# Evil bit

> Mediated Wiki article. Canonical URL: https://mediated.wiki/source/Evil_bit
> Markdown URL: https://mediated.wiki/source/Evil_bit.md
> Source: https://en.wikipedia.org/wiki/Evil_bit
> Source revision: 1322931120
> License: Creative Commons Attribution-ShareAlike 4.0 International (https://creativecommons.org/licenses/by-sa/4.0/)

{{short description|Fictional IPv4 header field indicating malicious intent}}
{{use mdy dates|date=September 2021}}
{{third-party|date=August 2015}}
The '''evil bit''' is a fictional [IPv4 packet header](/source/IPv4) field proposed in a humorous [April Fools' Day RFC](/source/April_Fools'_Day_RFC) from 2003,{{Ref RFC|3514}} authored by [Steve Bellovin](/source/Steven_M._Bellovin). The [Request for Comments](/source/Request_for_Comments) recommended that the last remaining unused bit, the "Reserved Bit"<ref>{{Cite web|url=https://countuponsecurity.com/2013/04/01/the-evil-bit/|title=The Evil Bit|last=Rocha|first=Luis|date=2013-04-01|website=Count Upon Security|access-date=2016-05-09}}</ref> in the [IPv4](/source/IPv4) packet header, be used to indicate whether a packet had been sent with malicious intent, thus making [computer security](/source/computer_security) engineering an easy problem{{snd}} simply ignore any messages with the evil bit set and trust the rest.

== Impact ==

A 2015 research done by network engineer Ben Cartwright-Cox revealed that a number of popular websites (436 websites out of [Alexa 20k](/source/Alexa_Internet) at the time), such as those belonging to several universities and banks, to antivirus provider [Kaspersky](/source/Kaspersky) and to remote desktop software provider [Teamviewer](/source/Teamviewer) respect the "evil bit" by dropping the inbound request, making them compliant with RFC 3514.<ref>{{cite web |title=I may be the only evil (bit) user on the internet |url=https://blog.benjojo.co.uk/post/evil-bit-RFC3514-real-world-usage |website=blog.benjojo.co.uk |access-date=13 September 2024}}</ref>

== Influence ==
The evil bit has become a synonym for all attempts to seek simple technical solutions for difficult human social problems which require the willing participation of malicious actors, in particular efforts to implement [Internet censorship](/source/Internet_censorship) using simple technical solutions.

As a joke, [FreeBSD](/source/FreeBSD) implemented support for the evil bit that day, but removed the changes the next day.<ref>[http://lists.freebsd.org/pipermail/cvs-all/2003-April/001098.html Implementation], [http://lists.freebsd.org/pipermail/cvs-all/2003-April/001295.html removal]</ref> A Linux patch implementing the iptables module "ipt_evil" was posted the next year.<ref>{{Cite web |url=http://lists.netfilter.org/pipermail/netfilter-devel/2004-April/014854.html |title=ipt_evil, kernel part |access-date=2011-01-01 |archive-date=2011-02-02 |archive-url=https://web.archive.org/web/20110202194608/http://lists.netfilter.org/pipermail/netfilter-devel/2004-April/014854.html |url-status=dead }}</ref> Furthermore, a patch for FreeBSD 7 is available,<ref>{{Cite web |url=http://unix.derkeiler.com/Mailing-Lists/FreeBSD/hackers/2008-04/msg00071.html |title=RFC3514 for FreeBSD7 |access-date=2013-12-26 |archive-date=2009-02-18 |archive-url=https://web.archive.org/web/20090218161455/http://unix.derkeiler.com/Mailing-Lists/FreeBSD/hackers/2008-04/msg00071.html |url-status=dead }}</ref> and is kept up-to-date.

There is an extension for [XMPP](/source/Extensible_Messaging_and_Presence_Protocol) protocol, inspired by evil bit.<ref>{{Cite web |url=http://xmpp.org/extensions/xep-0076.html |title=XEP-0076: Malicious Stanzas |archive-date=2013-04-16 |archive-url=https://archive.today/20130416055855/http://xmpp.org/extensions/xep-0076.html |url-status=live |last1=Saint-Andre |first1=Peter |last2=Hildebrand |first2=Joe |date=2003-04-01}}</ref>

This RFC has also been quoted in the otherwise completely serious RFC 3675, ".sex Considered Dangerous", which may have caused the proponents of [.xxx](/source/.xxx) to wonder whether the [Internet Engineering Task Force](/source/Internet_Engineering_Task_Force) (IETF) was commenting on their application for a [top-level domain](/source/top-level_domain) (TLD){{snd}} the document was not related to their application.<ref>{{Cite news|url=http://www.circleid.com/posts/adult_related_tlds_considered_dangerous|title=Adult-Related TLDs Considered Dangerous|access-date=2017-07-06|language=en}}</ref>

For April Fool's 2010, [Google](/source/Google) added an <code>&evil=true</code> parameter to requests through the Ajax APIs.<ref>{{Cite web|url=http://googleajaxsearchapi.blogspot.co.uk/2010/03/helping-you-help-us-help-you.html|title=Helping you help us help you|website=googleajaxsearchapi.blogspot.co.uk|access-date=2017-02-19}}</ref>

[Wireshark](/source/Wireshark) supports <nowiki>RFC 3514</nowiki> since version 1.4.0 (2010) when the <code>ip.security_flag</code> protocol preference is enabled.<ref>{{Cite web |title=Implement RFC 3514. (324b7484) · Commits · Wireshark Foundation / Wireshark · GitLab |url=https://gitlab.com/wireshark/wireshark/-/commit/324b7484d9d44f34ba678de7b10875023a6e5915 |access-date=2025-11-18 |website=Wireshark |language=en}}</ref>

== See also ==
* [Technological fix](/source/Technological_fix)
* [Do Not Track](/source/Do_Not_Track)
* [HTTP 451](/source/HTTP_451)
* Twit bit, used in early [Shadow banning](/source/Shadow_banning).

== References ==
{{Reflist}}

{{IETF RFC 1st april}}
Category:2003 in computing
Category:April Fools' Day jokes
Category:Computer network security
Category:Computer humour
Category:Censorship
Category:2003 hoaxes

---
Adapted from the Wikipedia article [Evil bit](https://en.wikipedia.org/wiki/Evil_bit) by Wikipedia contributors ([contributor history](https://en.wikipedia.org/wiki/Evil_bit?action=history)). Available under [Creative Commons Attribution-ShareAlike 4.0 International](https://creativecommons.org/licenses/by-sa/4.0/). Changes may have been made.
