Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.
According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…
Facebook Helped Develop a Tails Exploit
11–20 of 116 posts
Re: Facebook Helped Develop a Tails Exploit
#12Earlier quoted context omitted.
According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…
Given their track record, I don't really trust Facebook, but if I take this at it's face, reporting the exploit could get it patched faster and may help in finding similar issues in the code.
Re: Facebook Helped Develop a Tails Exploit
#13Think this is less about Tails and more about this "video-tagging" tech.
Re: Facebook Helped Develop a Tails Exploit
#14The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.
> entire company > Facebook had tasked a dedicated employee to unmasking Hernandez
If the government couldn't break in to Tails and required the outside help of two well-resourced organisations to find (and burn) a single exploit then overall that seems a pretty good endorsement of the security of a volunteer open-source project.
Re: Facebook Helped Develop a Tails Exploit
#15Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.
According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…
Re: Facebook Helped Develop a Tails Exploit
#16The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.
Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?
That’s one of the issues an aggregate system (which describes any system of meaningful size, these days) has to deal with.
How many of the massive breaches we hear about, originate with dependencies or subcontractors?
Re: Facebook Helped Develop a Tails Exploit
#17Re: Facebook Helped Develop a Tails Exploit
#18Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.
Re: Facebook Helped Develop a Tails Exploit
#19From Engadget coverage [1], I feel a bit of context is missing in TFA.
[1] https://www.engadget.com/facebook-fbi-hacking-tool-targeted-...
Re: Facebook Helped Develop a Tails Exploit
#20There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best
Similar to what happen to Jeff Bezos.