Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

211–220 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#211
post #204

Earlier quoted context omitted.

It's different if you own your own USB stick and only use that stick, and have the hosts configured correctly. Arbitrary USB devices picked up off the ground or provided by malicious people do terrify me, mainly because they can be keyboards or whatever in usb-stick physical packaging.

Even USB sticks that are your own USB sticks could be keyboards or whatever. Unless you've verified it isn't a store bought USB stick is just as risky as one that you picked up from the street or that someone gave you, in both cases you have no idea 'where it's been' before it got into your possession.

No, the vast majority of USB sticks in the world are not pwned. If you randomly go out to purchase one in a large market, it's pretty likely to be safe.

Things like the Bagram PX were concentrations of high value targets with only one source of supply. The general USB stick marketplace is a lot safer. In China they're often fake and thus unreliable (smaller than advertised), but in the US, I'd be pretty comfortable driving to a Best Buy 50 miles away and picking up a random USB token.

A USB key someone hands you is much more likely to be a targeted attack. A USB key randomly lying on the ground outside a target is also much more likely to be an attack.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#212
post #94
post #83

Earlier quoted context omitted.

Do you assume that the techniques used for something most would assume to be reasonable will not ever be used in less desirable ways?

Police "techniques" involve guns, tear gas, helicopters, etc. At any time the police could in theory fly to your house, launch tear gas into your windows, and shoot you in the head as you run out. And I don't know about you, but I'm not exactly worried about that happening to the point where I want to take guns, tear gas, and helicopters away from the police. This is the FBI taking down criminals engaging in a clear…

At any time the police could in theory fly to your house, launch tear gas into your windows, and shoot you in the head as you run out. And I don't know about you, but I'm not exactly worried about that happening to the point where I want to take guns, tear gas, and helicopters away from the police.

You might want to rethink your position: http://www.democracynow.org/2010/5/13/25_years_ago_philadelp...

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#213
post #211

Earlier quoted context omitted.

Even USB sticks that are your own USB sticks could be keyboards or whatever. Unless you've verified it isn't a store bought USB stick is just as risky as one that you picked up from the street or that someone gave you, in both cases you have no idea 'where it's been' before it got into your possession.

No, the vast majority of USB sticks in the world are not pwned. If you randomly go out to purchase one in a large market, it's pretty likely to be safe. Things like the Bagram PX were concentrations of high value targets with only one source of supply. The general USB stick marketplace is a lot safer. In China they're often fake and thus unreliable (smaller than advertised), but in the US, I'd be pretty comfortable d…

The vast majority of USB sticks are lost, not attacks, the vast majority of USB keys handed to you are handed to you in good faith, not as attacks.

That doesn't mean there are no attacks.

So prudence is adviced in either case, on the off chance that the one that you have is a bad one. Ditto for anything else that you stick into a USB port.

That webcam plugged into your computer, are you sure the mike isn't on all the time and that the driver doesn't pass your speech during the day out in compressed and encrypted form to some server farm at night ;)

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#214
post #118

Earlier quoted context omitted.

If you can come up with a backdoor that requires the non-obvious interaction of multiple parts of the kernel (or parts of the kernel and certain user-space actions) then it would be reasonable to break up the necessary changes and slip each one in as a part of a larger demonstrable improvement to each specific subsystem. For example (completely hypothetical), you could create a race condition in the kernel's page all…

That reminds me of a story I read about how the satellite companies foiled carders by slowly building up a new decryption system out of apparent garbage released across a long string of updates. I don't dare to search for it though, so I don't have a link.

http://www.codinghorror.com/blog/2008/05/revisiting-the-blac...

Original article: http://news.slashdot.org/story/01/01/25/1343218/directvs-sec...

Fascinating background story here: http://www.wired.com/politics/security/news/2008/05/tarnovsk...

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#215
post #125

The use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually…

> At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians?

It might be a stretch but..

"LSD was one of the materials tested in the MKUltra program. The final phase of LSD testing involved surreptitious administration to unwitting non-volunteer subjects in normal life settings by undercover officers of the Bureau of Narcotics acting for the CIA." - http://en.wikipedia.org/wiki/Project_MKUltra

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#216
post #151
post #88

It's sad everyone on here is amazed the good guys have good tools. Sure it probably cost them $1M USD to have some server record an incoming ip from an http request, but still. "Oh noes, we aren't 3 steps ahead of them, they are 3 steps ahead of us." Fuckin-a they are and I'm glad. Getting rid of scumbag terrorists, child porn shitbirds and spying on foreign adversaries is fine by me. And yes, I already know the comm…

What are you talking about? Nobody is amazed that the "good guys" (btw, whose good guys?) have good tools. It's been known for decades that the USA has some of the best signals intelligence people and systems. But that's not even relevant here. This particular attack exploits a known issue of Tor, which has existed by design since day one. Hacking machines isn't rocket science, and the particular vulnerability in Fir…

This particular attack exploits a known issue of Tor, which has existed by design since day one.

Just so everyone's clear, this was not a "known issue of Tor". It was a javascript based Firefox exploit.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#217
My two cents about the "french hosting provider" : The 22 of july, the french hosting provider OVH suffered an APT attack from intruders looking for the database of european clients. The 29 of july, OVH announce new rules about using Tor on their network... In august Marques is arrested.

http://d4n3ws.polux-hosting.com/2013/09/14/freedom-hosting-l...

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#218

Earlier quoted context omitted.

Use a machine that is used for absolutely nothing else.

And if your bank does not do 2 factor authentication switch to another bank.

Which banks actually do this? I've never encountered one.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#219

Earlier quoted context omitted.

And if your bank does not do 2 factor authentication switch to another bank.

Which banks actually do this? I've never encountered one.

Both my banks do (European banks, specifically Rabo and ABN/AMRO).

These are still not immune to phishing attacks but it's a lot better than TAN codes or some other 'dumb' authentication scheme.

Typically these systems work in conjunction with pin-and-chip card, a small piece of hardware that generates the codes and a challenge / response system built into the website you use for the authorization.

Separate challenges exist for logging in (read access) and transferring money.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#220
post #175

Earlier quoted context omitted.

What do you tell business owners to do when accessing their online banking?

Use a machine that is used for absolutely nothing else.

Wow, really good idea. Is a VM that is used for absolutely nothing else good enough?
Post reply on HN