The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.
Facebook Helped Develop a Tails Exploit
51–60 of 116 posts
Re: Facebook Helped Develop a Tails Exploit
#52Re: Facebook Helped Develop a Tails Exploit
#53The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.
Re: Facebook Helped Develop a Tails Exploit
#54There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best
In that case you are swapping one ISP for another. You would need a small botnet to act as your proxy provider set to make it harder to find you.
1. Since you share your vpn exit IP with several users, sometimes hundreds, it becomes harder for any website or service you use to track you by IP alone.
2. My ISP is mandated by law to save all my browsing data (germany here, this law changes every two month but you can assume they all log anyway). My VPN Provider is not mandated and has at least some incentive to not log any data. Cost and Reputation beeing the main ones.
3. I can for example have all my torrents exit in a country where filesharing is not illegal, making any persecution much less likely, same for other laws that are not the same everywhere.
Re: Facebook Helped Develop a Tails Exploit
#55The fact that it took thousands of dollars and an entire company to write an exploit shows how secure Tails really is.
Looks like the bug wasn't really in Talis but in other software they use, Firefox/Tor-Browser?
Re: Facebook Helped Develop a Tails Exploit
#56There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best
In both cases you need the tor daemon or the VPN software to be outside of the host running Tails.
Re: Facebook Helped Develop a Tails Exploit
#57Earlier quoted context omitted.
That would also be the perfect way to avoid disclosing the vulnerability so they could keep using it. Not saying that’s what is happening here, but it’s not like Facebook has a glowing reputation to begin with. Telling the vendor that a future release will patch the bug gets everyone to stop asking questions without really knowing if it’s true.
If you have need for Tails and you continue to use old versions of it out of laziness, then you really are just begging to be pwned. We're not talking about consumer-grade Ubuntu here.
By telling Tails that the vulnerability will be patched in a future release without disclosing the details of the vulnerability, Tails has no way of knowing if this is actually true.
It’s easy to be a little skeptical when a company spends 6 figures to develop an exploit and then state publicly “we can verify that the issue will be patched in a future Tails release, but we’re not going to tell them or anyone else what the exploit was in the first place.”
If you wanted to keep using that exploit, or sell it, the easiest way to do so would be to tell Tails that it’s going to be fixed without actually giving them any details about it.
Re: Facebook Helped Develop a Tails Exploit
#58This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever th…
For a for-profit company spending millions needs a justifications stronger than a penchant for vigilante justice.
A lot of big companies have a proven history of quietly cooperating with cops, three letter agencies and military.
That type of cooperation often leads to multi-million, even billion $ contracts and special favors from political power.
What is facebook trying to achieve?
Re: Facebook Helped Develop a Tails Exploit
#59Earlier quoted context omitted.
Other than webRTC being related to video playing, i dont see the connection. They don't really describe the exploit, so hard to say, but the webrtc leak isn't really in the video player part, its super well known (literally a feature not a bug) so i dont think you would need to pay six figures for it, and tails uses tor browser which doesn't support webrtc.
But you can install WebRTC enabled browsers in tails. Depending on how tech-savvy someone is, they could be motivated to install one of them.
Re: Facebook Helped Develop a Tails Exploit
#60In my apparent ignorance, when I first read the title I actually imagined Facebook developing a backdoor of some kind into Tails, given that Tails is open source. Then I understood that "developing" an exploit means taking advantage of existing properties/vulnerabilities. Is this standard wording in security circles?
The process of discovering a vulnerability is called 'vulnerability research'.
So when Schneier says Facebook paid for an exploit to be developed, it means they paid for software that exploits a vulnerability.
In the case of paying for such exploits, it's not always clear who exactly did the research. Often the research comes from a third party who put together a simple proof of concept that demonstrates only that the security control can be breached (the PoC) -- then, a contractor may buy this vulnerability ('0day') from e.g. zerodium and develop an exploit for it, which will usually be pretty much point and shoot so you don't need an exploit dev team to leverage it.
Hope that makes sense.