Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

161–170 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#161
post #63

Earlier quoted context omitted.

> The FBI used standard police techniques to infiltrate and eventually dismantle the those groups. Seriously, how do we know the FBI's story isn't "parallel construction"? It always seemed to me that tracking down Anonymous would be easy if you had NSA-scale monitoring. I don't want to sound like paranoid guy, but maybe the FBI's stories about tracking down clues from chat logs are all made up.

I don't think it sounds paranoid. I think it's at least plausible. I only recently learned about parallel construction: http://en.wikipedia.org/wiki/Parallel_construction Basically, the NSA is suspected to cooperate with other arms of the government, such as the DEA. The NSA supposedly provides information about who is involved in what illegal activity. Apparently this information is provided illegally, without a war…

Sabu had his identity compromised for a few reasons:

1) Old whois info with his real name on a domain (prvt.org) that he linked on IRC. He had long since changed it but someone looked it up.

2) Mistakenly logging into IRC without a VPN/Tor.

More: http://arstechnica.com/tech-policy/2012/03/doxed-how-sabu-wa...

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#162
post #51

Earlier quoted context omitted.

the way Bruce Schneier is now using GPG Which way is that? Also, from your Tinfoil Hat Linux link, this idea is hilariously awesome: Keystroke monitoring — THL has gpggrid, a wrapper for GPG that lets you use a video game style character entry system instead of typing in your passphrase. Keystroke loggers get a set of grid points, not your passphrase. I wonder if it might be possible to implement that idea into other…

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

I hope he's using one of those USB condoms with his memory stick.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#163
post #51

Earlier quoted context omitted.

the way Bruce Schneier is now using GPG Which way is that? Also, from your Tinfoil Hat Linux link, this idea is hilariously awesome: Keystroke monitoring — THL has gpggrid, a wrapper for GPG that lets you use a video game style character entry system instead of typing in your passphrase. Keystroke loggers get a set of grid points, not your passphrase. I wonder if it might be possible to implement that idea into other…

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

He's not doing that because of concerns about PGP, just to be clear, but because his host computer isn't secure (none of ours are); he's doing basically the same thing as the people who run their browsers in a VM, or the same thing that security professionals tell business owners to do when they want to access their online banking.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#164
post #156
post #141

Earlier quoted context omitted.

I kinda thought the same thing about flash-drive viruses, and why Bruce wasn't using CDs/DVDs instead. Then I realized if he was really serious, he wouldn't say what he's really using, and he'd have a USB honeypot plugged into his network-facing computer.

Named "Iocane Powder" of course.

"i'd bet my life on it..."

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#165
post #157

Earlier quoted context omitted.

You mean changing the number of "2048" to "4096"? I'm not sold on that being a meaningful improvement to his security, but even so, you realize that change costs him nothing , right? He needed to generate a new key... why not set it to 4096 bits? Everything he does with that key happens in human scale time --- even a 500ms per message delay wouldn't be noticeable. So, some evocatively named Linux distro recommends th…

I am using 8192 bits, just in case ;-) also applying one time pads when I can.

How do you get the one time pad to the recipient?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#166
post #125

The use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually…

The government poisoned alcohol during Prohibition.

They still poison medicines. Hydrocodone, a Schedule II substance, drops to Schedule III when sold with acetaminophen, a substance toxic to the liver.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#167
post #129
post #99

Earlier quoted context omitted.

It most likely falls under the FBI's legal wiretapping abilities.

wiretapping normally require a specific target, with a specific reason. Going after the tor email service, is like wiretapping the US postal service for a fishing expedition. It sounds to me as being outside the FBI's legal wiretapping abilities.

This is just wrong.

First, you are implying that Tor has an official Tor e-mail service, which it does not. Tormail is/was just a basic e-mail service someone not associated with the Tor project was hosting on the deep web. For all anyone knows, Tormail itself could have been run by the FBI or NSA or whatever all along. Anyone who thought Tormail guaranteed them anonymity was a fool, much like anyone who kept Javascript enabled while browsing the deep web was a fool.

Second, Tormail wasn't itself targeted. What was targeted was the hosting provider that was hosting 95% of child pornography in the deep web, and that hosting provider also happened to host Tormail and a bunch of other non child pornography websites.

Conspiracy theories will abound, of course, but keep in mind that the NSA's MO is not to disrupt communication but to intercept it. If the government's real concern here was with Tormail, they would have simply kept it around and tapped it, since they had clearly compromised the hosting provider's boxes and could have done so. They wouldn't have shut it down and just sent people fleeing to the dozens of other supposedly anonymous and secure e-mail services out there, including ones that perhaps they haven't yet compromised.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#169
post #141
post #73

Earlier quoted context omitted.

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008. http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

I kinda thought the same thing about flash-drive viruses, and why Bruce wasn't using CDs/DVDs instead. Then I realized if he was really serious, he wouldn't say what he's really using, and he'd have a USB honeypot plugged into his network-facing computer.

Note that he didn't say what software he's running on the new air-gapped computer. The difference between locking down one air-gapped PC running only software required for encryption and locking down the entire network of PCs running the wide variety of software required to do everything everyone needs to do on the SIPRnet is huge.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#170
post #14

Earlier quoted context omitted.

Meanwhile the way Bruce Schneier is now using GPG is really only one conceptual leap away from full-blown Tinfoil Hat Linux usage: http://en.wikipedia.org/wiki/Tinfoil_Hat_Linux The difference between "tinfoil hatters" and reasonable people like Bruce Schneier now seems to be how concerned they are with their ability to destroy a harddrive, and TEMPEST.

You mean changing the number of "2048" to "4096"? I'm not sold on that being a meaningful improvement to his security, but even so, you realize that change costs him nothing , right? He needed to generate a new key... why not set it to 4096 bits? Everything he does with that key happens in human scale time --- even a 500ms per message delay wouldn't be noticeable. So, some evocatively named Linux distro recommends th…

> You mean changing the number of "2048" to "4096"?

No, certainly not. I agree with you; the change from 2048 to 4096 isn't interesting.

The interesting part is that he 1) generated a new key (okay, not actually interesting in itself), 2) is using it in an isolated install, 3) this isolate install is on entirely separate hardware, not just a VM, 4) this separate hardware is new hardware that has never been networked.

Tinfoil Hat Linux was never really about using large PGP keys, you could use large PGP keys on a co-located RHEL box just as well as you could on an old crusty THL box covered with shoes and bluejeans in your closet. Rather, Tinfoil Hat Linux was about cautious (really, hyper-paranoid for the hell of it) treatment of private keys and plaintext. Extremely cautious treatment of plaintext and private keys is what he is currently going out of his way to do.

Is going to such an extreme (new hardware that has never been networked?) really necessary? I don't have the expertise to say. What I can say is that is nearing the sort of baseline paranoid treatment of private keys and plaintext that THL is known for. He's not blinking out leaked documents in morse code yet, he isn't worried about white vans down the street reconstructing the images on his monitor or RF leakage from his CPU giving them bits of his private key, but we are at the point where that is the next logical step.

(And no, aliens never landed at Roswell (or anywhere else), JFK was shot from the Book Depository (and only the Book Depository), and Stanley Kubrick did not film the moon landings (that was done with television cameras mounted on tripods, the LEM lander legs, and the astronauts' chests))

Post reply on HN