Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

101–110 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#101
post #95

Earlier quoted context omitted.

That isn't proven. The FBI blew a TOR 0day on this user, it just didn't work against his Tails OS. It's possible that the 0day was sourced from another 3-letter agency.

Where did you get that they used a Tor 0day? I don't see it in the vice or schneier articles, I only see mentions of a "Tails exploit"... Anyway, of course it isn't proven, but I would be extremely surprised if said 3-letter agencies even needed a 0-day exploit to identify a Tor user... Needing Facebook and a consulting firm to find a vulnerability in a video player? Come on, I would find more credible that they used…

You are correct. I have no evidence of a TOR 0day.

I think I inferred what I said from this quote:

> Several FBI field offices were involved in the hunt, and the FBI made a first attempt to hack and deanonymize him, but failed, as the hacking tool they used was not tailored for Tails. Hernandez noticed the attempted hack and taunted the FBI about it, according to the two former employees.

Re: Facebook Helped Develop a Tails Exploit

#103
post #54
post #22

Earlier quoted context omitted.

In that case you are swapping one ISP for another. You would need a small botnet to act as your proxy provider set to make it harder to find you.

Thats always the, excuse my french, bullshit reaction i see here and is ignoring several important facts: 1. Since you share your vpn exit IP with several users, sometimes hundreds, it becomes harder for any website or service you use to track you by IP alone. 2. My ISP is mandated by law to save all my browsing data (germany here, this law changes every two month but you can assume they all log anyway). My VPN Provi…

Yes it increases the $$$ barrier to get you, but when your this level of criminal where they make custom 0days just for you, it's doubtful they would find subpoenaing the VPN providers to find out which customer they are much of a barrier too. Many paid VPN providers in the past have also shown no problem secretly selling out their customers too.

That is why I say rotating botnet, because there is nobody to subpoena and it would require even more $$$. When your that level of criminal, might as well go all the way.

Re: Facebook Helped Develop a Tails Exploit

#105
post #97

Earlier quoted context omitted.

> it could be someone you hate today and an activist the next Facebook had no control over the exploit once it was handed over to the FBI. It could have been simultaneously used on the child predator and 100 activists at the same time.

Yes, this is it, exactly. Which is why Apple didn't help the FBI break iOS. They did choose to not provide true E2E encryption for iCloud, however :(

The FBI doesn't need Apple's help currently. iOS exploits have become cheaper and more common than Android

https://threatpost.com/android-zero-days-worth-more-iphone-e....

Re: Facebook Helped Develop a Tails Exploit

#107
post #98
post #75

Earlier quoted context omitted.

Since they never released the exploit, in reality we have no way of verifying this is actually true. It very well could be the case Tails still has this vulnerability.

In my opinion, Hernandez screwed up by not appreciating the risk profiles for Tails and Whonix. Tails is a LiveOS, which doesn't leave traces in RAM or on disk. Whonix is a pair of VMs, one with the Tor process, and the other with user apps. Using Whonix, exploits like this are impossible, because the apps VM has no public IP address, and can hit the Internet only via Tor.

I can imagine for high-value target there are stacking exploits:

1) escape from browser into VM

2) escape from VM into host

3) run exploit on host

Re: Facebook Helped Develop a Tails Exploit

#108
post #98

Earlier quoted context omitted.

In my opinion, Hernandez screwed up by not appreciating the risk profiles for Tails and Whonix. Tails is a LiveOS, which doesn't leave traces in RAM or on disk. Whonix is a pair of VMs, one with the Tor process, and the other with user apps. Using Whonix, exploits like this are impossible, because the apps VM has no public IP address, and can hit the Internet only via Tor.

I can imagine for high-value target there are stacking exploits: 1) escape from browser into VM 2) escape from VM into host 3) run exploit on host

Could you use a ring of VPSs spawning independent VM sessions, which are randomly connected to as needed, and puppeted by scripts or ML, used by others in the meantime, and torn down randomly and on a schedule. Cloud hop in the noise.

Re: Facebook Helped Develop a Tails Exploit

#109
post #98

Earlier quoted context omitted.

In my opinion, Hernandez screwed up by not appreciating the risk profiles for Tails and Whonix. Tails is a LiveOS, which doesn't leave traces in RAM or on disk. Whonix is a pair of VMs, one with the Tor process, and the other with user apps. Using Whonix, exploits like this are impossible, because the apps VM has no public IP address, and can hit the Internet only via Tor.

I can imagine for high-value target there are stacking exploits: 1) escape from browser into VM 2) escape from VM into host 3) run exploit on host

They don't need to stack anything. Everything that solely uses tor for protectioncan be pwned by pwning Tor. Happens once in while.

Re: Facebook Helped Develop a Tails Exploit

#110
post #98

Earlier quoted context omitted.

In my opinion, Hernandez screwed up by not appreciating the risk profiles for Tails and Whonix. Tails is a LiveOS, which doesn't leave traces in RAM or on disk. Whonix is a pair of VMs, one with the Tor process, and the other with user apps. Using Whonix, exploits like this are impossible, because the apps VM has no public IP address, and can hit the Internet only via Tor.

I can imagine for high-value target there are stacking exploits: 1) escape from browser into VM 2) escape from VM into host 3) run exploit on host

True. However, such high-value targets would be isolating the Tor process and apps at the hardware level. It's over my head, but I can imagine elements from Tinfoil Chat and Qubes Air.

And yes, vulnerabilities in Tor have been exploited. So it's prudent to hit Tor via nested VPN chains, just in case.

Post reply on HN