> The firm worked with a Facebook engineer and wrote a program that would attach an exploit taking advantage of a flaw in Tails’ video player to reveal the real IP address of the person viewing the video. Doesn't Tails route all traffic through Tor by default?
Facebook Helped Develop a Tails Exploit
91–100 of 116 posts
Re: Facebook Helped Develop a Tails Exploit
#92In my apparent ignorance, when I first read the title I actually imagined Facebook developing a backdoor of some kind into Tails, given that Tails is open source. Then I understood that "developing" an exploit means taking advantage of existing properties/vulnerabilities. Is this standard wording in security circles?
Re: Facebook Helped Develop a Tails Exploit
#93Earlier quoted context omitted.
or how easily a 600B company spends thousands of dollars
Other articles on this topic described that they had hired at least one full time employee just to track this one malicious user. I'm sure they also have additional fractional costs for legal, moderation, administration, PR, government oversight, and lobbying. They might even have legal liabilities to the victims (not sure). They previously worked with the FBI to try and trap this malicious user with a TOR exploit th…
Re: Facebook Helped Develop a Tails Exploit
#94This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
> it could be someone you hate today and an activist the next Facebook had no control over the exploit once it was handed over to the FBI. It could have been simultaneously used on the child predator and 100 activists at the same time.
Re: Facebook Helped Develop a Tails Exploit
#95Earlier quoted context omitted.
and how the FBI doesn't waste the NSA's jewels for normal crimes
That isn't proven. The FBI blew a TOR 0day on this user, it just didn't work against his Tails OS. It's possible that the 0day was sourced from another 3-letter agency.
Anyway, of course it isn't proven, but I would be extremely surprised if said 3-letter agencies even needed a 0-day exploit to identify a Tor user...
Needing Facebook and a consulting firm to find a vulnerability in a video player? Come on, I would find more credible that they used a consulting firm to choose which exploit to use, if they could use all those available to the various agencies... :)
Re: Facebook Helped Develop a Tails Exploit
#96Earlier quoted context omitted.
or how easily a 600B company spends thousands of dollars
Other articles on this topic described that they had hired at least one full time employee just to track this one malicious user. I'm sure they also have additional fractional costs for legal, moderation, administration, PR, government oversight, and lobbying. They might even have legal liabilities to the victims (not sure). They previously worked with the FBI to try and trap this malicious user with a TOR exploit th…
Re: Facebook Helped Develop a Tails Exploit
#97This guy deserves what was coming to him, I can understand how it would be very tiresome to deal with a pest like this who keeps coming back, but breaking norms about reporting bugs to vendors like this sets a very nasty precedent. As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
> it could be someone you hate today and an activist the next Facebook had no control over the exploit once it was handed over to the FBI. It could have been simultaneously used on the child predator and 100 activists at the same time.
Which is why Apple didn't help the FBI break iOS.
They did choose to not provide true E2E encryption for iCloud, however :(
Re: Facebook Helped Develop a Tails Exploit
#98Earlier quoted context omitted.
Well yes, but the fact that it was already patched in the next Tails release, and that was the reason they pulled the trigger when they did, makes even that concern less of a practical problem. It was basically going to get fixed in short order no matter what they did.
Since they never released the exploit, in reality we have no way of verifying this is actually true. It very well could be the case Tails still has this vulnerability.
Re: Facebook Helped Develop a Tails Exploit
#99Earlier quoted context omitted.
But you can install WebRTC enabled browsers in tails. Depending on how tech-savvy someone is, they could be motivated to install one of them.
The article specificly says the issue was in code that used to be in tails and isnt anymore. Additionally, the motherboard article describes the payload as a video file uploaded to dropbox, which doesnt sound like webrtc.
0) https://securityaffairs.co/wordpress/43442/cyber-crime/fbi-u...
Re: Facebook Helped Develop a Tails Exploit
#100Earlier quoted context omitted.
Other articles on this topic described that they had hired at least one full time employee just to track this one malicious user. I'm sure they also have additional fractional costs for legal, moderation, administration, PR, government oversight, and lobbying. They might even have legal liabilities to the victims (not sure). They previously worked with the FBI to try and trap this malicious user with a TOR exploit th…
I now noticed that you mention a TOR exploit here too, as said at https://news.ycombinator.com/item?id=23545331 I wasn't able to find references to that
> Several FBI field offices were involved in the hunt, and the FBI made a first attempt to hack and deanonymize him, but failed, as the hacking tool they used was not tailored for Tails. Hernandez noticed the attempted hack and taunted the FBI about it, according to the two former employees.
No evidence that it was a TOR exploit, but I interpreted it that way because they FBI and Facebook would most certainly have known he was using TOR from his exit IP rotating frequently and FB explicitly supports a TOR server hostname.