Live data from Hacker News

Javascript exploit actively used against TorBrowser

lists.torproject.org

131–138 of 138 posts

Re: Javascript exploit actively used against TorBrowser

#131

Earlier quoted context omitted.

This likely points to this being an FBI "network investigative technique".* I'm really curious where this attack was injected, as that also means that that .onion is also compromised. My guess? Some darknet market. * Sure, this could be some type of awkward false flag, but it seems unlikely to my gut.

It's on a CP site (giftbox). The exploit got loaded on the confirmation page after logging in.

https://motherboard.vice.com/read/tor-browser-zero-day-explo...

Re: Javascript exploit actively used against TorBrowser

#132
post #90

Earlier quoted context omitted.

You look at this from the privacy perspective of someone who wants to hide something within the constraints and confines of a working - and at least somewhat ethical - legal and judiciary framework. The original use case for Tor is for people who actually need to be able to use the net and hide. If their location and they get it with the equivalent of their local government's "search warrant", it's more likely a raid…

TL;DR: A plurality of Tor users are from Western countries with arguably decent judicial frameworks. Those that have life-or-death consequences to network anonymity will need a lot, lot more than the Tor Browser Bundle or Tor itself. > If their location and they get it with the equivalent of their local government's "search warrant", it's more likely a raid, interrogation, threats, harassment, censorship, and possibl…

Regarding the beginning of your answers: note that nowhere in my comment did I make an assumption about the distribution of the TOR users by use-case. I spoke of the original intent. I don't really care what the vast majority of users use it for and in what context. I care about its original goals.

Regarding needing more than TOR, not necessarily so. There are many oppressive states (on different points of a large spectrum, from basic censorship to actual physical oppression), and though we read many stories about their crackdowns on privacy rights and monitoring facilities, very often we over-estimate their capabilities (e.g. the GFW of China is rather sad joke, technically speaking). So if you're not your state's Public Enemy Number 1, you're within a risk range that's most likely acceptable using TOR, so long as you use it correctly and carefully (and that you accept that risk...). Basically, it boils down to what you said: "if they do care enough to come for you, and they have the resources".

Indeed, I was also probably a bit over-simplistic in my previous answer: there are different leagues with different ball-games.

For the rest, we're in agreement.

Re: Javascript exploit actively used against TorBrowser

#133

Earlier quoted context omitted.

This likely points to this being an FBI "network investigative technique".* I'm really curious where this attack was injected, as that also means that that .onion is also compromised. My guess? Some darknet market. * Sure, this could be some type of awkward false flag, but it seems unlikely to my gut.

It's on a CP site (giftbox). The exploit got loaded on the confirmation page after logging in.

I found the following note in a pastebin-similar website on TOR (Deep Paste): http://pastebin.com/iNRasUFT

Re: Javascript exploit actively used against TorBrowser

#134

Earlier quoted context omitted.

What's their biggest struggle with it? PS, if you're ever on the US West Coast or in Singapore, drop me a DM. I'll buy you a drink someplace.

Honestly? Many things: -It's tricky for a non-technical user to setup -It disrupts their regular workflow -People get frustrated with speeds of Tor etc -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner. -People get annoyed as it doesn't solve their problems and exposure on mobile -You have to restart to run it -They can't run their regular programs on it - MS…

> -It's tricky for a non-technical user to setup

What exactly? A non-technical user can plug a flashdrive on an usb port. Other than that, it's basically read instructions and doing exactly what the instructions are telling, which should be what "regular" operating systems already make you do. But obviously that is the perspective of a power user. In the quality of someone trying to teach people how to use tails I also perceive the barrier imposed. I am convinced that the best path to lower this barrier is to constantly question "what exactly", until we find out.

---

> -It disrupts their regular workflow

I am afraid that this is non negotiable, although other people may disagree. I advocate that security and privacy is less about the digital tools I use and more about my habits and perspective. Much energy is wasted trying to make "fool-proof" tools, but that is ignoring the fact that the responsibility shall be on the end user, and not in the developers. There are parts of the tails documentation explaining those things much better worded than my comment.

---

> -People get frustrated with speeds of Tor etc

That is frustrating for much people. Many people don't want to be part of any anarchist agenda, but there is simply no alternative. The tor network probably will continue to be volunteer driven and an instrument of tech resistance, and that's not a hipster thing, the network is suffering real world attacks and almost always being flagged as a bad thing.

---

> -People get frustrated with Captcha (Dam Cloudflare!) and other things caused by using Tor in a safe manner.

Adding to the above comment, it boils down to the same thing. I understand that people don't want to be tricked in political agenda, but this really is about system administrators deliberately blocking tor traffic because they don't want to deal with the tor network, or because they've read somewhere that tor traffic is bad. This basically should be motivating "genuine" tor users to demand that tor network stops being blocked everywhere, but like I said, people shouldn't have to feel obligated to engage in political agenda. Although I personally advocate for the exact opposite elsewhere ;)

---

> -People get annoyed as it doesn't solve their problems and exposure on mobile

That's important. Being android a linux based system, one would think that by now we'd have something like tails for smartphones too. But is not that simple. These devices started to being manufactured in a time that placing backdoors in the hardware or in a lower software level is easier, therefore making harder to secure them, compared to desktops/laptops. That said, there are plenty initiatives and things being developed to bring security and privacy for mobile devices, but I agree that it's not yet "for the masses".

---

> -You have to restart to run it

> -They can't run their regular programs on it - MS Office, Outlook, Adobe, etc.

> -It's Linux based, so a big mental jump for most people coming from Windows (or most people not at the command line on OS X)

I can't think of other answer to that than "that's closed source people's fault, blame microsoft and adobe". I am aware that this answer doesn't solve people's problems.

---

> -It's hard to access files on other drives

I don't fully agree with this one. However, I agree that the default GNOME look and feel doesn't provide an obvious "my computer" sort of thing. That is well done on many ways in linux distros. Previous versions of tails had that solved. GTK devs, where are thou? The tails website has called everyone already, little help here =)

---

> -Documentation and TAILS is only available in certain languages

I am one of the lazy volunteer translators who should dedicate more time translating tails than the other futile things I do with my life. I hope more potential translators feel ashamed as well.

---

> -It often has driver problems - e.g Macbook Pro 2015 WIFI issues

I acknowledge that as a big problem, because people shouldn't have to compile drivers just to use an operational system. But I can't miss this one: "that's apple's fault!".

---

> -In developing states, computer literacy is low, so anything other than the norm (Windows) is confusing

> -In developing states, hardware tends to be slow (often counterfeit) so running TAILS in RAM is slow

> -People lose the USB sticks they put TAILS on (also many counterfeits, so they often fail or have a false size)

Here is the magic point where the "go blame microsoft" arguments have no sense and lose their meaning. This is the kind of reality that I see everyday and that I think should be top priority in tails development. Whose privacy and security issues are we trying to address? I don't mean to be rude, but I believe people with easy access to macbooks, fast internet connection and with means to buy many disposable usb flashdrives won't understand easily, if not at all, what it is having to operate frankenstein machines and to have only one usb flashdrive which is probably used by other people. This is serious shit because apart from the everyday problems, when these people are offered "digital inclusion", it is often something to take away for good their privacy and security, and everyday there are less gaps and possibilities of "hacking" the way out of censorship and surveillance. See internet dot org for the most nefarious example.

---

> -TAILS often requires training, which not everyone has access to

> -Skills fade for digital security training with journalists/activists is often quite high, especially if they don't need it that often.

Again that divides my opinion. I recognize that the tails doc people should always improve it bearing in mind that anyone should be able to operate tails just from reading the docs, and should be the most accessible as possible. In the other hand, security and privacy are not subjects you can solve by means of digital tools alone. There are not, and there shall be not any magical tool that dispenses the concomitant lectures people should listen to while trying to address privacy and security.

Re: Javascript exploit actively used against TorBrowser

#135

Earlier quoted context omitted.

> If the activists/journalists/whatever don't want to take the necessary precautions to use computers to talk to people in a way in which they are protected from capable adversaries, then I'm not sure what it is that they are expecting. The problem with this mentality is, often its not themselves they're protecting but others . If Alice and Bob are communicating, and only Alice is the one under threat: Alice may be w…

Yep. That's the beauty of Signal App or WhatsApp use of Signal Protocol. You a making it much easier to meet the person-at-risk on a platform where they already are. As opposed to tasking to use something like Pidgin.

While that's true, the trade offs imposed are not only controversial and paradoxical, but effectively disrupts many security and privacy models.

I feel the urge to mention https://chatsecure.org/ as a notable middle of the way alternative.

Re: Javascript exploit actively used against TorBrowser

#136

Earlier quoted context omitted.

Fine. Replace Tails with Whonix-Workstation and Whonix-Gateway, if you need to worry about leaking the IP address.

"If"? Are there any Tor users who don't need to worry about leaking their IP address? Then why do they use Tor in the first place? The Tor project itself seems to promote Tails much more than Whonix, which seems very odd to me.

Tor has a whole alternative network often labeled "deep web" that is accessible either via tor or Aaron's initiative 'tor2web'.

That's enough to state that there are cases where the access to information is more important than anonymity.

R.I.P. Aaron

Re: Javascript exploit actively used against TorBrowser

#137

Earlier quoted context omitted.

"If"? Are there any Tor users who don't need to worry about leaking their IP address? Then why do they use Tor in the first place? The Tor project itself seems to promote Tails much more than Whonix, which seems very odd to me.

After thinking about this, I agree with your point, but it's past me being able to edit my original comment to address this issue there. OK, now you have an IP. Now what? You get a warrant and search the place. What do you find? A computer, maybe an amnesic virtual machine. No actual access to the website/onion in question. IMO Tails promotes better opsec when using Tor - you don't leave any traces behind of your bro…

Also it should be noted that whenever someone raids my home, they'll find the qubes laptop which my ISP will be able to identify as the whonix computer, and therefore I will probably be tortured until I spill out the f*cking hard drive encryption password. That's useless for the tails computers.

Re: Javascript exploit actively used against TorBrowser

#138

Earlier quoted context omitted.

It's on a CP site (giftbox). The exploit got loaded on the confirmation page after logging in.

Eh, with that being the case, I don't personally have too much sympathy. +1 to FBI on this being pretty well targeted; you had to have had a successful login for them to be attempting this in the first place. It's about as precise as they can get; you're only going after users that are active members of the service. They are at least being reasonable in who they are targeting. I can't really think of how they can be…

> Illegal actions shouldn't be taken to fight crime.

I disagree with that and I am on favor of illegal actions against criminal actions.

I just think that this is not FBI's role. Illegal organizations should assume the illegal work. If FBI commits crimes to fight crimes, then to me they're as criminal as the folks they're hunting, and therefore I would treat them the same way I treat the "regular" criminal people.

Post reply on HN