21 ms·
FBI Admits It Controlled Tor Servers Behind Mass Malware Attack
"It wasn’t ever seriously in doubt, but the FBI yesterday acknowledged that it secretly took control of Freedom Hosting last July, days before the servers of the largest provider of ultra-anonymous hosting were found to be serving custom malware designed to identify visitors." ...
- mindcrime 13y agoLooks like it's all out war between the government and people who value their privacy... Really, it always was, but it was a sort of "undeclared war". Now there's really no question about what's going on, so it's time for the gloves to come off.
- eulerphi 13y agoLet the dark wars begin.
- chris_mahan 13y agoBegun the Dark Wars have.
- jauer 13y agoThe hilarity here is that Anonymous and the FBI had the same target this go-round.
- marshray 13y agoIn case you hadn't heard, much of "Anonymous" has been FBI-sponsored activity.
- codyb 13y agoSource?
- pyrocat 13y agohttps://news.ycombinator.com/item?id=6383435 https://news.ycombinator.com/item?id=6383435
- marshray 13y agoE.g., http://www.theguardian.com/technology/2012/mar/06/lulzsec-sabu-working-for-us-fbi http://www.theguardian.com/technology/2012/mar/06/lulzsec-sa... Check the timelines. Some of Lulzsec's most dramatic attacks were carried out with an FBI agent literally looking over Sabu's shoulder. 'Opdarknet' in particular seemed quite a bit different from the rest, in the MO (basically the same as the FBI used against Freedom Hosting) and the wording of their release.
- codyb 13y agoI forgot about the whole Sabu thing. Thanks.
- aclevernickname 13y agohttp://edramalpl7oq5npk.onion/Sabu http://edramalpl7oq5npk.onion/Sabu is a good explanation
- alcari 13y agoIn case you hadn't heard, much of "Anonymous" has been related in name only.
- marshray 13y agoThat's why I said "Anonymous".
- pygy_ 13y agoSource and details would be welcome.
- hack_edu 13y agoRead up on Sabu and the timeline of events between his initial arrest and the various Anonymous Operations. He's a narc, has admitted it and was very much involved in most of the operations. Coincidentally, most people in those operations were rolled on and his assistance has been used in their arrests/cases.
- pygy_ 13y agoSo this was referring to the Lulzsec attacks carried in the few months between Sabu's arrest and their demise. I wouldn't call that "much of Annonymous".
- aclevernickname 13y agohttp://edramalpl7oq5npk.onion/Sabu http://edramalpl7oq5npk.onion/Sabu is a good explanation
- deleted 13y ago[deleted]
- smtddr 13y agoI don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!", I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/08/cracking-kernelorg http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....
- r4pha 13y agoI remember reading about Richard Stallman's setup [0] and thought it sounded indeed crazy. I couldn't understand why he needed so much 'freedom'. I do now. [0]: http://richard.stallman.usesthis.com/ http://richard.stallman.usesthis.com/
- claudius 13y agoRegarding the kernel.org hack: Even with git’s hashing, wouldn’t an attack on Linus’ – or even a subsystem maintainer’s – computer still be a viable way to get code into the kernel, as said code would be a variant of new, unpublished code rather than changed old code?
- jlgreco 13y agoIt wouldn't be particularly easier to do it that way than just submitting your subversive code normally. Either way your change would need to be "underhanded" such that anybody viewing it wouldn't suspect anything. In fact, trying to slip it in under the radar like that would actually just increase the chances of getting caught, because then it becomes something that isn't suppose to be there instead of merely something that does something that it isn't suppose to do.
- javajosh 13y agoThere is every possibility, however, that there is open-source code in the Linux kernel that, at runtime, interacts with specific microcode instructions that can backdoor a system. Runtime remote backdoor triggers are more useful anyway, because the one thing the NSA can't do is hide from network sniffers. (Of course the best way to hide would be piggybacking on something like automatic software update requests - which I happen to disable, as a nod to my tinfoil wearing brethren.)
- Margaret12 13y agomy buddy's mother-in-law makes $75 every hour on the internet. She has been without a job for seven months but last month her check was $17516 just working on the internet for a few hours. useful source... http://xurl.es/w2x2a http://xurl.es/w2x2a
- molsongolden 13y agoMargaret come on now, that would be 233 hours of work if she was paid on a 1099. She still needs to pay tax and self-employment tax on all of that money. That said, I don't think 233 hours really counts as "just a few hours".
- ChuckMcM 13y agoEspecially since 4 weeks (28 days) at 40hrs/week is 160 hours :-)
- chris_mahan 13y agoEssentially, she's making less than a very good programmer.
- jlgaddis 13y agoSounds like somebody's random number generation function has its upper limit set a little too high.
- yapcguy 13y ago> "Mozilla confirmed the code exploited a critical memory management vulnerability in Firefox that was publicly reported on June 25, and is fixed in the latest version of the browser." Will Rust help eliminate the problem of buffer overflows and other memory related hacks?
- Moral_ 13y agoThis was actually a use after free vulnerability, not a buffer overflow.
- lambda 13y agoWhich Rust should help with as well, as long as people don't use unsafe pointers too much. Of course, this is assuming Rust and Servo ever gain enough traction to build a viable browser; they're still at an early enough stage to be vulnerable to the problems lots of young, ambitious projects have, of taking on too much at once to ever be done enough for production use, interest petering out and never quite getting to the point of something widely usable (like Perl 6).
- pcwalton 13y agoIs it intended to? Yes. Will it? Time will tell. :)
- olsonjeffery 13y agoIIRC the original attack was a JS heap spray (using JavaScript Typed Arrays, no less), so not only would the browser have to be written in rust, but also the JavaScript engine which, AFAIK, isn't on Mozilla's roadmap (but I don't speak for them).
- khuey 13y agoUh, no. A heap spray is not an attack. It's a method of exploiting a vulnerability, but it's a) trivial to do and b) useless without said vuln. Also rewriting the JS engine in Rust doesn't change the ability to heap spray.
- DanBC 13y agoSo, uh, that's a criminal offence in many jurisdictions. Are we going to see international arrest warrants and extradition and trials?
- noonespecial 13y agoHorray. A new growth industry for the us-ians. We'll export prison sentences! Just in time too. I hear we're running low on minorities with dime-bags of pot to incarcerate.
- sillysaurus2 13y agoWhat's worrisome is that if they were willing to burn this Firefox JavaScript exploit, then that probably means they know of at least one more.
- anonymous 13y agoKeep in mind that this was a known and fixed vulnerability, not an 0day. 'Burning' is a bit misleading in this context.
- MacsHeadroom 13y ago0days like this go for $80k to $200k each for exclusive rights. The FBI owns dozens, at least. Source: HBGary dumps, industry experience.
- pekk 13y agoMisleading title - the FBI did not conduct a 'mass malware attack'
- dictum 13y agoThe FBI didn't conduct a 'mass malware attack' on the open web. It did, however, inject malicious code in Tor hidden services that were hosted in Freedom Hosting. How is that not a 'mass malware attack'?
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- aspensmonster 13y agoIf this is the only manner that the FBI --or any law enforcement for that matter-- has for identifying TOR users, then wouldn't the best operational security just be to firewall yourself off completely except for Tor connections? Better yet, you could monitor what applications are trying to broadcast out even if they are designed or intended not to leak. Isn't this what the TAILS live-CD does? For this case, even if your software was out of date and vulnerable to the initial attack on the browser, the attempt to broadcast out would hit a firewall and fail (and ideally be logged and alerted).
- revelation 13y agoI think you will want to use a router that automatically tunnels everything leaving the local network through TOR. And then put in a permanent "everything read-only mode" by burning a fuse or something... Can't trust the local machine to tunnel things correctly.
- a1a 13y ago..or just adhere to common sense and disable javascript.
- hack_edu 13y ago... at the packet level.
- marshray 13y agoThe attacker could just as easily made the connection out via Tor, but it might not have been as considered quite as strong for their evidence gathering process. Another example, it sounds like one might have dodged this particular attack by using a browser other than the Firefox bundled in the TBB. But whether or not using a non-TBB browser gives you a net increase in security probably depends a lot on the user.
- jlgaddis 13y agoAn easy way to prevent this sort of thing is to use two machines. Run Tor and privoxy on one of those machines and allow it to build its circuits and such. The second machine should be configured to use the privoxy instance as an HTTP proxy and should not have a default gateway configured. (Also, on the first machine, you could use iptables to only permit outgoing traffic from the uid that Tor is running as and to drop everything else, just as an extra precaution.)
- bsullivan01 13y agoWTF? Can we even trust the water we get from the government? Maybe they put some meds in there to make us dumb and complaint. Is that too far fetched now after what we've reading? >> Donahue also said Marque had been researching the possibility of moving his hosting, and his residence, to Russia. Nice try FBI, but I have a feeling that Puttin's Russia will have him a gulag after a 5 minute "trial," appeal included.
- deleted 13y ago[deleted]
- bsullivan01 13y agoOK, let's be honest. Do you think Russia would give him asylum or a visa? There you go. Thank you.
- codyb 13y agoSource for your second statement?
- pyrocat 13y agohttps://news.ycombinator.com/item?id=6383435 https://news.ycombinator.com/item?id=6383435
- krapp 13y agoWTF? Can we even trust the water we get from the government? Maybe they put some meds in there to make us dumb and complaint. Funny you should mention that -- I believe that water fluoridation was once suspected of being a communist plot to more or less the same effect.
- mistercow 13y agoNot just "once". Many conspiracy theorists still believe that it is some form of government plot or another. The theories range from it being a toxic waste disposal scheme that is poisoning people (and as far as I know, there is some basis for the claim that fluoridation came about as a way to cheaply get rid of a relatively toxic byproduct; that doesn't validate any other part of it though), to fluoride being used as a mind control chemical (usually pointing to drugs like Prozac that include fluoride as "evidence"). Of course, none of these "theories" manage to address the fact that there is fairly strong evidence that water fluoridation does in fact reduce tooth decay.
- hubble87 13y agoSo the more you try to hide your ass, the more you get targeted
- tokenadult 13y ago"Freedom Hosting has long been notorious for allowing child porn to live on its servers. In 2011, the hactivist collective Anonymous singled out the service for denial-of-service attacks after allegedly finding the firm hosted 95 percent of the child porn hidden services on the Tor network. In the hearing yesterday, Donahue said the service hosted at least 100 child porn sites with thousands of users, and claimed Marques had visited some of the sites himself." So this paragraph of the news report suggests that sometimes Anonymous and the FBI can be united in the goal of stopping child pornography, although not united in how they try to deal with it.
- sillysaurus2 13y agoThe reason the FBI and Anonymous seemed to join forces is because the FBI turned Anonymous's leader, Sabu. http://gawker.com/5890847/revered-anonymous-leader-rats-out-his-pals-to-the-fbi http://gawker.com/5890847/revered-anonymous-leader-rats-out-...
- tokenadult 13y agoPlease tell me more background about that. (I recall mention of this before on HN, but I'm not recalling many details.) What's our best information on how leadership of Anonymous has changed over time? AFTER EDIT: Thanks for your link, which I think came as an edit to your comment. Here is a link to follow-up news: http://www.theguardian.com/technology/2013/feb/22/lulzsec-sabu-sentencing-monsegur-postponed http://www.theguardian.com/technology/2013/feb/22/lulzsec-sa...
- sillysaurus2 13y agoSomeone else should step up and give a comprehensive overview, because I can only recount the timeline from memory, not provide sources. But iirc, Anonymous was a loose coalition of random people on the internet, some of which turned out to have some basic hacking skills. They weren't really taken seriously until they embarrassed HBGary. At that point, the FBI began investigating them. Anonymous changed their name to LulzSec (or possibly AntiSec). The FBI used standard police techniques to infiltrate and eventually dismantle the those groups. The technique was simply to 1) figure out who was a member of Anonymous, 2) threaten them with prosecution unless they cooperate, 3) repeat. This eventually led them to turn Sabu, Anonymous's leader. I'm going to dig for an interesting HN comment I remember reading about the relationship between FBI, Anonymous, and the takedown of Freedom Hosting. EDIT: Here it is: http://news.ycombinator.com/item?id=6154642 http://news.ycombinator.com/item?id=6154642 In order to be friendly to mobile users, I'll copy-paste the comment here (although the link is worth reading because of the informative replies): --- redthrowaway 40 days ago | link | parent | flag Interesting. Freedom Hosting had been a target of Anonymous' Operation Darknet from the beginning--they're well-known for refusing to take down exploitative sites. Operation Darknet is, itself, a pretty interesting phenomenon: Anonymous hacks onion sites, then hands over user information to the FBI for investigation. Anonymous does what the FBI legally can't, and in exchange they're not prosecuted for it. I can't find the article now, but I recall reading an interview with an FBI agent in Wired or Ars or some such where he described the anons as "Internet Superheroes". (sic) That, in and of itself, is kind of curious. Curiouser? One of the original Op Darknet principals was Sabu. You may remember him as the hacker the FBI rolled and got to bust up LulzSec. Sabu was turned by the FBI on June 7th, 2011.[1] Operation Darknet began several months later, in October, 2011.[2] The obvious question, then, is this: Did the FBI use Sabu to entice Anons into attacking child porn networks, thereby evading the laws against them doing it themselves? Did they use the fact they turned a well-known hacktivist to help them deal with criminals they lacked the legal tools to go after? Is this arrest the culmination of those efforts? [1] https://en.wikipedia.org/wiki/Sabu_(hacktivist) https://en.wikipedia.org/wiki/Sabu_(hacktivist) [2] http://www.informationweek.com/security/attacks/anonymous-at.. http://www.informationweek.com/security/attacks/anonymous-at....
- jpmonette 13y agoThis is crazy, but really interesting at the same time. I always thought that this was the way to break anonymity on the Tor network. FBI basically generated a shit-load of Tor nodes (https://blog.torproject.org/blog/how-to-handle-millions-new-tor-clients https://blog.torproject.org/blog/how-to-handle-millions-new-...) for some while to increase their chances of intercepting traffic. Following the data collection and using statistic, they were able to pin-point the origin of most Freedom-hosting request/response, and then raided the place. Think about it: if you own 9/10 of the node of the Tor network (and they did for a while) and simply analyze all the traffic, it's just a matter of time before you can find what you are looking for. The second interesting thing is how they planned everything using the Firefox exploit to find out who was going on each Website. I'm pretty sure they got what they were looking for. Even thought this is highly scary in term of government control, I think we can all learn a lot about it. Also, I'm wondering how much this attack cost.
- jlgaddis 13y agoYou realize that the FBI admission discussed in the article has nothing to do with the blog post on the Tor web site that you linked to, right? Those are two completely separate events.
- quasque 13y ago> FBI basically generated a shit-load of Tor nodes (https://blog.torproject.org/blog/how-to-handle-millions-new-... https://blog.torproject.org/blog/how-to-handle-millions-new-...) for some while to increase their chances of intercepting traffic. The blog post you link to was about a recent massive increase in Tor clients, not Tor nodes. From what I've read I was under the impression that Freedom Hosting itself was hacked to disclose its IP addresses, rather than the FBI taking over the Tor network.
- yk 13y agoYou are confusing two things, one is the sudden increase in tor traffic you linked to, and which was possibly caused by a botnet which used tor as command & control network. The other is the attack on freedom host, which the FBI perpetrated. There the FBI injected a trojan into websites and could therefore deanonymyze users of the websites. So in that case tor did protect the malware as designed, but could not protect the anonymity of the user, because the local computer did made a connection over TCP/IP.
- skwirl 13y agoThe FBI was never going to ignore huge stockpiles of easily accessible child pornography on the deep web, and Hacker News was never going to believe that this wasn't about more than child pornography. Just another day.
- deleted 13y ago[deleted]
- alan_cx 13y agoDo you assume that the techniques used for something most would assume to be reasonable will not ever be used in less desirable ways?
- skwirl 13y agoPolice "techniques" involve guns, tear gas, helicopters, etc. At any time the police could in theory fly to your house, launch tear gas into your windows, and shoot you in the head as you run out. And I don't know about you, but I'm not exactly worried about that happening to the point where I want to take guns, tear gas, and helicopters away from the police. This is the FBI taking down criminals engaging in a clear criminal activity, and it is silly to implicitly compare it to the NSA fishing for terrorists. All the evidence gathered here will be presented in a court of law, all the techniques used will have to be approved by judges as in accordance with laws and the constitution or the gathered evidence will be thrown out. The suspect and any other future suspects will get a trial if they want. It will be out in the open. If you are upset that the software you thought was secure and anonymous isn't as secure and anonymous as you thought, that isn't the FBI's fault.
- kazagistar 13y agoI would actually quite like to take military grade weaponry, as you described, away from the police, or at least significantly scale it down. That level of armament is a sign of something dreadfully wrong with American society, and certainly not helpful towards fixing it.
- 13y ago
- powertower 13y ago> The apparent FBI-malware attack was first noticed on August 4, when all of the hidden service sites hosted by Freedom Hosting began displaying a “Down for Maintenance” message. The underlining reason for this has been the notion that the FBI was attempting to catch people engaged in CP related activities... This maybe a little tin-foil here, but... If you deliver a 404-type of a page on all requests, no website is traversed, no CP is viewed, transferred, replicated, or distributed. Meaning there is nothing here to charge the person with. Does this article get the facts wrong, or was the purpose of this exploit something entirely different. Because if the article is true (this exploit was only in "Down for Maintenance" pages, which were the only pages served), all they did was get a bunch of useless IP to MAC to host-name correlation/mapping data for that moment in time. There is also the 'Fruit of a poisonous tree' argument here. Would this untargeted hacking even stand up in court if this data is used to prosecute someone? This sounds more like flexing of the muscles - the FBI saying we can get you if we want to. Or something else was going on. It also seems like a waist of a good exploit that they would probably use towards terrorist or national security related issues (ex: if they knew the MAC or host-name of a bad guy using TOR that day, but did not know his IP / so they put this out).
- sillysaurus2 13y agoThe way Tor works is that anyone can set up something called a "hidden service". It's basically a website that can only be visited by using Tor. These websites have a unique URL. For example, Bitcoin Fog's URL is http://fogcore5n3ov3tui.onion/ http://fogcore5n3ov3tui.onion/ If you try to visit that using a standard web browser, it won't work. But if you use Tor browser, then it takes you to the Bitcoin Fog hidden service. Some of those websites were devoted specifically to delivering CP. Now the FBI's reasoning goes like this: anyone who was visiting those websites were very likely visiting them for the purpose of looking at CP. The FBI delivered an exploit designed to identify as many of those people as possible. So even though no CP was being served, people were still accessing the URL. The malware collected the MAC address and hostname of the computer, then submitted that info to an FBI server. So those people were apparently added to a centralized FBI database. One way that database might be powerful is if e.g. a politician (or any other government worker) were was identified as a visitor of one of these websites, because whoever controls that database now controls them.
- Tloewald 13y agoThis would make the FBI guilty of a whole bunch of felonies, would it not? (Independent of whether what they were doing is morally right or wrong, isn't this exactly what they imprison hackers for?)
- unreal37 13y agoYou cannot arrest the U.S. government for felonies.
- tlrobinson 13y agoHuh? Surely if they started killing innocent people you could arrest them. The question is what gives them the authority to use these tactics? Wiretapping laws?
- baddox 13y agoThey started killing innocent people very early in the government's history and have yet to stop.
- tlrobinson 13y agoSigh, I should have expected this response. You know what I mean.
- baddox 13y agoWhite innocent people?
- Tloewald 13y agoBut you can arrest individuals who, using their office, engage in felonies. If this is organizational, i believe we could use RICO.
- unreal37 13y ago
- deleted 13y ago[deleted]
- jumby 13y agoIt's sad everyone on here is amazed the good guys have good tools. Sure it probably cost them $1M USD to have some server record an incoming ip from an http request, but still. "Oh noes, we aren't 3 steps ahead of them, they are 3 steps ahead of us." Fuckin-a they are and I'm glad. Getting rid of scumbag terrorists, child porn shitbirds and spying on foreign adversaries is fine by me. And yes, I already know the comments will be "what if they designate you a terrorist some day". I suppose I will cross that bridge when that happens.
- enneff 13y agoWhat are you talking about? Nobody is amazed that the "good guys" (btw, whose good guys?) have good tools. It's been known for decades that the USA has some of the best signals intelligence people and systems. But that's not even relevant here. This particular attack exploits a known issue of Tor, which has existed by design since day one. Hacking machines isn't rocket science, and the particular vulnerability in Firefox was public before the attack. What people are surprised by is the brazen and open use of an illegal hack by law enforcement officials. We have laws for a reason and lawmen to uphold those laws. When the lawmen are breaking the laws we're pretty much fucked. I'm sorry that you can't see that.
- kropotkin 13y agoThis particular attack exploits a known issue of Tor, which has existed by design since day one. Just so everyone's clear, this was not a "known issue of Tor". It was a javascript based Firefox exploit.
- enneff 13y agoThe known issue of Tor that I refer to (and sorry for not being more specific) is that a buggy client can leak your identity. The Firefox exploit leverages this design weakness.
- autodidakto 13y ago> I suppose I will cross that bridge when that happens. No. When that happens, you won't cross it. You'll fall right into the river.
- jrockway 13y agoThis is actually a pretty good attack. The only problem I see is the usefulness of the evidence that the attack gathers. Visiting an FBI warning over Tor isn't illegal, so appearing in some child-porn-user database because you were curious about how the exploit worked is a little disturbing, given the stigma child porn has. I'd also like to see the legal theory they used to seize control of someone's computer. Did a judge sign off on this attack strategy? But ultimately, I think they used some pretty good software engineering to solve a problem they wanted to solve.
- skwirl 13y agoIt most likely falls under the FBI's legal wiretapping abilities.
- belorn 13y agowiretapping normally require a specific target, with a specific reason. Going after the tor email service, is like wiretapping the US postal service for a fishing expedition. It sounds to me as being outside the FBI's legal wiretapping abilities.
- skwirl 13y agoThis is just wrong. First, you are implying that Tor has an official Tor e-mail service, which it does not. Tormail is/was just a basic e-mail service someone not associated with the Tor project was hosting on the deep web. For all anyone knows, Tormail itself could have been run by the FBI or NSA or whatever all along. Anyone who thought Tormail guaranteed them anonymity was a fool, much like anyone who kept Javascript enabled while browsing the deep web was a fool. Second, Tormail wasn't itself targeted. What was targeted was the hosting provider that was hosting 95% of child pornography in the deep web, and that hosting provider also happened to host Tormail and a bunch of other non child pornography websites. Conspiracy theories will abound, of course, but keep in mind that the NSA's MO is not to disrupt communication but to intercept it. If the government's real concern here was with Tormail, they would have simply kept it around and tapped it, since they had clearly compromised the hosting provider's boxes and could have done so. They wouldn't have shut it down and just sent people fleeing to the dozens of other supposedly anonymous and secure e-mail services out there, including ones that perhaps they haven't yet compromised.
- aclevernickname 13y agothis is fantastic. now I know who I can sue for destroying the tormail accounts I was using for (legal) business purposes. Probably the best news I've had since Tormail went down.
- anonymous 13y agoOh, the malware! What do they do about users who do not turn on Javascript? Or users who do not use the popular browsers? It seems like the malware authors here, government employees or contractors, are just like all the others that form the underbelly of the internet... they only focus on the least sophisticated users or the users who always follow the herd (not the Hurd): Windows and OSX/iOS users. Assumptions, assumptions, ...
- thefreeman 13y agoThey were specifically targetting the version of firefox bundled with the Tor Browser Bundle.
- dthunt 13y agoWhy are MAC's persistent? They're totally insecure, so you can't make sensible security decisions off of them. Why aren't they randomly assigned on power-up?
- drivebyacct2 13y agoLots of networking gear and applications make a lot of assumptions that MAC addresses are static and persistent. Things would certainly break if this contract were broken at this stage.
- mynameisme 13y agodrivebyacct2, you're hell banned
- belorn 13y agoThe use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually have legal usage like hunting or self defense. A better example would be a under cover cop, selling real drugs to real people with the intent to impress a local drug cartel. It has to my knowledge never happen, but it would be interesting to know if the cop could be held liable if someone dies from a overdose from those drugs. Let say that a police virus spreads out of control, and infects millions of computers. What if this specific firefox exploit get copied by a botnet, and is used to execute credit card stealing software on unsuspected users. How liable can the police become when millions of people are effected? I really have no clue.
- deleted 13y ago[deleted]
- noselasd 13y ago>At what other point in history has police distributed a >completly illegal tool onto unsuspected and non-targeted >civilians? For quite a while. Law enforcement have installed physical surveilance and tracking devices since as long as they have existed - and unsuspecting innocents have been caught on those tapes and recorders. It's also a question of whether those tools are illegal - there may be laws against them , but the government can get special permissions
- greenyoda 13y agoFor a wiretap, they'd definitely need a warrant. And I think there was a recent court decision that says that police need a warrant to put a GPS tracker on someone's car. What they did here was to install malware on thousands of machines, without any probable cause to believe that any specific machine owner was involved with child porn. If I understand the law correctly, they would need to obtain a specific warrant for each machine they wanted to search. Let's say that there was a store in a neighborhood that was known to sell child porn. No judge would sign a warrant that gave police permission to put a GPS device on every car in that neighborhood to track whether they ever visited that store (and they may have visited but bought only legal merchandise). So why is it different if you do it on the internet?
- DigitalSea 13y agoWhat is happening to this world? The Government and it's so-called agencies vested with protecting America and its allies are treating everyone like criminals, privately harvesting our information via any means possible. They don't even have to hide it any more. They can admit things like this and nobody can do anything about it. We've passed the point of being able to defend ourselves against actions like this. Every step we take to protect our privacy, the Government is presumably two-steps ahead. We just can't win...
- anigbrowl 13y agoPff. That's like saying the government is spying on you because you saw a police officer look at you when you walked past a police car. Personally, I am just fine with the FBI harvesting the details of anyone who visits a CP site. So this puts strain on the network and causes loss of functionality for non-illegal uses of Tor - inconvenient, but then it's also inconvenient when you can't park because a police car, fire truck, or ambulance is taking up the space you hoped to park in. On a scale of 1 to 10, the harm suffered by non-criminal Tor users during this sting operation looks to me to be about a 1 or a 2.
- teeja 13y agoI know. It's as if (ex-CIA-case officer) Phil Agee's claim back in the mid-80s that America was about to be Latinized is true. Healthcare, education, housing ... what's next?
- sidcool 13y agoThis is about child pornography. I support this action by FBI for a change. The deep web is rotten in some respects. Child pornography cannot be allowed anywhere. If I were in the FBI, I would do anything to stop child abuse.
- smutticus 13y agoIt's like the government isn't even pretending anymore that they don't constantly break the law.
- mariuolo 13y agoI don't understand why he isn't being prosecuted in Ireland.
- jacquesm 13y agoIn a proper judicial system any evidence gained resulting from infecting computers with malware by law enforcement would automatically be inadmissible because the owners of those computers were no longer the only ones with access.
- d4n3ws 13y agoMy two cents about the "french hosting provider" : The 22 of july, the french hosting provider OVH suffered an APT attack from intruders looking for the database of european clients. The 29 of july, OVH announce new rules about using Tor on their network... In august Marques is arrested. http://d4n3ws.polux-hosting.com/2013/09/14/freedom-hosting-lattaque-de-de-anonymisation-sur-tor-est-bien-a-linitiative-du-fbi/ http://d4n3ws.polux-hosting.com/2013/09/14/freedom-hosting-l...
- tete 13y agoFrom my point of view there appears to be a huge campaign to discredit Tor or short FUD going on. Okay, lately there appears the be a huge campaign to discredit Tor going on. The botnet, the Freedom Hosting thing. We should fight back on that. Tor is still the best took we have and maybe these attacks are the best sign of it. If you consider switching to a VPN like many do.. That's a bad idea. VPNs are no technology for anonymity. There are various reasons. They don't defend against various attacks, but more importantly they are owned by private entities. Did you hear of this PRISM thing? [rhetoric question] Well, guess what a private company.. even outside of the US would do if any government would ask for a backdoor, maybe even offering money. A reason why there are these great releases about attacks on Tor is the fact that it is the best tool we have. There are attacks on it, but way less than on any comparable technology. Numerous institutions, universities, etc. work on both finding attacks and improving Tor. The Tor community is attracting the smartest people in the world, just like the NSA is. There is no other anonymity software with so many scientific papers written about it. There are attacks, none of them reaching beyond what can be done to VPNs, etc. and there are tons of improvements that are outlined, that only need a tiny bit more research or only the actual implementation. If you want to work on a real quality product for the greater good there probably is no better place than the Tor Project. If you wanna help right now (meaning in seconds to minutes) here are some places to go. If you want to host a Tor Bridge on the cloud for free or really cheaply: https://cloud.torproject.org/ https://cloud.torproject.org/ If you are using Firefox: https://addons.mozilla.org/en-US/firefox/ https://addons.mozilla.org/en-US/firefox/ If you are using Chrome/Chromium: https://chrome.google.com/webstore/detail/cupcake/dajjbehmbnbppjkcnpdkaniapgdppdnc https://chrome.google.com/webstore/detail/cupcake/dajjbehmbn... If you have a website/blog: http://crypto.stanford.edu/flashproxy/ http://crypto.stanford.edu/flashproxy/ If you have more than just a few minutes: https://www.torproject.org/getinvolved/volunteer.html.en https://www.torproject.org/getinvolved/volunteer.html.en
- Blahah 13y agoFlashproxy seems pretty dark unless I've misunderstood it - automatically opting website visitors in to becoming a transient TOR node is deeply unethical.
- tinalumfoil 13y agoSo, don't trust spy agencies?