A preliminar analysis of the 0day used: http://pastebin.mozilla.org/2777139 edit : Maybe is a good idea to submit this link (or another related) to discuss about it in a new HN thread.
Freedom Hosting sites compromised, founder arrested
31–40 of 140 posts
Re: Freedom Hosting sites compromised, founder arrested
#32Earlier quoted context omitted.
It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…
The word 'sociopath' describes these actions very well. Considering that the United States is in a state of enduring war, and considering that all of the effort to monitor the internet comes from a desire to strengthen national security (which is a vital concern), it makes sense for the United States to behave this way. After all, what is war other than purely sociopathic behavior? The monitoring of the internet is j…
If you'll let it off the leash entirely in "wartime", well, then the leash was never there.
Re: Freedom Hosting sites compromised, founder arrested
#33Earlier quoted context omitted.
It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…
> America The American government, you mean.
Re: Freedom Hosting sites compromised, founder arrested
#34They make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the marke…
Furthermore, Tor Browser Bundle disallows JavaScript by default, and one should be cautious while allowing execution of arbitrary client-side code whilst intent on keeping their direct IP address secret. You have to take at least a couple of steps to be affected by this bug.
EDIT: The author has updated the OP and now claims that he believes Firefox 17 is the only affected version. His language is ambiguous such that it is unclear whether the exploit only affects Windows or if the code distributed by FH is simply not attempting to exploit any non-Windows environments (perhaps they were trying to get specific players).
Re: Freedom Hosting sites compromised, founder arrested
#35Think of the children! Yes .. a good front to make it so that they can just bust anything using SWAT forces.
Is pedophilia such a big problem? Really ? I would like to see one study about pedophilia and the problems it creates, instead of what the problems that NSA and FBI are facing when people start encrypting their traffic and we actually have some freedom of speech in some areas.
Re: Freedom Hosting sites compromised, founder arrested
#36As of now there is some guy stating that some hoster has been pwnd and uploaded some JS that expoloited something that might be FF17 that might have been shipped with the tor browser bundle.
Why exactly does he thing FBI/NSA is involved? If he has the exploit code why didn't he upload it?
Lots of conclusions based on assumptions. As of now I'd think it's more likely someone just pwnd the largest TOR hidden host provider, uploaded a sploit that will affect most of the users (tor browser bundle) and called it a day.
Sure there MIGHT be some GOV/whatever involvment. But wouldn't it be time to wait with such accusations until we got some actual proof? Not even uploading the alleged exploit doesn't really help his position.
I would think that since about 60% of TOR projects funding comes from the .gov[0], that they have an incencitive to keep it online. I could imagine they have some nodes for which they wouldn't want to reveal the physical location. I don't know warhead controllers or something. Of course that only works if the're are enough nodes involved so you can hide yourself. That's why I think this might not have been a .gov action.
[0] https://www.torproject.org/about/findoc/2012-TorProject-Annu...
Re: Freedom Hosting sites compromised, founder arrested
#37Earlier quoted context omitted.
It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…
> America The American government, you mean.
Re: Freedom Hosting sites compromised, founder arrested
#38We should be clear that this isn't a vulnerability in the Tor software or network, but an (apparent) vulnerability in this unrelated "Freedom Hosting" company's site: https://blog.torproject.org/blog/hidden-services-current-eve...
Not according to TFA: "In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization" http://www.ieee-security.org/TC/SP2013/papers/4977a080.pdf
Re: Freedom Hosting sites compromised, founder arrested
#39Here is real reason why little sisters force everything into browser. Because they care about security >:-) People should stop using web/browsers for everything.
It'd be crazy to download a full local client for something as shady as SilkRoad or many other hidden services. The browser is the safest place for that kind of thing.
Re: Freedom Hosting sites compromised, founder arrested
#40They make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the marke…
The quote in the article claims that the exploit affects 17 and higher , only on NT-based platforms. Furthermore, Tor Browser Bundle disallows JavaScript by default, and one should be cautious while allowing execution of arbitrary client-side code whilst intent on keeping their direct IP address secret. You have to take at least a couple of steps to be affected by this bug. EDIT: The author has updated the OP and now…