Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

31–40 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#31
post #15
post #10

Earlier quoted context omitted.

According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…

It's a little bit short-sighted, divulging the exploit makes sure it is known and reduces the chances it happens again in the future

There's a clear downside that this can't be used against the next kid-molestor.

But then, this also can't be used against every other human being who needs privacy either. E.g.: Journalists, activists, anyone who disagrees with a large government, etc,

Re: Facebook Helped Develop a Tails Exploit

#32
post #25

Earlier quoted context omitted.

Weakest link. That’s one of the issues an aggregate system (which describes any system of meaningful size, these days) has to deal with. How many of the massive breaches we hear about, originate with dependencies or subcontractors?

Speaking of, I always find it very telling that the knee-jerk reaction is to blame a dependency or subcontractor. That's the same mentality that says "paid for code must be better" when, last I checked, there aren't any more Windows phones, are there? But there was a Windows password hash method in the early 2000s that could be brute forced on a single consumer grade CPU in less than 24 hours on their current-at-the-…

I have no idea why you made that post.

Re: Facebook Helped Develop a Tails Exploit

#33
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

I don't think it was a WebRTC issue, I think they crafted a video such that the decoder would end up executing code. Similar to what happen to Jeff Bezos.

The point is that you can't have the Tails machine decide what connections are proxied through Tor and which are not. If you have an external device like a router or a Raspberry that transparently tunnels the data, a compromise of the Tails machine can't trivially expose your real network connection.

Re: Facebook Helped Develop a Tails Exploit

#34
post #6

The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.

Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?

The Vice article mentions the video was sent over Dropbox. I'd say the default Gnome videos app making a network request is also possible.

Re: Facebook Helped Develop a Tails Exploit

#35
post #4
post #2

« They also paid a third party contractor "six figures" to help develop a zero-day exploit in Tails: a bug in its video player that enabled them to retrieve the real I.P. address of a person viewing a clip. » This sounds like they describe the well-known WebRTC leak: https://restoreprivacy.com/webrtc-leaks/

Other than webRTC being related to video playing, i dont see the connection. They don't really describe the exploit, so hard to say, but the webrtc leak isn't really in the video player part, its super well known (literally a feature not a bug) so i dont think you would need to pay six figures for it, and tails uses tor browser which doesn't support webrtc.

But you can install WebRTC enabled browsers in tails. Depending on how tech-savvy someone is, they could be motivated to install one of them.

Re: Facebook Helped Develop a Tails Exploit

#36
post #10
post #8

Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.

According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…

That would also be the perfect way to avoid disclosing the vulnerability so they could keep using it.

Not saying that’s what is happening here, but it’s not like Facebook has a glowing reputation to begin with. Telling the vendor that a future release will patch the bug gets everyone to stop asking questions without really knowing if it’s true.

Re: Facebook Helped Develop a Tails Exploit

#37
This is something to consider in the recent development of Amazon and Microsoft saying they won't sell facial recognition to law enforcement. I expect police will approach this minor inconvenience by outsourcing to a private company who will do the face scanning for them.

Re: Facebook Helped Develop a Tails Exploit

#39
post #15

Earlier quoted context omitted.

It's a little bit short-sighted, divulging the exploit makes sure it is known and reduces the chances it happens again in the future

There's a clear downside that this can't be used against the next kid-molestor. But then, this also can't be used against every other human being who needs privacy either. E.g.: Journalists, activists, anyone who disagrees with a large government, etc,

This is in line with the arguments for/against Tor in general. I believe if you agree with Tor as a principle, then you should agree that making this exploit known is better overall.

As an aside, I believe everyone needs privacy, so I'd rather say that everyone benefits from it, not just the usual journalists, activists, whistleblowers, etc...

Re: Facebook Helped Develop a Tails Exploit

#40
post #10
post #8

Facebook could at-least have had the decency to report the bug after they were done, who knows what the FBI / NSA are using it for now.

According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…

> As far as the Facebook team knew, Tails developers were not aware of the flaw, despite removing the affected code. One of the former Facebook employees who worked on this project said the plan was to eventually report the zero-day flaw to Tails, but they realized there was no need to because the code was naturally patched out. "

So there's no way for anybody to verify that the code is actually being removed, or that the exploit won't crop up again in the future. I don't trust them or the FBI at all in this.

Post reply on HN