Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

61–70 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#61
post #17

There's an easy way to fix the Web RTC Leak issue network wide: Use a VPN on your Router so your network clients literally don't know their "real" ip and therefore can't leak it. Same thing works for TOR. In my experience OpenWRT and an Wireguard VPN Provider works best

if you're dealing with a major corporation paying six figures for a novel exploit to be developed specifically so a national intelligence agency can catch you, i think going to all the effort of preventing disclosure of your IP address by this method is somewhat plugging a hole in a sieve

Re: Facebook Helped Develop a Tails Exploit

#62

Fascinating part in the story about his arrest (first link in the vice article) is that the FBI set up cameras outside his home to correlate his physical presence with internet activity from the IP address. You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.

IIRC the authorities did something similar to bust one of the LulzSec members in Chicago. Once they identified a suspect, they surveilled his residence and correlated his physical presence with online chat logs despite his use of tor.

Re: Facebook Helped Develop a Tails Exploit

#63
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever th…

I think stories like these reinforce the idea that it's okay to develop certain technologies or adopt certain policies or create infrastructure to stop the bad guys.

For example, there's a reason most justifications we've seen regarding mass surveillance or automatic recognition systems are boiled down to two things:

stopping harmful material

terrorism

Of course, they take a topic that you wouldn't even dream or arguing against and using that against you.

If they wanted to erode our freedoms to stop harmful material I'm sure most would likely accept that outcome as I feel they have done (AI/facial tech)

Re: Facebook Helped Develop a Tails Exploit

#64
post #2

« They also paid a third party contractor "six figures" to help develop a zero-day exploit in Tails: a bug in its video player that enabled them to retrieve the real I.P. address of a person viewing a clip. » This sounds like they describe the well-known WebRTC leak: https://restoreprivacy.com/webrtc-leaks/

If it is that simple, this is used in most widespread adtech analytics..

Re: Facebook Helped Develop a Tails Exploit

#65

The vulnerability should have been disclosed to Tails developers as soon as Hernandez was arrested.

Well yes, but the fact that it was already patched in the next Tails release, and that was the reason they pulled the trigger when they did, makes even that concern less of a practical problem. It was basically going to get fixed in short order no matter what they did.

Re: Facebook Helped Develop a Tails Exploit

#66

This is something to consider in the recent development of Amazon and Microsoft saying they won't sell facial recognition to law enforcement. I expect police will approach this minor inconvenience by outsourcing to a private company who will do the face scanning for them.

This is why I think we need to be careful when considering a ban on facial recognition. Pandora's box is open.

Even if we do decide on some kind of ban, we need to assume facial recognition will always be used by someone, somewhere, and design our social systems to account for that fact.

Re: Facebook Helped Develop a Tails Exploit

#67

Earlier quoted context omitted.

Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever th…

Why the stupid downvotes? For a for-profit company spending millions needs a justifications stronger than a penchant for vigilante justice. A lot of big companies have a proven history of quietly cooperating with cops, three letter agencies and military. That type of cooperation often leads to multi-million, even billion $ contracts and special favors from political power. What is facebook trying to achieve?

> What is facebook trying to achieve?

Good PR for stopping predators.

Flexing their power in front the FBI and other tech firms.

Trying to demonstrate how obliterating privacy can sometimes have upsides.

Plus, it's clear that Brian Kil was a particularly bad actor and worthy of taking down.

Re: Facebook Helped Develop a Tails Exploit

#68

Fascinating part in the story about his arrest (first link in the vice article) is that the FBI set up cameras outside his home to correlate his physical presence with internet activity from the IP address. You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.

A slightly more complicated timing attack...

Re: Facebook Helped Develop a Tails Exploit

#69

This is something to consider in the recent development of Amazon and Microsoft saying they won't sell facial recognition to law enforcement. I expect police will approach this minor inconvenience by outsourcing to a private company who will do the face scanning for them.

Government contractors like General Dynamics are already all over facial and license plate recognition. AMZN and MSFT not getting on board isn't going to slow it down, just delay it from landing in consumer software.

Re: Facebook Helped Develop a Tails Exploit

#70

Earlier quoted context omitted.

And paid six figures for outside help. The FBI's approach "was not tailored for Tails" - surely if they had any approach that would work they would use it. If the government couldn't break in to Tails and required the outside help of two well-resourced organisations to find (and burn) a single exploit then overall that seems a pretty good endorsement of the security of a volunteer open-source project.

> If the government couldn't break in to Tails Or they didn't want to. Now we all know it costs a measly "six figures" (100k??) to zero day a system used by journalists and activists.

Thats 100k for Facebook. They have the ability to find these white- or black-hat folks, and pay them. For you, random dude or dudette on the street, that might be a little more expensive.

I would assume a huge, IT-focused org like FB already has 3-4 high-end security orgs doing pen-testing and digging for zero-days in their code; they just poured a little sugar on top of an existing contract to help squash this one online predator douche.

Post reply on HN