Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

151–160 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#151
post #88

It's sad everyone on here is amazed the good guys have good tools. Sure it probably cost them $1M USD to have some server record an incoming ip from an http request, but still. "Oh noes, we aren't 3 steps ahead of them, they are 3 steps ahead of us." Fuckin-a they are and I'm glad. Getting rid of scumbag terrorists, child porn shitbirds and spying on foreign adversaries is fine by me. And yes, I already know the comm…

What are you talking about?

Nobody is amazed that the "good guys" (btw, whose good guys?) have good tools. It's been known for decades that the USA has some of the best signals intelligence people and systems.

But that's not even relevant here. This particular attack exploits a known issue of Tor, which has existed by design since day one. Hacking machines isn't rocket science, and the particular vulnerability in Firefox was public before the attack.

What people are surprised by is the brazen and open use of an illegal hack by law enforcement officials. We have laws for a reason and lawmen to uphold those laws. When the lawmen are breaking the laws we're pretty much fucked. I'm sorry that you can't see that.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#152
post #88

It's sad everyone on here is amazed the good guys have good tools. Sure it probably cost them $1M USD to have some server record an incoming ip from an http request, but still. "Oh noes, we aren't 3 steps ahead of them, they are 3 steps ahead of us." Fuckin-a they are and I'm glad. Getting rid of scumbag terrorists, child porn shitbirds and spying on foreign adversaries is fine by me. And yes, I already know the comm…

> I suppose I will cross that bridge when that happens.

No. When that happens, you won't cross it. You'll fall right into the river.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#153

What is happening to this world? The Government and it's so-called agencies vested with protecting America and its allies are treating everyone like criminals, privately harvesting our information via any means possible. They don't even have to hide it any more. They can admit things like this and nobody can do anything about it. We've passed the point of being able to defend ourselves against actions like this. Ever…

Pff. That's like saying the government is spying on you because you saw a police officer look at you when you walked past a police car. Personally, I am just fine with the FBI harvesting the details of anyone who visits a CP site. So this puts strain on the network and causes loss of functionality for non-illegal uses of Tor - inconvenient, but then it's also inconvenient when you can't park because a police car, fire truck, or ambulance is taking up the space you hoped to park in. On a scale of 1 to 10, the harm suffered by non-criminal Tor users during this sting operation looks to me to be about a 1 or a 2.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#154
post #76

Earlier quoted context omitted.

The original idea of a "tinfoil hatter" was that the "hatter" wore a head garment made of tinfoil, to block the mind-control radio waves the [government|aliens] were using to take over people's brains. I don't think we have any particular indication that is likely, yet.

To be fair, there is plenty of documentation that diverse subliminals find their ways into television programming, and even the music in supermarkets. Just like Fight Club. https://en.wikipedia.org/wiki/Subliminal_message

There is also plenty of research that these don't actually work, or at least not nearly as well as you think they do.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#155
post #88

It's sad everyone on here is amazed the good guys have good tools. Sure it probably cost them $1M USD to have some server record an incoming ip from an http request, but still. "Oh noes, we aren't 3 steps ahead of them, they are 3 steps ahead of us." Fuckin-a they are and I'm glad. Getting rid of scumbag terrorists, child porn shitbirds and spying on foreign adversaries is fine by me. And yes, I already know the comm…

The problem is, as you're crossing that bridge it's burning behind you.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#156
post #141
post #73

Earlier quoted context omitted.

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008. http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

I kinda thought the same thing about flash-drive viruses, and why Bruce wasn't using CDs/DVDs instead. Then I realized if he was really serious, he wouldn't say what he's really using, and he'd have a USB honeypot plugged into his network-facing computer.

Named "Iocane Powder" of course.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#157
post #14

Earlier quoted context omitted.

Meanwhile the way Bruce Schneier is now using GPG is really only one conceptual leap away from full-blown Tinfoil Hat Linux usage: http://en.wikipedia.org/wiki/Tinfoil_Hat_Linux The difference between "tinfoil hatters" and reasonable people like Bruce Schneier now seems to be how concerned they are with their ability to destroy a harddrive, and TEMPEST.

You mean changing the number of "2048" to "4096"? I'm not sold on that being a meaningful improvement to his security, but even so, you realize that change costs him nothing , right? He needed to generate a new key... why not set it to 4096 bits? Everything he does with that key happens in human scale time --- even a 500ms per message delay wouldn't be noticeable. So, some evocatively named Linux distro recommends th…

I am using 8192 bits, just in case ;-) also applying one time pads when I can.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#158
post #132

Earlier quoted context omitted.

LulzSec was not Anonymous. While some of its membership may have overlapped, that doesn't really mean anything, because anyone can be a part of Anonymous, simply by carrying out acts in the group's name. Sabu forgot to activate TOR before logging into IRC just a single time, and the FBI was able to locate him. Sabu was the legal guardian of his siblings, and was pretty much told that he would never see them again if…

If I had to guess, best case scenario he is going to be sentenced to 10 years. Ten years? Even with a deal? Really? That's astonishing if accurate.

Like I said, that's just a guess based both on the severity of his crimes and the tendency of the United States to overreact to anything that involves a computer.

I could very well be wrong.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#159
post #14
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

Meanwhile the way Bruce Schneier is now using GPG is really only one conceptual leap away from full-blown Tinfoil Hat Linux usage: http://en.wikipedia.org/wiki/Tinfoil_Hat_Linux The difference between "tinfoil hatters" and reasonable people like Bruce Schneier now seems to be how concerned they are with their ability to destroy a harddrive, and TEMPEST.

Bruce Schneier is not a reasonable person about his own computer security any more than a virologist is a reasonable person over her own infectivity.

He knows too much to be a reasonable person.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#160
post #73
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008. http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

SD cards have a physical switch you can flip for read-only.
Post reply on HN