Live data from Hacker News

Freedom Hosting sites compromised, founder arrested

twitlonger.com

31–40 of 140 posts

Re: Freedom Hosting sites compromised, founder arrested

#31

A preliminar analysis of the 0day used: http://pastebin.mozilla.org/2777139 edit : Maybe is a good idea to submit this link (or another related) to discuss about it in a new HN thread.

It's not really 0-day: since it only affects Firefox 17, it was apparently fixed long ago. But see this comment regarding why it may be of interest to lots of TOR users:

https://news.ycombinator.com/item?id=6156779

Re: Freedom Hosting sites compromised, founder arrested

#32

Earlier quoted context omitted.

It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…

The word 'sociopath' describes these actions very well. Considering that the United States is in a state of enduring war, and considering that all of the effort to monitor the internet comes from a desire to strengthen national security (which is a vital concern), it makes sense for the United States to behave this way. After all, what is war other than purely sociopathic behavior? The monitoring of the internet is j…

The USA has never not been at war against somebody or something in living memory, counting the cold war and the drug war.

If you'll let it off the leash entirely in "wartime", well, then the leash was never there.

Re: Freedom Hosting sites compromised, founder arrested

#33
post #20

Earlier quoted context omitted.

It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…

> America The American government, you mean.

Are you so sure the government is opposed to the public in this?

Re: Freedom Hosting sites compromised, founder arrested

#34
post #11

They make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the marke…

The quote in the article claims that the exploit affects 17 and higher, only on NT-based platforms.

Furthermore, Tor Browser Bundle disallows JavaScript by default, and one should be cautious while allowing execution of arbitrary client-side code whilst intent on keeping their direct IP address secret. You have to take at least a couple of steps to be affected by this bug.

EDIT: The author has updated the OP and now claims that he believes Firefox 17 is the only affected version. His language is ambiguous such that it is unclear whether the exploit only affects Windows or if the code distributed by FH is simply not attempting to exploit any non-Windows environments (perhaps they were trying to get specific players).

Re: Freedom Hosting sites compromised, founder arrested

#35
Am I the only one who is f*cking tired of FBI and other violence based organizations using pedophilia as their excuse to raid and bust people ?

Think of the children! Yes .. a good front to make it so that they can just bust anything using SWAT forces.

Is pedophilia such a big problem? Really ? I would like to see one study about pedophilia and the problems it creates, instead of what the problems that NSA and FBI are facing when people start encrypting their traffic and we actually have some freedom of speech in some areas.

Re: Freedom Hosting sites compromised, founder arrested

#36
Uhm, so where exactly does the FBI/NSA come in?

As of now there is some guy stating that some hoster has been pwnd and uploaded some JS that expoloited something that might be FF17 that might have been shipped with the tor browser bundle.

Why exactly does he thing FBI/NSA is involved? If he has the exploit code why didn't he upload it?

Lots of conclusions based on assumptions. As of now I'd think it's more likely someone just pwnd the largest TOR hidden host provider, uploaded a sploit that will affect most of the users (tor browser bundle) and called it a day.

Sure there MIGHT be some GOV/whatever involvment. But wouldn't it be time to wait with such accusations until we got some actual proof? Not even uploading the alleged exploit doesn't really help his position.

I would think that since about 60% of TOR projects funding comes from the .gov[0], that they have an incencitive to keep it online. I could imagine they have some nodes for which they wouldn't want to reveal the physical location. I don't know warhead controllers or something. Of course that only works if the're are enough nodes involved so you can hide yourself. That's why I think this might not have been a .gov action.

[0] https://www.torproject.org/about/findoc/2012-TorProject-Annu...

Re: Freedom Hosting sites compromised, founder arrested

#37
post #20

Earlier quoted context omitted.

It's not just that they're stealing everyone's privacy. They're acting like "it's foreigners, so we don't have to care" - even the latests attempts to rein in NSA make no effort to cut back its international misbehavior. Basically, I think most civilized people have been operating on the premise that democratic western states are behaving in a vaguely civilized way towards people in other such states. But it's clear…

> America The American government, you mean.

For us foreigners, knowing that America has strong democratic roots, it is obvious (and worrying) that the majority of american citizens actually agree with that.

Re: Freedom Hosting sites compromised, founder arrested

#38
post #10
post #2

We should be clear that this isn't a vulnerability in the Tor software or network, but an (apparent) vulnerability in this unrelated "Freedom Hosting" company's site: https://blog.torproject.org/blog/hidden-services-current-eve...

Not according to TFA: "In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization" http://www.ieee-security.org/TC/SP2013/papers/4977a080.pdf

The author never explained how the contents of that paper were related to the js attack on freedomhost users. It just seemed like an aside about the security of the Tor network in general. Since they (allegedly) found the guy running freedomhosting, maybe they were using those cookies to do a traffic correlation attack to find the host?

Re: Freedom Hosting sites compromised, founder arrested

#39
post #17

Here is real reason why little sisters force everything into browser. Because they care about security >:-) People should stop using web/browsers for everything.

The browser provides much more control over what's happening than executing the code directly on the OS. You can block JavaScript, you can easily analyze the executed source code before you allow its execution, you can manipulate the page as you see fit, you can use extensions to alter your experience in many other ways, and you get the browser's default security sandboxing stuff that prevents it from accessing external domains, your filesystem, or otherwise interrupting non-browsing related tasks.

It'd be crazy to download a full local client for something as shady as SilkRoad or many other hidden services. The browser is the safest place for that kind of thing.

Re: Freedom Hosting sites compromised, founder arrested

#40
post #11

They make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the marke…

The quote in the article claims that the exploit affects 17 and higher , only on NT-based platforms. Furthermore, Tor Browser Bundle disallows JavaScript by default, and one should be cautious while allowing execution of arbitrary client-side code whilst intent on keeping their direct IP address secret. You have to take at least a couple of steps to be affected by this bug. EDIT: The author has updated the OP and now…

TBB does not disallow javascript by default. In fact they recommend you do not disable javascript because it makes your browser fingerprint more traceable.
Post reply on HN