Live data from Hacker News

Freedom Hosting sites compromised, founder arrested

twitlonger.com

61–70 of 140 posts

Re: Freedom Hosting sites compromised, founder arrested

#61

This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at…

It's specifically targeting Firefox 17 for Windows. Versions less than 17 seem to be targeted as well, but the resource (content_1.html) doesn't seem to have ever been available. It does not target anything above 17.

http://pastebin.mozilla.org/2777139

Re: Freedom Hosting sites compromised, founder arrested

#62

Earlier quoted context omitted.

The word 'sociopath' describes these actions very well. Considering that the United States is in a state of enduring war, and considering that all of the effort to monitor the internet comes from a desire to strengthen national security (which is a vital concern), it makes sense for the United States to behave this way. After all, what is war other than purely sociopathic behavior? The monitoring of the internet is j…

The USA has never not been at war against somebody or something in living memory, counting the cold war and the drug war. If you'll let it off the leash entirely in "wartime", well, then the leash was never there.

The nature of the war on terror has legitimized this type of behavior. Specifically, the nature of terrorism seems to motivate the United States government to go to great lengths in order to cause damage to an enemy that is largely immune to defeat, for cultural and religious reasons. Drones are a great example of how far they will go.

The use of nuclear bombs signaled the end of world war two. Maybe the Obama administration is hopeful that surveillance of all communication is the final step towards a resolution of this war. That's not legitimate in my eyes, but oh well (i certainly don't know the solution). On top of everything else that has happened, zero expectation of privacy seems to be the equivalent of the nuclear option at this point.

Re: Freedom Hosting sites compromised, founder arrested

#63
post #19

Earlier quoted context omitted.

The idea of having JS enabled is directly at odds with a secure system, too. All TOR sites should have non-JS friendly interaction. There's really negligible benefit compared to exploits like the on in TFA.

I remember a bit over ten years ago, "javascript is annoying" was a mainstream position among hacker types. That seems to be long gone by now. I guess hardware catching up with resource requirements took away one of the biggest reasons against it. And most people really embraced the web as more than a document platform. I think part of me still misses the old way of thinking about it.

I don't have any base issue with javascript; I think it's a wonderful way to build web applications. However, TOR and the dark net has entirely different considerations, and the cost of letting unvetted code run without asking you from a site you know nothing about is far, far greater. I wouldn't be surprised if just being on TOR would be convincing evidence for an unknowledgable jury, even if the site was about something legal but connotative (activism targeting the federal government, for example).

Re: Freedom Hosting sites compromised, founder arrested

#64
post #36

Uhm, so where exactly does the FBI/NSA come in? As of now there is some guy stating that some hoster has been pwnd and uploaded some JS that expoloited something that might be FF17 that might have been shipped with the tor browser bundle. Why exactly does he thing FBI/NSA is involved? If he has the exploit code why didn't he upload it? Lots of conclusions based on assumptions. As of now I'd think it's more likely som…

TOR is also a great honeypot. There are no ways of validating a given node is not governmental, either.

Re: Freedom Hosting sites compromised, founder arrested

#66
post #29

Earlier quoted context omitted.

Yet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.

I didn't know that. It plugs a hole in the targeted surveillance programs, at the expense of all prepaid users. The target demographics for prepaid is mostly kids and teens, poor people, and people concerned about their privacy, split between sensitized geeks, unfaithful lovers and criminals. For the first two demographics cheap monthly plans are now emerging (in France, Free offers two hours of talk and infinite SMS…

> On a slightly related topic, in demonstrations, people caught without a cell phone during an ID check often end up arrested for "administrative reasons".

So the likely reason for this is so that they can get an accounting of who was there, right? Where are you referring to?

Re: Freedom Hosting sites compromised, founder arrested

#67
Software that creates randomly TBs of fake email, voice (skype) and other communication daily to disrupt NSA. Possible? Helpful?

I.e. billions of emails created daily originating from millions of email accounts created daily that contain random words including the ones the NSA is looking for.

I mean, they went on the path of the least resistance with this whole PRISM thing. Kind of blatantly stupid approach of "just listen to everything". That can possibly be derailed by simple creating tons and tons of "everything" daily to feed their stupid programs.

Re: Freedom Hosting sites compromised, founder arrested

#68
post #37
post #20

Earlier quoted context omitted.

> America The American government, you mean.

For us foreigners, knowing that America has strong democratic roots, it is obvious (and worrying) that the majority of american citizens actually agree with that.

Well, can't blame the electorate this time: Obama is doing the opposite of what he always promised and got elected for.

Re: Freedom Hosting sites compromised, founder arrested

#69

Anyone who was using Windows for TOR browsing was already asking for trouble. Anyone browsing outside a "sealed" VM setup such as Whonix was also asking for trouble.

Browsing in a VM doesn't help: the VM still has an IP address.

If you just run tor inside the VM, the above is true. If all the traffic out of the VM is routed through tor, then the IP address they will get is a tor (not clearnet) IP address. In order to get a clearnet IP address off a VM, you'll need to exploit the VM itself, a task clearly much harder than misusing javascript in a browser.

Re: Freedom Hosting sites compromised, founder arrested

#70
post #54

Earlier quoted context omitted.

Checking on this now. I find it dubious, but possible. I haven't used the Tor Browser Bundle for quite a while, but last I recall they definitely had a mechanism to keep JavaScript from executing. It seems ridiculous that they wouldn't, given their long history of advocacy for NoScript et al. Will edit when done installing/checking. EDIT: So it seems that NoScript is installed as part of the package, but that scripts…

[EDIT: edited typo, clarified what TAILS was] I had mentioned (split between a couple other posts) that even with JS enabled, Noscript will prevent many XSS/CSRF and clickjacking attempts, which has been explained to me as the reason for its inclusion. And That disabling Javascript actually makes you more fingerprintable because it's rare for browsers to do this. I am guessing that the payload that article mentions s…

>prevented TBB Firefox from even making a network connection that's not to the Tor tunnel, or possibly even prevent Firefox from knowing it's own IP. Dunno if something like this is even possible on Windows.

I don't currently use Tor, but I've thought about it and this is how I would do it. This can be done on windows using a virtual machine that disallows internet connections. Have the VM only able to network with the host OS, which is running the Tor app. That way the VM doesn't have an internet IP to leak, and if firefox itself is compromised there isn't anything on the VM that could give you away.

Post reply on HN