10 ms·
Freedom Hosting sites compromised, founder arrested
- cookiecaper 13y agoThis whole post is a mess. Someone distributes an exploit via a popular hosting provider for onion sites (and it's curious why anyone with a serious interest in privacy would outsource onion site hosting anyway) and suddenly Tor is damaged? There's a link to a paper that claims people can do things you're not supposed to be able to do with onion sites, but I don't see how that's relevant -- this post is conflating at least a few things. So here's what I can grok from it: * "Freedom Hosting" founder has been arrested; presumably, many people were using "Freedom Hosting" to host onion sites (is this where "half of all Tor sites compromised" comes from?). No charges listed, article slightly hints at child pornography charges. * Someone, presumably the FBI, has set up an exploit to be distributed through Freedom Hosting sites that will phone home and reveal your non-Tor IP address (solution: seven proxies). "Freedom Hosting" founder was probably coerced into allowing distribution of this exploit. * Author claims that said exploit only affects Firefox >= 17 on Windows. * There's a link to a paper about possible problems with hidden services, which is apparently not relevant to any of this other than the fact that there was just a shakedown on a big onion site provider. I'm flagging this article because it is utterly incoherent and the headline is sensationalist. There is no evidence of a fundamental flaw in Tor being related to any of the events mentioned. Hopefully someone will write a comprehensible piece soon and put it out there.
- RivieraKid 13y agoI'm pretty sure that most of the upvoters did just read the title, not the article.
- secure 13y agoHere is a statement by the tor project about it: https://blog.torproject.org/blog/hidden-services-current-events-and-freedom-hosting https://blog.torproject.org/blog/hidden-services-current-eve...
- syncerr 13y agoIt's specifically targeting Firefox 17 for Windows. Versions less than 17 seem to be targeted as well, but the resource (content_1.html) doesn't seem to have ever been available. It does not target anything above 17. http://pastebin.mozilla.org/2777139 http://pastebin.mozilla.org/2777139
- aqme28 13y agoHow is it sensationalist? The headline was not that there is a vulnerability in TOR, but a vulnerability in "half of all TOR sites."
- erikpukinskis 13y agoIt's just misleading. It's like if there was an exploit for iPhones and the headline was "Half of Verizon network hacked". It's not some arbitrary half of the Tor network, it's 100% of Freedom Hosting's clients.
- cookiecaper 13y agoThe headline implies that the "compromise" is an inherent failure in the protocol (or else how could "half" of all sites be infected?) instead of the reality that the hosting provider intentionally placed an exploit in all of their pages. A better title may be like: "major .onion hosting service infiltrated by feds, all sites converted to honeypots; founder arrested". This does not imply any fundamental flaws in Tor itself or the technology in use, it does not falsely attribute a specific portion of .onion sites as infected, it does not communicate uncertainty into which sites are damaged (only sites hosted by Freedom Hosting were affected afawk), and it correctly reflects the events.
- RodericDay 13y agolanguage is incredibly important. thank you a lot for the explanation.
- hnnnnng 13y ago'infiltrated by feds' is a presumption based on speculation at this point. Assumptions dont 'correctly reflect events'. If you want to fix something, fix it entirely.
- cookiecaper 13y agoIt correctly reflects events as detailed by the post. The post clearly assumes that "the FBI" originated the exploit code and has been using it to harvest visitor IP addresses. I believe "infiltrated" is a fine summarization for that. I suppose it's possible that the founder had a change of heart two days prior to his arrest and started collecting everyone's IP and sending it to the FBI based on nothing but a sense of personal moral obligation, but it doesn't seem too likely, and it's irrelevant either way because again, the proposed title is an accurate description of the posted article, even if the posted article is an inaccurate depiction of Real Life(tm).
- makomk 13y agoThe exploit is targeted at the version of Firefox in the Tor Browser Bundle on Windows, which means most Tor users are vulnerable. While you can use a different browser the Tor developers have generally recommended that people don't; it's hard to lock down browsers against information leaks, and the fact that someone's using an unusual browser helps an attacker track them.
- mbrubeck 13y agoActually it turns out to exploit an vulnerability that was already fixed in both Firefox and Firefox ESR: https://blog.mozilla.org/security/2013/08/04/investigating-security-vulnerability-report/comment-page-1/#comment-111200 https://blog.mozilla.org/security/2013/08/04/investigating-s... The fix was included in a Tor Browser Bundle update on June 26, 2013: https://blog.torproject.org/blog/new-tor-browser-bundles-and-tor-02414-alpha-packages https://blog.torproject.org/blog/new-tor-browser-bundles-and...
- lelf 13y agomany people were using "Freedom Hosting" to host onion sites tormail.org amongst them it seems. It's used at times by users of one famous online store of particular substances. Just info. It's their problem if db leaked and they didn't use encryption of course.
- duaneb 13y ago> solution: seven proxies Is it possible to route TOR traffic over TOR?
- makomk 13y agoPrevious discussion of arrest: https://news.ycombinator.com/item?id=6154493 https://news.ycombinator.com/item?id=6154493 Previous discussion of malicious Javascript: https://news.ycombinator.com/item?id=6154246 https://news.ycombinator.com/item?id=6154246
- inDigiNeous 13y agoAm I the only one who is f*cking tired of FBI and other violence based organizations using pedophilia as their excuse to raid and bust people ? Think of the children! Yes .. a good front to make it so that they can just bust anything using SWAT forces. Is pedophilia such a big problem? Really ? I would like to see one study about pedophilia and the problems it creates, instead of what the problems that NSA and FBI are facing when people start encrypting their traffic and we actually have some freedom of speech in some areas.
- abrichr 13y ago...perhaps you could argue that there's nothing wrong with pedophilia per se, but there is definitely something wrong with child abuse, and I shouldn't need to link you to a study to convince you of that. By shutting down child pornography rings, police are preventing further abuse. How else would you propose they go about it?
- tbrownaw 13y agoBy shutting down child pornography rings, police are preventing further abuse. Maybe, maybe not. Probably in some or even many cases, but certainly not all. But, it also provides an unquestionable excuse to not care about "accidental" overreach or collateral damage. Someone's hosting something they don't like on a shared server? Guess what happens when they "discover" kiddie porn hosted by someone else on that same server?
- gts 13y agoYes, paedophilia really is such a Big problem; you want to see a study to understand that? are you serious? further to police efforts I would support any independent effort to get these people and hand them over to the police when it comes to this matter. Paedos will be paedos no matter whether privacy exists or does not exist, and it is not an issue related to privacy and freedom, do not link it as such; freedom ceases to be freedom when it violates another individual's freedom(=abuse or product of abuse) so the abuser has to be stopped from further violating it. As the previous poster said, you could argue around consent and/or having an inclination, but as to the actual abuse taking place there can be no question about it. In a truly anonymous internet that respects privacy, it would be up to individuals to find, isolate and condemn these people, much like Anonymous did in 2011. Abuse of freedom and privacy can only lead to and justify not having any freedom and privacy, it fuels the whole pro Big Brother argument; if there was a way to demonstrate that Internet self regulation/regulation by the people works, then this would be a major blow to all kinds of 'higher authority' monitoring and fear mongering.
- lawl 13y agoUhm, so where exactly does the FBI/NSA come in? As of now there is some guy stating that some hoster has been pwnd and uploaded some JS that expoloited something that might be FF17 that might have been shipped with the tor browser bundle. Why exactly does he thing FBI/NSA is involved? If he has the exploit code why didn't he upload it? Lots of conclusions based on assumptions. As of now I'd think it's more likely someone just pwnd the largest TOR hidden host provider, uploaded a sploit that will affect most of the users (tor browser bundle) and called it a day. Sure there MIGHT be some GOV/whatever involvment. But wouldn't it be time to wait with such accusations until we got some actual proof? Not even uploading the alleged exploit doesn't really help his position. I would think that since about 60% of TOR projects funding comes from the .gov[0], that they have an incencitive to keep it online. I could imagine they have some nodes for which they wouldn't want to reveal the physical location. I don't know warhead controllers or something. Of course that only works if the're are enough nodes involved so you can hide yourself. That's why I think this might not have been a .gov action. [0] https://www.torproject.org/about/findoc/2012-TorProject-Annual-Report.pdf https://www.torproject.org/about/findoc/2012-TorProject-Annu...
- duaneb 13y agoTOR is also a great honeypot. There are no ways of validating a given node is not governmental, either.
- superuser2 13y agoThere are no ways of validating anything is not governmental.
- duaneb 13y agoYes, but there are degrees of this, and TOR gives you nothing without the resources of the government.
- superuser2 13y agoThe government is allowed to create fake identities and corporations, use private facilities and infrastructure, etc. in order to run sting operations against sophisticated criminals. That's exactly the sort of "real police work" they should be doing, rather than surveillance. Where is there ever a "degree" of visibility as to whether something is a government honeypot?
- marincounty 13y agoI'm afraid to comment out of fear being picked on? I didn't read the article very well(depressed about things, and what the Internet is morphing into), but didn't the U.S. federal government put money into TOR?
- brador 13y agoTake a news break for a few days, your health is important.
- Paul12345534 13y agoAnyone who was using Windows for TOR browsing was already asking for trouble. Anyone browsing outside a "sealed" VM setup such as Whonix was also asking for trouble.
- quotemstr 13y agoBrowsing in a VM doesn't help: the VM still has an IP address.
- prolde 13y agoIf you just run tor inside the VM, the above is true. If all the traffic out of the VM is routed through tor, then the IP address they will get is a tor (not clearnet) IP address. In order to get a clearnet IP address off a VM, you'll need to exploit the VM itself, a task clearly much harder than misusing javascript in a browser.
- vertis 13y agoYou have to respect an effort like this.
- rogerthis 13y agoAs a Catholic, I don't know what I hate most: child pornographics or the FBI.
- LekkoscPiwa 13y agoSoftware that creates randomly TBs of fake email, voice (skype) and other communication daily to disrupt NSA. Possible? Helpful? I.e. billions of emails created daily originating from millions of email accounts created daily that contain random words including the ones the NSA is looking for. I mean, they went on the path of the least resistance with this whole PRISM thing. Kind of blatantly stupid approach of "just listen to everything". That can possibly be derailed by simple creating tons and tons of "everything" daily to feed their stupid programs.
- badfile 13y agoEven if I don't see why you are saying it on this specific thread, it actually came to my mind few days ago. I think it is a good, simple idea. No technical difficulties, just spamming and make the whole thing unanalyzable.
- bobbydavid 13y agoThis has been discussed before, in the context of network security. You can read about efficacy/bandwidth constraints, but basically to provide any strong security you need to spend an overwhelming amount of bandwidth on noise. You must always operate at peak bandwidth to everyone. It becomes prohibitively slow and expensive.
- joshfraser 13y agoThis has given us a pretty rare chance to look at a 0-day exploit being used in the wild by the US government. Has anyone traced the code enough to know how it works? http://pastebin.mozilla.org/2777139 http://pastebin.mozilla.org/2777139
- D9u 13y agoSince I've never been an .onion site user, I've not noticed any issues with my Tor connections to the "regular" net. It's my understanding that one can host a .onion "hidden" site without having to go through any such provider as Freedom Hosting, so I don't see how my privacy is being affected by this situation.
- losethos 13y agoexcitement comes from being watched and seeing targets you're at risk from. God says... C:\TAD\Text\WEALTH.TXT revenue and wealth of their society. Nations, therefore, which, like France or England, consist in a great measure, of proprietors and cultivators, can be enriched by industry and enjoyment. Nations, on the contrary, which, like Holland and Hamburgh, are composed chiefly of merchants, artificers, and manufacturers, can grow rich only through parsimony and privation. As the interest of nations so differently circumstanced is very different, so is likewise the common character of the people. In thos
- cjbprime 13y agoWe should be clear that this isn't a vulnerability in the Tor software or network, but an (apparent) vulnerability in this unrelated "Freedom Hosting" company's site: https://blog.torproject.org/blog/hidden-services-current-events-and-freedom-hosting https://blog.torproject.org/blog/hidden-services-current-eve...
- mintplant 13y agoAnd possibly in Firefox (!), with some sort of JavaScript exploit. This is the most worrying part for me--does anyone have any info on what the payload does?
- tmbeihl 13y agoIt breaks out of the browser sandbox and submits a get request to some server with the guid identifying the user and the tor site they were on.
- keyme 13y agoDoesn't have to do much. Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. Also, by including a tracking cookie in the JS, they can cross reference all user activity on the compromised websites with the newly discovered IP address.
- shabble 13y ago> Once you execute pretty much any (non-sandboxed) code on a machine, you can bypass something like TOR easily. From this point, any network packet sent by the payload to the feds effectively de-anonymizes the user completely. One partial solution would be to run the Tor client on a physically separate machine which acts as a transparent proxy for your browsing/internet box, and blocks any direct contact with the public internet via iptables trickery. I dunno what the processing overhead of running tor client is, but in theory you might be able to do so on a router running openWRT or similar.
- iM8t 13y agoEuropeans point of view: Am I the only one who feels that the US is taking over the Internet and all of our privacy with it?
- keyme 13y agoTaking over? You should probably realize by now that what you see in the media about classified government ops is just the tip of the iceberg. Considering the inherently insecure nature of computer systems, and the heavy reliance of security mechanisms on trusted authorities, you need to realized that, in fact, you've lost any privacy online a long time ago.
- unknownian 13y agoI'm sorry but this sounded like it just came out of r/circlejerk. Unfortunately satire and reality mix here.
- ghostdiver 13y agoEuropeans point of view: European bureaucrats are not any better, think about David Cameron idea of Porngate
- pygy_ 13y agoAFAIK, the European parliament is so far reasonable regarding the Internet and privacy. However, the Commission (the executive branch, and especially the Trade Commisioner, Karel De Gucht) has been pushing hard for ACTA, going as far as lying, several times, to the Parliament. When the Parliament rejected ACTA, De Gucht said he would look for other means to bypass the decision.
- Sprint 13y agohttp://en.wikipedia.org/wiki/Data_Retention_Directive http://en.wikipedia.org/wiki/Data_Retention_Directive
- ghostdiver 13y agoYet, in EU, when you use prepaid cellphone, you can be eavesdropped for no reason, only because it is prepaid cellphone.
- kaoD 13y ago> The JavaScript zero-day exploit that creates a unique cookie and sends a request to a random server that basically fingerprints your browser in some way, which is probably then correlated somewhere else since the cookie doesn't get deleted. Presumably it reports the victim's IP back to the FBI. "in some way", "probably", "presumably" = I have no idea what's going on.
- Shank 13y agoIt's more that we know very well that up to the transmission point, it creates a unique identifier. If we're following the most likely guess (that this is targeting distribution of Child Pornography), then it seems like a reasonable goal to simply identify and fingerprint Tor users. That being said, there is always a point that this could be used for something else entirely, though. Compromising Tor mail is a lot less of a targeted attack.
- __float 13y agoThey make note that the vulnerability used is only in Firefox 17--the current ESR (extended support release). What they do not mention is that the Tor Browser Bundle[1]--created so users can simply download one executable and feel protected by Tor--is based on this very release. Among all internet users, Firefox 17 is probably rare, but among Tor users? My bet is that it owns a significantly higher chunk of the market. [1] Tor Browser Bundle: https://www.torproject.org/projects/torbrowser.html.en https://www.torproject.org/projects/torbrowser.html.en
- cookiecaper 13y agoThe quote in the article claims that the exploit affects 17 and higher, only on NT-based platforms. Furthermore, Tor Browser Bundle disallows JavaScript by default, and one should be cautious while allowing execution of arbitrary client-side code whilst intent on keeping their direct IP address secret. You have to take at least a couple of steps to be affected by this bug. EDIT: The author has updated the OP and now claims that he believes Firefox 17 is the only affected version. His language is ambiguous such that it is unclear whether the exploit only affects Windows or if the code distributed by FH is simply not attempting to exploit any non-Windows environments (perhaps they were trying to get specific players).
- Torgo 13y agoTBB does not disallow javascript by default. In fact they recommend you do not disable javascript because it makes your browser fingerprint more traceable.
- cookiecaper 13y agoChecking on this now. I find it dubious, but possible. I haven't used the Tor Browser Bundle for quite a while, but last I recall they definitely had a mechanism to keep JavaScript from executing. It seems ridiculous that they wouldn't, given their long history of advocacy for NoScript et al. Will edit when done installing/checking. EDIT: So it seems that NoScript is installed as part of the package, but that scripts are enabled globally by default. I just experienced this with a fresh install. Here's the answer confirming it: https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEnabled https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEna... . Personally I think that's a horrible compromise, and it's obviously something that's changed since last time I used it. This should be undone ASAP. Some education is required to use Tor properly even without considering things like JavaScript, so teaching someone to enable JS only when prudent should be fine to include as part of that educational package. It seems like there is some nefarious force at work here trying to trick people who really shouldn't be using Tor into using Tor. I know, for instance, that I had to stop several of my friends from using Tor after they heard about it from the news or whatever after the PRISM leaks. Do NOT use Tor if you don't fully understand the implications, like that all data you send through it is going to be decrypted to plaintext at a random exit node that could be run by literally anyone with a modern computer and internet connection. Fortunately, NoScript continues to warn pretty blatantly with a big red exclamation point that scripts should not be allowed globally, and an educated Tor user will automatically forbid all scripts despite the awful default, so this is probably only a problem for people who are just dinking around anyway.
- galapago 13y agoA preliminar analysis of the 0day used: http://pastebin.mozilla.org/2777139 http://pastebin.mozilla.org/2777139 edit: Maybe is a good idea to submit this link (or another related) to discuss about it in a new HN thread.
- greenyoda 13y agoIt's not really 0-day: since it only affects Firefox 17, it was apparently fixed long ago. But see this comment regarding why it may be of interest to lots of TOR users: https://news.ycombinator.com/item?id=6156779 https://news.ycombinator.com/item?id=6156779
- makomk 13y agoFirefox 17 is their most recent ESR release for enterprises that want a more stable platform, and at least in theory it's still receiving security updates.
- popee 13y agoHere is real reason why little sisters force everything into browser. Because they care about security >:-) People should stop using web/browsers for everything.
- cookiecaper 13y agoThe browser provides much more control over what's happening than executing the code directly on the OS. You can block JavaScript, you can easily analyze the executed source code before you allow its execution, you can manipulate the page as you see fit, you can use extensions to alter your experience in many other ways, and you get the browser's default security sandboxing stuff that prevents it from accessing external domains, your filesystem, or otherwise interrupting non-browsing related tasks. It'd be crazy to download a full local client for something as shady as SilkRoad or many other hidden services. The browser is the safest place for that kind of thing.
- revelation 13y agoApparently people have just readily forgotten about the time where computing everywhere was done using terminals. Just pure input/output with some special characters for fancy things.
- duaneb 13y agoThe idea of having JS enabled is directly at odds with a secure system, too. All TOR sites should have non-JS friendly interaction. There's really negligible benefit compared to exploits like the on in TFA.
- asveikau 13y agoI remember a bit over ten years ago, "javascript is annoying" was a mainstream position among hacker types. That seems to be long gone by now. I guess hardware catching up with resource requirements took away one of the biggest reasons against it. And most people really embraced the web as more than a document platform. I think part of me still misses the old way of thinking about it.
- ToothlessJake 13y agoI must yet again point to a company like Endgame Systems[1] as being a likely contractor for this service rendered for the FBI. Some of Endgame's products used by the likes of the NSA: "There are even target packs for democratic countries in Europe and other U.S. allies. Maui (product names tend toward alluring warm-weather locales) is a package of 25 zero-day exploits that runs clients $2.5 million a year. The Cayman botnet-analytics package gets you access to a database of Internet addresses, organization names, and worm types for hundreds of millions of infected computers, and costs $1.5 million." Exploiting an unknowable amount of users of a service as to hunt them. Using illegally harvested data from botnets, while others get hunted and prosecuted for coding them. This tiered society where the legally immune can profit off acts that get others jailed. The market manipulation that comes with bribing companies for data access, the government giving less regulatory oversight to companies it has secret 'deals' with. For the sake of society, economy, basic morality. It must end. [1] http://wiki.echelon2.org/wiki/Endgame_Systems http://wiki.echelon2.org/wiki/Endgame_Systems
- jenandre 13y ago"Exploiting an unknowable amount of users of a service as to hunt them. Using illegally harvested data from botnets, while others get hunted and prosecuted for coding them. This tiered society where the legally immune can profit off acts that get others jailed." Not that I disagree with this sentiment, but how is this different from the fact the government is "legally immune" from using/possessing weapons and firearms that the average person can't possess or use?
- tomp 13y agoIt's more like the government hiring non-government forces that can then legally possess arms that other "non-affiliated" people (i.e. civilians) can't, and being given legal immunity for killing random people, some of which might turn out to be criminals. I.e. Batman, with a bit less moral compass.
- bigiain 13y agoOr even "Batman with a completely normal corporate moral compass – 100% focused on its primary goal – of 'increasing shareholder value'"…
- belorn 13y agoI think there is a large insight to be had by all this. State can and will use computer exploits in military and law enforcement. Like with PRISM, its no longer just the tinfoil - Its confirmed. The businesses model for a few companies are to hoard zero-day exploits, and sell it on the market. The military, police, "business intelligence" a.k.a industry spying, and criminals are their customers. In contrast to disease research, software virus research are not regulated or illegal, so both good and bad is the result. It is good when independent research find vulnerabilities in software we use, and less so when its hoarded and sold to be used against us.
- synchronise 13y agoI have a question for Tor users. Would such an exploit to the system encourage you to transition to similar darknet services such as I2P, or will you be sticking with Tor with greater caution?
- Zuider 13y agoAnyone notice this: >3. Bitcoin and all crypto currenecies set to absolutely CRASH as a result since the feds can not completely control this currency as they please.
- dlitz 13y agoI wouldn't think too much of it. It could be a bit of wishful thinking, or an attempt to manipulate the price of Bitcoins by spreading rumors. Both are fairly popular among Bitcoin speculators.
- denzil_correa 13y agoWhat does it mean by "Half of Tor sites compromised". Was not it just "Freedom Hosting" which was compromised?
- Amarok 13y agoI'm curious if the exploits would work with javascript enabled, but with noscript installed. This is default for the current TBB I think.