Live data from Hacker News

The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

wired.com

41–50 of 58 posts

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#41
post #17

A separate BSD firewall box to prevent any connections outside Tor would've prevented this, or thegrugqs p.o.r.t.a.l. box. These attacks will only get better, FF 0day isn't all that expensive so simply disabling JavaScript won't be an option in the future, which prevented the second attack where a custom exploit was used by the FBI. What's the legal defense if a random .onion address is posted claiming it's leaked ju…

>FF 0day isn't all that expensive so simply disabling JavaScript won't be an option in the future Do you have any example of exploit that would no require javascript? AFAIK they are usually about javascript memory handling in order to evade the sandbox

Just go through FF CVEs and look for vulnerabilities that enable remote code execution without .js like .cpp malformed text rendering.

Doesn't seem to me that the FBI cares about hiding the fact your browser has been exploited as their last known attempt (freedom hosting) didn't try very hard to cover it's tracks.

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#42

Earlier quoted context omitted.

Interesting to me though is that that article seems to imply that if you are after an Onion server you only need one "idiot" using it in order to unmask it. By compromising that user, their compromised system will get you information about the server. Or did I mis-read what they were implying?

You're misreading it. They already had a guy at the web hotel. The injected code unmasked the visitors, allowing the FBI to go out and arrest them along with taking down the site itself.

Thanks.

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#43

This article is talking about 2 different things. If you write a simple Flash program that opens a socket to a remote server, you can embed that on a site and use it to identify certain people running through Tor or any other SOCKS/HTTP proxy. It will only catch people who have configured their proxy very poorly. This has been known for well over a decade and it just catches the low-hanging fruit; it's really not an…

Isn't it recommended that users turn off JavaScript when trying to anonymize?

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#44

A separate BSD firewall box to prevent any connections outside Tor would've prevented this, or thegrugqs p.o.r.t.a.l. box. These attacks will only get better, FF 0day isn't all that expensive so simply disabling JavaScript won't be an option in the future, which prevented the second attack where a custom exploit was used by the FBI. What's the legal defense if a random .onion address is posted claiming it's leaked ju…

> "How do they draw a legal distinction between a pervert and an idiot who clicks a link?"

Much of child porn law centers around "intent" -- it's not illegal to see child porn (and be like "oh nasty, don't want that, alt-f4"), it's illegal to intentionally produce, procure, possess, or distribute it.

If the FBI controls the server, they can monitor connections and behavior. Did the user open the site and then immediately leave? Did they scroll around? Did they click images or videos? Did they access multiple pages which are clearly identified as perv material rather than leaked juicy Sony e-mails? Loading the site and then immediately leaving doesn't show intent, but loading the site and then digging around on it does. (There's also the next level -- once the FBI identifies a potential perv-or-idiot and seizes their box, they can check for additional evidence, like whether someone has accumulated a collection of child porn.)

The legal defense concept that would apply is called an "affirmative defense". It basically says yes, you did the thing in question, but explains that there was no criminal intent. Like, yes, I clicked on a link that took me to a website with illegal content, but I was misled, as you can see from my behavior of immediately hitting the "back" button. (Likewise, if you find in your large porn collection that a few images are actually illegal, you can safely delete them or turn them over to police -- the fact that your main collection is legal, and that you acted to get rid of the illegal content, shows that you did not have criminal intent.)

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#45

Earlier quoted context omitted.

According to the article, Operation Torpedo happened one year earlier than the Freedom Hosting hack. I don't think we have seen the results of the latter yet.

The Freedom Hosting event was over 1.5 years ago. I'm starting to wonder if there was some procedural / legal issue with that operation. I don't know what would delay the investigation this long otherwise.

The extradition case in Ireland hasn't concluded yet, but looks like it's being heard tomorrow.

http://www.breakingnews.ie/ireland/extradition-case-against-...

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#46
post #31

This article is talking about 2 different things. If you write a simple Flash program that opens a socket to a remote server, you can embed that on a site and use it to identify certain people running through Tor or any other SOCKS/HTTP proxy. It will only catch people who have configured their proxy very poorly. This has been known for well over a decade and it just catches the low-hanging fruit; it's really not an…

>>It will only catch people who have configured their proxy very poorly. To add to this, in Firefox if you use this: http://i.imgur.com/ajT98xC.png , Flash does not obey it. I kinda think Mozilla should put some kind of warning-text on this dialog window to warn uses that it doesn't apply to flash, silverlight or any plugins. This surprised me at first but it makes sense if you think about it. You really have to do a…

Careful, sshuttle doesn't route UDP, and by default does not route DNS requests either.

For Firefox, I don't think they should bother anyway, the world is killing flash, if you want to be anonymous on the internet use noscript and don't install flash in the first place.

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#47

Apparently it's a surprise to Wired that a group that engages in hacking uses a tool commonly used for hacking.

The surprise is surely that a group expected to use complex and highly technical exploits which come from the minds of top government crackers instead uses years old hacks distributed with a tool known, rightly or wrongly, as the preserve of script-kiddies everywhere?

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#48

Every one of these threads, here and on Reddit, ends up packed with accounts demanding "proof" of vulnerability or saying it's a silly conspiracy to say that the typical Tor install provides very weak protection.

This post is now 12 hours old, and I can't see a single response along those lines, let alone a comment section packed with such things. You may want to rethink your prejudice...

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#49

This kind of scares me. I don't know much about the case, but the guy is an IT worker, and it's hard for me to believe he'd have such terrible opsec, and he says it wasn't him. I'm all for catching pedophiles and everything, but how did we know it was actually him behind the computer at the time the flash file was loaded? What if it were a friend at the house (maybe even someone intending to frame him), or a virus on…

> This kind of scares me. I don't know much about the case, but the guy is an IT worker, and it's hard for me to believe he'd have such terrible opsec There is a wide range of "IT workers". I would guess that 50% of them could easily make this mistake. Security is hard. Maintaining a bunch of computers with poor security is easy (ask sony).

to be fair, the attack surface on sony is much larger than my home computer's.

Re: The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users

#50

Apparently it's a surprise to Wired that a group that engages in hacking uses a tool commonly used for hacking.

The surprise is surely that a group expected to use complex and highly technical exploits which come from the minds of top government crackers instead uses years old hacks distributed with a tool known, rightly or wrongly, as the preserve of script-kiddies everywhere?

Why would they use their own tools and risk revealing them to the public when they can use a recognized existing tool and mask their full capabilities?
Post reply on HN