Slashdot Mirror


Exodus Intelligence Details Zero-Day Vulnerabilities In Tails OS

New submitter I Ate A Candle (3762149) writes Tails OS, the Tor-reliant privacy-focused operating system made famous by Edward Snowden, contains a number of zero-day vulnerabilities that could be used to take control of the OS and execute code remotely. At least that's according to zero-day exploit seller Exodus Intelligence, which counts DARPA amongst its customer base. The company plans to tell the Tails team about the issues "in due time", said Aaron Portnoy, co-founder and vice president of Exodus, but it isn't giving any information on a disclosure timeline. This means users of Tails are in danger of being de-anonymised. Even version 1.1, which hit public release today (22 July 2014), is affected. Snowden famously used Tails to manage the NSA files. The OS can be held on a USB stick and leaves no trace once removed from the drive. It uses the Tor network to avoid identification of the user, but such protections may be undone by the zero-day exploits Exodus holds.

132 comments

  1. Curious by Anonymous Coward · · Score: 0

    What could allow remote code execution in Tails but not affect Firefox or any of the other software us non-terrorists use. A bug in tor itself?

    1. Re:Curious by Penguinisto · · Score: 3, Interesting

      What could allow remote code execution in Tails but not affect Firefox or any of the other software us non-terrorists use. A bug in tor itself?

      Given that they likely had to add a few custom bits to insure anonymity, and likely modified or ripped out a few other bits, odds are good that the customizations are where the issue lies.

      (...then again, perhaps the bug(s) can be found in the std. packages, but the researchers wanted to scare a smaller organization into becoming a customer first?)

      --
      Quo usque tandem abutere, Nimbus, patientia nostra?
    2. Re:Curious by Anonymous Coward · · Score: 0

      What could allow remote code execution in Tails but not affect Firefox or any of the other software us non-terrorists use. A bug in tor itself?

      Given that they likely had to add a few custom bits to insure anonymity, and likely modified or ripped out a few other bits, odds are good that the customizations are where the issue lies.

      (...then again, perhaps the bug(s) can be found in the std. packages, but the researchers wanted to scare a smaller organization into becoming a customer first?)

      ensure.

    3. Re:Curious by almitydave · · Score: 1

      Replying to pedantic ACs is a waste of time, I know, but I see this mistake made often enough. "Insure" and "ensure" are largely interchangeable: http://dictionary.reference.com/browse/insure.

      --
      my, your, his/her/its, our, your, their
      I'm, you're, he's/she's/it's, we're, you're, they're
    4. Re: Curious by Demena · · Score: 1

      Why did you call hims a piece of firewood or baked potato?

    5. Re:Curious by gweihir · · Score: 1

      What is certainly there is at least several JavaScript zero-days. JavaScript is complex to implement and easy to get wrong. As this is a commercial effort (as can be seen by its immorality and focus on profit), they will go after low-hanging fruit. The JavaScript engine is the most promising one.

      And who said it would not affect other users too?

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  2. Wait, wait... by Penguinisto · · Score: 5, Insightful

    The company plans to tell the Tails team about the issues "in due time"

    I'm 100% certain "in due time" would come a lot sooner if the Tails OS maintainers coughed up the right fee, which means that this is most definitely NOT responsible disclosure.

    I get that security researchers have to eat too, but damn - this sort of reeks of extortion. Maybe I'm wrong, but I know if I had a code project and some company said they knew I had holes but refused to tell me upon asking, extortion would be the first effing thought that would come to mind.

    --
    Quo usque tandem abutere, Nimbus, patientia nostra?
    1. Re:Wait, wait... by Noryungi · · Score: 3, Insightful

      No, not extortion against Tails - extortion of money from the NSA or whoever else their ''clients'' are.

      I am sure a lot of TLAs right now are salivating -- unless they have discovered these vulnerabilities before Exodus. In which case, silence can be golden, indeed.

      --
      The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
    2. Re:Wait, wait... by Anonymous Coward · · Score: 1

      If you don't think these fees are fair, you can pay someone else to audit your code.

    3. Re:Wait, wait... by sjames · · Score: 4, Insightful

      Doesn't that put them dangerously close to criminal like the guys that sell zero days to the Russian mob?

      I'm thinking yes but it will be ignored because their customers include bad guys within the U.S. government.

    4. Re:Wait, wait... by mrchaotica · · Score: 4, Insightful

      The arguments I'm used to hearing go something like "but it's obviously unethical, they should just responsibly report and disclose vulnerabilities they find". But this is a total crap argument. The options Exodus has aren't "sell to governments" or "responsibly disclose for little to no fee". The options are "sell to governments" or "go out of business". So maybe someone will say "fine, they should go out of business, then we will all obviously be safer!".

      But, well, it's not really clear that's the case. If Exodus (or Vupen, or whomever) quit, it's not like suddenly the government would stop looking for exploits. And if the US government did, it's not like China or Russia would. And if they did, it's not like criminal organizations would stop. You aren't going to stop vulnerabilities from happening or being sold. Game theoretically, it seems like the right choice is to keep the US government snatching up what vulnerabilities it can to keep in its back pocket for espionage. Not doing so would be a huge blow to US intelligence agencies, when every other major government out there is working on the same capabilities.

      So what you're saying is that what Exodus is doing is unethical, but criminals would do the same thing anyway, so we might as well ignore Exodus' unethical behavior because they're on "our side?"

      Fuck that, and fuck you!

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    5. Re:Wait, wait... by Unordained · · Score: 2

      http://www.wired.com/2014/04/o...

      We can still break into the systems we "need" to break into, without keeping a full hand of all possible vulnerabilities. To reduce our overall exposure to risk, it makes sense to disclose most of these to vendors for patching, maybe some with a delay. Our government can buy up vulnerabilities from Exodus, then release them -- Exodus gets paid, we get somewhat better security all around, and the NSA gets a few last holes to work with.

    6. Re:Wait, wait... by gl4ss · · Score: 1

      but if I did it and sold it on the market on the country that I am in or their neighbouring countries then I would be unethical/criminal?

      wtf? there's no "due time".

      they could be just bullshitting too and just waiting for fixes to come in and then say "yeah those were the vulns".

      furthermore, they would be vulnurabilities on the firefox code or the tor code which would count as news on their own. or perhaps they're just buggy drivers for wifi or ethernet. we don't know and now they're just doing two things, scaremongering and fishing for money from companies. they're using this as advertisement. "pay us or we'll sell exploits to your sw and not tell you" which is pretty much exactly what "black hat" exploit sellers are doing so does their work bother you? if not, ok.

      --
      world was created 5 seconds before this post as it is.
    7. Re:Wait, wait... by Anonymous Coward · · Score: 0

      But for what it's worth, I'd still trust the US government (even with all its faults) far more than the Russians or Chinese.

      You just as well forget that Exodus is just, if not more, probable to be selling these exploits to the Russians and the Chinese. It is, after all, the case that Tor was created and then supported by the US government precisely for those in oppressive regimes like Russia and China (and ironically can be applied to the US, but that's another story) who otherwise would have their free speech suppressed. So, who would logically be on the short list to buy vulnerabilities? Why, governments that have no compunction about violating the privacy and speech rights of individuals in the name of "national harmony".

      So, when Exodus wants to invest time and money in finding exploits in your favorite application and turning a profit to help their government against Chinese/Russian/criminal agencies, that doesn't bother me.

      Even presuming they're not selling the exploits to Chinese/Russian/criminal agencies, there's every bit of evidence the NSA has used their own surveillance for corporate espionage against foreign multinational corporations for American corporations. Now, perhaps in your eyes that makes them a "criminal organization". But, if not, then it stands to reason that any corporation doing their own espionage would be fair game to buy these exploits as well.

      You see, the whole notion that unethical things can be done ethically by a select few and therefore it's okay is just wrong. The whole Justice system isn't based upon the idea that the executioner is some holy sage engaging in some divine right. It's that if a death penalty or an imprisonment is a necessary evil, yet an evil none the less. And at every step along the way, we should be as transparent as possible about what is happening and try to correct when unnecessary evil happens.

      Every bit of Exodus making clandestine sales to who knows whom and organizations like the NSA being incredibly opaque only highlights how wrong the system is. Waving a magic level of trust in them is just plain stupidity--except to the extent that the degree of unnecessary evil has, in the past, shown to be less than the Russian or Chinese governments so we can likely presume that the unnecessary evil of today will likely be less as well (although that inherently grants them the ability to be nearly as bad as the Russians and still be okay by you). No matter how you look at it, the argument that we're heading towards an even worse police state so we should side with the lesser of two or three evils is just wrong.

    8. Re:Wait, wait... by Boronx · · Score: 1

      Libertarianism run amok. Apparently the need to stay in business trumps any moral concerns.

    9. Re:Wait, wait... by Anonymous Coward · · Score: 0

      Selling someone's schedule, alarm code and house keys to the highest bidder is not auditing. They're knowingly helping criminals in committing a crime. Of course, the criminal happens to be the government so nothing will come of it.

    10. Re:Wait, wait... by compro01 · · Score: 1

      Our government can buy up vulnerabilities from Exodus, then release them

      Or just buy up Exodus, period, continue operating it as a GOC, and release vulnerabilities are they're discovered.

      --
      upon the advice of my lawyer, i have no sig at this time
    11. Re:Wait, wait... by Anonymous Coward · · Score: 0

      i don't know if i'd believe this, this company would be under an NDA etc. it's prolly just a scare tactic to move you away from it, along similar lines of as tor being used to paint targets.

    12. Re:Wait, wait... by Anonymous Coward · · Score: 0

      I don't think the comparison of a private house to a public repository is helpful. If you don't want these guys looking through your code and doing whatever they want with the bugs, then don't publish it.

    13. Re:Wait, wait... by Anonymous Coward · · Score: 0

      if vupen and exodus weren't wormy pieces of #$!% they would responsibly disclose vulns to free software projects for free. If they want to find and sell info on vulns in proprietary code then that's fine. that's part of the deal with the devil that closed source vendors made and they deserve what that produces.

    14. Re:Wait, wait... by Anonymous Coward · · Score: 0

      (I posted the above, but /. is having weird issues with my cookie or something, so it logged me out and posted as AC. Probably beta's fault)

       

      So what you're saying is that what Exodus is doing is unethical, but criminals would do the same thing anyway, so we might as well ignore Exodus' unethical behavior because they're on "our side?"

      Fuck that, and fuck you!

      So you seem to be saying hacking is never ethical. I'm not really sure that's fair either. Is it ethical for criminals to break into computers to steal money from your bank account? No, I think we can agree on that.

      Is it ethical for the CIA to break into computers of terrorists (for the sake of the argument, let's assume they are indeed terrorists)? Let's say they wanted to hack into the computer of Russian separatists to intercept communications to see if they were responsible for the MH 17 incident. Is that ethical? I think it is. Especially when often the alternative to getting necessary intelligence (we don't have to agree all the intelligence the CIA gets is necessary, but surely some of it is) by breaking into computers involves killing people.

      So no, I guess what I'm saying is that if Exodus weren't selling bugs to the government, we would be worse off, not better. The world would be a better place if you could prevent 100% of people from having weapons, but that will never happen. Especially if all it takes to make those weapons are people in a room with computers.

    15. Re:Wait, wait... by Anonymous Coward · · Score: 0

      don't blame this on libertarianism you fucking slav

    16. Re:Wait, wait... by Anonymous Coward · · Score: 0

      and you know they aren't selling to criminals because....????

    17. Re:Wait, wait... by Anonymous Coward · · Score: 0

      Is it ethical for criminals to break into computers to steal money from your bank account? No, I think we can agree on that.

      Is it ethical for the CIA to break into computers of terrorists (for the sake of the argument, let's assume they are indeed terrorists)? Let's say they wanted to hack into the computer of Russian separatists to intercept communications to see if they were responsible for the MH 17 incident. Is that ethical? I think it is.

      it may be 'ethical' from your point of view
      but do they have a warrant?
      sure they have reasonable suspicion but does that constitute an invasion of privacy?
      should people in the ukraine expect privacy?
      should the rest of the world?
      should the united states?
      if i thought my wife was at your house because i am an over-bearing suspicious asshole and i saw you talking to her yesterday -
      does that mean it's ethical for me to peep in your windows
      trespass on your property or break into your house?

      ethics are funny, and just like the rest of reality they are prone to the the many, various viewing angles of our limited perception.

    18. Re:Wait, wait... by mrchaotica · · Score: 1

      So you seem to be saying hacking is never ethical.

      Hacking with responsible disclosure is ethical. The fact that it may not be possible to do so profitably is irrelevant.

      Hacking without responsible disclosure is always unethical, and what others choose to do is irrelevant. The fact that somebody else is acting unethically is not an excuse for you to act unethically too!

      So no, I guess what I'm saying is that if Exodus weren't selling bugs to the government, we would be worse off, not better.

      No. We're exactly equally bad off in either case. An attacker is an attacker. I have no confidence whatsoever that giving the NSA the exploits helps the American public, but even if I did the act of doing so would still be unethical!

      Didn't your parents ever ask you rhetorical questions like "if your friends all jumped off a bridge, does that mean you should do it too?" or tell you "the ends do not justify the means" when you were a kid?

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    19. Re:Wait, wait... by Boronx · · Score: 1

      Response to parent post, you brain-dead moron.

    20. Re:Wait, wait... by tylerni7 · · Score: 1
      Ugh, maybe on this computer my replies will show up with my user account (I don't mind a bit of bad karma every now and then, and I think it is hard to have an actual discussion with an AC post). Anyway..

      Didn't your parents ever ask you rhetorical questions like "if your friends all jumped off a bridge, does that mean you should do it too?" or tell you "the ends do not justify the means" when you were a kid?

      I think this is more akin to "an eye for an eye makes the whole world blind". But obviously, just because something is a catchy statement, that doesn't mean it's good advice.
      If other people are attacking you, should you lay down all your weapons and hope they do the same? Maybe, but it's not a cut and dry situation like you make it out to be. I agree that in an ideal world, no one would exploit anyone, and all of our software would be bug free. But it seems naive to base our actions off of that world view when it is not the case. Is fighting and war bad? Yes. But I don't think a Ghandi approach will work in all situations, and sometimes fighting back is necessary. (That doesn't mean all cases, of course.)

      Hacking without responsible disclosure is always unethical, and what others choose to do is irrelevant.

      I think this is an incredibly bold statement. I think it's a bit hard to judge the ethics of exploiting a computer "in a vacuum", the context certainly matters. Let's take a hypothetical situation: if a computer was used as the trigger for a bomb which was going to go off and kill 100 people, would it not be ethical to hack in to the computer and disable it? [we can assume it also has all the fancy triggering mechanisms in place.. capacitive sensing in case someone gets too close, tilt/shock sensors in case something tries to move it, etc]
      I find that belief absurd. And while I'm sure that wasn't the situation you envisioned when you made that claim, I think it's important to note there are cetainly extreme cases where hacking into a computer is clearly ethical.
      If we're able to agree that
      sometimes computer hacking is ethical, then it just becomes a question of where the line is drawn. How much personal information needs to be on the computer about to detonate a bomb before you decide it isn't The Right Thing To Do to hack in? I am sure there are cases where the government is happy to hack into something that I think is ethically dubious, but again, I think it is absurd to say it is never ethical.

      The other thing is you have to consider that "cyber weapons" mean governments can gain intelligence or affect systems without hurting people. Stuxnet is an interesting example. How many lives would have been lost if instead someone bombed the Iranian nuclear facility, or killed off Iranian scientists (yes, I know this still happens anyway, sadly)? Stuxnet was a virus that infected the public's computers as well.
      Based on our discussion so far I would expect you to say something like "well sure, maybe it's better than bombing, but having neither would be even better". That's a totally understandable stance, but again, that isn't the world we live in. I think it's a step in the right direction to at least try to minimize deaths.


      Anyway, it doesn't sound like we're going to come to an agreement on anything, and that's fine. I definitely understand how hacking can be a moral grey area, and not everyone has to agree. However, I just hope people will accept that it is at least a moral grey area, rather than a moral black area.

    21. Re:Wait, wait... by Archangel+Michael · · Score: 1

      Business is neither moral, nor immoral but AMORAL. People are either moral, or immoral, they are not amoral. Everyone is a hypocrite, at some point will violate their own moral code. This is called situational ethics, and is popular in politics.

      If your personal code of ethics prevents you from doing business with people who are hypocritical(evil, bad, immoral etc), then you'll be doing business with nobody, The best you can do is do business with people who support your ideals more often that the other guys.

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    22. Re:Wait, wait... by mrchaotica · · Score: 1

      If other people are attacking you, should you lay down all your weapons and hope they do the same?

      Are people attacking Exodus via TOR? If not, then what ethical justification does it have for involving itself as the NSA's mercenary?

      I'm all for self-defense; it's aiding aggression that I find unethical.

      Hacking without responsible disclosure is always unethical, and what others choose to do is irrelevant.

      I think this is an incredibly bold statement. I think it's a bit hard to judge the ethics of exploiting a computer "in a vacuum", the context certainly matters. Let's take a hypothetical situation: if a computer was used as the trigger for a bomb which was going to go off and kill 100 people, would it not be ethical to hack in to the computer and disable it? [we can assume it also has all the fancy triggering mechanisms in place.. capacitive sensing in case someone gets too close, tilt/shock sensors in case something tries to move it, etc]

      Clearly, I'm failing to understand -- what is there about your hypothetical situation that precludes responsible disclosure?

      Also, responsible disclosure is sort of tautologically ethical because it does consider context (that's what the "responsible" part means). If you're not sure what kind of disclosure is responsible, then the only ethical option would be to forgo the hacking.

      The other thing is you have to consider that "cyber weapons" mean governments can gain intelligence or affect systems without hurting people. Stuxnet is an interesting example. How many lives would have been lost if instead someone bombed the Iranian nuclear facility, or killed off Iranian scientists (yes, I know this still happens anyway, sadly)? Stuxnet was a virus that infected the public's computers as well. Based on our discussion so far I would expect you to say something like "well sure, maybe it's better than bombing, but having neither would be even better". That's a totally understandable stance, but again, that isn't the world we live in. I think it's a step in the right direction to at least try to minimize deaths.

      Being forced to choose the lesser of two evils doesn't mean you should become the active accomplice of that evil.

      Besides, on a more practical note, you're also failing to consider the rest of the collateral damage. By supporting Exodus's position, you're saying that hypothetically saving the lives of the Iranian scientists is worth hypothetically risking the lives of TOR users worldwide.

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    23. Re: Wait, wait... by Anonymous Coward · · Score: 0

      Because they're only finding exploits in open source? I seriously doubt it.

    24. Re:Wait, wait... by Anonymous Coward · · Score: 0

      i think, ethical - and 'reasonable' are convoluted and oft confused.

      don't forget that the term 'reasonable' is very close to 'actionable'.

    25. Re:Wait, wait... by Anonymous Coward · · Score: 0

      in the spirif of FUD,
      who's to say this isn't HBGary's replacement - and they sought to stir the pot.

    26. Re:Wait, wait... by tylerni7 · · Score: 1

      If other people are attacking you, should you lay down all your weapons and hope they do the same?

      Are people attacking Exodus via TOR? If not, then what ethical justification does it have for involving itself as the NSA's mercenary?

      I'm all for self-defense; it's aiding aggression that I find unethical.

      I don't think it matters whether we take Exodus or the US Government. I'm not really sure why being a mercenary is so bad? What is the difference if the US Government pays Exodus or hires the people working for Exodus to write exploits directly?
      And yes, people are using Tor to fight against the US; certainly hackers and terrorists use Tor. (I don't believe more than a small fraction of Tor users are malicious, but malicious users undoubtedly exist.

      Clearly, I'm failing to understand -- what is there about your hypothetical situation that precludes responsible disclosure?

      Also, responsible disclosure is sort of tautologically ethical because it does consider context (that's what the "responsible" part means). If you're not sure what kind of disclosure is responsible, then the only ethical option would be to forgo the hacking.

      If you have responsibly disclosed every exploit you know about, you are not going to be able to hack into the computer which triggers the bomb. I'm not sure why this isn't obvious. Unless somehow your "responsible disclosure" allows for holding on to exploits until you need them for dire situations, you have no way to stop such a computerized device.

      Let's be more concrete here: someone has hooked up a Raspberry Pi to detonate a bomb, which is triggered, say, over Tor. Whoever made this wasn't stupid: it has a heartbeat which will detonate the bomb if it fails, so you can't just jam it or cut off internet access. It has normal motion sensors, etc. You have 1 hour to disable it.
      I propose that given the possibility of such a scenario (or scenarios like this; obviously this is an extreme and contrived example to try to prove a point), it is ethical to withhold disclosure of vulnerabilities. In your proposed scenario, the government has "emptied its cyber arsenal". It has nothing it can do to prevent such an attack. I believe it is superior to have the capability to prevent such an attack.

      Being forced to choose the lesser of two evils doesn't mean you should become the active accomplice of that evil.

      Besides, on a more practical note, you're also failing to consider the rest of the collateral damage. By supporting Exodus's position, you're saying that hypothetically saving the lives of the Iranian scientists is worth hypothetically risking the lives of TOR users worldwide.

      Except it isn't that simple.. one side has to win. If the US Government doesn't have people writing exploits, they are losing tools that help them to fight $ENEMY.

      It's like saying we shouldn't have fought in Wold War II against Hitler, because war is bad. The Allied forces were the "lesser of two evils"--evil, of course, because war is unethical just like hacking is. Why choose to actively help the lesser of two evils? We should have remained neutral.
      We can ignore any historical facts for the sake of hypothetical arguments and say Hitler would have succeeded with 100% certainty without US support. In this sort of scenario are you trying to say that the ethical thing to do is nothing? It really sounds like we have some huge differences of opinion in all of this, so this probably isn't going anywhere.

    27. Re:Wait, wait... by MacDork · · Score: 1

      Or it's bullshit to scare people away from tails. Have they demonstrated the exploit?

    28. Re:Wait, wait... by gweihir · · Score: 1

      Commercial enterprises (such as Exodus) will do anything and everything that is or should be criminal, provided they can get away with it. Do not even look for minimal ethics there, it is a complete waste of time.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    29. Re:Wait, wait... by mrchaotica · · Score: 1

      I don't think it matters whether we take Exodus or the US Government. I'm not really sure why being a mercenary is so bad? What is the difference if the US Government pays Exodus or hires the people working for Exodus to write exploits directly?

      The difference is motivation. If you're partisan -- if you're motivated because you think the cause is just -- then maybe it's ethical to fight. If you're motivated by money and otherwise don't care, it's clearly unethical.

      (I say "maybe" because it's not ethical to fight if you're mistaken in your belief that the cause is just -- it has to genuinely be so. But if you don't care, fighting is unethical even before considering the justness of the cause because it's not your fight.)

      And yes, people are using Tor to fight against the US; certainly hackers and terrorists use Tor. (I don't believe more than a small fraction of Tor users are malicious, but malicious users undoubtedly exist.

      If the American Revolution were happening today, the Founding Fathers would be labeled "hackers and terrorists" from the perspective of the British Crown. In other words, unless you're purposefully targeting innocents, those sorts of labels are a matter of perspective. I'm not at all convinced that using TOR to fight against the US government is actually a bad thing.

      If you have responsibly disclosed every exploit you know about, you are not going to be able to hack into the computer which triggers the bomb. I'm not sure why this isn't obvious. Unless somehow your "responsible disclosure" allows for holding on to exploits until you need them for dire situations, you have no way to stop such a computerized device.

      Let's be more concrete here: someone has hooked up a Raspberry Pi to detonate a bomb, which is triggered, say, over Tor. Whoever made this wasn't stupid: it has a heartbeat which will detonate the bomb if it fails, so you can't just jam it or cut off internet access. It has normal motion sensors, etc. You have 1 hour to disable it. I propose that given the possibility of such a scenario (or scenarios like this; obviously this is an extreme and contrived example to try to prove a point), it is ethical to withhold disclosure of vulnerabilities. In your proposed scenario, the government has "emptied its cyber arsenal". It has nothing it can do to prevent such an attack. I believe it is superior to have the capability to prevent such an attack.

      First of all, I understood your previous scenario to be that you're discovering a new exploit in the process of defusing the bomb, and deciding whether to responsibly disclose it afterwards or to keep it in your pocket for later use. That's different from what you wrote this time, which is that you're using a previously-discovered but undisclosed exploit to defuse a bomb at the present time.

      The problem with your scenario is that you're presupposing it "will" happen, and judging your actions after the fact. That's not a valid mode of reasoning, since there's no way to know that the scenario will actually occur (or even that it's more than infinitesimally likely to occur) at the time you're making the decision to disclose or not.

      In other words, you're saying that it's perfectly ethical to do actual harm now because you guess that it might lessen the possibility of doing potential harm later. If you don't understand the problem with this, there's nothing more I can do to explain it to you more clearly.

      It's like saying we shouldn't have fought in Wold War II against Hitler, because war is bad. The Allied forces were the "lesser of two evils"--evil, of course, because war is unethical just like hacking is. Why choose to actively help the lesser of two evils? We should have remained neutral.

      That's exactly what we did do until the Japanese attacked us directly at Pearl Harbor. I think we acted pretty appropriately in that case!

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    30. Re:Wait, wait... by Samizdata · · Score: 1

      Nothing personal, but vaporous unconfirmable zero day reports like this strike me as more of a "My uncle works at Nintendo, and he got a copy of the secret developer nude Mario Brothers cart. No, it's at his house...In Hawaii. No, he won't mail it to me to show you."

      --
      It's not the years, honey, it's the mileage. - Colonel Henry Walton Jones, Jr., Ph.D.
  3. They have no accountability by stewsters · · Score: 4, Insightful

    So they are selling vulnerabilities to hackers rather than telling the source maintainers? That's irresponsible at best.

    1. Re:They have no accountability by Minupla · · Score: 1

      Agreed - and in this case "Hackers" == "Nation Sates"

      --
      On the whole, I find that I prefer Slashdot posts to twitter ones because I don't get limited to 140 chars before
    2. Re:They have no accountability by klui · · Score: 1

      They're either selling or sold the vulnerability to government agencies or just FUD against Tails.

    3. Re:They have no accountability by eulernet · · Score: 1

      No, this is business.
      Why would you want to use morality in business ?

    4. Re:They have no accountability by gweihir · · Score: 1

      It is the most unethical thing they can do. On the plus-side, this may help Tails (and Tor) to get ahead of the game again, as this draws a lot of attention to the problem.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  4. Scaremongering? by Anonymous Coward · · Score: 1

    Every OS has 0-day issues - no such thing an OS without them. However, dare I say that there is a little scaremongering on here in relation to Tails? If you can't stop them throw some mud or sow the seeds of doubt?

    1. Re:Scaremongering? by K.+S.+Kyosuke · · Score: 1

      Every OS has 0-day issues - no such thing an OS without them.

      Except for Oberon... (And other similar designs in the spirit of "obviously no deficiencies")

      --
      Ezekiel 23:20
    2. Re:Scaremongering? by Actually,+I+do+RTFA · · Score: 1

      How does that work? If there is an easy way to guarantee no deficiencies, why isn't it used always?

      --
      Your ad here. Ask me how!
    3. Re:Scaremongering? by K.+S.+Kyosuke · · Score: 1

      Because small software fell out of favor some time ago. And it doesn't do HTML5 yet. :-) (It may not be actually easy, but compared to the man-years needed to create the 100MLOC behemoths of today, it doesn't seem such a far-fetched prospect to me! Especially if we're talking about specialized secure computing systems, where one might be expected to be willing to do a few sacrifices...)

      --
      Ezekiel 23:20
    4. Re:Scaremongering? by Actually,+I+do+RTFA · · Score: 1

      How does it assure no deficiencies? And why don't other projects use that methodology?

      --
      Your ad here. Ask me how!
    5. Re:Scaremongering? by K.+S.+Kyosuke · · Score: 1

      How does it assure no deficiencies?

      I spelled out the "obviously no efficiencies" part, haven't I? How much up to date are you with your Hoare lectures?

      And why don't other projects use that methodology?

      Because they'd have to change their whole direction? As I said, compact things fell out for fashion in the SW arena.

      --
      Ezekiel 23:20
    6. Re:Scaremongering? by K.+S.+Kyosuke · · Score: 1

      That should have read "obviously no deficiencies", of course!

      --
      Ezekiel 23:20
  5. FUD? by timrod · · Score: 5, Insightful

    This sounds like FUD against Tails. A security research firm finds some undisclosed zero-days in Tails, but doesn't describe what they could do - arbitrary code execution? De-anonymization? They then go on to say that they haven't told the Tails maintainers what the vulnerabilities are, but will "in due time", implying they're going to sell them off to the government first. Exodus Intelligence also does a lot of business with the US government, possibly including the NSA.

    To me, this sounds like they probably found some minor zero-days and are trying to spread FUD (likely spurred on by their clients in the government) to get people to stop using Tails. After all, we know that the NSA is trying to put people who attempt to download Tails on a watchlist for further scrutiny.

    1. Re:FUD? by Anonymous Coward · · Score: 0

      This is indeed, FUD.

    2. Re:FUD? by Anonymous Coward · · Score: 0

      I came here to post this comment, but in a shorter form:

      That's what they would say, wouldn't they.

    3. Re:FUD? by thoriumbr · · Score: 3, Insightful

      I don't think this is FUD.

      If any government gets to know that you have an exploit for a very secure system they are targeting, you will surely be contacted and will earn a lot of money. Disclosing the vulnerability to the mantainers will destroy a great part of the value.

      I would tell it's FUD if the vulns were advertised by some competing Linux distro.

    4. Re:FUD? by bmo · · Score: 4, Insightful

      Carnegie Mellon is suppressing de-anonymising TOR discussion at Black Hat.

      Talk on cracking Internet anonymity service Tor withdrawn from conference

      By Joseph Menn

      SAN FRANCISCO, July 21 Mon Jul 21, 2014 1:05pm EDT

              Technology

      (Reuters) - A heavily anticipated talk on how to identify users of the Tor Internet privacy service has been withdrawn from the upcoming Black Hat security conference.

      A Black Hat spokeswoman told Reuters that the talk had been canceled at the request of lawyers for Carnegie-Mellon University, where the speakers work as researchers. A CMU spokesman had no immediate comment. (Reporting by Joseph Menn; Editing by Chris Reese)

      ------

      My guess is that someone wants the hole (if there is one) kept open a while longer or the suspicion that TOR is somehow ineffective alive. Let your mind run wild with speculation.

      --
      BMO

      http://www.reuters.com/article...

    5. Re:FUD? by Anonymous Coward · · Score: 3, Informative

      > My guess is that someone wants the hole (if there is one) kept open a while longer or the suspicion
      > that TOR is somehow ineffective alive. Let your mind run wild with speculation.

      Or...

      The lawyers are worried that the testing violated wiretap laws and are trying to reduce CMU's legal liability.

    6. Re:FUD? by Anonymous Coward · · Score: 0

      OR they're pissed cuz they did find a zero day in tails and got blocked by something else in it lol

    7. Re:FUD? by Anonymous Coward · · Score: 0

      It's more like FU.

      There's fear and uncertainty, but no doubt that Exodus and/or Carnegie Mellon could do a lot of harm to Tails and Tor over the next few weeks should they choose to. At least Carnegie Mellon seems to be working with the Tor project to close the holes AFAICT.

      So Exodus plans to tell Tails huh? I'm sure 1 month would be enough time for the NSA to have their way with the current users, and cause a permanent crisis of confidence in the project.

      Dark times are coming. Lots of FU.

      Captcha: realists

    8. Re:FUD? by gweihir · · Score: 1

      Well, I am not sure about "minor". But a prime source of zero-days should be the Java-Script engine. Turn it off or use NoScript, and you may be still secure.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    9. Re:FUD? by Anonymous Coward · · Score: 0

      The Carnegie Mellon TOR research sounded like a lot more than a JavaScript bug. It sounded like some kind of traffic analysis to find which IPs correspond to users and darksites.

    10. Re:FUD? by gweihir · · Score: 1

      And that is a different story discussed in a different place. This discussion here is about zero-days in Tails, not about TOR vulnerabilities.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  6. Bogus Article by Anonymous Coward · · Score: 0

    Consider the details:
    - "We have a vulnerability and we're not telling you what it is!"
    - The vulnerability only worst is the newest upcoming Tails release! If you want to be secure, run old unpatched OSes.

    If this doesn't sound like the NSA selling Dual_EC_DRBG or one of their other super secure extra-short key length ECC solutions, I don't know what does.

  7. what environments allow USB boot? by Gothmolly · · Score: 1

    What kind of real environment allows boot from a USB drive?

    --
    I want to delete my account but Slashdot doesn't allow it.
    1. Re:what environments allow USB boot? by Noryungi · · Score: 2

      Anything that has a USB port, really.

      Essentially, anything that is run by NGOs or individuals.

      Sure, in a corporate or governmental/military environment, USB ports are usually a big ''no no'' but some of use like them USB gadgets.

      (Yes, before anyone ask, there has been infiltration through contaminated USB drives and keys ''abandoned'' in strategic locations...)

      --
      The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
    2. Re:what environments allow USB boot? by Anonymous Coward · · Score: 0

      Everything but a Windows RT box.

    3. Re:what environments allow USB boot? by dave562 · · Score: 5, Insightful

      The kind of environment where the attacker is a sysadmin with access to the box and the ability to do whatever they feel like with BIOS, including enabling USB boot.

      The default security posture of most organizations these days is to assume that a trusted insider will exploit the system at some point. Therefore everyone is implementing damage mitigation techniques so that they can respond quickly and understand the scope of the inevitable breach when it does occur.

      Everyone is watching everyone else. The security guys get access to the firewalls and the IDS, but cannot touch the servers. The server guys cannot touch the backups. The backup team cannot initiate a restore without two levels of change control approval. It is a serious PITA for everyone involved and a gross inefficiency.

      The first time an auditor told me that they cannot trust me, my knee jerk reaction was to tell them to go fuck themselves. Eventually I realized that I am in a very risky position with access to a lot of sensitive information. The key is not that they do not trust me, it is that they CANNOT trust me. While I may be trustworthy, who is to say that someone else in my same position, with my same level of access, is also trustworthy? Just like I have to assume that any executable downloaded from the internet is potentially full of malicious code, the risk management folks have to assume that every sysadmin in the organization is potentially full of malicious intent.

    4. Re:what environments allow USB boot? by watcher-rv4 · · Score: 1

      Stuxnet on that Iran's nuclear plant?

    5. Re:what environments allow USB boot? by mspohr · · Score: 1

      I've used TAILS to do banking when I'm traveling and only have access to dodgy WiFi or hotel computers. I've found that it will boot and run on most any computer... sometimes you need to call up the boot menu and select the USB drive, other times "it just works".
      It boots and runs from the USB stick and doesn't use the computers mass storage at all. It performs a wipe of the RAM on exit. It encrypts everything, uses HTTPS and TOR; has a minimal secure browser and a more full featured insecure browser. OpenPGP for email and documents.
      However, it probably has some vulnerabilities. For instance, a hardware keylogger on the machine... however, they have a randomized on-screen keyboard to use to get around this.
      That said, this "security" company which sent out this press release seems like your typical collection of greedy entitled bastards who aim to benefit financially from their FUD.

      --
      I don't read your sig. Why are you reading mine?
    6. Re:what environments allow USB boot? by Anonymous Coward · · Score: 0

      This is it in a nutshell: you give my physical access to a box, it's my box. Either you trust me with that responsibility, or you don't, but don't kid yourself into thinking that I couldn't do whatever I want with it.

      So, as you say, you CANNOT trust me. But, you sort of have to. So... now what?

    7. Re:what environments allow USB boot? by dave562 · · Score: 2

      Trust but verify.

    8. Re:what environments allow USB boot? by Actually,+I+do+RTFA · · Score: 2

      you give my physical access to a box, it's my box.

      Well, the BIOS could be password protected, the case alarmed if opened. In either case you could work around those, but if I put that box in a busy hallway, that's not going to happen. Combine that with no optical media or USB ports, and I think that's a pretty safe box.

      Now, you could mess with the hardware, via a hardware key logger, but that could be mitigated by soldering the wires directly as opposed to allowing a PS/2 port. And the keyboard could probably be physically hardened to the point that you cannot easily open it.

      Bottom line, physical access is one thing. But tamper-evident measures combined with regular but not continuous observations should enable me to trust that if you do gain access, I will know about it while you are present. Possibly even before you are able to finish gaining access.

      --
      Your ad here. Ask me how!
    9. Re:what environments allow USB boot? by Anonymous Coward · · Score: 0

      No USB ports? How will you plug in the mouse?

    10. Re:what environments allow USB boot? by Actually,+I+do+RTFA · · Score: 1

      Well, you could use PS/2, or serial, or even say "fuck it, no mouse for you. Here's a command line and a tab key."

      --
      Your ad here. Ask me how!
    11. Re:what environments allow USB boot? by Anonymous Coward · · Score: 0

      I've used TAILS to do banking when I'm traveling

      Doing your online banking over tor is a bad idea. There are bad exit nodes which may try to run a MITM attack and mimic your banking site in order to capture your login details, or inject code in an attempt to deanonymize you, or to outright break the SSL in the case of the 3-letter agencies. You don't want your banking going through a bad exit node.

    12. Re:what environments allow USB boot? by gweihir · · Score: 1

      Using Tor (Tails) _and_ doing financial transactions with it! You are sure to be on the short list for a drone-strike...

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  8. Classic Spook Stuff... by CaptainOfSpray · · Score: 0

    Tails is clearly a big problem for the NSA. They can't crack it, so they spread disinformation and FUD instead, to put people off using it.

    These people "Exodus Inteligence", who are they, where do they come from, what is their agenda, and how much are the Five-Eyes paying to discredit Tails.

    Obligatory NSA food: Kalashnikov, Handbook of Urban Guerilla, bomb factory, Edward Snowden was right, GCHQ is staffed by lackeys and lickspittles.

    --
    "Cock Up Your Beaver" does not mean what you think. This sig is intended to clog filters and annoy do-gooders
    1. Re:Classic Spook Stuff... by Noryungi · · Score: 1

      I think you forgot "FCUK NSA" somewhere in that NSA food... Or is it "FSCK GCHQ''?

      --
      The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
    2. Re:Classic Spook Stuff... by CaptainOfSpray · · Score: 1

      F**k 'em both, and the equivalents in Canada, Oz, and NZ, and the lazy, corrupt and incompetent oversight committees. Oh and by the way, did you notice the Germans have been at it too, though not on the same scale.

      I am now Officially In a Bad Mood, at which point I am quite likely to send a sizable donation to the people who make Tails, and I encourage y'all to do the same.

      --
      "Cock Up Your Beaver" does not mean what you think. This sig is intended to clog filters and annoy do-gooders
    3. Re:Classic Spook Stuff... by Noryungi · · Score: 1

      Amen, brother.

      (And don't forget the French!)

      --
      The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
    4. Re:Classic Spook Stuff... by dave562 · · Score: 2

      You you realize that you forgot to fnord that and they can totally see what you wrote, right?

    5. Re:Classic Spook Stuff... by Anonymous Coward · · Score: 0

      o how about this the tails os was made by the NSA or Russia. It really depends on whether or not snowden is a double or triple agent :-p.

    6. Re:Classic Spook Stuff... by CaptainOfSpray · · Score: 1

      Oh sorry, should I be encrypting my NSA Food, to make sure they read it?

      --
      "Cock Up Your Beaver" does not mean what you think. This sig is intended to clog filters and annoy do-gooders
    7. Re:Classic Spook Stuff... by Anonymous Coward · · Score: 0

      They can't crack Tails? Hahahaahaha. Best joke posted all day.

    8. Re:Classic Spook Stuff... by dave562 · · Score: 1

      Have no fear. /. is collection friendly, with the data being sent in plaintext. They have all of our posts, and sort them for content and categorize them by context.

    9. Re:Classic Spook Stuff... by Demena · · Score: 1

      Snowden is not an agent. Even NSA says that.

  9. Re:Open sores software? No thanks! by Mordok-DestroyerOfWo · · Score: 1

    My theory is that Steve Balmer is bored in his retirement and feels the need to troll open source sites.

    --
    "Never let your sense of morals prevent you from doing what is right" - Salvor Hardin
  10. Conspiracy theory by Charliemopps · · Score: 3, Interesting

    Sounds fishy to me...
    Perhaps the NSA (or another agency) has another Snowden on their hands and paid Exodus for this "release" to scare the leaker into not sending their data out...

    1. Re:Conspiracy theory by dave562 · · Score: 4, Funny

      Now THIS is the level of paranoia that I like to see.

    2. Re:Conspiracy theory by Anonymous Coward · · Score: 0

      You are not paranoid if they really are out to get you. So I keep my data on paper tape and punch cards. Nobody has equipment to read that anymore...

    3. Re:Conspiracy theory by Charliemopps · · Score: 1

      Now THIS is the level of paranoia that I like to see.

      It's funny what you'll believe when you can't believe anything anymore.

    4. Re:Conspiracy theory by Anonymous Coward · · Score: 0

      It's an appropriate level of paranoia if you have a serious need for anything like Tails, to begin with. Which is just about everyone, if they think about it.

      Seriously looks like disinfo of some sort, tho. Arbitrage, at best. Put up or shut up, Exodus. So far you have shown 0 evidence of 0-day exploits. Just a bare assertion. Much like the entire news media, anymore. Facts? Don't confuse us with facts. We KNOW what happened.

      Folks, this is why full disclosure is necessary. Nothing else can be trusted.

    5. Re:Conspiracy theory by meta-monkey · · Score: 1

      That's a depressingly accurate statement.

      --
      We don't have a state-run media we have a media-run state.
  11. Re:Open sores software? No thanks! by Anonymous Coward · · Score: 0

    Way to not address my points. Defend and deflect at all costs!!

    Tor's "security" is a total joke. The FBI and NSA can easily deanonymise people or simply use their own nodes to inject malware into people's computers to pwn you that way.

  12. Asshats by Anonymous Coward · · Score: 0

    They are doing it wrong. Notify then publicize.

  13. Wait, wait... by Anonymous Coward · · Score: 0, Interesting

    <rant>
    I don't think people understand what vulnerability sellers really do. They invest thousands of man and computer hours into finding bugs which people are willing to pay lots of money for. As a business, they want to keep their customer base happy, which means allowing their customers (yes, presumably the NSA/FBI/etc.) to use their exploits rather than selling them to Tails OS maintainers. Yes, it's probably the case that these exploits don't just go to nabbing child pornographers or drug traffickers, they also probably try to catch the next Snowden, which not everyone agrees is The Right Thing To Do. But for what it's worth, I'd still trust the US government (even with all its faults) far more than the Russians or Chinese.

    But let's be honest here, Tails OS maintainers probably couldn't afford the same price that Exodus's customers will happily pay. Even if Exodus were happy to sell it to the Tails folks, that is certainly going to be a loss of money.

    The arguments I'm used to hearing go something like "but it's obviously unethical, they should just responsibly report and disclose vulnerabilities they find". But this is a total crap argument. The options Exodus has aren't "sell to governments" or "responsibly disclose for little to no fee". The options are "sell to governments" or "go out of business". So maybe someone will say "fine, they should go out of business, then we will all obviously be safer!".

    But, well, it's not really clear that's the case. If Exodus (or Vupen, or whomever) quit, it's not like suddenly the government would stop looking for exploits. And if the US government did, it's not like China or Russia would. And if they did, it's not like criminal organizations would stop. You aren't going to stop vulnerabilities from happening or being sold. Game theoretically, it seems like the right choice is to keep the US government snatching up what vulnerabilities it can to keep in its back pocket for espionage. Not doing so would be a huge blow to US intelligence agencies, when every other major government out there is working on the same capabilities.

    At this point some folks might say: but doesn't that mean we'd all just be safer if the government just released all the vulnerabilities they knew about to vendors to have them patched? then the Chinese/Russians/criminals wouldn't be able to break in! Sadly, that's not how security works. You can patch 100 vulnerabilities, but if you miss one, you'll still lose. Staying open about every vulnerability would almost certainly hurt foreign intelligence, true, but if the US government is sharing every vulnerability they know about, and $ENEMY isn't, then US intelligence is going to be at a disadvantage, hands down.

    So, when Exodus wants to invest time and money in finding exploits in your favorite application and turning a profit to help their government against Chinese/Russian/criminal agencies, that doesn't bother me.
    </rant>

  14. Curiosity by watcher-rv4 · · Score: 1

    All this gave me will to take a loot at Tails.

  15. Re:Somehow by Anonymous Coward · · Score: 0

    Sure, cold fjord. Not even trying to hide your shilling anymore?

  16. One...MIIIILLLLION Dollars! by Anonymous Coward · · Score: 0

    Dr. Evil strikes again.

  17. Re:Open sores software? No thanks! by Anonymous Coward · · Score: 0

    Wow... you shills comment on literally every post don't you? How much money do you guys make? Is this a legitimate work-at-home with full government benefits or do you worry sometimes that they won't cut you a check? I've had bad luck with these kinds of things. Let a brotha know!

    I think you know it already, as you happen to have an established shilling career for The Linux Foundation.

  18. It's FUD? by Cid+Highwind · · Score: 1

    Disclosing the existence of a vulnerability destroys a lot of its value, too. People who can stop using Tails until the issue is sorted out will do so, shutting off whatever intelligence could be gathered from them. If these guys had a real-world exploitable vulnerability and a willingness to sell it to the NSA, they would have sold it and said nothing.

    --
    0 1 - just my two bits
    1. Re:It's FUD? by Anonymous Coward · · Score: 0

      this was exactly my two points

    2. Re:It's FUD? by Anonymous Coward · · Score: 0

      what if the bug isn't in tails/tor, but i2p ?
      misinformation win.

  19. They have nothing! by xednieht · · Score: 0

    Exodus Intelligence - a euphemism for cock-sucking maggots. It's just FUD. Their techs are second rate hacks who couldn't make it in the ether and decided to get day jobs and pay taxes instead.

    --

    Hope is the currency of fools
    1. Re:They have nothing! by gweihir · · Score: 1

      There are some things you can do even when second-rate, just by throwing resources at the problem. They may also have _bought_ these exploits form people that are not second-rate.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  20. Info arbitrage for fun and profit by Anonymous Coward · · Score: 0

    Wonder if Exodus' directors have considered what the civil or criminal liabilities could be for knowingly witholding information that could have prevented deaths, torture, catastrophic damages, data loss or theft, etc., just for a few bucks. Wonder also if their customers couldn't be liable or complicit as well. Would RICO apply here, I wonder? Patriot Act? Could not advertising such knowledge be considered a form of terrorism? Reverse blackmail?

    If not, then why is there such a double standard vis-a-vis "white hats" and cops who constantly have to shit on hackers in order to shine their Eagle Scout good-guy badges, when anyone with any knowledge knows they're as dirty as anyone else. If not more so.

    Whatever. Anyway, I hear some room's been freed up at Gitmo...

    1. Re:Info arbitrage for fun and profit by Anonymous Coward · · Score: 0

      Not just hackers, either. Simply being an honest, uncompromising reporter or whistleblower will do. Course, there are less and less of them, and most have been harassed and chokepointed into "mere" uncredentialed bloggers of dubious repute.

      P.S. for all you honest cops and businessmen out there, didn't mean to tar you with that brush. You know who we're talking about here. If, and I say this advisedly, you don't have your head up your ass, like some misguided, brainwashed, bamboozled Dudley Do-Rights I know.

  21. Zero Days? Updates? by cant_get_a_good_nick · · Score: 1

    Not a troll, but how do you get updates on a LiveCD? a good safe distro would not only update bad code easily, but also prevent whatever malware gets in from writing to local disc. What to do?

    1. Re:Zero Days? Updates? by Anonymous Coward · · Score: 0

      you download the new version and burn it, dude.

    2. Re:Zero Days? Updates? by mspohr · · Score: 1

      We're talking about a USB stick.
      I just updated my TAILS USB... password, trusted repository, good to go.
      If you want, you can use a Live CD but then you can't have any encrypted local storage.

      --
      I don't read your sig. Why are you reading mine?
    3. Re:Zero Days? Updates? by cant_get_a_good_nick · · Score: 1

      My point is - part of the security of a LiveCD is the fact it's a Read Only medium. Malware can't write to it.. But it also means you can't update buggy code. What if my LiveCD has Heartbleed?

      The AC who commented "burn a new one" doesn't know how most distros do things, which is not to create a new CD image every time a package changes. The CD image is current on Day 1, and deviates from the true distro starting possibly on Day 2. Unless you only use the CD Image on release days, you'll always be slightly behind on (at least some) packages.

      Yes yes, i know part of the point of a USB stick is a controlled Distro where you know the current state of all things on it. But, it still has issues with Zero Days. Lets say there's a Zero day, and I write to your USB stick. Now you're compromised, with a false sense of security. Do people drop to "single user with networking" on their USB sticks, do updates, then run in multi-user with parts of the file system read-only?

  22. OT: signature by cant_get_a_good_nick · · Score: 1

    Im stealing your signature...

  23. Re: Open sores software? No thanks! by Anonymous Coward · · Score: 0

    Yes, but open source (volunteer) shilling doesn't pay so good.

  24. How do you think they get your IP? by Anonymous Coward · · Score: 0

    I suppose if they can execute remote code, they can find the BIOS, MB, and hardware Mac address, but if you never use your hardware Mac address and never not use Tor, then it's not correlatable. They can ping a server that will give away your ip, but what if your router is routing through Tor and your computer does not have access to it? I figured it was hackable, although I thought it was likely a browser issue because, being in a life-long weird ass CIA experiment, everything I use gets hacked into, like a sort of game, and it's usually noticeable, although they may make it noticeable on purpose, but I'm wondering if there are precautions that can be taken, like the aforementioned set the router to route through tor so no IP can be deduced and don't give your computer access to the router and the one that does have access should be kept offline, plus the router should not allow configuration access from the computer being used, in addition, I think the entry point to Tor should be a trusted entry point, as if you're connected to one of their relays or a hacked relay, then they can correlate data patterns with your IP. The problem is largely a long-held IP system.

    1. Re:How do you think they get your IP? by gweihir · · Score: 1

      They just send data to some server they own in clear and they know your last public IP. For spywork, that is enough. If laws are draconian enough, they are also sure to find _something_ when they kick down your door. Also, when you are not on US ground (warning: current state, this may change), they may also just drone-murder you and bypass any legality whatsoever.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  25. Earlier Submission by Anonymous Coward · · Score: 0

    "We're happy to see that TAILS 1.1 is being released tomorrow. Our multiple RCE/de-anonymization zero-days are still effective."

    via @ExodusIntel: https://twitter.com/ExodusInte...

    #$%#

    "Exploit Dealer: Snowden's Favourite OS TAILS Has Zero-Day Vulnerabilities Lurking Inside"

    Thomas Brewster | Security | 7/21/2014 @ 2:14PM

    http://www.forbes.com/sites/th...

    #$%#

    "The flaws work on the latest version of TAILS and allow for the ability to exploit a targeted user, both for de-anonymisation and remote code execution," said Loc Nguyen a researcher at Exodus. Remote code execution means a hacker can do almost anything they want to the victimâ(TM)s system, such as installing malware or siphoning off files.

    "Considering that the purpose of TAILS is to provide a secure non-attributable platform for communications, users are verifiably at-risk due to these flaws. For the TAILS platform, privacy is contingent on maintaining anonymity and ensuring their actions and communications are not attributable. Thus, any violation of those foundational pillars should be considering highly critical," added Nguyen. This affects every user of TAILS, who should all "diversify security platforms so as not to put all your eggs in one basket", he added.

    All users, including Snowden, should be wary of using TAILS with a false sense of security, though itâ(TM)s still more likely to protect anonymity than Windows. Exodus sells to private and public businesses hoping to use the findings for either offensive or defensive means. Those unconcerned about governments targeting their systems might not be concerned about the TAILS zero-days. Others will likely be anxious one of their trusted tools to avoid government hackers contains vulnerabilities that could be exploited to spy on any user of the OS."

    #$%#

    Don't look, Snowden: Security biz chases TAILS with zero-day flaws alert
    Exodus vows not to sell secrets of whistleblower's favorite OS

    By Iain Thomson | 21 Jul 2014

    http://www.theregister.co.uk/2...

    #$%#

    RE: TAILS: https://tails.boum.org/

  26. Re:Open sores software? No thanks! by Anonymous Coward · · Score: 0

    what your co-conspiritors at your favorite slaveware peddling company didn't use openssl? If companies donated just 10% of what they shell out for slaveware the open source projects they use would be way better than anything else available (even though lots already are, despite the selfish users). These dumb bastards think they are comparing two "products" so it's ok to criticize. One is a deceptive product aimed at stealing your kids' future and one is a contribution to humanity. You don't get to criticize b/c you're part of the problem. I think deep down you already know this is true, but you're too much of a liar to admit it.

  27. "Details"? by Anonymous Coward · · Score: 0

    That word must have undergone some rapid semantic shift. They're spreading unspecific rumours to discredit Tails.

  28. They're everywhere! by viperidaenz · · Score: 1

    It's an NSA backdoor!

  29. Re:Somehow, downvote by Anonymous Coward · · Score: 0

    ^-- downvote this misinformation.

  30. what crap by Anonymous Coward · · Score: 0

    man, the website of exodus unintelligence gives a blow by blow timeline some retarded jocks aaron and paul and zef? telling of all their awesome geeky fudge packing. Is this really an intelligence business? fuckin' facebook fartburgers, give me a break. More importantly hand over the details of the exploit and stop being bitches.

  31. Re:Open sores software? No thanks! by Anonymous Coward · · Score: 0

    Nope, we don't use unmaintained, unaudited, open sores garbage.

  32. As Easy to See Through as Glass by TechForensics · · Score: 1

    Hmmmm.... Let's see... Snowden embarrasses NSA using Tails; suddenly tails has scary "vulnerabilities"; a new company / entity on the scene says it will make everything nice.

    What's the likely truth here? Snowden embarrassed NSA using Tails; NSA plants disinformation campaign to the exent of "vulnerabilities"; the new company / entity is an NSA puppet that will give you a new Tails every bit as reliable as the new TrueCrypt.

    First grade simple so it's not suspected until..... (complete the sentence).

    What do YOU think?

    --
    Those are my principles, and if you don't like them... well, I have others.
  33. Headline is utter crap. by Anonymous Coward · · Score: 0

    Exodus Intelligence Details Zero-Day Vulnerabilities In Tails OS.

    No it fucking doesn't, Timothy, you illiterate moron. Detail them is exactly what Exodus have not done. They have done nothing except assert their existence, sans proof or evidence.

  34. Well. by Demena · · Score: 1

    Snowden gave nothing to Russia or China. Even the head of the NSA has stated that. He gave nothing to any national party. It makes me wonder what you are. But I doubt you will ever be a little star.

  35. Re:Open sores software? No thanks! by Anonymous Coward · · Score: 0

    If you don't want open sores, don't bang AC's mom without a raincoat.

  36. Re:Open sores software? No thanks! by cbiltcliffe · · Score: 1

    Nope, we don't use unmaintained, unaudited, open sores garbage.

    So I guess that means you use unauditable, backdoored, closed source garbage then, huh?

    --
    "City hall" in German is "Rathaus" Kinda explains a few things......