Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

271–280 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#271
post #228

Earlier quoted context omitted.

> You mean changing the number of "2048" to "4096"? No, certainly not. I agree with you; the change from 2048 to 4096 isn't interesting. The interesting part is that he 1) generated a new key (okay, not actually interesting in itself) , 2) is using it in an isolated install, 3) this isolate install is on entirely separate hardware, not just a VM, 4) this separate hardware is new hardware that has never been networked…

> Is going to such an extreme... really necessary? Since Schneier's now doing analysis of unreleased Snowden documents for the Guardian, he now has reason to believe that the NSA has a strong motive to see what documents he's working on. Seems to me that the level of tin-foil-hattery that's reasonable to protect against an organisation likely to be targeting you specifically needs to be an order of magnitude greater…

Well, tin-foil-hattery traditionally refers not only to the paranoia associated with the probability of being watched but also with the malicious or manipulative intent of those people or groups. Schneier needs to protect himself from the possibility of either his data being used in a manner to prosecute or punish or action taken to stifle work he has so far kept private. It's more than reasonable for him to give credence to the threat of a self-interested government agency acting maliciously toward him.

However, Schneier was a target well before this due to the nature of his work. It is exactly the scope of the recent revelations that throws the conventional thinking on where the fuzzy line between an appropriate risk assessment based on position of interest and the general population. When the potential dragnet is widespread and permanent I no longer have to only consider how important I am now (which I'm not), but I also have to consider if I will ever be take on a role that IS important not just now, but then.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#272
post #24

Earlier quoted context omitted.

WTF? Can we even trust the water we get from the government? Maybe they put some meds in there to make us dumb and complaint. Funny you should mention that -- I believe that water fluoridation was once suspected of being a communist plot to more or less the same effect.

Not just "once". Many conspiracy theorists still believe that it is some form of government plot or another. The theories range from it being a toxic waste disposal scheme that is poisoning people (and as far as I know, there is some basis for the claim that fluoridation came about as a way to cheaply get rid of a relatively toxic byproduct; that doesn't validate any other part of it though), to fluoride being used a…

One of the more sensible theories I've heard is that the fluoridation push happened at about the same time as the need to ramp-up uranium hexafluoride use for enrichment processes ... and that the sudden demand for fluoride could be masked by a civilian "decay prevention" program.

See also: Donora death fog. http://www.fluoridation.com/donora.htm

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#273

What is happening to this world? The Government and it's so-called agencies vested with protecting America and its allies are treating everyone like criminals, privately harvesting our information via any means possible. They don't even have to hide it any more. They can admit things like this and nobody can do anything about it. We've passed the point of being able to defend ourselves against actions like this. Ever…

I know. It's as if (ex-CIA-case officer) Phil Agee's claim back in the mid-80s that America was about to be Latinized is true.

Healthcare, education, housing ... what's next?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#274
post #125

The use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually…

Cops have been picking locks for as long as both have existed.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#275

Earlier quoted context omitted.

Wow, really good idea. Is a VM that is used for absolutely nothing else good enough?

The VM is easily vulnerable to the host OS, so running in a VM only protects the activities you do in the VM in the sense that the software pwning the host might not be looking for it. So not really.

Unless you are not using the host OS for anything _other_ than virtualization. If the host OS is used to host VMs[1], which are then used for specific tasks (casual browsing, banking, development, etc). Any exploit will be limited to the VM. This would be a pretty solid setup. It is only vulnerable to attackers that have direct access to the hardware, or have the ability to exploit the hypervisor.

[1] in other words if the host OS is used as a hypervisor, or if the host OS _is_ a hypervisor.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#276
post #197

Earlier quoted context omitted.

Germany's best-selling PC magazine c't periodically distributes "Bankix" on their CD. It's a Linux live system (with permanent storage on a USB stick) geared specifically towards online banking. I believe that quite a few people actually use it. Of course the hardware is the same, but you get a clean single purpose software system.

> Germany's best-selling PC magazine c't periodically distributes "Bankix" on their CD. >I believe that quite a few people actually use it. That sounds like a great attack vector. How secure are factories where discs are pressed? Even without access to the factory you could buy a bunch of magazines and repackage them with compromised CDs.

Someone would probably notice, checking the DVD against a checksum.

Repackaging it seems to be tricky, since the paper inlay is bound in the magazine, it's not just stuck on the cover or whatever. You tear it out at a perforation, leaving part of the DVD cover inside.

There are much more exposed attack vectors on online banking users, I would think.

And you can always just download the ISO and check it against the hash (and the PGP key).

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#277
post #51

Earlier quoted context omitted.

the way Bruce Schneier is now using GPG Which way is that? Also, from your Tinfoil Hat Linux link, this idea is hilariously awesome: Keystroke monitoring — THL has gpggrid, a wrapper for GPG that lets you use a video game style character entry system instead of typing in your passphrase. Keystroke loggers get a set of grid points, not your passphrase. I wonder if it might be possible to implement that idea into other…

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

Air-gapping is really the only way to stay secure. Plus, I would worry about cameras, microphones and vibration monitors, so I would want to put the air-gapped machine in a room that is away from any other electronics. Ideally in some sort of faraday cage, or at least located a reasonable distance away from walls - to bring it up to TEMPEST (or similar) standards. Unfortunately, most of us do not have the space in our homes to do it properly, so we have to resign ourselves to losing control of our machines and our data.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#278
post #262

Earlier quoted context omitted.

It is unethical or illicit for me to tap someone's phone or install malware on their computer. That doesn't mean it's illicit or unethical for the FBI to do so. The whole point of having a state is to trust it with powers that individuals should not exercise on their own authority.

Right, and when the FBI goes rogue (because that's whats happening) what?

Obama fires the FBI director? If they're not following his policies or the law, why hasn't he?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#279
post #151

Earlier quoted context omitted.

What are you talking about? Nobody is amazed that the "good guys" (btw, whose good guys?) have good tools. It's been known for decades that the USA has some of the best signals intelligence people and systems. But that's not even relevant here. This particular attack exploits a known issue of Tor, which has existed by design since day one. Hacking machines isn't rocket science, and the particular vulnerability in Fir…

This particular attack exploits a known issue of Tor, which has existed by design since day one. Just so everyone's clear, this was not a "known issue of Tor". It was a javascript based Firefox exploit.

The known issue of Tor that I refer to (and sorry for not being more specific) is that a buggy client can leak your identity. The Firefox exploit leverages this design weakness.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#280

Earlier quoted context omitted.

You cannot arrest the U.S. government for felonies.

But you can arrest individuals who, using their office, engage in felonies. If this is organizational, i believe we could use RICO.

Only if it's unsanctioned. Like Watergate.

But if the government as an official approved sanctioned policy directs an employee to do an action (like, hack into Facebook's servers), good luck trying to get that employee arrested. The government may be doing illegal acts, but no one can be arrested over those since they are sanctioned by the two law making branches of government (executive and congress).

Post reply on HN