Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

51–60 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#54
post #22
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

In that case you are swapping one ISP for another. You would need a small botnet to act as your proxy provider set to make it harder to find you.

Thats always the, excuse my french, bullshit reaction i see here and is ignoring several important facts:

1. Since you share your vpn exit IP with several users, sometimes hundreds, it becomes harder for any website or service you use to track you by IP alone.

2. My ISP is mandated by law to save all my browsing data (germany here, this law changes every two month but you can assume they all log anyway). My VPN Provider is not mandated and has at least some incentive to not log any data. Cost and Reputation beeing the main ones.

3. I can for example have all my torrents exit in a country where filesharing is not illegal, making any persecution much less likely, same for other laws that are not the same everywhere.

Re: Facebook Helped Develop a Tails Exploit

#55
post #6

The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.

Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?

Tails is the sum of all components including browser and video players.

Re: Facebook Helped Develop a Tails Exploit

#56
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

A VPN does not provide better protection than Tor. If anything, is far less.

In both cases you need the tor daemon or the VPN software to be outside of the host running Tails.

Re: Facebook Helped Develop a Tails Exploit

#57

Earlier quoted context omitted.

That would also be the perfect way to avoid disclosing the vulnerability so they could keep using it. Not saying that’s what is happening here, but it’s not like Facebook has a glowing reputation to begin with. Telling the vendor that a future release will patch the bug gets everyone to stop asking questions without really knowing if it’s true.

If you have need for Tails and you continue to use old versions of it out of laziness, then you really are just begging to be pwned. We're not talking about consumer-grade Ubuntu here.

I think you misunderstand me.

By telling Tails that the vulnerability will be patched in a future release without disclosing the details of the vulnerability, Tails has no way of knowing if this is actually true.

It’s easy to be a little skeptical when a company spends 6 figures to develop an exploit and then state publicly “we can verify that the issue will be patched in a future Tails release, but we’re not going to tell them or anyone else what the exploit was in the first place.”

If you wanted to keep using that exploit, or sell it, the easiest way to do so would be to tell Tails that it’s going to be fixed without actually giving them any details about it.

Re: Facebook Helped Develop a Tails Exploit

#58
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever th…

Why the stupid downvotes?

For a for-profit company spending millions needs a justifications stronger than a penchant for vigilante justice.

A lot of big companies have a proven history of quietly cooperating with cops, three letter agencies and military.

That type of cooperation often leads to multi-million, even billion $ contracts and special favors from political power.

What is facebook trying to achieve?

Re: Facebook Helped Develop a Tails Exploit

#59
post #35
post #4

Earlier quoted context omitted.

Other than webRTC being related to video playing, i dont see the connection. They don't really describe the exploit, so hard to say, but the webrtc leak isn't really in the video player part, its super well known (literally a feature not a bug) so i dont think you would need to pay six figures for it, and tails uses tor browser which doesn't support webrtc.

But you can install WebRTC enabled browsers in tails. Depending on how tech-savvy someone is, they could be motivated to install one of them.

The article specificly says the issue was in code that used to be in tails and isnt anymore. Additionally, the motherboard article describes the payload as a video file uploaded to dropbox, which doesnt sound like webrtc.

Re: Facebook Helped Develop a Tails Exploit

#60
post #48

In my apparent ignorance, when I first read the title I actually imagined Facebook developing a backdoor of some kind into Tails, given that Tails is open source. Then I understood that "developing" an exploit means taking advantage of existing properties/vulnerabilities. Is this standard wording in security circles?

"develop" here refers to the process of (potentially) researching and then subsequently writing the software that exploits a vulnerability (an 'exploit'). It's used in the same sense as any other software development.

The process of discovering a vulnerability is called 'vulnerability research'.

So when Schneier says Facebook paid for an exploit to be developed, it means they paid for software that exploits a vulnerability.

In the case of paying for such exploits, it's not always clear who exactly did the research. Often the research comes from a third party who put together a simple proof of concept that demonstrates only that the security control can be breached (the PoC) -- then, a contractor may buy this vulnerability ('0day') from e.g. zerodium and develop an exploit for it, which will usually be pretty much point and shoot so you don't need an exploit dev team to leverage it.

Hope that makes sense.

Post reply on HN