Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

21–30 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#21

Seems like the lede is buried -- what is the video player exploit? Is there really a way to modify video files such that playing them locally can broadcast an IP address? Think this is less about Tails and more about this "video-tagging" tech.

some DRM video formats can ping the servers for sure.

Re: Facebook Helped Develop a Tails Exploit

#22
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

In that case you are swapping one ISP for another. You would need a small botnet to act as your proxy provider set to make it harder to find you.

Re: Facebook Helped Develop a Tails Exploit

#23
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever the media or a big company focuses on a single individual, it's never actually about that individual. It's either about some higher social concept or it's simply a PR stunt to control the narrative. I think anything of this sort which comes out of Facebook is more likely to be damage control. They probably came up with the narrative before they even implemented this backdoor.

Facebook has teams of people whose entire job is covering Facebook's ass. Before Facebook even does something bad, they already figured out an excuse for it before they even started doing it. If they didn't have an alibi, they wouldn't even do the crime. That's the kind of operation they run. They preemptively create the narrative, then they act. Why do people treat Facebook as if it were a conscientious person?

Re: Facebook Helped Develop a Tails Exploit

#24
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Disclosure: Throwaway as I am a former employee. No inside knowledge in this case.

> This guy deserves what was coming to him,

I agree.

And on the scale of users FB has, he is most assuredly not the only one like him on Facebook.

I wonder how many there are that the company has no idea about, that perhaps are in countries that are not so well connected that they will get a dedicated FB employee to look into, who frankly FB does not and will not give a shit about.

I am therefore having some trouble believing they did this entirely in good faith. How many others are there that they will do absolutely nothing about?

Re: Facebook Helped Develop a Tails Exploit

#25
post #6

Earlier quoted context omitted.

Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?

Weakest link. That’s one of the issues an aggregate system (which describes any system of meaningful size, these days) has to deal with. How many of the massive breaches we hear about, originate with dependencies or subcontractors?

Speaking of, I always find it very telling that the knee-jerk reaction is to blame a dependency or subcontractor. That's the same mentality that says "paid for code must be better" when, last I checked, there aren't any more Windows phones, are there?

But there was a Windows password hash method in the early 2000s that could be brute forced on a single consumer grade CPU in less than 24 hours on their current-at-the-time flagship network server OS. So there's that...

Re: Facebook Helped Develop a Tails Exploit

#26
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Disclosure: Throwaway as I am a former employee. No inside knowledge in this case. > This guy deserves what was coming to him, I agree. And on the scale of users FB has, he is most assuredly not the only one like him on Facebook. I wonder how many there are that the company has no idea about, that perhaps are in countries that are not so well connected that they will get a dedicated FB employee to look into, who fran…

Ofc it is not only good faith but I guess it is also a factor. They did it because:

- It makes their platform more secure. - Good PR - Assisting LEO prevents future problems with new laws etc. - It is good faith

In general decisions like this, always have multiple dimensions. Always it is calculated decision.

Re: Facebook Helped Develop a Tails Exploit

#28
post #22
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

In that case you are swapping one ISP for another. You would need a small botnet to act as your proxy provider set to make it harder to find you.

Depending on where you live and who you use for a VPN, you're at least swapping a known bad-agent ISP for a potentially non-bad-agent ISP.

Re: Facebook Helped Develop a Tails Exploit

#29
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

I don't think it was a WebRTC issue, I think they crafted a video such that the decoder would end up executing code. Similar to what happen to Jeff Bezos.

Even so, wouldn't running Tails on a VPN have only exposed the IP address of the VPN connection?

Re: Facebook Helped Develop a Tails Exploit

#30
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever th…

Well, Facebook actively campaigns against privacy, and the FBI actively campaigns against encryption.

This is great PR for themm to say that both privacy and encryption are bad and should be outlawed.

Wouldn't be surprising at all if that's how they spin it.

Post reply on HN