Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

1–10 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#2
«They also paid a third party contractor "six figures" to help develop a zero-day exploit in Tails: a bug in its video player that enabled them to retrieve the real I.P. address of a person viewing a clip.»

This sounds like they describe the well-known WebRTC leak: https://restoreprivacy.com/webrtc-leaks/

Re: Facebook Helped Develop a Tails Exploit

#4
post #2

« They also paid a third party contractor "six figures" to help develop a zero-day exploit in Tails: a bug in its video player that enabled them to retrieve the real I.P. address of a person viewing a clip. » This sounds like they describe the well-known WebRTC leak: https://restoreprivacy.com/webrtc-leaks/

Other than webRTC being related to video playing, i dont see the connection. They don't really describe the exploit, so hard to say, but the webrtc leak isn't really in the video player part, its super well known (literally a feature not a bug) so i dont think you would need to pay six figures for it, and tails uses tor browser which doesn't support webrtc.

Re: Facebook Helped Develop a Tails Exploit

#9
This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent.

As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Re: Facebook Helped Develop a Tails Exploit

#10
post #8

Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.

According to this article [1] the code involved with this exploit should be removed at some point.

" A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool.

As far as the Facebook team knew, Tails developers were not aware of the flaw, despite removing the affected code. One of the former Facebook employees who worked on this project said the plan was to eventually report the zero-day flaw to Tails, but they realized there was no need to because the code was naturally patched out. "

[1] https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fb...

Post reply on HN