How to track a PC anywhere it connects to the Net
By Renai LeMay, ZDNet Australia
04 March 2005
Anonymous Internet access is now a thing of the past. A doctoral student at the University of California has conclusively fingerprinted computer hardware remotely, allowing it to be tracked wherever it is on the Internet.
In a paper on his research, primary author and Ph.D. student Tadayoshi Kohno said: "There are now a number of powerful techniques for remote operating system fingerprinting, that is, remotely determining the operating systems of devices on the Internet. We push this idea further and introduce the notion of remote physical device fingerprinting ... without the fingerprinted device's known cooperation."
The potential applications for Kohno's technique are impressive. For example, "tracking, with some probability, a physical device as it connects to the Internet from different access points, counting the number of devices behind a NAT even when the devices use constant or random IP identifications, remotely probing a block of addresses to determine if the addresses correspond to virtual hosts (for example, as part of a virtual honeynet), and unanonymising anonymised network traces."
--snip--
Kohno seems to be aware of the interest from surveillance groups that his techniques could generate, saying in his paper: "One could also use our techniques to help track laptops as they move, perhaps as part of a Carnivore-like project". Carnivore was Internet surveillance software built by the United States' Federal Bureau of Investigation. Earlier in the paper Kohno overshadowed possible forensics applications, saying that investigators could use his techniques "to argue whether a given laptop was connected to the Internet from a given access location".
http://www.zdnet.com.au/news/security/0,2000061744,39183346,00.htmThis means they can "fingerprint" physical computer hardware and track the fingerprint the way they track human fingerprints, completely bypassing any software barriers. Carnivore and its ilk won't need to install any software or hack into your system or anything...just measure a system's physical fingerprint online. The measurement doesn't require any cooperation on your part, and can't be obstructed by firewalls or any software barriers. The online fingerprint of your physical hardware remains the same even if you reformat and reinstall all your software.