil Packet for thirty fricken years throw me a fricken bit...

    A bit isn't evil. It's semi-evil...quasi-evil.

    When packets come with laser beams on their head then maybe I'll pay attn.

  92. Austin Powers by invisik · · Score: 0

    Is this a line from the upcoming 4th movie? :)

    -m

    --
    http://www.invisik.com
  93. Fortunately dupes are now evil, and must set it. by stienman · · Score: 1

    "In the still of the night, I accepted another dupe. Oh how I love, love to post, promise you'll never post the most, in the still of the night. Shoo dupe dupe du dupe, shoo dupe dupe de waah!"

    -Adam

  94. It WON'T work.... by Ghengis · · Score: 1
    Unless we add a parity bit for the evil bit!

    --

    "The best laid plans of mice and men gang oft agley..." - ROBERT BURNS

  95. Evil Bit? by t0ny · · Score: 1
    Sing along!

    I am Evil Homer, I am Evil Homer!

    I am Evil Homer, I am Evil Homer!

    --

    Manipulate the moderator system! Mod someone as "overrated" today.

  96. Re:Maybe Linus would be interested in addopting th by bheerssen · · Score: 1

    To quote Abraham Simpson:

    "Evil, I tells ya! EEEEEEEEEEEvvviiiilll!!!!"

    --
    (Score: -1, Stupid)
  97. Mirror by Martin+S. · · Score: 1
  98. Did anyone else forget that today was April Fool's by QuadGoatBoy · · Score: 1
    I was reading this article, rolling my eyes, and mumbling about stupid people and how such a solution won't prevent anything... *sigh*

    On a brighter note, at least our networking products won't have to be rewritten... Caffeine... Where the heck is the caffeine?...

    Quadgoatboy

  99. Dupes by captainclever · · Score: 1

    Well done Taco,
    Subtle, yet funny.

    --
    Last.fm - join the social music revolution
  100. First 1st April Joke Dupe! by _ph1ux_ · · Score: 1

    Yay!

  101. START READING YOUR OWN SITE ASS MONKEY by Anonymous Coward · · Score: 0

    I mean, really! It's no longer a funny joke.

  102. Not me by commodoresloat · · Score: 1

    I'm going to sit back and post dupes of comments from the duped story and collect duplicitous karma.

  103. karma whoring on dupe!!!1111 by oPless · · Score: 1

    Network Working Group S. Bellovin
    Request for Comments: 3514 AT&T Labs Research
    Category: Informational 1 April 2003
    The Security Flag in the IPv4 Header

    Status of this Memo

    This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited.

    Copyright Notice

    Copyright (C) The Internet Society (2003). All Rights Reserved.

    Abstract

    Firewalls, packet filters, intrusion detection systems, and the like often have difficulty distinguishing between packets that have malicious intent and those that are merely unusual. We define a security flag in the IPv4 header as a means of distinguishing the two cases.

    1. Introduction

    Firewalls CBR03 , packet filters, intrusion detection systems, and the like often have difficulty distinguishing between packets that have malicious intent and those that are merely unusual. The problem is that making such determinations is hard. To solve this problem, we define a security flag, known as the "evil" bit, in the IPv4 RFC791 header. Benign packets have this bit set to 0; those that are used for an attack will have the bit set to 1.

    1.1. Terminology

    The keywords MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, SHOULD NOT, RECOMMENDED, MAY, and OPTIONAL, when they appear in this document, are to be interpreted as described in RFC2119 .

    2. Syntax

    The high-order bit of the IP fragment offset field is the only unused bit in the IP header. Accordingly, the selection of the bit position is not left to IANA.

    The bit field is laid out as follows:

    0
    +-+
    |E|
    +-+

    Currently-assigned values are defined as follows:

    0x0 If the bit is set to 0, the packet has no evil intent. Hosts, network elements, etc., SHOULD assume that the packet is harmless, and SHOULD NOT take any defensive measures. (We note
    that this part of the spec is already implemented by many common desktop operating systems.)

    0x1 If the bit is set to 1, the packet has evil intent. Secure systems SHOULD try to defend themselves against such packets. Insecure systems MAY chose to crash, be penetrated, etc.

    3. Setting the Evil Bit

    There are a number of ways in which the evil bit may be set. Attack applications may use a suitable API to request that it be set. Systems that do not have other mechanisms MUST provide such an API; attack programs MUST use it.

    Multi-level insecure operating systems may have special levels for attack programs; the evil bit MUST be set by default on packets emanating from programs running at such levels. However, the system MAY provide an API to allow it to be cleared for non-malicious activity by users who normally engage in attack behavior.

    Fragments that by themselves are dangerous MUST have the evil bit set. If a packet with the evil bit set is fragmented by an intermediate router and the fragments themselves are not dangerous, the evil bit MUST be cleared in the fragments, and MUST be turned back on in the reassembled packet.

    Intermediate systems are sometimes used to launder attack connections. Packets to such systems that are intended to be relayed to a target SHOULD have the evil bit set.

    Some applications hand-craft their own packets. If these packets are part of an attack, the application MUST set the evil bit by itself.

    In networks protected by firewalls, it is axiomatic that all attackers are on the outside of the firewall. Therefore, hosts inside the firewall MUST NOT set the evil bit on any packets.

    Because NAT RFC3022 boxes modify packets, they SHOULD set the evil bit on such packets. "Transparent" http and email proxies SHOULD set the evil bit on their reply packets to the innocent client host.

    Some hosts scan other hosts in a fashion that can alert intrusion detection systems. If the scanning is part of a benign research project, the evil bit MUST NOT be set

  104. With all this complaining of "dupes" by Anonymous Coward · · Score: 0

    You'd think someone would notice that this article was actually posted first...

  105. Good April fool, but FIVE times???? by gfreeman · · Score: 1


    Come on ...

    --
    Ceci n'est pas un sig.
  106. Last Post! by alpg · · Score: 0

    Keep your Eye on the Ball,
    Your Shoulder to the Wheel,
    Your Nose to the Grindstone,
    Your Feet on the Ground,
    Your Head on your Shoulders.
    Now... try to get something DONE!

    - this post brought to you by the Automated Last Post Generator...