Live data from Hacker News

Freedom Hosting sites compromised, founder arrested

twitlonger.com

121–130 of 140 posts

Re: Freedom Hosting sites compromised, founder arrested

#121

Software that creates randomly TBs of fake email, voice (skype) and other communication daily to disrupt NSA. Possible? Helpful? I.e. billions of emails created daily originating from millions of email accounts created daily that contain random words including the ones the NSA is looking for. I mean, they went on the path of the least resistance with this whole PRISM thing. Kind of blatantly stupid approach of "just…

This has been discussed before, in the context of network security. You can read about efficacy/bandwidth constraints, but basically to provide any strong security you need to spend an overwhelming amount of bandwidth on noise. You must always operate at peak bandwidth to everyone. It becomes prohibitively slow and expensive.

Re: Freedom Hosting sites compromised, founder arrested

#122
post #24

Earlier quoted context omitted.

The point is the iframe/JS is used to break out of the browser sandbox, due to a bug in the browser, with techniques like heap spraying (mentioned in the article). Once you manage to get arbitrary code running in the context of the browser, you can do anything the browser can, including (presumably) making raw non-TOR connections to anywhere, identifying the TOR user and correlating that with what they were doing ove…

That's why there are things like Whonix

[deleted]

Re: Freedom Hosting sites compromised, founder arrested

#123

This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at…

many people were using "Freedom Hosting" to host onion sites

tormail.org amongst them it seems. It's used at times by users of one famous online store of particular substances.

Just info. It's their problem if db leaked and they didn't use encryption of course.

Re: Freedom Hosting sites compromised, founder arrested

#125
post #124

Anyone notice this: >3. Bitcoin and all crypto currenecies set to absolutely CRASH as a result since the feds can not completely control this currency as they please.

I wouldn't think too much of it. It could be a bit of wishful thinking, or an attempt to manipulate the price of Bitcoins by spreading rumors. Both are fairly popular among Bitcoin speculators.

Re: Freedom Hosting sites compromised, founder arrested

#126
post #64
post #36

Uhm, so where exactly does the FBI/NSA come in? As of now there is some guy stating that some hoster has been pwnd and uploaded some JS that expoloited something that might be FF17 that might have been shipped with the tor browser bundle. Why exactly does he thing FBI/NSA is involved? If he has the exploit code why didn't he upload it? Lots of conclusions based on assumptions. As of now I'd think it's more likely som…

TOR is also a great honeypot. There are no ways of validating a given node is not governmental, either.

Indeed. Many people seem to misunderstand the purpose of the tor network. It is designed to conceal the sourcing node of a packet. That's it. Nothing more, nothing less. The only guarantee you get --and the only one you really need to remain anonymous-- is that your IP isn't stamped on the packets coming out of the exit node. You're not supposed to trust the exit node --or anything else you connect to through it-- for anything else. That's why you don't send login credentials in the clear over the exit node. It's why you don't send plaintext email over tor, or sign into services that are ever touched by a non-tor connection, or engage in plaintext conversation on IRC and have any expectation of privacy. Tor guarantees a different IP on the network packet, and that is it. And so far, it seems that the Tor project has made good on this guarantee. I've yet to hear about a deanonymization incident that can't be traced back to mistakes such as the ones above.

Re: Freedom Hosting sites compromised, founder arrested

#127
post #37
post #20

Earlier quoted context omitted.

> America The American government, you mean.

For us foreigners, knowing that America has strong democratic roots, it is obvious (and worrying) that the majority of american citizens actually agree with that.

>> America has strong democratic roots

No, America has strong American roots. Democracies and Republics both corrupt themselves over time.

America is unlike any other nation on earth, it's a hybrid, a democratic republic.

Re: Freedom Hosting sites compromised, founder arrested

#128

Earlier quoted context omitted.

The headline implies that the "compromise" is an inherent failure in the protocol (or else how could "half" of all sites be infected?) instead of the reality that the hosting provider intentionally placed an exploit in all of their pages. A better title may be like: "major .onion hosting service infiltrated by feds, all sites converted to honeypots; founder arrested". This does not imply any fundamental flaws in Tor…

You're being bizarrely pedantic. If the headline had read "half of all web sites compromised" I would never have it thought it was because of some underlying fault with HTTP.

Onion sites are (typically) accessed over HTTP, so the fact that I didn't think HTTP was flawed demonstrates that there's some misinterpretation here.

I'd suggest that you're the one being overly pedantic. "Protocol" doesn't necessarily have to refer to something explicitly labeled as a "protocol".

Re: Freedom Hosting sites compromised, founder arrested

#130
post #14

Earlier quoted context omitted.

AFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.

Yet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.

Citation, please?
Post reply on HN