A separate BSD firewall box to prevent any connections outside Tor would've prevented this, or thegrugqs p.o.r.t.a.l. box. These attacks will only get better, FF 0day isn't all that expensive so simply disabling JavaScript won't be an option in the future, which prevented the second attack where a custom exploit was used by the FBI. What's the legal defense if a random .onion address is posted claiming it's leaked ju…
>FF 0day isn't all that expensive so simply disabling JavaScript won't be an option in the future Do you have any example of exploit that would no require javascript? AFAIK they are usually about javascript memory handling in order to evade the sandbox
Doesn't seem to me that the FBI cares about hiding the fact your browser has been exploited as their last known attempt (freedom hosting) didn't try very hard to cover it's tracks.