[Whonix-devel] [tor-talk] Can TCP Sequence Numbers leak System Clock?

Murdoch, Steven s.murdoch at ucl.ac.uk
Tue Aug 4 16:44:05 CEST 2015

On 25 Jul 2015, at 17:49, Patrick Schleizer <patrick-mailinglists at whonix.org> wrote:
> On the other hand, I've read the claim "The kernel embeds the system
> time in microseconds in TCP connections.", but I haven't found the code
> in question to confirm, that this is so. Any idea?

The code is here:

In particular the seq_scale(u32 seq) function introduces the timestamp.

So if you see two initial sequence numbers for TCP streams between the same source/destination port/IP then you can work out the time difference (in units of 64 ns) according to the clock of the other end point.

Best wishes,

More information about the Whonix-devel mailing list