Live data from Hacker News

Facebook Helped Develop a Tails Exploit

vice.com

91–100 of 116 posts

Re: Facebook Helped Develop a Tails Exploit

#91
post #85

> The firm worked with a Facebook engineer and wrote a program that would attach an exploit taking advantage of a flaw in Tails’ video player to reveal the real IP address of the person viewing the video. Doesn't Tails route all traffic through Tor by default?

The video player must not use the default protocols.

Re: Facebook Helped Develop a Tails Exploit

#92
post #48

In my apparent ignorance, when I first read the title I actually imagined Facebook developing a backdoor of some kind into Tails, given that Tails is open source. Then I understood that "developing" an exploit means taking advantage of existing properties/vulnerabilities. Is this standard wording in security circles?

I think it would have said "backdoor" somewhere if they had developed the actual vulnerability.

Re: Facebook Helped Develop a Tails Exploit

#93
post #51

Earlier quoted context omitted.

or how easily a 600B company spends thousands of dollars

Other articles on this topic described that they had hired at least one full time employee just to track this one malicious user. I'm sure they also have additional fractional costs for legal, moderation, administration, PR, government oversight, and lobbying. They might even have legal liabilities to the victims (not sure). They previously worked with the FBI to try and trap this malicious user with a TOR exploit th…

I'm sure it was proportionate to the costs they incurred, but I doubt it's really necessary to spend so much money to find an exploit in Tails, I imagine a single good hacker would be able to find another one at most in few weeks of dedicated work

Re: Facebook Helped Develop a Tails Exploit

#94
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

> it could be someone you hate today and an activist the next Facebook had no control over the exploit once it was handed over to the FBI. It could have been simultaneously used on the child predator and 100 activists at the same time.

[deleted]

Re: Facebook Helped Develop a Tails Exploit

#95
post #53

Earlier quoted context omitted.

and how the FBI doesn't waste the NSA's jewels for normal crimes

That isn't proven. The FBI blew a TOR 0day on this user, it just didn't work against his Tails OS. It's possible that the 0day was sourced from another 3-letter agency.

Where did you get that they used a Tor 0day? I don't see it in the vice or schneier articles, I only see mentions of a "Tails exploit"...

Anyway, of course it isn't proven, but I would be extremely surprised if said 3-letter agencies even needed a 0-day exploit to identify a Tor user...

Needing Facebook and a consulting firm to find a vulnerability in a video player? Come on, I would find more credible that they used a consulting firm to choose which exploit to use, if they could use all those available to the various agencies... :)

Re: Facebook Helped Develop a Tails Exploit

#96
post #51

Earlier quoted context omitted.

or how easily a 600B company spends thousands of dollars

Other articles on this topic described that they had hired at least one full time employee just to track this one malicious user. I'm sure they also have additional fractional costs for legal, moderation, administration, PR, government oversight, and lobbying. They might even have legal liabilities to the victims (not sure). They previously worked with the FBI to try and trap this malicious user with a TOR exploit th…

I now noticed that you mention a TOR exploit here too, as said at https://news.ycombinator.com/item?id=23545331 I wasn't able to find references to that

Re: Facebook Helped Develop a Tails Exploit

#97
post #9

This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.

> it could be someone you hate today and an activist the next Facebook had no control over the exploit once it was handed over to the FBI. It could have been simultaneously used on the child predator and 100 activists at the same time.

Yes, this is it, exactly.

Which is why Apple didn't help the FBI break iOS.

They did choose to not provide true E2E encryption for iCloud, however :(

Re: Facebook Helped Develop a Tails Exploit

#98
post #75

Earlier quoted context omitted.

Well yes, but the fact that it was already patched in the next Tails release, and that was the reason they pulled the trigger when they did, makes even that concern less of a practical problem. It was basically going to get fixed in short order no matter what they did.

Since they never released the exploit, in reality we have no way of verifying this is actually true. It very well could be the case Tails still has this vulnerability.

In my opinion, Hernandez screwed up by not appreciating the risk profiles for Tails and Whonix. Tails is a LiveOS, which doesn't leave traces in RAM or on disk. Whonix is a pair of VMs, one with the Tor process, and the other with user apps. Using Whonix, exploits like this are impossible, because the apps VM has no public IP address, and can hit the Internet only via Tor.

Re: Facebook Helped Develop a Tails Exploit

#99
post #59
post #35

Earlier quoted context omitted.

But you can install WebRTC enabled browsers in tails. Depending on how tech-savvy someone is, they could be motivated to install one of them.

The article specificly says the issue was in code that used to be in tails and isnt anymore. Additionally, the motherboard article describes the payload as a video file uploaded to dropbox, which doesnt sound like webrtc.

Yes, I doubt that it's WebRTC. Or at least, I recall similar vulnerabilities in video player code that predated WebRTC. There used to be a Metasploit leak-testing site (Metasploit Decloaking Engine) which checked for IP leaks via video, PDFs, etc. And it included an early version of the NIT that the FBI has used since ~2011.[0]

0) https://securityaffairs.co/wordpress/43442/cyber-crime/fbi-u...

Re: Facebook Helped Develop a Tails Exploit

#100
post #96

Earlier quoted context omitted.

Other articles on this topic described that they had hired at least one full time employee just to track this one malicious user. I'm sure they also have additional fractional costs for legal, moderation, administration, PR, government oversight, and lobbying. They might even have legal liabilities to the victims (not sure). They previously worked with the FBI to try and trap this malicious user with a TOR exploit th…

I now noticed that you mention a TOR exploit here too, as said at https://news.ycombinator.com/item?id=23545331 I wasn't able to find references to that

I think I inferred what I said from this quote:

> Several FBI field offices were involved in the hunt, and the FBI made a first attempt to hack and deanonymize him, but failed, as the hacking tool they used was not tailored for Tails. Hernandez noticed the attempted hack and taunted the FBI about it, according to the two former employees.

No evidence that it was a TOR exploit, but I interpreted it that way because they FBI and Facebook would most certainly have known he was using TOR from his exit IP rotating frequently and FB explicitly supports a TOR server hostname.

Post reply on HN