Live data from Hacker News

Freedom Hosting sites compromised, founder arrested

twitlonger.com

131–140 of 140 posts

Re: Freedom Hosting sites compromised, founder arrested

#132

Earlier quoted context omitted.

>prevented TBB Firefox from even making a network connection that's not to the Tor tunnel, or possibly even prevent Firefox from knowing it's own IP. Dunno if something like this is even possible on Windows. I don't currently use Tor, but I've thought about it and this is how I would do it. This can be done on windows using a virtual machine that disallows internet connections. Have the VM only able to network with t…

Whonix already does this.

Looks sweet. I'll check it out.

Re: Freedom Hosting sites compromised, founder arrested

#133
post #101

This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at…

The exploit is targeted at the version of Firefox in the Tor Browser Bundle on Windows, which means most Tor users are vulnerable. While you can use a different browser the Tor developers have generally recommended that people don't; it's hard to lock down browsers against information leaks, and the fact that someone's using an unusual browser helps an attacker track them.

Actually it turns out to exploit an vulnerability that was already fixed in both Firefox and Firefox ESR:

https://blog.mozilla.org/security/2013/08/04/investigating-s...

The fix was included in a Tor Browser Bundle update on June 26, 2013:

https://blog.torproject.org/blog/new-tor-browser-bundles-and...

Re: Freedom Hosting sites compromised, founder arrested

#134

Earlier quoted context omitted.

Whonix already does this.

Looks sweet. I'll check it out.

Be careful, I don't think it has received a great deal of peer review and the community doesn't seem to be large.

Re: Freedom Hosting sites compromised, founder arrested

#135
post #71
post #13

Earlier quoted context omitted.

Doesn't have to do much. Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. Also, by including a tracking cookie in the JS, they can cross reference all user activity on the compromised websites with the newly discovered IP address.

> Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. One partial solution would be to run the Tor client on a physically separate machine which acts as a transparent proxy for your browsing/internet box, and blocks any direct contact with the pub…

I actually use a setup that involves a bunch of VMs for pretty good separation. It's a bit of a complicated setup, so I won't elaborate here. The main thing about it, is that even if an attacker runs with root privs on the "anonymous" VM, they'll need a 0-day in the Virtualization engine itself to de-anonymize the machine. I make sure that the VMs are as isolated from the host machine as they can be, so the attack surface is indeed minimized to the VM engine itself. Some "VM busting" attacks did occur in the past, but I believe very few (if any) attacked the VM engine itself. Most used the wider attack surface provided by stuff like the "VMWare tools" API (which for "isolated" VMs should be disabled). Edit: come to think of it, I should probably write up my method and post it to HN at some point...

Re: Freedom Hosting sites compromised, founder arrested

#136
post #119
post #111

Earlier quoted context omitted.

Two viable parties are plenty enough if they are real parties and not a collection of people that use different-colored jerseys to play the same game. Unfortunately, right now majority of voter will vote for "their guy" almost no matter what, which lets "their guy" very broad license on any bad behavior. If the voters would say "either you put a leash on NSA or we're not voting for you, period" - then things may have…

Two parties aren't enough by any stretch, given how varied and multi-headed politics are. There are so many different facets and foci, that there's no way you can do a representative bipolar split across them all. The other problem with systems that settle to two-party systems is that swing voters hold a disproportionate amount of power... which is ironic, given that the swing voters are usually not as politically in…

People do not vote for parties - at least technically - they vote for people.

>>> that swing voters hold a disproportionate amount of power

How is it a bad thing? You say people that actually look at the issues at hand and not just mindlessly pull the lever for "our guy" whoever he is hold "disproportionate amount of power". I say they should hold 100% of the power - or 100% of the voters should be like this. The fact that they aren't is exactly the problem!

>>> given that the swing voters are usually not as politically interested as bloc supporters.

"Politically interested" can mean different thing. If bloc voters' only interest is getting "their guy" in power, and keep him there whatever happens, I don't have any sympathy for such kind of political interest. And if you want to see how well it works for those bloc voters, see how well it worked for voters in Detroit or Chicago, who are constantly voting in crooks and mob men.

Re: Freedom Hosting sites compromised, founder arrested

#137
post #63

Earlier quoted context omitted.

I don't have any base issue with javascript; I think it's a wonderful way to build web applications. However, TOR and the dark net has entirely different considerations, and the cost of letting unvetted code run without asking you from a site you know nothing about is far, far greater. I wouldn't be surprised if just being on TOR would be convincing evidence for an unknowledgable jury, even if the site was about some…

I see the first two sentences of your reply as inextricably linked and contradictory. You don't think it's the culture of it being acceptable to make sites that won't work without JS that is ultimately forcing the Tor folks to enable it? For instance, reading up on this subject I found this: > Why is NoScript configured to allow JavaScript by default in the Tor Browser Bundle? Isn't that unsafe? > We configure NoScri…

I see the purposes of the internet serving content-rich web apps and the purposes of TOR as different. They may have compatible protocols, but if GMail ran on TOR nobody would even use it. Why bother? It's slow and it's gonna leak information like a watering hose.

Re: Freedom Hosting sites compromised, founder arrested

#138
post #11

They make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the marke…

To be honest, I tried to use TOR without the bundle and couldn't figure out how to make it work. The software appears only be available as the bundle to a cursory look.

Re: Freedom Hosting sites compromised, founder arrested

#139

This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at…

> solution: seven proxies

Is it possible to route TOR traffic over TOR?

Re: Freedom Hosting sites compromised, founder arrested

#140
post #100

Earlier quoted context omitted.

There are no ways of validating anything is not governmental.

Yes, but there are degrees of this, and TOR gives you nothing without the resources of the government.

The government is allowed to create fake identities and corporations, use private facilities and infrastructure, etc. in order to run sting operations against sophisticated criminals. That's exactly the sort of "real police work" they should be doing, rather than surveillance.

Where is there ever a "degree" of visibility as to whether something is a government honeypot?

Post reply on HN