Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

201–210 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#201

Earlier quoted context omitted.

Use a machine that is used for absolutely nothing else.

How many of them actually do?

I've set up VMs for people with their credentials in the VM and nowhere else, and the host firewalled pretty restrictively such that that VM is pretty useless except for banking. I suspect compliance is high on systems like that.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#202
post #149
post #128

Earlier quoted context omitted.

IANAL, but I'd be surprised if the police was allowed to raid me, launch tear gas through my window and shoot me in the head. Even with a warrant. I'm not worried about this happening, because it doesn't. If it did, I'm sure it would blow up into a huge scandal. I am worried about government agencies intercepting my traffic / communications because it does happen, it's really hard to find out unless you know what you…

> Even with a warrant. I'm not worried about this happening, because it doesn't. Spend a little time in here: https://duckduckgo.com/?q=warrant+no+knock+raid+mistake&t=ca... Or here: https://duckduckgo.com/?q=warrant++raid+mistake+death&t=cano... Or here: http://www.newyorker.com/online/blogs/comment/2013/08/swat-t... I'm still waiting for the scandal.

Is there a difference between ddg and startpage.com principles? Because I find startpage to be more in-line with the results I want to see.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#203
post #128
post #94

Earlier quoted context omitted.

Police "techniques" involve guns, tear gas, helicopters, etc. At any time the police could in theory fly to your house, launch tear gas into your windows, and shoot you in the head as you run out. And I don't know about you, but I'm not exactly worried about that happening to the point where I want to take guns, tear gas, and helicopters away from the police. This is the FBI taking down criminals engaging in a clear…

IANAL, but I'd be surprised if the police was allowed to raid me, launch tear gas through my window and shoot me in the head. Even with a warrant. I'm not worried about this happening, because it doesn't. If it did, I'm sure it would blow up into a huge scandal. I am worried about government agencies intercepting my traffic / communications because it does happen, it's really hard to find out unless you know what you…

> If it did, I'm sure it would blow up into a huge scandal.

how are you sure of that? Do you honestly think the public is privy to the movements of the people in charge?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#204
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

Given what we know about USB sticks, especially their use in Iran, you would have to be ABSOLUTELY FUCKING RETARDED to trust them. Oh so he encrypted his files, and walked them between his stand alone and his internet machines. Yeah, okay this established the file's integrity, and that's just fantastic. But what assurance does he have that the USB stick isn't getting infected on the internet machine, and then deployi…

It's different if you own your own USB stick and only use that stick, and have the hosts configured correctly. Arbitrary USB devices picked up off the ground or provided by malicious people do terrify me, mainly because they can be keyboards or whatever in usb-stick physical packaging.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#206
post #175

Earlier quoted context omitted.

What do you tell business owners to do when accessing their online banking?

Use a machine that is used for absolutely nothing else.

And if your bank does not do 2 factor authentication switch to another bank.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#207
post #204

Earlier quoted context omitted.

Given what we know about USB sticks, especially their use in Iran, you would have to be ABSOLUTELY FUCKING RETARDED to trust them. Oh so he encrypted his files, and walked them between his stand alone and his internet machines. Yeah, okay this established the file's integrity, and that's just fantastic. But what assurance does he have that the USB stick isn't getting infected on the internet machine, and then deployi…

It's different if you own your own USB stick and only use that stick, and have the hosts configured correctly. Arbitrary USB devices picked up off the ground or provided by malicious people do terrify me, mainly because they can be keyboards or whatever in usb-stick physical packaging.

Even USB sticks that are your own USB sticks could be keyboards or whatever. Unless you've verified it isn't a store bought USB stick is just as risky as one that you picked up from the street or that someone gave you, in both cases you have no idea 'where it's been' before it got into your possession.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#209

This is actually a pretty good attack. The only problem I see is the usefulness of the evidence that the attack gathers. Visiting an FBI warning over Tor isn't illegal, so appearing in some child-porn-user database because you were curious about how the exploit worked is a little disturbing, given the stigma child porn has. I'd also like to see the legal theory they used to seize control of someone's computer. Did a…

The effect is to dissuade CP traders. It's a warning shot, and it probably scared a lot of people off of Tor. I wonder what the effect on Silk Road has been.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#210
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

Stuxnet jumped an air gap.

Well, to be fair, this was in an OS that reads whatever is in a media you plug.

KDE/Gnome do the same thing, and there are possible attacks there.

Post reply on HN