Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

11–20 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#11
If this is the only manner that the FBI --or any law enforcement for that matter-- has for identifying TOR users, then wouldn't the best operational security just be to firewall yourself off completely except for Tor connections? Better yet, you could monitor what applications are trying to broadcast out even if they are designed or intended not to leak. Isn't this what the TAILS live-CD does? For this case, even if your software was out of date and vulnerable to the initial attack on the browser, the attempt to broadcast out would hit a firewall and fail (and ideally be logged and alerted).

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#12

my buddy's mother-in-law makes $75 every hour on the internet. She has been without a job for seven months but last month her check was $17516 just working on the internet for a few hours. useful source... http://xurl.es/w2x2a

Margaret come on now, that would be 233 hours of work if she was paid on a 1099. She still needs to pay tax and self-employment tax on all of that money. That said, I don't think 233 hours really counts as "just a few hours".

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#13
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

Regarding the kernel.org hack: Even with git’s hashing, wouldn’t an attack on Linus’ – or even a subsystem maintainer’s – computer still be a viable way to get code into the kernel, as said code would be a variant of new, unpublished code rather than changed old code?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#14
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

Meanwhile the way Bruce Schneier is now using GPG is really only one conceptual leap away from full-blown Tinfoil Hat Linux usage: http://en.wikipedia.org/wiki/Tinfoil_Hat_Linux

The difference between "tinfoil hatters" and reasonable people like Bruce Schneier now seems to be how concerned they are with their ability to destroy a harddrive, and TEMPEST.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#15
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

Regarding the kernel.org hack: Even with git’s hashing, wouldn’t an attack on Linus’ – or even a subsystem maintainer’s – computer still be a viable way to get code into the kernel, as said code would be a variant of new, unpublished code rather than changed old code?

It wouldn't be particularly easier to do it that way than just submitting your subversive code normally. Either way your change would need to be "underhanded" such that anybody viewing it wouldn't suspect anything.

In fact, trying to slip it in under the radar like that would actually just increase the chances of getting caught, because then it becomes something that isn't suppose to be there instead of merely something that does something that it isn't suppose to do.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#16
post #6

> "Mozilla confirmed the code exploited a critical memory management vulnerability in Firefox that was publicly reported on June 25, and is fixed in the latest version of the browser." Will Rust help eliminate the problem of buffer overflows and other memory related hacks?

Is it intended to? Yes. Will it? Time will tell. :)

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#18
WTF? Can we even trust the water we get from the government? Maybe they put some meds in there to make us dumb and complaint. Is that too far fetched now after what we've reading?

>> Donahue also said Marque had been researching the possibility of moving his hosting, and his residence, to Russia.

Nice try FBI, but I have a feeling that Puttin's Russia will have him a gulag after a 5 minute "trial," appeal included.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#19

If this is the only manner that the FBI --or any law enforcement for that matter-- has for identifying TOR users, then wouldn't the best operational security just be to firewall yourself off completely except for Tor connections? Better yet, you could monitor what applications are trying to broadcast out even if they are designed or intended not to leak. Isn't this what the TAILS live-CD does? For this case, even if…

..or just adhere to common sense and disable javascript.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#20

my buddy's mother-in-law makes $75 every hour on the internet. She has been without a job for seven months but last month her check was $17516 just working on the internet for a few hours. useful source... http://xurl.es/w2x2a

Margaret come on now, that would be 233 hours of work if she was paid on a 1099. She still needs to pay tax and self-employment tax on all of that money. That said, I don't think 233 hours really counts as "just a few hours".

Especially since 4 weeks (28 days) at 40hrs/week is 160 hours :-)
Post reply on HN