Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

41–50 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#41
post #7

Earlier quoted context omitted.

> entire company > Facebook had tasked a dedicated employee to unmasking Hernandez

And paid six figures for outside help. The FBI's approach "was not tailored for Tails" - surely if they had any approach that would work they would use it. If the government couldn't break in to Tails and required the outside help of two well-resourced organisations to find (and burn) a single exploit then overall that seems a pretty good endorsement of the security of a volunteer open-source project.

> If the government couldn't break in to Tails

Or they didn't want to. Now we all know it costs a measly "six figures" (100k??) to zero day a system used by journalists and activists.

Re: Facebook Helped Develop a Tails Exploit

#42
To deepen the ethical quandary: what if Facebook had developed the exploit for this case, and then the FBI used it for an unrelated, not-child-molesty case?

At some point you have to wrestle with the fact that law enforcement is predicated upon having strong tools with which to deal with law breakers of all kinds, not just the few you find particularly onerous. They're going to need to perform ethical hacking to prosecute people under laws or circumstances you disagree with. And it would probably be better for us if they didn't always have to hack to get the information.

I think we need to work much more closely with law enforcement, not just technically on being able to lawfully intercept private communications, but in what laws and what cases its use is allowed. Nobody trusts the government in this age, but I think that needs to change, and it's the people that need to step up to reign in their government, not vice versa. That means more oversight, restrictions on when and how powerful tools can be used, periodic review, input into the design phase of new technologies, and so on.

We can use our brains to both make it more difficult for them to abuse advanced tools, and also make it more convenient to use them to solve serious crimes. We don't have to live in a black and white world where we either allow everything or allow nothing. We can live in a world of gray, but we have to step up to create that world; we can't just expect to keep saying 'no' to law enforcement and them being able to do their jobs, which is keeping our people safe.

Re: Facebook Helped Develop a Tails Exploit

#43
post #10

Earlier quoted context omitted.

According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool. As far as the Facebook team…

That would also be the perfect way to avoid disclosing the vulnerability so they could keep using it. Not saying that’s what is happening here, but it’s not like Facebook has a glowing reputation to begin with. Telling the vendor that a future release will patch the bug gets everyone to stop asking questions without really knowing if it’s true.

If you have need for Tails and you continue to use old versions of it out of laziness, then you really are just begging to be pwned. We're not talking about consumer-grade Ubuntu here.

Re: Facebook Helped Develop a Tails Exploit

#44

Earlier quoted context omitted.

That would also be the perfect way to avoid disclosing the vulnerability so they could keep using it. Not saying that’s what is happening here, but it’s not like Facebook has a glowing reputation to begin with. Telling the vendor that a future release will patch the bug gets everyone to stop asking questions without really knowing if it’s true.

If you have need for Tails and you continue to use old versions of it out of laziness, then you really are just begging to be pwned. We're not talking about consumer-grade Ubuntu here.

I think the parent is saying that Facebook could have been lying about the exploit being patched away, in order to keep the exploit available and have an excuse as to why they didn't reveal how they did it.

Re: Facebook Helped Develop a Tails Exploit

#45
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

Ideally Tor users should use something like the Whonix approach: two VMs are set up, a gateway for connecting to the internet and a workstation the user browses from. The gateway sets up the Tor connection, and the workstation is on a restricted virtual network that can only connect to the gateway.

Re: Facebook Helped Develop a Tails Exploit

#47

Seems like the lede is buried -- what is the video player exploit? Is there really a way to modify video files such that playing them locally can broadcast an IP address? Think this is less about Tails and more about this "video-tagging" tech.

Without a zero day in the actual decoder (which is probably a possibility given the resources they poured into this), one way would be to send someone a playlist file that tells the player to fetch the video from some URL. Does the player on Tails obey proxy settings when playing URLs from an m3u? Maybe it was that easy or maybe they had to abuse something like fragmented nature of Linux media playback to find a neglected component that carelessly makes network connections, or find a way to call youtube-dl which is often integrated with these players.

Re: Facebook Helped Develop a Tails Exploit

#48
In my apparent ignorance, when I first read the title I actually imagined Facebook developing a backdoor of some kind into Tails, given that Tails is open source.

Then I understood that "developing" an exploit means taking advantage of existing properties/vulnerabilities.

Is this standard wording in security circles?

Re: Facebook Helped Develop a Tails Exploit

#49
post #48

In my apparent ignorance, when I first read the title I actually imagined Facebook developing a backdoor of some kind into Tails, given that Tails is open source. Then I understood that "developing" an exploit means taking advantage of existing properties/vulnerabilities. Is this standard wording in security circles?

> Is this standard wording in security circles?

Yes. There is a large industry that develops products for law enforcement and intelligence agencies focused on "exploit development," which is largely focused on developing exploits for zero day vulnerabilities in widely used software.

Re: Facebook Helped Develop a Tails Exploit

#50
Fascinating part in the story about his arrest (first link in the vice article) is that the FBI set up cameras outside his home to correlate his physical presence with internet activity from the IP address.

You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.

Post reply on HN