Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

71–80 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#71

It's worth reading the original article in full. I simultaneously understand why they did it and am deeply uncomfortable with the tactic. https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fb...

Url changed to that from https://www.schneier.com/blog/archives/2020/06/facebook_help.... Thanks!

Re: Facebook Helped Develop a Tails Exploit

#72

Fascinating part in the story about his arrest (first link in the vice article) is that the FBI set up cameras outside his home to correlate his physical presence with internet activity from the IP address. You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.

I don't know about the US, but it is generally very easy: go to the ISP with the IP+date and an order from a judge and they'll tell you who was using it.

Re: Facebook Helped Develop a Tails Exploit

#73
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

Facebook are masters when it comes to controlling the narrative (damage control is their expertise). There is almost certainly something else under the surface. I find it implausible that Facebook would care enough to go after a single individual. No matter how bad that individual was. If they did this for every criminal of that level who uses Facebook, they'd run out of money. They simply cannot do this. Whenever th…

Facebook have spectacularly shit PR.

The only reason the world isn't hating on them as much is because people need the platform to stay in touch during covid.

They carry far less info about people than google, google literally are funnelling data to all sorts of shady companies, and yet people trust google more.

Google literally tracks you across all of the internet, meatspace and beyond. Facebook can't do anywhere near as much (yet, ar glasses might change that)

Zuckerburg's utter inability to deal with trump effectively is symptomatic of the PR incompetence at the top. They have no idea that the outside world might think ill of actions. They are continually surprised when shit blows up in thier faces.

In short, no, FB are utterly terrible at controlling the narrative.

Re: Facebook Helped Develop a Tails Exploit

#74

Earlier quoted context omitted.

Why the stupid downvotes? For a for-profit company spending millions needs a justifications stronger than a penchant for vigilante justice. A lot of big companies have a proven history of quietly cooperating with cops, three letter agencies and military. That type of cooperation often leads to multi-million, even billion $ contracts and special favors from political power. What is facebook trying to achieve?

> What is facebook trying to achieve? Good PR for stopping predators. Flexing their power in front the FBI and other tech firms. Trying to demonstrate how obliterating privacy can sometimes have upsides. Plus, it's clear that Brian Kil was a particularly bad actor and worthy of taking down.

or, more obviously, that having a famous paedophile prancing around on its platform is bad for business. So knocking him offline is worth the cash.

Re: Facebook Helped Develop a Tails Exploit

#75

The vulnerability should have been disclosed to Tails developers as soon as Hernandez was arrested.

Well yes, but the fact that it was already patched in the next Tails release, and that was the reason they pulled the trigger when they did, makes even that concern less of a practical problem. It was basically going to get fixed in short order no matter what they did.

Since they never released the exploit, in reality we have no way of verifying this is actually true. It very well could be the case Tails still has this vulnerability.

Re: Facebook Helped Develop a Tails Exploit

#76

Fascinating part in the story about his arrest (first link in the vice article) is that the FBI set up cameras outside his home to correlate his physical presence with internet activity from the IP address. You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.

IIRC the authorities did something similar to bust one of the LulzSec members in Chicago. Once they identified a suspect, they surveilled his residence and correlated his physical presence with online chat logs despite his use of tor.

Jeremy Hammond.

Re: Facebook Helped Develop a Tails Exploit

#77
post #33

Earlier quoted context omitted.

I don't think it was a WebRTC issue, I think they crafted a video such that the decoder would end up executing code. Similar to what happen to Jeff Bezos.

The point is that you can't have the Tails machine decide what connections are proxied through Tor and which are not. If you have an external device like a router or a Raspberry that transparently tunnels the data, a compromise of the Tails machine can't trivially expose your real network connection.

One thing that I've thought about this is that whether you do the firewalling on the end-user device or on another device, the firewall will normally permit connections to every Tor guard. That means that if an attacker can make the device make a "special" TCP connection of any kind (e.g. just an HTTP request) to an arbitrary IP address and port number, it could make that connection to an actual Tor guard node run by an affiliate of the attacker. Then the attacker can distinguish that connection from other Tor activity because it isn't Tor traffic.

The point of that is to say that "only allowing the machine to talk to Tor nodes" wouldn't stop an exploit from effectively bypassing Tor—by talking in a slightly unusual way to an adversary-controlled Tor node!

If they're not already doing it, it might be safer for Tails to learn the specific guard that its copy of Tor is using at a particular time, and only allow outbound traffic to that guard rather than to any Tor node. (Another precaution which they might already be taking: only the Tor daemon process should be able to open remote sockets at all.)

Re: Facebook Helped Develop a Tails Exploit

#78
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

> it could be someone you hate today and an activist the next

Facebook had no control over the exploit once it was handed over to the FBI. It could have been simultaneously used on the child predator and 100 activists at the same time.

Re: Facebook Helped Develop a Tails Exploit

#79

The vulnerability should have been disclosed to Tails developers as soon as Hernandez was arrested.

The FBI would rather let a suspect go than reveal the vulnerabilities it is exploiting.

https://www.schneier.com/blog/archives/2017/03/fbis_exploit_...

Re: Facebook Helped Develop a Tails Exploit

#80

The vulnerability should have been disclosed to Tails developers as soon as Hernandez was arrested.

Well yes, but the fact that it was already patched in the next Tails release, and that was the reason they pulled the trigger when they did, makes even that concern less of a practical problem. It was basically going to get fixed in short order no matter what they did.

Did they disclose it anyways? If not, why not even if it was already ineffective?
Post reply on HN