12 ms·
cameradust, browser fingerprinting, graphic/sound card canvas, memory canvas mouse usage, keyboard usage, cpu serial number, MAC, router MAC, system logs, tele
by meetuu 8y ago
cameradust, browser fingerprinting, graphic/sound card canvas, memory canvas mouse usage, keyboard usage, cpu serial number, MAC, router MAC, system logs, telemetry
- megous 8y agoSounds too complicated, and half of that is not even accessible from the browser. He used just the browser.
- meetuu 8y agojavascript has a lot of power, and it acesses more than the browser, and none of this is remotely too complicated, it happens on a daily basis. your browser does a lot more than you think. FB most definately does not stay in your browser when it gets its hooks on you. BTW modal dialog buttons do more than the label says, the old meme "what button do i push to hack someone" can be written to "what button do i click to let facebook hack me" It soon becomes apparent that not a lot of people know as much about thier hardware, and or software as they think they do. Dont forget zuckerburgs roots, hes a black hat 101% FWIW all you dvoters need to bone up on your skills if you think this, and more is too complex.
- strictnein 8y ago> javascript has a lot of power, and it acesses more than the browser, and none of this is remotely too complicated While you can finger print a browser relatively well with javascript, it does not have access to a number of the things you list, like MAC, router MAC, CPU serial number, etc.
- zucksablackhat 8y agowhen you click a modal button are you sure it does what is assumed? recall win10 upgrade scandal? (the X)
- SketchySeaBeast 8y ago>when you click a modal button are you sure it does what is assumed? recall win10 upgrade scandal? (the X) Hijacking a button to do something different is a matter of attaching a different event to it - which is exactly what you can do with windows forms for things like "do you want to save?" To access information that's not actually available is a whole other level. Why would you consider those two are equivalent? edit: To include parent's question and clarify why it's trivial.
- snazz 8y agoHow would you access my CPU serial number or my router MAC address from JS? I would think you’d need a zero-day to accomplish this, and it seems dumb for Facebook to be burning browser exploits on fingerprinting when they could make much more money selling them.
- rbinv 8y agoToo much "1337 h4x0r" stuff. It's public knowledge (or even open source code) what browsers expose, and system logs or CPU serial numbers are certainly not part of that.
- zucksablackhat 8y agoif you give permission from an admin login, it is trivial to take carte blanche of a machine, its trivial to convince someone to give you full access
- rbinv 8y agoYou're implying that Facebook is - widely - using unknown privilege escalation exploits in browsers for tracking purposes? That's absurd.
- ohWARisme 8y agoof course the practice is absurd, but that doesnt make it non existent. a non trivial number of average users run around the web in an administrative account, there is no escalation required when a script is already executed with admin, or even root permissions. The rest is academic.
- SketchySeaBeast 8y agoCould you provide the JavaScript code that would allow a modal button to access these items?
- ohWARisme 8y agoYou should look at what microsoft did to sneak its way into a win10 install, you should also look at what google does to snarf permissions with a button by another name. the breadcrumbs can start here. https://apenwarr.ca/log/20190201 https://apenwarr.ca/log/20190201 your smart kid figure it out youll learn more that way versus being spoon fed. BTW im sure that posting such code here would be a criminal activity that dang and others would frown upon profusely.
- SketchySeaBeast 8y agoOriginal: Link? Edit: >You should look at what microsoft did to sneak its way into a win10 install, you should also look at what google does to snarf permissions with a button by another name. the breadcrumbs can start here. >https://apenwarr.ca/log/20190201 https://apenwarr.ca/log/20190201 > your smart kid figure it out youll learn more that way versus being spoon fed. That has zero technical information, just a lot of vague hand-waving. Give me something technical here. New Edit: > BTW im sure that posting such code here would be a criminal activity that dang and others would frown upon profusely. You're claiming this can be done in JavaScript. If it can be done in JavaScript, it's not going to be illegal.
- iownu 8y agothats right, find a BlckHT forum and have a look around, gain thier trust and infiltrate, you will love it im sure. Follow the bread crumbs my lad, and you will find a magic looking glass.
- meetuu 8y agoBTW stop creating voting cadres, it is trivial to trace them back to the central login and ban that too
- albeebe1 8y agocameradust? that's clever if it means what i think it means, aka looking at artifacts in a photo caused by "gunk" on your lens.
- meetuu 8y agoyes it does, there is also acoustic analysis of keyboard noise, quite a lot and this all happens at the time of account creation and early account use until the FB AI thinks it knows who you are, there is no need for constant listening or watching,
- strictnein 8y agoSo you're claiming that Facebook is using 0days to bypass browser controls on your mic to do acoustical analysis of keyboard noise when you sign up?
- debatem1 8y agoDo you have a source for this? I've done a reasonable amount of work on weaponizing these sorts of attacks and it's definitely nontrivial. I'd be shocked to find out that Facebook had successfully deployed them at scale.
- zucksablackhat 8y agonontrivial is in the eyes of the beholder. FB does a lot of things quite shocking, and uses zero days, and soc eng like jack the bear, dont forget zucks roots, he did this stuff from day one. BTW im not abou to distribute hack source on HN, pearls among swine goes nowhere here.
- debatem1 8y agoLet's please not hypothesize exotic attack capability without evidence. It makes it difficult to get people to pay attention when we really need them to be concerned about sophisticated adversaries.
- dymk 8y ago@mod team/dang, can you take a look at the origin of accounts ohWARisme, meetuu, and zucksablackhat? Highly suspect they're just alt accounts, and they're spamming this thread with... questionable quality discussion/FUD.
- grzm 8y agoThe best way to get the mods' attention for matters like this is to email them directly via the Contact link in the footer.