Live data from Hacker News

Freedom Hosting sites compromised, founder arrested

twitlonger.com

21–30 of 140 posts

Re: Freedom Hosting sites compromised, founder arrested

#21
post #13

Earlier quoted context omitted.

And possibly in Firefox (!), with some sort of JavaScript exploit. This is the most worrying part for me--does anyone have any info on what the payload does?

Doesn't have to do much. Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. Also, by including a tracking cookie in the JS, they can cross reference all user activity on the compromised websites with the newly discovered IP address.

I still don't understand this concept. Any iframe or JS executed is still going through Tor. They'd need to load up Chrome or start another Firefox process.

Re: Freedom Hosting sites compromised, founder arrested

#22
post #3

Europeans point of view: Am I the only one who feels that the US is taking over the Internet and all of our privacy with it?

It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…

The word 'sociopath' describes these actions very well.

Considering that the United States is in a state of enduring war, and considering that all of the effort to monitor the internet comes from a desire to strengthen national security (which is a vital concern), it makes sense for the United States to behave this way.

After all, what is war other than purely sociopathic behavior? The monitoring of the internet is just an extension of these behaviors which manifest themselves during wartime.

Re: Freedom Hosting sites compromised, founder arrested

#23
post #14

Earlier quoted context omitted.

Europeans point of view: European bureaucrats are not any better, think about David Cameron idea of Porngate

AFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.

Yet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.

Re: Freedom Hosting sites compromised, founder arrested

#24
post #21
post #13

Earlier quoted context omitted.

Doesn't have to do much. Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. Also, by including a tracking cookie in the JS, they can cross reference all user activity on the compromised websites with the newly discovered IP address.

I still don't understand this concept. Any iframe or JS executed is still going through Tor. They'd need to load up Chrome or start another Firefox process.

The point is the iframe/JS is used to break out of the browser sandbox, due to a bug in the browser, with techniques like heap spraying (mentioned in the article).

Once you manage to get arbitrary code running in the context of the browser, you can do anything the browser can, including (presumably) making raw non-TOR connections to anywhere, identifying the TOR user and correlating that with what they were doing over TOR.

Among other things like installing arbitrary malware kits that completely compromise the machine.

Re: Freedom Hosting sites compromised, founder arrested

#25
post #6

> The JavaScript zero-day exploit that creates a unique cookie and sends a request to a random server that basically fingerprints your browser in some way, which is probably then correlated somewhere else since the cookie doesn't get deleted. Presumably it reports the victim's IP back to the FBI. "in some way", "probably", "presumably" = I have no idea what's going on.

It's more that we know very well that up to the transmission point, it creates a unique identifier. If we're following the most likely guess (that this is targeting distribution of Child Pornography), then it seems like a reasonable goal to simply identify and fingerprint Tor users.

That being said, there is always a point that this could be used for something else entirely, though. Compromising Tor mail is a lot less of a targeted attack.

Re: Freedom Hosting sites compromised, founder arrested

#26
post #2

We should be clear that this isn't a vulnerability in the Tor software or network, but an (apparent) vulnerability in this unrelated "Freedom Hosting" company's site: https://blog.torproject.org/blog/hidden-services-current-eve...

And possibly in Firefox (!), with some sort of JavaScript exploit. This is the most worrying part for me--does anyone have any info on what the payload does?

I don't think anyone's fully reverse-engineered the payload yet.

Re: Freedom Hosting sites compromised, founder arrested

#27
This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at least a few things.

So here's what I can grok from it:

* "Freedom Hosting" founder has been arrested; presumably, many people were using "Freedom Hosting" to host onion sites (is this where "half of all Tor sites compromised" comes from?). No charges listed, article slightly hints at child pornography charges.

* Someone, presumably the FBI, has set up an exploit to be distributed through Freedom Hosting sites that will phone home and reveal your non-Tor IP address (solution: seven proxies). "Freedom Hosting" founder was probably coerced into allowing distribution of this exploit.

* Author claims that said exploit only affects Firefox >= 17 on Windows.

* There's a link to a paper about possible problems with hidden services, which is apparently not relevant to any of this other than the fact that there was just a shakedown on a big onion site provider.

I'm flagging this article because it is utterly incoherent and the headline is sensationalist. There is no evidence of a fundamental flaw in Tor being related to any of the events mentioned. Hopefully someone will write a comprehensible piece soon and put it out there.

Re: Freedom Hosting sites compromised, founder arrested

#29
post #14

Earlier quoted context omitted.

AFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.

Yet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.

I didn't know that. It plugs a hole in the targeted surveillance programs, at the expense of all prepaid users.

The target demographics for prepaid is mostly kids and teens, poor people, and people concerned about their privacy, split between sensitized geeks, unfaithful lovers and criminals.

For the first two demographics cheap monthly plans are now emerging (in France, Free offers two hours of talk and infinite SMS for 2€ per month and unlimited talk, SMS and 3GB of data for 20€ per month).

It sucks for the last three.

On a slightly related topic, in demonstrations, people caught without a cell phone during an ID check often end up arrested for "administrative reasons".

Re: Freedom Hosting sites compromised, founder arrested

#30
post #14

Earlier quoted context omitted.

AFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.

Yet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.

Thank you, I didn't know it. Any source for this claim (so I could dig deeper)?
Post reply on HN