Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

81–90 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#81
post #72

Fascinating part in the story about his arrest (first link in the vice article) is that the FBI set up cameras outside his home to correlate his physical presence with internet activity from the IP address. You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.

I don't know about the US, but it is generally very easy: go to the ISP with the IP+date and an order from a judge and they'll tell you who was using it.

> they'll tell you who was using it

IP only tells the investigator whose name is on the ISP account, not which person was at the keyboard. Your recommendation only helps the police know where to set up the surveillance, not who to bring charges against.

Re: Facebook Helped Develop a Tails Exploit

#82
post #6

The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.

Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?

The nature/architecture of tails means this kind of attack is possible. Apps that can "break through" the OS networking, get access to the "real connection". Excuse my non-technical language.

Disclosure/ad: I work on Whonix, which is, uh, tails in VM essentially (to the person who only knows tails and not whonix). In Whonix, the desktop is in an VM, separate from another OS in another VM running the networking. No program in the desktop VM can reveal the public IP. On top of that, for advanced users, the desktop hardware itself might be separate from the hardware connected to the public internet.

The VM (virtualbox, kvm, whatever) is the single (practical) attack service, which is safer than ensuring every program the user may run is patched. Excuse the rant/ad/competition-bashing.

Re: Facebook Helped Develop a Tails Exploit

#84
post #72

Fascinating part in the story about his arrest (first link in the vice article) is that the FBI set up cameras outside his home to correlate his physical presence with internet activity from the IP address. You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.

I don't know about the US, but it is generally very easy: go to the ISP with the IP+date and an order from a judge and they'll tell you who was using it.

They'll tell you who pays for the connection. They can't reliably tell you who uses it. Maybe it was a family member, roommate or anybody who knows the wifi password.

Re: Facebook Helped Develop a Tails Exploit

#85
> The firm worked with a Facebook engineer and wrote a program that would attach an exploit taking advantage of a flaw in Tails’ video player to reveal the real IP address of the person viewing the video.

Doesn't Tails route all traffic through Tor by default?

Re: Facebook Helped Develop a Tails Exploit

#86
post #75

Earlier quoted context omitted.

Well yes, but the fact that it was already patched in the next Tails release, and that was the reason they pulled the trigger when they did, makes even that concern less of a practical problem. It was basically going to get fixed in short order no matter what they did.

Since they never released the exploit, in reality we have no way of verifying this is actually true. It very well could be the case Tails still has this vulnerability.

Let's hope somebody works backwards and looks at patches made to the Tails video player and looks for something that could have been an exploit

Re: Facebook Helped Develop a Tails Exploit

#87
post #51

The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.

or how easily a 600B company spends thousands of dollars

Other articles on this topic described that they had hired at least one full time employee just to track this one malicious user. I'm sure they also have additional fractional costs for legal, moderation, administration, PR, government oversight, and lobbying. They might even have legal liabilities to the victims (not sure).

They previously worked with the FBI to try and trap this malicious user with a TOR exploit that didn't work against Tails where the malicious user saw the effect and mocked his investigators.

The $0.5million reportedly spent for the Tails 0day seems like it might actually be proportionate (perhaps even affordable) to the costs they incurred. I'm typically pretty skeptical of the costs the FBI and large corporations assign to corporate hacks or copyright theft, but this seems like it carries legit risk if FB doesn't try to do a lot to disable these malicious actions on their platform.

Re: Facebook Helped Develop a Tails Exploit

#88
post #53

The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.

and how the FBI doesn't waste the NSA's jewels for normal crimes

That isn't proven.

The FBI blew a TOR 0day on this user, it just didn't work against his Tails OS. It's possible that the 0day was sourced from another 3-letter agency.

Re: Facebook Helped Develop a Tails Exploit

#90

To deepen the ethical quandary: what if Facebook had developed the exploit for this case, and then the FBI used it for an unrelated, not-child-molesty case? At some point you have to wrestle with the fact that law enforcement is predicated upon having strong tools with which to deal with law breakers of all kinds, not just the few you find particularly onerous. They're going to need to perform ethical hacking to pros…

> and then the FBI used it for an unrelated, not-child-molesty case?

You must assume this is the case. The FBI isn't going to stop using a tool just because they caught one suspect in once case.

Post reply on HN