Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

11–20 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#11
post #10
post #8

Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.

According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…

Given their track record, I don't really trust Facebook, but if I take this at it's face, reporting the exploit could get it patched faster and may help in finding similar issues in the code.

Re: Facebook Helped Develop a Tails Exploit

#12
post #11
post #10

Earlier quoted context omitted.

According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…

Given their track record, I don't really trust Facebook, but if I take this at it's face, reporting the exploit could get it patched faster and may help in finding similar issues in the code.

True. Also this information, if true, could help locate the vulnerable code. I'm not sure if it would be worth it however, it depends on how many outdated tails are in the wild and the exploit complexity.

Re: Facebook Helped Develop a Tails Exploit

#14
post #7

The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.

> entire company > Facebook had tasked a dedicated employee to unmasking Hernandez

And paid six figures for outside help. The FBI's approach "was not tailored for Tails" - surely if they had any approach that would work they would use it.

If the government couldn't break in to Tails and required the outside help of two well-resourced organisations to find (and burn) a single exploit then overall that seems a pretty good endorsement of the security of a volunteer open-source project.

Re: Facebook Helped Develop a Tails Exploit

#15
post #10
post #8

Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.

According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…

It's a little bit short-sighted, divulging the exploit makes sure it is known and reduces the chances it happens again in the future

Re: Facebook Helped Develop a Tails Exploit

#16
post #6

The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.

Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?

Weakest link.

That’s one of the issues an aggregate system (which describes any system of meaningful size, these days) has to deal with.

How many of the massive breaches we hear about, originate with dependencies or subcontractors?

Re: Facebook Helped Develop a Tails Exploit

#17
There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

Re: Facebook Helped Develop a Tails Exploit

#19
> For years, a California man harassed and terrorized young girls, extorting them for nude photos and videos and threatening to kill and rape them or shoot up their schools. Much of this abuse took place on Facebook, and now, months after the man, Buster Hernandez or “Brian Kil,” pleaded guilty,

From Engadget coverage [1], I feel a bit of context is missing in TFA.

[1] https://www.engadget.com/facebook-fbi-hacking-tool-targeted-...

Re: Facebook Helped Develop a Tails Exploit

#20
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

I don't think it was a WebRTC issue, I think they crafted a video such that the decoder would end up executing code.

Similar to what happen to Jeff Bezos.

Post reply on HN