
2025-06-04 04:10:37
today's "I can't believe I wasted half a hour on this" computer issue: whether Wireshark validates the Ethernet checksum in packets depends on the capture format you're using
.snoop: nope, and ignores all settings including "always check FCS"
.pcap: yep
saving a .snoop file as a .pcap file makes it immediately check all FCS