6 ms·
According to this article [1] the code involved with this exploit should be removed at some point. " A factor that convinced Facebook’s security team that this
by ivann 6y ago
According to this article [1] the code involved with this exploit should be removed at some point.
" A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool.
As far as the Facebook team knew, Tails developers were not aware of the flaw, despite removing the affected code. One of the former Facebook employees who worked on this project said the plan was to eventually report the zero-day flaw to Tails, but they realized there was no need to because the code was naturally patched out. "
[1] https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fbi-hack-child-predator-buster-hernandez https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fb...
- suizi 6y agoGiven their track record, I don't really trust Facebook, but if I take this at it's face, reporting the exploit could get it patched faster and may help in finding similar issues in the code.
- ivann 6y agoTrue. Also this information, if true, could help locate the vulnerable code. I'm not sure if it would be worth it however, it depends on how many outdated tails are in the wild and the exploit complexity.
- rakoo 6y agoIt's a little bit short-sighted, divulging the exploit makes sure it is known and reduces the chances it happens again in the future
- WhyNotHugo 6y agoThere's a clear downside that this can't be used against the next kid-molestor. But then, this also can't be used against every other human being who needs privacy either. E.g.: Journalists, activists, anyone who disagrees with a large government, etc,
- rakoo 6y agoThis is in line with the arguments for/against Tor in general. I believe if you agree with Tor as a principle, then you should agree that making this exploit known is better overall. As an aside, I believe everyone needs privacy, so I'd rather say that everyone benefits from it, not just the usual journalists, activists, whistleblowers, etc...
- save_ferris 6y agoThat would also be the perfect way to avoid disclosing the vulnerability so they could keep using it. Not saying that’s what is happening here, but it’s not like Facebook has a glowing reputation to begin with. Telling the vendor that a future release will patch the bug gets everyone to stop asking questions without really knowing if it’s true.
- vinceguidry 6y agoIf you have need for Tails and you continue to use old versions of it out of laziness, then you really are just begging to be pwned. We're not talking about consumer-grade Ubuntu here.
- sfj 6y agoI think the parent is saying that Facebook could have been lying about the exploit being patched away, in order to keep the exploit available and have an excuse as to why they didn't reveal how they did it.
- save_ferris 6y agoI think you misunderstand me. By telling Tails that the vulnerability will be patched in a future release without disclosing the details of the vulnerability, Tails has no way of knowing if this is actually true. It’s easy to be a little skeptical when a company spends 6 figures to develop an exploit and then state publicly “we can verify that the issue will be patched in a future Tails release, but we’re not going to tell them or anyone else what the exploit was in the first place.” If you wanted to keep using that exploit, or sell it, the easiest way to do so would be to tell Tails that it’s going to be fixed without actually giving them any details about it.
- FakeRemore 6y ago> As far as the Facebook team knew, Tails developers were not aware of the flaw, despite removing the affected code. One of the former Facebook employees who worked on this project said the plan was to eventually report the zero-day flaw to Tails, but they realized there was no need to because the code was naturally patched out. " So there's no way for anybody to verify that the code is actually being removed, or that the exploit won't crop up again in the future. I don't trust them or the FBI at all in this.