I wonder how this is possible. As far as I understand, tails uses two VMs, so the entire VM uses tor without running the tor service. So how did it send the real IP if all the system's traffic is routed through an external Tor router? It's also quite surprising to me that the FBI spends so much resources on catching ordinary paedophiles, I'd expect such a high level of operations to be used to find high-level ransomw…
Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
21–28 of 28 posts
Re: Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
#22I wonder how this is possible. As far as I understand, tails uses two VMs, so the entire VM uses tor without running the tor service. So how did it send the real IP if all the system's traffic is routed through an external Tor router? It's also quite surprising to me that the FBI spends so much resources on catching ordinary paedophiles, I'd expect such a high level of operations to be used to find high-level ransomw…
Re: Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
#23I wonder how this is possible. As far as I understand, tails uses two VMs, so the entire VM uses tor without running the tor service. So how did it send the real IP if all the system's traffic is routed through an external Tor router? It's also quite surprising to me that the FBI spends so much resources on catching ordinary paedophiles, I'd expect such a high level of operations to be used to find high-level ransomw…
Yeah I’d love to read the details of the exploit. There’s a chance it became classified, if for example the exploit depends on the existence of FBI managed tor nodes, and we aren’t ready to let everyone know that the feds are all over the onion network infra.
There have been a number of very strange arrests of tor users by FBI and other western special services. The one I remember was when they took down the hydra's (basically russian silk road) and doxed it's creators. The idea of tor being infiltrated by feds seems very logical, considering that Tor got a good reputation, and is, basically, a great honeypot. I'd consider it a real threat if I were a criminal. But are there any networks that are resistant to malicious nodes?
Re: Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
#24> But they did so quietly and without notifying the developers of Tails afterwards of the major security flaw, I don't immediately see an ethical problem with developing a zero-day exploit to catch a suspected/presumed very bad person like that, so long as: (1) it's used only for that one target; (2) you promptly start the responsible disclosure to upstream, and later public. Unfortunately, the nice, clean ethics get…
Re: Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
#25> But they did so quietly and without notifying the developers of Tails afterwards of the major security flaw, I don't immediately see an ethical problem with developing a zero-day exploit to catch a suspected/presumed very bad person like that, so long as: (1) it's used only for that one target; (2) you promptly start the responsible disclosure to upstream, and later public. Unfortunately, the nice, clean ethics get…
The vulnerable code was scraped in later releases so I don't think they could use this exploit against other people anyway.
Going back to a particular exploit, certainly it could be used against multiple targets, in a small time window.
There multiple potential targets (for various reasons) at any time.
And there's also the option of mass-compromising endpoints or servers of a platform, and adding new hidden backdoors/weaknesses that persist long after the initial vulnerability is removed (e.g., in various kinds of firmware).
Or even just mass-cataloging of one-time compromised identities.
Re: Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
#26Earlier quoted context omitted.
- Which law enforcement agencies do you choose to work with? - All of them? - Just the US ones? - What about employees who aren't US citizens? - Which crimes are you happy to help enforce? - To what extent are you happy to be used as a tool of the US criminal justice system? - Do you want to enable the US government to have dragnet surveillance of the entire world? Bear in mind, the US government is very keen on usin…
- any as long as they meet my criteria - see above - see above - what? - any crimes that involve coercion of others and nothing else - to the extent I can help stop coercion of others and nothing else - no.
Re: Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
#27> But they did so quietly and without notifying the developers of Tails afterwards of the major security flaw, I don't immediately see an ethical problem with developing a zero-day exploit to catch a suspected/presumed very bad person like that, so long as: (1) it's used only for that one target; (2) you promptly start the responsible disclosure to upstream, and later public. Unfortunately, the nice, clean ethics get…
Re: Facebook Helped the FBI Exploit Vulnerability in a Secure Linux Distro (2020)
#28Earlier quoted context omitted.
- any as long as they meet my criteria - see above - see above - what? - any crimes that involve coercion of others and nothing else - to the extent I can help stop coercion of others and nothing else - no.
Does economic coercion count? What are your criteria?