Live data from Hacker News

Freedom Hosting sites compromised, founder arrested

twitlonger.com

41–50 of 140 posts

Re: Freedom Hosting sites compromised, founder arrested

#41
post #40

Earlier quoted context omitted.

The quote in the article claims that the exploit affects 17 and higher , only on NT-based platforms. Furthermore, Tor Browser Bundle disallows JavaScript by default, and one should be cautious while allowing execution of arbitrary client-side code whilst intent on keeping their direct IP address secret. You have to take at least a couple of steps to be affected by this bug. EDIT: The author has updated the OP and now…

TBB does not disallow javascript by default. In fact they recommend you do not disable javascript because it makes your browser fingerprint more traceable.

Checking on this now. I find it dubious, but possible. I haven't used the Tor Browser Bundle for quite a while, but last I recall they definitely had a mechanism to keep JavaScript from executing. It seems ridiculous that they wouldn't, given their long history of advocacy for NoScript et al. Will edit when done installing/checking.

EDIT: So it seems that NoScript is installed as part of the package, but that scripts are enabled globally by default. I just experienced this with a fresh install. Here's the answer confirming it: https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEna... .

Personally I think that's a horrible compromise, and it's obviously something that's changed since last time I used it. This should be undone ASAP. Some education is required to use Tor properly even without considering things like JavaScript, so teaching someone to enable JS only when prudent should be fine to include as part of that educational package. It seems like there is some nefarious force at work here trying to trick people who really shouldn't be using Tor into using Tor. I know, for instance, that I had to stop several of my friends from using Tor after they heard about it from the news or whatever after the PRISM leaks. Do NOT use Tor if you don't fully understand the implications, like that all data you send through it is going to be decrypted to plaintext at a random exit node that could be run by literally anyone with a modern computer and internet connection.

Fortunately, NoScript continues to warn pretty blatantly with a big red exclamation point that scripts should not be allowed globally, and an educated Tor user will automatically forbid all scripts despite the awful default, so this is probably only a problem for people who are just dinking around anyway.

Re: Freedom Hosting sites compromised, founder arrested

#42
post #19
post #17

Here is real reason why little sisters force everything into browser. Because they care about security >:-) People should stop using web/browsers for everything.

The idea of having JS enabled is directly at odds with a secure system, too. All TOR sites should have non-JS friendly interaction. There's really negligible benefit compared to exploits like the on in TFA.

I remember a bit over ten years ago, "javascript is annoying" was a mainstream position among hacker types. That seems to be long gone by now.

I guess hardware catching up with resource requirements took away one of the biggest reasons against it. And most people really embraced the web as more than a document platform. I think part of me still misses the old way of thinking about it.

Re: Freedom Hosting sites compromised, founder arrested

#43
post #40

Earlier quoted context omitted.

The quote in the article claims that the exploit affects 17 and higher , only on NT-based platforms. Furthermore, Tor Browser Bundle disallows JavaScript by default, and one should be cautious while allowing execution of arbitrary client-side code whilst intent on keeping their direct IP address secret. You have to take at least a couple of steps to be affected by this bug. EDIT: The author has updated the OP and now…

TBB does not disallow javascript by default. In fact they recommend you do not disable javascript because it makes your browser fingerprint more traceable.

Uhm, I think they have noscript bundled with JS globally disallowed? IIRC, that is.

Re: Freedom Hosting sites compromised, founder arrested

#46
post #2

We should be clear that this isn't a vulnerability in the Tor software or network, but an (apparent) vulnerability in this unrelated "Freedom Hosting" company's site: https://blog.torproject.org/blog/hidden-services-current-eve...

And possibly in Firefox (!), with some sort of JavaScript exploit. This is the most worrying part for me--does anyone have any info on what the payload does?

It breaks out of the browser sandbox and submits a get request to some server with the guid identifying the user and the tor site they were on.

Re: Freedom Hosting sites compromised, founder arrested

#47
post #43
post #40

Earlier quoted context omitted.

TBB does not disallow javascript by default. In fact they recommend you do not disable javascript because it makes your browser fingerprint more traceable.

Uhm, I think they have noscript bundled with JS globally disallowed? IIRC, that is.

They do include noscript, but with JS globally enabled. Noscript will cleanse XSS/CSRF requests and prevent some sorts of clickjacking (according to noscript.)

Re: Freedom Hosting sites compromised, founder arrested

#48

A preliminar analysis of the 0day used: http://pastebin.mozilla.org/2777139 edit : Maybe is a good idea to submit this link (or another related) to discuss about it in a new HN thread.

It's not really 0-day: since it only affects Firefox 17, it was apparently fixed long ago. But see this comment regarding why it may be of interest to lots of TOR users: https://news.ycombinator.com/item?id=6156779

Firefox 17 is their most recent ESR release for enterprises that want a more stable platform, and at least in theory it's still receiving security updates.

Re: Freedom Hosting sites compromised, founder arrested

#49

I must yet again point to a company like Endgame Systems[1] as being a likely contractor for this service rendered for the FBI. Some of Endgame's products used by the likes of the NSA: "There are even target packs for democratic countries in Europe and other U.S. allies. Maui (product names tend toward alluring warm-weather locales) is a package of 25 zero-day exploits that runs clients $2.5 million a year. The Cayma…

"Exploiting an unknowable amount of users of a service as to hunt them. Using illegally harvested data from botnets, while others get hunted and prosecuted for coding them. This tiered society where the legally immune can profit off acts that get others jailed."

Not that I disagree with this sentiment, but how is this different from the fact the government is "legally immune" from using/possessing weapons and firearms that the average person can't possess or use?

Post reply on HN