Live data from Hacker News

Freedom Hosting sites compromised, founder arrested

twitlonger.com

81–90 of 140 posts

Re: Freedom Hosting sites compromised, founder arrested

#81

Am I the only one who is f*cking tired of FBI and other violence based organizations using pedophilia as their excuse to raid and bust people ? Think of the children! Yes .. a good front to make it so that they can just bust anything using SWAT forces. Is pedophilia such a big problem? Really ? I would like to see one study about pedophilia and the problems it creates, instead of what the problems that NSA and FBI ar…

...perhaps you could argue that there's nothing wrong with pedophilia per se, but there is definitely something wrong with child abuse, and I shouldn't need to link you to a study to convince you of that.

By shutting down child pornography rings, police are preventing further abuse. How else would you propose they go about it?

Re: Freedom Hosting sites compromised, founder arrested

#82
post #11

They make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the marke…

I use Tor, but I don't use the Tor Browser Bundle... It's simple enough to configure my browser to use Tor without relying on yet another executable to do it for me.

Re: Freedom Hosting sites compromised, founder arrested

#83

This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at…

How is it sensationalist? The headline was not that there is a vulnerability in TOR, but a vulnerability in "half of all TOR sites."

Re: Freedom Hosting sites compromised, founder arrested

#84

Am I the only one who is f*cking tired of FBI and other violence based organizations using pedophilia as their excuse to raid and bust people ? Think of the children! Yes .. a good front to make it so that they can just bust anything using SWAT forces. Is pedophilia such a big problem? Really ? I would like to see one study about pedophilia and the problems it creates, instead of what the problems that NSA and FBI ar…

Yes, paedophilia really is such a Big problem; you want to see a study to understand that? are you serious? further to police efforts I would support any independent effort to get these people and hand them over to the police when it comes to this matter.

Paedos will be paedos no matter whether privacy exists or does not exist, and it is not an issue related to privacy and freedom, do not link it as such; freedom ceases to be freedom when it violates another individual's freedom(=abuse or product of abuse) so the abuser has to be stopped from further violating it. As the previous poster said, you could argue around consent and/or having an inclination, but as to the actual abuse taking place there can be no question about it.

In a truly anonymous internet that respects privacy, it would be up to individuals to find, isolate and condemn these people, much like Anonymous did in 2011.

Abuse of freedom and privacy can only lead to and justify not having any freedom and privacy, it fuels the whole pro Big Brother argument; if there was a way to demonstrate that Internet self regulation/regulation by the people works, then this would be a major blow to all kinds of 'higher authority' monitoring and fear mongering.

Re: Freedom Hosting sites compromised, founder arrested

#85
post #83

This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at…

How is it sensationalist? The headline was not that there is a vulnerability in TOR, but a vulnerability in "half of all TOR sites."

It's just misleading. It's like if there was an exploit for iPhones and the headline was "Half of Verizon network hacked". It's not some arbitrary half of the Tor network, it's 100% of Freedom Hosting's clients.

Re: Freedom Hosting sites compromised, founder arrested

#86
post #83

This whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at…

How is it sensationalist? The headline was not that there is a vulnerability in TOR, but a vulnerability in "half of all TOR sites."

The headline implies that the "compromise" is an inherent failure in the protocol (or else how could "half" of all sites be infected?) instead of the reality that the hosting provider intentionally placed an exploit in all of their pages.

A better title may be like: "major .onion hosting service infiltrated by feds, all sites converted to honeypots; founder arrested". This does not imply any fundamental flaws in Tor itself or the technology in use, it does not falsely attribute a specific portion of .onion sites as infected, it does not communicate uncertainty into which sites are damaged (only sites hosted by Freedom Hosting were affected afawk), and it correctly reflects the events.

Re: Freedom Hosting sites compromised, founder arrested

#87
post #17

Here is real reason why little sisters force everything into browser. Because they care about security >:-) People should stop using web/browsers for everything.

The browser provides much more control over what's happening than executing the code directly on the OS. You can block JavaScript, you can easily analyze the executed source code before you allow its execution, you can manipulate the page as you see fit, you can use extensions to alter your experience in many other ways, and you get the browser's default security sandboxing stuff that prevents it from accessing exter…

Apparently people have just readily forgotten about the time where computing everywhere was done using terminals. Just pure input/output with some special characters for fancy things.

Re: Freedom Hosting sites compromised, founder arrested

#88
post #54

Earlier quoted context omitted.

[EDIT: edited typo, clarified what TAILS was] I had mentioned (split between a couple other posts) that even with JS enabled, Noscript will prevent many XSS/CSRF and clickjacking attempts, which has been explained to me as the reason for its inclusion. And That disabling Javascript actually makes you more fingerprintable because it's rare for browsers to do this. I am guessing that the payload that article mentions s…

>prevented TBB Firefox from even making a network connection that's not to the Tor tunnel, or possibly even prevent Firefox from knowing it's own IP. Dunno if something like this is even possible on Windows. I don't currently use Tor, but I've thought about it and this is how I would do it. This can be done on windows using a virtual machine that disallows internet connections. Have the VM only able to network with t…

Whonix already does this.

Re: Freedom Hosting sites compromised, founder arrested

#89
post #82
post #11

They make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the marke…

I use Tor, but I don't use the Tor Browser Bundle... It's simple enough to configure my browser to use Tor without relying on yet another executable to do it for me.

The concept is that it's actually not as simple as it may seem. You're using the same cookie jar -- what if you inadvertently send back a cookie with the session ID of your public profile? You'll have flagged yourself as a Tor user and this can be tied back to your public IP. You're using the exact same browser fingerprint, which is more unique than you imagine -- it's not just a matter of useragent, but the combination of all information that can be obtained by a site about your browser. The EFF runs a demo site that shows this can be practically unique in many instances. You've probably enabled scripts on certain sites that may not need to execute JavaScript when you're viewing them through Tor. You probably have less restrictive rules around the injection of plugins that may expose your interface IP address, like Flash. You may do something shady and forget to cleanse it from your history (and/or enter private browsing mode). You may have an extension running that shares more information than you'd like, with either the site or the extension provider.

For all these reasons, TBB exists, and is the safest way (short of a live environment) to ensure you have a sanitized environment. At the very least, you should use a separate browser profile before you switch to an activity that mandates the usage of Tor, unless you're using it only for very rudimentary circumventions.

Re: Freedom Hosting sites compromised, founder arrested

#90
post #64
post #36

Uhm, so where exactly does the FBI/NSA come in? As of now there is some guy stating that some hoster has been pwnd and uploaded some JS that expoloited something that might be FF17 that might have been shipped with the tor browser bundle. Why exactly does he thing FBI/NSA is involved? If he has the exploit code why didn't he upload it? Lots of conclusions based on assumptions. As of now I'd think it's more likely som…

TOR is also a great honeypot. There are no ways of validating a given node is not governmental, either.

There are no ways of validating anything is not governmental.
Post reply on HN