Earlier quoted context omitted.
And possibly in Firefox (!), with some sort of JavaScript exploit. This is the most worrying part for me--does anyone have any info on what the payload does?
Doesn't have to do much. Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. Also, by including a tracking cookie in the JS, they can cross reference all user activity on the compromised websites with the newly discovered IP address.
Freedom Hosting sites compromised, founder arrested
21–30 of 140 posts
Re: Freedom Hosting sites compromised, founder arrested
#22Europeans point of view: Am I the only one who feels that the US is taking over the Internet and all of our privacy with it?
It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…
Considering that the United States is in a state of enduring war, and considering that all of the effort to monitor the internet comes from a desire to strengthen national security (which is a vital concern), it makes sense for the United States to behave this way.
After all, what is war other than purely sociopathic behavior? The monitoring of the internet is just an extension of these behaviors which manifest themselves during wartime.
Re: Freedom Hosting sites compromised, founder arrested
#23Earlier quoted context omitted.
Europeans point of view: European bureaucrats are not any better, think about David Cameron idea of Porngate
AFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.
Re: Freedom Hosting sites compromised, founder arrested
#24Earlier quoted context omitted.
Doesn't have to do much. Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. Also, by including a tracking cookie in the JS, they can cross reference all user activity on the compromised websites with the newly discovered IP address.
I still don't understand this concept. Any iframe or JS executed is still going through Tor. They'd need to load up Chrome or start another Firefox process.
Once you manage to get arbitrary code running in the context of the browser, you can do anything the browser can, including (presumably) making raw non-TOR connections to anywhere, identifying the TOR user and correlating that with what they were doing over TOR.
Among other things like installing arbitrary malware kits that completely compromise the machine.
Re: Freedom Hosting sites compromised, founder arrested
#25> The JavaScript zero-day exploit that creates a unique cookie and sends a request to a random server that basically fingerprints your browser in some way, which is probably then correlated somewhere else since the cookie doesn't get deleted. Presumably it reports the victim's IP back to the FBI. "in some way", "probably", "presumably" = I have no idea what's going on.
That being said, there is always a point that this could be used for something else entirely, though. Compromising Tor mail is a lot less of a targeted attack.
Re: Freedom Hosting sites compromised, founder arrested
#26We should be clear that this isn't a vulnerability in the Tor software or network, but an (apparent) vulnerability in this unrelated "Freedom Hosting" company's site: https://blog.torproject.org/blog/hidden-services-current-eve...
And possibly in Firefox (!), with some sort of JavaScript exploit. This is the most worrying part for me--does anyone have any info on what the payload does?
Re: Freedom Hosting sites compromised, founder arrested
#27So here's what I can grok from it:
* "Freedom Hosting" founder has been arrested; presumably, many people were using "Freedom Hosting" to host onion sites (is this where "half of all Tor sites compromised" comes from?). No charges listed, article slightly hints at child pornography charges.
* Someone, presumably the FBI, has set up an exploit to be distributed through Freedom Hosting sites that will phone home and reveal your non-Tor IP address (solution: seven proxies). "Freedom Hosting" founder was probably coerced into allowing distribution of this exploit.
* Author claims that said exploit only affects Firefox >= 17 on Windows.
* There's a link to a paper about possible problems with hidden services, which is apparently not relevant to any of this other than the fact that there was just a shakedown on a big onion site provider.
I'm flagging this article because it is utterly incoherent and the headline is sensationalist. There is no evidence of a fundamental flaw in Tor being related to any of the events mentioned. Hopefully someone will write a comprehensible piece soon and put it out there.
Re: Freedom Hosting sites compromised, founder arrested
#28Previous discussion of malicious Javascript: https://news.ycombinator.com/item?id=6154246
Re: Freedom Hosting sites compromised, founder arrested
#29Earlier quoted context omitted.
AFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.
Yet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.
The target demographics for prepaid is mostly kids and teens, poor people, and people concerned about their privacy, split between sensitized geeks, unfaithful lovers and criminals.
For the first two demographics cheap monthly plans are now emerging (in France, Free offers two hours of talk and infinite SMS for 2€ per month and unlimited talk, SMS and 3GB of data for 20€ per month).
It sucks for the last three.
On a slightly related topic, in demonstrations, people caught without a cell phone during an ID check often end up arrested for "administrative reasons".
Re: Freedom Hosting sites compromised, founder arrested
#30Earlier quoted context omitted.
AFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.
Yet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.