Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

71–80 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#71

> The apparent FBI-malware attack was first noticed on August 4, when all of the hidden service sites hosted by Freedom Hosting began displaying a “Down for Maintenance” message. The underlining reason for this has been the notion that the FBI was attempting to catch people engaged in CP related activities... This maybe a little tin-foil here, but... If you deliver a 404-type of a page on all requests, no website is…

The way Tor works is that anyone can set up something called a "hidden service". It's basically a website that can only be visited by using Tor.

These websites have a unique URL. For example, Bitcoin Fog's URL is http://fogcore5n3ov3tui.onion/ If you try to visit that using a standard web browser, it won't work. But if you use Tor browser, then it takes you to the Bitcoin Fog hidden service.

Some of those websites were devoted specifically to delivering CP. Now the FBI's reasoning goes like this: anyone who was visiting those websites were very likely visiting them for the purpose of looking at CP.

The FBI delivered an exploit designed to identify as many of those people as possible. So even though no CP was being served, people were still accessing the URL. The malware collected the MAC address and hostname of the computer, then submitted that info to an FBI server. So those people were apparently added to a centralized FBI database.

One way that database might be powerful is if e.g. a politician (or any other government worker) were was identified as a visitor of one of these websites, because whoever controls that database now controls them.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#73
post #51

Earlier quoted context omitted.

the way Bruce Schneier is now using GPG Which way is that? Also, from your Tinfoil Hat Linux link, this idea is hilariously awesome: Keystroke monitoring — THL has gpggrid, a wrapper for GPG that lets you use a video game style character entry system instead of typing in your passphrase. Keystroke loggers get a set of grid points, not your passphrase. I wonder if it might be possible to implement that idea into other…

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008.

http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#74
post #19

If this is the only manner that the FBI --or any law enforcement for that matter-- has for identifying TOR users, then wouldn't the best operational security just be to firewall yourself off completely except for Tor connections? Better yet, you could monitor what applications are trying to broadcast out even if they are designed or intended not to leak. Isn't this what the TAILS live-CD does? For this case, even if…

..or just adhere to common sense and disable javascript.

... at the packet level.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#75
post #52

Earlier quoted context omitted.

> Of course, none of these "theories" manage to address the fact that there is fairly strong evidence that water fluoridation does in fact reduce tooth decay. Not agreeing with those theories, but this argument is flawed. Even if it does "reduce tooth decay", so what, in the context of their argument? Who said a substance can't do two things at one time?

It isn't proof, it's supporting evidence.

It's only "supporting evidence" if they said that it doesn't also help with teeth.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#76
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

The original idea of a "tinfoil hatter" was that the "hatter" wore a head garment made of tinfoil, to block the mind-control radio waves the [government|aliens] were using to take over people's brains. I don't think we have any particular indication that is likely, yet.

To be fair, there is plenty of documentation that diverse subliminals find their ways into television programming, and even the music in supermarkets. Just like Fight Club.

https://en.wikipedia.org/wiki/Subliminal_message

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#77

"Freedom Hosting has long been notorious for allowing child porn to live on its servers. In 2011, the hactivist collective Anonymous singled out the service for denial-of-service attacks after allegedly finding the firm hosted 95 percent of the child porn hidden services on the Tor network. In the hearing yesterday, Donahue said the service hosted at least 100 child porn sites with thousands of users, and claimed Mar…

The reason the FBI and Anonymous seemed to join forces is because the FBI turned Anonymous's leader, Sabu. http://gawker.com/5890847/revered-anonymous-leader-rats-out-...

Anonymous doesn't have leaders. Good documentary on Anonymous: http://www.youtube.com/watch?v=2ZUHOELgif0

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#78
post #63

Earlier quoted context omitted.

Someone else should step up and give a comprehensive overview, because I can only recount the timeline from memory, not provide sources. But iirc, Anonymous was a loose coalition of random people on the internet, some of which turned out to have some basic hacking skills. They weren't really taken seriously until they embarrassed HBGary. At that point, the FBI began investigating them. Anonymous changed their name to…

> The FBI used standard police techniques to infiltrate and eventually dismantle the those groups. Seriously, how do we know the FBI's story isn't "parallel construction"? It always seemed to me that tracking down Anonymous would be easy if you had NSA-scale monitoring. I don't want to sound like paranoid guy, but maybe the FBI's stories about tracking down clues from chat logs are all made up.

I don't think it sounds paranoid. I think it's at least plausible.

I only recently learned about parallel construction: http://en.wikipedia.org/wiki/Parallel_construction

Basically, the NSA is suspected to cooperate with other arms of the government, such as the DEA. The NSA supposedly provides information about who is involved in what illegal activity. Apparently this information is provided illegally, without a warrant. So if the DEA gets info from the NSA, the DEA needs to make up a story about how they came to possess that info, since that info was collected illegally without a warrant. That's parallel construction.

I don't know whether NSA would bother with a target like Anonymous, but it's not outside the realm of realistic possibility.

The biggest question is, how did the FBI identify Sabu? He supposedly revealed himself by visiting the website 2600.com, and selling stolen credit cards on Facebook. But how did visiting that website reveal Sabu?

Actually, now that I think about it, the best explanation is probably the simplest: 2600.com probably runs forums, and Sabu probably posted to those forums from his home IP address like an idiot. So the FBI simply demanded his IP address from 2600.com.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#79

Earlier quoted context omitted.

Please tell me more background about that. (I recall mention of this before on HN, but I'm not recalling many details.) What's our best information on how leadership of Anonymous has changed over time? AFTER EDIT: Thanks for your link, which I think came as an edit to your comment. Here is a link to follow-up news: http://www.theguardian.com/technology/2013/feb/22/lulzsec-sa...

Someone else should step up and give a comprehensive overview, because I can only recount the timeline from memory, not provide sources. But iirc, Anonymous was a loose coalition of random people on the internet, some of which turned out to have some basic hacking skills. They weren't really taken seriously until they embarrassed HBGary. At that point, the FBI began investigating them. Anonymous changed their name to…

Lulzsec was a group of people that split from anonymous. They used "AntiSec" as their slogan. Anonymous is still around and often they either disagreed or completely fought against what Lulzsec was doing.

Anonymous itself does not have leadership, it's more of a swarm mentality.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#80
post #36

Earlier quoted context omitted.

In case you hadn't heard, much of "Anonymous" has been FBI-sponsored activity.

Source and details would be welcome.

Read up on Sabu and the timeline of events between his initial arrest and the various Anonymous Operations. He's a narc, has admitted it and was very much involved in most of the operations. Coincidentally, most people in those operations were rolled on and his assistance has been used in their arrests/cases.
Post reply on HN