Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

241–250 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#242
post #167
post #129

Earlier quoted context omitted.

wiretapping normally require a specific target, with a specific reason. Going after the tor email service, is like wiretapping the US postal service for a fishing expedition. It sounds to me as being outside the FBI's legal wiretapping abilities.

This is just wrong. First, you are implying that Tor has an official Tor e-mail service, which it does not. Tormail is/was just a basic e-mail service someone not associated with the Tor project was hosting on the deep web. For all anyone knows, Tormail itself could have been run by the FBI or NSA or whatever all along. Anyone who thought Tormail guaranteed them anonymity was a fool, much like anyone who kept Javascr…

> What was targeted was the hosting provider that was hosting 95% of child pornography in the deep web, and that hosting provider also happened to host Tormail and a bunch of other non child pornography websites.

What the government did was the equivalent of show up at the houses of everyone who used a particular post office and forcibly finger print them because that post office routed 95% of the child porn magazines in the US (regardless of what percentage of their traffic that actually was, which you don't even mention besides 'there were other sites, too').

That would be a clear abuse of powers, as is this.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#244

Earlier quoted context omitted.

And if your bank does not do 2 factor authentication switch to another bank.

Which banks actually do this? I've never encountered one.

Most European banks do. Only few US banks do. Primary reason for this difference is that it's trivial to transfer money from one European bank account to any other bank account. It basically works like email, where you can just enter any destination bank account number. With US bank accounts the process is much harder, as you first need to add and confirm the second bank account (which somewhat reduces the risk of what can happen if someone gets access to your account).

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#245
post #33

Earlier quoted context omitted.

Source?

E.g., http://www.theguardian.com/technology/2012/mar/06/lulzsec-sa... Check the timelines. Some of Lulzsec's most dramatic attacks were carried out with an FBI agent literally looking over Sabu's shoulder. 'Opdarknet' in particular seemed quite a bit different from the rest, in the MO (basically the same as the FBI used against Freedom Hosting) and the wording of their release.

I forgot about the whole Sabu thing. Thanks.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#246

Earlier quoted context omitted.

Use a machine that is used for absolutely nothing else.

Wow, really good idea. Is a VM that is used for absolutely nothing else good enough?

The VM is easily vulnerable to the host OS, so running in a VM only protects the activities you do in the VM in the sense that the software pwning the host might not be looking for it. So not really.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#247
post #168

Earlier quoted context omitted.

Personally.

Just out of curiosity - assume you took a key of 8096 bits - and it is super long - could you then make a hash of the key which were shorter, and provide the hash, with instructions on how to reverse it, and then use the hash to produce the 8096 keylength with less digits between you and the recipient?

No - one of the main points of a hash is that it is non-reversible.

Also, if you had a short string that could be expanded into the larger key, then what you really have is a short key to a slightly different crypto system, which is less secure than the original key in the original system.

Also, if you can significantly compress a string of truly random data, you can also probably compress digital video by a significant factor as well, and should therefore found a startup selling your groundbreaking compression technology.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#248
post #36

Earlier quoted context omitted.

In case you hadn't heard, much of "Anonymous" has been FBI-sponsored activity.

Source and details would be welcome.

http://edramalpl7oq5npk.onion/Sabu is a good explanation

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#250
post #125

The use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually…

> At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It might be a stretch but.. "LSD was one of the materials tested in the MKUltra program. The final phase of LSD testing involved surreptitious administration to unwitting non-volunteer subjects in normal life settings by undercover officers of the Bureau of Narcotics acting for the CIA." - htt…

Thank you. It was a covert human research operation experiment rather than police enforcement, but it still bear some meaning on this issue. The government offered one victims family an out-of-court settlement of $750,000.

If the government release a virus and it cause damages, government might be found liable. Still, an out-of-court settlement is not exactly a predicate, so its hard to know what would happen.

Post reply on HN