Seems like the lede is buried -- what is the video player exploit? Is there really a way to modify video files such that playing them locally can broadcast an IP address? Think this is less about Tails and more about this "video-tagging" tech.
Facebook Helped Develop a Tails Exploit
21–30 of 116 posts
Re: Facebook Helped Develop a Tails Exploit
#22There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best
Re: Facebook Helped Develop a Tails Exploit
#23This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
Facebook has teams of people whose entire job is covering Facebook's ass. Before Facebook even does something bad, they already figured out an excuse for it before they even started doing it. If they didn't have an alibi, they wouldn't even do the crime. That's the kind of operation they run. They preemptively create the narrative, then they act. Why do people treat Facebook as if it were a conscientious person?
Re: Facebook Helped Develop a Tails Exploit
#24This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
> This guy deserves what was coming to him,
I agree.
And on the scale of users FB has, he is most assuredly not the only one like him on Facebook.
I wonder how many there are that the company has no idea about, that perhaps are in countries that are not so well connected that they will get a dedicated FB employee to look into, who frankly FB does not and will not give a shit about.
I am therefore having some trouble believing they did this entirely in good faith. How many others are there that they will do absolutely nothing about?
Re: Facebook Helped Develop a Tails Exploit
#25Earlier quoted context omitted.
Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?
Weakest link. That’s one of the issues an aggregate system (which describes any system of meaningful size, these days) has to deal with. How many of the massive breaches we hear about, originate with dependencies or subcontractors?
But there was a Windows password hash method in the early 2000s that could be brute forced on a single consumer grade CPU in less than 24 hours on their current-at-the-time flagship network server OS. So there's that...
Re: Facebook Helped Develop a Tails Exploit
#26This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
Disclosure: Throwaway as I am a former employee. No inside knowledge in this case. > This guy deserves what was coming to him, I agree. And on the scale of users FB has, he is most assuredly not the only one like him on Facebook. I wonder how many there are that the company has no idea about, that perhaps are in countries that are not so well connected that they will get a dedicated FB employee to look into, who fran…
- It makes their platform more secure. - Good PR - Assisting LEO prevents future problems with new laws etc. - It is good faith
In general decisions like this, always have multiple dimensions. Always it is calculated decision.
Re: Facebook Helped Develop a Tails Exploit
#27Re: Facebook Helped Develop a Tails Exploit
#28There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best
In that case you are swapping one ISP for another. You would need a small botnet to act as your proxy provider set to make it harder to find you.
Re: Facebook Helped Develop a Tails Exploit
#29There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best
I don't think it was a WebRTC issue, I think they crafted a video such that the decoder would end up executing code. Similar to what happen to Jeff Bezos.
Re: Facebook Helped Develop a Tails Exploit
#30This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever th…
This is great PR for themm to say that both privacy and encryption are bad and should be outlawed.
Wouldn't be surprising at all if that's how they spin it.