Slashdot Mirror


The FBI Is Infecting Tor Users With Malware With Drive-By Downloads

Advocatus Diaboli (1627651) writes For the last two years, the FBI has been quietly experimenting with drive-by hacks as a solution to one of law enforcement's knottiest Internet problems: how to identify and prosecute users of criminal websites hiding behind the powerful Tor anonymity system. The approach has borne fruit—over a dozen alleged users of Tor-based child porn sites are now headed for trial as a result. But it's also engendering controversy, with charges that the Justice Department has glossed over the bulk-hacking technique when describing it to judges, while concealing its use from defendants.

182 comments

  1. Re: LOL by Anonymous Coward · · Score: 0

    And the proprietary-tards are stupid enough to think software os supposed to be idiot-proof

  2. Re: LOL by Anonymous Coward · · Score: 0

    Edit : is* supposed

  3. This doesn't seem legit by Anonymous Coward · · Score: 1

    What ever happened to not breaking the law to collect evidence?

    1. Re:This doesn't seem legit by Austerity+Empowers · · Score: 4, Insightful

      The same thing as what happened to unicorns and leprechauns.

    2. Re:This doesn't seem legit by Anonymous Coward · · Score: 2

      Government is above the law. You do as they say, not as they do.
      Unless you're one of the elite, you're not allowed to participate in computer fraud, destruction of property, and accessing an electronic device with malicious intent.

    3. Re:This doesn't seem legit by Anonymous Coward · · Score: 0

      How are they breaking the law? Care to cite the statute?

    4. Re:This doesn't seem legit by postbigbang · · Score: 1

      Hey- Google does this, and legally, and gets child porn emails!

      The ends always justify the means. That's what the world has come to.

      Sadly.

      Rule of law? Holders of the gold filigreed rulers get the law, it would seem.

      --
      ---- Teach Peace. It's Cheaper Than War.
    5. Re:This doesn't seem legit by Lazere · · Score: 2

      That would be the CFAA and the Fourth Amendment (but who gives a shit about the Fourth anyway?)

    6. Re:This doesn't seem legit by Anonymous Coward · · Score: 0

      The CFAA doesn't apply to the FBI.

    7. Re:This doesn't seem legit by Opportunist · · Score: 1

      Nice distraction by omission, but how about the 4th?

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    8. Re: This doesn't seem legit by bill_mcgonigle · · Score: 1

      Have you not been paying attention? It clearly doesn't bind the FBI, NSA, or CIA. In maybe one in a thousand cases you might catch them and you might get redress, but 999/1000 is the reality.

      --
      My God, it's Full of Source!
      OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    9. Re:This doesn't seem legit by WillAffleckUW · · Score: 1

      What ever happened to not breaking the law to collect evidence?

      Oh please. Only the rich and powerful have rights in East German America.

      --
      -- Tigger warning: This post may contain tiggers! --
    10. Re:This doesn't seem legit by Anonymous Coward · · Score: 0

      The same thing as what happened to unicorns and leprechauns.

      Ah, so they get ground up and used as the rainbow sprinkle sweetener on my breakfast cereal? Awesome!

    11. Re: This doesn't seem legit by slick7 · · Score: 1

      May the fourth be with you.

      --
      The mind conceives, the body achieves, the spirit manifests.
    12. Re:This doesn't seem legit by Sir+Foxx · · Score: 1

      Okay I understand what your saying but can you tell me what the ratio of Unicorns to Leprechauns are to ShruteBucks to StanleyNickels?

      --
      "I don't which is worse, that everyone has a price, or that the price is always so low"--Hobbes
    13. Re:This doesn't seem legit by omnichad · · Score: 1

      They should have had a warrant before infecting them. But a drive-by download can hit anyone, so it's almost certainly breaking 4th Amendment protection.

    14. Re:This doesn't seem legit by Anonymous Coward · · Score: 0

      In all fairness, do you think the undercover cop trying to get on the good side of the mob isnt going to break a few fingers to gain some trust?

      And really, they're taking down people who view/distribute Child porn, so its a good thing. Yes this does mean that they could potentially do it elsewhere too, but you could always just not buy your drugs online from now on.

      Or...Sandbox your tor client

    15. Re:This doesn't seem legit by Anonymous Coward · · Score: 0

      Oh. So they latched onto the excuse of going after "bad people," so it is OK for the government to break the laws. Makes perfect sense, really. I mean, it worked out so well for this terrorism thing we've been hearing about for this last decade. Never once has the government abused that!

  4. Re: obvious M$-fan troll by Anonymous Coward · · Score: 0

    Yeah, trust blackboxes made by Orwellian companies, where mediocrity is the norm, instead...

  5. Hide behind todays popular hate-topic... by MindPrison · · Score: 5, Informative

    ...and that's how and WHY they get away with this. This is against any human rights, but shout "won't anyone PLEASE think of the Children", and these agencies can get away with murder.

    So that said, to any whistleblower out there who doesn't have the tech savvy that we have, I'd offer a little bit of advice, read it - and don't forget it, you might just be next if you do:

    1) Download Tails. Install it preferably on a CD.
    2) Remove your hard disk connection (removing the power is enough) when you intend to boot from Tails.
    3) Shut down your WiFi. And only use WIRED connections.
    4) Boot tails, and when you start Iceweasel - make sure to turn NoScript ON for ALL sites. It's not on by default, when the SHIELD shows...it's on!
    5) Never - ever use an acronym you'd use with your normal ISP (IP address), this WILL unmask you.
    6) Do NOT use FLASH or JAVASCRIPT.
    7) Do NOT do any banking business or anything that would identify the real you using TOR. Tor is like walking into an underworld of the worst place you could imagine in a bad movie (except Darknet is very real, and can be a VERY dark place, it has freedom...but freedom is precious there, and there's someone waiting on every corner to con you, and remember - this threat is VERY REAL!), so don't be a fool. Do what you have to, but stay safe.
    8) Do NOT brag to friends that you're safe with Tor. As far as you know, you don't even know what Tor is.
    9) If you can, use Tor with a laptop that has never been used on a wired or wireless KNOWN network with you, but only used for TOR ...without a harddisk! Use it to connect with TOR on a different network, preferably in a different city than where you live. You can't get much safer than that....IF...you apply the other 8 rules above.
    10) Don't SURF TOO LONG AT ONCE - People are working to unmask TOR users all the time with Injection attacts, and they succeed often! Notice that when the chain of relays break (refreshes)...always keep looking at the NETWORK MAP...ALWAYS, DISCONNECT LIKE THE WIND and find another time to connect short sessions. Keep things brief, and as many clusters as you can.
    11) Always make sure that the TAILS CHECKSUM IS MATCHING! I've downloaded TAILS TWICE from their so called official server and had CHECKSUM MISMATCH, this could be as simple as a faulty packet...but it could also be much more serious than that, imagine the rest yourself - BE PARANOID! It's your life!

    Information is the only power we have left!

    --
    What this world is coming to - is for you and me to decide.
    1. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      > this could be as simple as a faulty packet..

      Unlikely given that TCP is fully check-summed and if you used SSL then its even less likely given that a single flipped bit would have triggered a problem with the decryption as well.

    2. Re:Hide behind todays popular hate-topic... by MindPrison · · Score: 1

      > this could be as simple as a faulty packet..

      Unlikely given that TCP is fully check-summed and if you used SSL then its even less likely given that a single flipped bit would have triggered a problem with the decryption as well.

      Even a check-sum can be wrong, albeit not very likely. Give the following scenario a thought. The number 255 becomes 200 at address $0002. At Address $0004 the number contained is 00 but becomes 55, the check-sum total will still be the same (unless I missed something, which is possible...I don't know everything).

      --
      What this world is coming to - is for you and me to decide.
    3. Re:Hide behind todays popular hate-topic... by sconeu · · Score: 1

      Download checksum are usually one or more of MD5SUM, SHA1SUM and SHA256SUM.

      A simple transposition of bytes will not generate identical hashes.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    4. Re:Hide behind todays popular hate-topic... by anthroboy · · Score: 5, Funny

      5) Never - ever use an acronym you'd use with your normal ISP (IP address), this WILL unmask you.

      ASAP, scuba, laser, Nabisco, Esso, ISP, HTTP, USB, PDF, CYA... Who knew acronyms were so dangerous?

    5. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      TCP only uses checksums on the headers. It's doubtful he was using SSL to download Tails, but if he were, the data could've been corrupted before the SSL encapsulation.

      But what is he doing that's so secret he needs a separate laptop? I smell trolling, or mental health issues.

    6. Re:Hide behind todays popular hate-topic... by CreatureComfort · · Score: 1

      9) If you can, use Tor with a laptop that has never been used on a wired or wireless KNOWN network with you, but only used for TOR ...without a harddisk! Use it to connect with TOR on a different network, preferably in a different city than where you live. You can't get much safer than that....IF...you apply the other 8 rules above.

      While this sounds ludicrous on its face, (Really? Driving to different cities just to surf anonymously?), I would have suggested connecting via a VPN, or chained VPNs depending on your paranoia and tolerance for network delay. If every time you connect you set your opposite end point to a different country each time. Especially if reconnecting frequently as noted in 10).

      12) If you have to go through this much trouble to function on the Internet, seriously reconsider your life and lifestyle. Is it really worth it?

      --
      "Unheard of means only it's undreamed of yet,
      Impossible means not yet done." ~~ Julia Ecklar
    7. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      TCP checksum is indeed trivial to foil

    8. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 1

      I suppose the topic was TCP checksums, not download checksums. Download checksums placed on pages served over http could probably be compromised with just 's/original checksum/infected checksum/' or equivalent, in a MITM scenario.

    9. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      ...and that's how and WHY they get away with this. This is against any human rights, but shout "won't anyone PLEASE think of the Children", and these agencies can get away with murder.

      Except this time actual pedophiles were caught, their sites brought down and houses searched.

      There isn't some big system that is supposed to "save the children" that actually doesn't help the children at all. There still are child porn blocking filters in Europe, that just "block bad material" and AFAIK don't actually incriminate anyone, just block.

    10. Re:Hide behind todays popular hate-topic... by godel_56 · · Score: 1

      ...and that's how and WHY they get away with this. This is against any human rights, but shout "won't anyone PLEASE think of the Children", and these agencies can get away with murder.

      So that said, to any whistleblower out there who doesn't have the tech savvy that we have, I'd offer a little bit of advice, read it - and don't forget it, you might just be next if you do:

      1) Download Tails. Install it preferably on a CD.
      2) Remove your hard disk connection (removing the power is enough) when you intend to boot from Tails.
      3) Shut down your WiFi. And only use WIRED connections.
      4) Boot tails, and when you start Iceweasel - make sure to turn NoScript ON for ALL sites. It's not on by default, when the SHIELD shows...it's on!

      Stuff deleted

      If you really need to be anonymous, use a computer that you bought for cash, that is ONLY used for communicating over Tor with Tails, preferably using somebody else's Wi-Fi. Even if the Feds do manage to plant a beacon on this computer, it will only show up when you are communicating anonymously. Your secure computer should be air gapped from your main work/internet computer.

    11. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      "Install it preferably on a CD."
      But if I do that, how do I keep TOR up to date? Can it download the latest and keep it in the RAM for the time of run? Or should I write a new CD after every release?

    12. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 1

      Let's turn that last question on its head.

      What, exactly, does my lifestyle have to do with wanting to be able to anonymously browse the internet? The short answer is absolutely nothing. I shouldn't have to fear being spied upon, and let's be honest here this is spying in every sense of that word, because I choose to try to be anonymous. Being anonymous isn't a flag of anything, anywhere, anytime. We keep trying to make boogeymen out of anonymity when in fact, the biggest monsters we've seen in all-too-human context have always been right in front of us. You can name them, you can even see how their rise to power has been charted by the news of the day.

      So your #12 there does not have one iota of reason to it. And yes, it is worth it.

    13. Re:Hide behind todays popular hate-topic... by Jane+Q.+Public · · Score: 2

      Your item 12 is the whole point here. In a free country you should not have to go through all these steps just to keep your communications private. You don't have to be a criminal in order to have legitimate reasons for private conversations and business deals.

    14. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      He may have meant "pseudonym"

    15. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      Just buy a hard drive with a physical write protect lock.

    16. Re:Hide behind todays popular hate-topic... by jeIIomizer · · Score: 1

      Except this time actual pedophiles were caught, their sites brought down and houses searched.

      The ends justify the means, huh? One of you people always pop out. I'd rather have freedom and privacy than your 'safety.'

      There isn't some big system that is supposed to "save the children" that actually doesn't help the children at all.

      Yes, there is. Going after people who look at porn is just a waste of time and saves no one.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    17. Re:Hide behind todays popular hate-topic... by triclipse · · Score: 1

      Be that as it may, we will never have a free country again. Ever. So I thank those of you who can educate us on how to keep our communications private for legitimate reasons.

      --
      No Inflation Taxation without Representation
    18. Re:Hide behind todays popular hate-topic... by lister+king+of+smeg · · Score: 1

      I would also change my mac address regularly just to make it harder to track your physical location You could always just use a random mac or if you want to be a real pain in the ass you could start mac cloning and find other people mac and copy them so when you go browse porn ^H^H^H^H the darkwebs it looks like the hipster with his macbook pro that just finished his mocha and left the coffee shop you happen to be sitting in.

      --
      ---Saying gnome 3 is better than windows 8 not so much a compliment as it is damning with light praise.
    19. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      Oh, Cmon...

      Plenty of pedophiles were killed when we carpet bombed Dresden in WWII...

      it was for a good cause!

    20. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      8) Do NOT brag to friends that you're safe with Tor. As far as you know, you don't even know what Tor is. you seem to be breaking this rule

    21. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      You are thinking about IPv4, the IP checksum is only for the header to ensure delivery to the correct address. The payload protocol could be tolerant against errors or have error correction.
      The TCP checksum covers the payload and throws away the packet on incorrect checksum to trigger a retransmission.

    22. Re: Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      Information is not power. Power is power.

    23. Re:Hide behind todays popular hate-topic... by f3rret · · Score: 1

      5) Never - ever use an acronym you'd use with your normal ISP (IP address), this WILL unmask you.

      ASAP, scuba, laser, Nabisco, Esso, ISP, HTTP, USB, PDF, CYA... Who knew acronyms were so dangerous?

      Most of those are initialisms though.

      --
      Admit nothing. Deny Everything. Make Counter-accusations.
    24. Re:Hide behind todays popular hate-topic... by Sigma+7 · · Score: 1

      Download checksum are usually one or more of MD5SUM, SHA1SUM and SHA256SUM.

      A simple transposition of bytes will not generate identical hashes.

      From RFC793:

      The checksum field is the 16 bit one's complement of the one's complement sum of all 16 bit words in the header and text. If a segment contains an odd number of header and text octets to be checksummed, the last octet is padded on the right with zeros to form a 16 bit word for checksum purposes. The pad is not transmitted as part of the segment. While computing the checksum, the checksum field itself is replaced with zeros.

      The extremely weak checksum of the TCP header (or even IP header) will not detect byte transposition.

      And no amount of checksumming will stop drive-by-downloads from browsers that still don't understand basic security. (Really, Javascript permissions should have been introduced in Netscape 2.0.)

    25. Re:Hide behind todays popular hate-topic... by anthroboy · · Score: 1

      If one can't be bothered to observe a distinction between pseudonym and acronym then one can hardly complain about the distinction between acronym and initialism.

    26. Re:Hide behind todays popular hate-topic... by sconeu · · Score: 1

      Ah, I misunderstood. I thought you were referring to published file checksums, not TCP/IP checksumming.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    27. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      I work in the field of Web analytics, so I see this type of functionality at play every day. The acronym statement is absolutely correct. Patterns in a person's phrasing and vocabulary can be easily identified, given even a modest amount of content, so as to support seemingly magical inferences about a person's identity. With a properly designed ontology -- and the big models have had over a decade to mature -- none of this is hard to do. That's one reason why this message is salted (that is, why I'm using a prose style lifted from another poster below).

      I also want to add one other rule to MindPrison's outstanding list above. NEVER NEVER NEVER post on a cesspool like Slashdot except as an AC. Posters who use the same nick more than a few times might as well be signing each posting with a photo of that mole on their penis. Making the issue an order of magnitude worse is Slashdot's inexplicably fucked up policy of not allowing users to change nicks. Consequently, despite the often-interesting subject matter, this is one site at which I almost never post.

    28. Re:Hide behind todays popular hate-topic... by sconeu · · Score: 1

      That's why most sites also PGP sign their checksums.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    29. Re:Hide behind todays popular hate-topic... by Anonymous Coward · · Score: 0

      The above post can be taken SERIOUSLY because some words are in CAPS. Also: BEWARE acronyms or they WILL be your undoing.

  6. Fuck the children by Anonymous Coward · · Score: 0

    - George Carlin

    1. Re:Fuck the children by Anonymous Coward · · Score: 0

      That's what the Feds are trying to keep from happening. A noble goal, although it's being implemented in a misguided and probably illegal manner.

  7. Re:Shit software by armanox · · Score: 2

    Never trust open sores software written by amateurs.

    You have a few too many words in there.

    Never trust software.

    --
    I'm starting to think GNU is the problem with "GNU/Linux" these days.
  8. Re: LOL by Anonymous Coward · · Score: 0

    well it is if you're talking about M$ windoze, but not any of the *nix variants. any problem with windoze is M$' fault. any problem with *nix is the users fault.

  9. the CP sites is one thing, Freedom Hosting another by raymorris · · Score: 1

    From the article, it sounds like we know they used it to identify computers browsing child porn sites. They had warrants. Okay, I'm not too upset about that. MAYBE they also did it to all sites hosted by Freedom Hosting. THAT would be a problem.

  10. Re: LOL by meerling · · Score: 4, Insightful

    How the hell do you turn a discussion over the FBI compromising TOR into a fucking offtopic Apple/MS pissing contest?!
    And "slashdot" is not a valid answer.

  11. Malware? by Anonymous Coward · · Score: 0

    So these people are so concerned about online privacy that they use Tor...on a proprietary OS!
    Facepalm.

  12. Re: obvious M$-fan troll by meerling · · Score: 2

    More to the point, never trust the FBI.

  13. Fourth Amendment? by Anonymous Coward · · Score: 1

    In the article, they mention that one of the drive by malware installations by the FBI hit the servers of a webmail service called Tormail in the process of going after a site that was believed to be hosting child porn. Presumably, they used the malware to search PCs, including those of Tormail users who had committed no crime. Wouldn't this be a massive violation of the fourth amendment?

    1. Re:Fourth Amendment? by Anonymous Coward · · Score: 0

      In the article, they mention that one of the drive by malware installations by the FBI hit the servers of a webmail service called Tormail in the process of going after a site that was believed to be hosting child porn

      Ooopsie!

      - NSA

      Personally, I'm convinced that tormail was the real target, the pedos were just the icing on the cake that would justify the whole thing to the court of public opinion.

  14. The problem here isn't the FBI. by BitterOak · · Score: 4, Insightful

    I know this won't be a popular position here, but the problem here isn't with what the FBI is doing, but rather the fact that they can do it. The problem is with the technology: it just isn't as secure as it's supposed to be. When a hacker finds a vulnerability in a security system, most people on Slashdot say don't blame the hacker, but rather fix the underlying vulnerabilities in the system. Instead of pointing the finger at the FBI for using vulnerabilities in TOR, web browsers, and/or operating systems, we should be glad that they're making this public, so the vulnerabilities can be fixed. After all, if the FBI can do this, so can criminals, governments hostile to free speech, and many other malicious parties. Let's learn from what the FBI is doing and harden the systems, to make legitimate users of Tor and similar services safer.

    --
    If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    1. Re:The problem here isn't the FBI. by Anonymous Coward · · Score: 4, Informative

      > we should be glad that they're making this public

      That's the problem, they are working as hard as possible to prevent the information from becoming public.

      While this is the FBI we are talking about here, I would be sooooo onboard with the NSA if they amended their charter to simply shoring up vulnerabilities rather than exploiting them for their own opaque purposes.

    2. Re:The problem here isn't the FBI. by Anonymous Coward · · Score: 0

      ... the problem here isn't with what the FBI is doing, but rather the fact that they can do it.

      Well, it is a problem if what they're doing is in violation of the 4th amendment, because then an organization that is supposed to help safeguard our rights is violating them. That's the theme of this article - should the FBI be allowed to do this? Not whether it's surprising they can.

      (AC to preserve mods)

    3. Re:The problem here isn't the FBI. by jeIIomizer · · Score: 1

      but the problem here isn't with what the FBI is doing, but rather the fact that they can do it.

      The problem is both.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    4. Re:The problem here isn't the FBI. by Anonymous Coward · · Score: 0

      authoritarian shill much ? ? ?
      the problem isn't the feebs illegally entered my house and violated my rights, but that the lock on my door was laughably simple to pick...
      *ahem* if logic is your friend, you *should* be VERY embarrassed now...

    5. Re:The problem here isn't the FBI. by Anonymous Coward · · Score: 0

      Really, really true. This is not qualitatively different than J. Edgar exploiting current technology of his day to create the national fingerprint registry.

      I'm a great believer in the power of technology to alter fundamental elements of our culture. I have to laugh when Rush Limbo whines about how Liberals have destroyed the nuclear family. I want to call him and say, "No, dumbfuck, it was the automobile, the telephone, the personal computer, and the Internet. And also you, as a disturbingly influential gee-whiz on-the-air proponent of every new Macintosh and iPad product that Apple released over the last two decades." Back in Downton Abbey days, Rush would surely have been an early adopter of the horseless carriage.

    6. Re:The problem here isn't the FBI. by Anonymous Coward · · Score: 0

      "[I]f the FBI can do this, so can ... governments hostile to free speech ...."

      Why the redundancy?

  15. Re:LOL by MindPrison · · Score: 5, Informative

    But the freetards tell us that Tor is so secure!! Open sores fails again.

    It's not TOR itself, sure...Tor isn't perfect, but today you really don't have many other options. In fact...I can't think of a single one. But it's the users that fails to understand that TOR really isn't the solution to all their anonymity wishes. I'd say 90% safety is up to the users themselves, I've written a little list a few posts below (look it up if you care), it's mostly about common sense. You don't walk into a dark alley with an open wallet telling everyone that you won big on the casino tonight, right? Same thing applies to Tor usage, don't reveal your name, use no-script religiously, don't use flash or any other app/software that can see your IP locally and forward it anywhere. Don't use your real name. Don't even use your nickname (unless it's anonymous coward of course), because everything that ties you as a user to a user on TOR...is bad for you.

    Tor is actually pretty damn good, why do you think it's such a pain in the ass for the feds? Heck...it's even KNOWN to be a giant wart on NSA's butts simply because it's so good at WHAT it does. But it's not 100%, you need to apply common sense to the rest, and learn of it's flaws and the things TOR can not do for you. If you do...there really is no better alternative to freedom of speech out there.

    --
    What this world is coming to - is for you and me to decide.
  16. Simply put... by Anonymous Coward · · Score: 0

    We are one slippery slide away from specifically targeting all users of TOR regardless of what services and sites they use.

    At least this was a targeted attack against people actually breaking a law. Not as bad as the general fishing that the article explains. Still it is scary to think that thought crimes are being so focus'd on when we have more pressing issues as a society to deal with.

    1. Re:Simply put... by Opportunist · · Score: 1

      If "breaking the law" matters in that case, I think we should not run those TOR exit nodes for people trying to circumvent the filters of their country...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  17. the CP sites is one thing, Freedom Hosting another by Anonymous Coward · · Score: 0

    They also did it to all sites hosted by Freedom Hosting THAT would is a problem.
    FTFY

  18. Re:Shit software by king+neckbeard · · Score: 1

    As do you.
    Never trust.

    --
    This is my signature. There are many like it, but this one is mine.
  19. Smart by TheCarp · · Score: 4, Insightful

    I hate to say it, but this is pretty smart. They seem to have realized that using their new techniques against child porn is the best way forward for them because the issue has stigma to spare that can help quell dissent, then, once the practice is firmly established, they can quietly expand it to everything else they desire.

    --
    "I opened my eyes, and everything went dark again"
    1. Re:Smart by Opportunist · · Score: 1

      It would be smart if it was a new idea. But in fact it's just a rather old practice, just that it's "on the internet" this time.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Smart by mrchaotica · · Score: 2

      Quick! Somebody patent it and force them to stop!

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    3. Re:Smart by AHuxley · · Score: 1

      It seems what was tracked in the past has now moved to a drift net system.
      From 2007 "....a tracking system capable of pinpointing specific workstations that searched for and downloaded....."
      http://www.zdnet.com/blog/secu...

      --
      Domestic spying is now "Benign Information Gathering"
    4. Re:Smart by Innominandum · · Score: 2

      They've been passing laws in Canada using this technique for at least a decade. More recently there was the 'With us or with the child pornographers' comment by Vic Toews which pretty much ended his career. People are getting a bit more savvy to this type of bullshit.

    5. Re:Smart by Anonymous Coward · · Score: 0

      lol Hackers have been doing this for a very long time, but this is nothing new or smart a script kiddie could do it. The fact that it is so easy is the reason I block all ads on all my devices. I don't have a problem with ignoring ads until I was hit by a zero day exploit on a perfectly legit search engine. "you know who" I learned from my mistake to allow ads and I've not been infected by a zero day in years. No container>no data to load>no virus, but it's still possible to be hit if a website is hijacked.

      The real problem is the FBI should be working to help fix these vulnerabilities, if they know about them it's extremely likely hackers do as well. Honestly it would not surprise me if they acquired them from underground hacker markets. Thinking about that possibility and just how likely it is pisses me off even more...

    6. Re:Smart by TheCarp · · Score: 1

      > lol Hackers have been doing this for a very long time, but this is nothing new or smart a script kiddie could do it

      Sure but it isn't so much about the technology being used as that they are now using it and legitimizing their use of it by targeting a group that is so reviled as to taint any discussion of how they were targeted.

      --
      "I opened my eyes, and everything went dark again"
  20. Re:LOL by Opportunist · · Score: 1

    Mmm... predictable, a hint too many words aimed at offending... 2/10 on the troll scale. Tops.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  21. Looks like a fairly simple hack they did. by jcochran · · Score: 3, Interesting

    In a nutshell, they simply had any computer that contacted the web site send back the computer's real IP address and its MAC address. The actual security of the Tor wasn't affected. Just that compromising information was sent through the Tor network. Just as any other data would be sent through the Tor network.

    Now I suspect the MAC address was sent so that they could identify the actual computer when they seized it via a warrant. That way the suspect couldn't claim that it wasn't their computer since the IP address was on the other side of a NAT and there were multiple computers using NAT. And the IP address was simply to make identifying the physical location easier.

    Which raises an interesting question....
    What if someone alters their MAC address and then enters the Tor network via a public wifi hotspot?
    The connection is encrypted so the fact that the hotspot is publicly accessible shouldn't be a problem.
    And when the computer is turned off, the MAC spoofing goes away so even if the computer is seized, they don't have a matching MAC address to prove it's the computer they hacked. And of course, since access was via an open hot spot, there's plenty of computers that could have been connected. Proving which one would be rather ... difficult ... without that MAC address.

    1. Re:Looks like a fairly simple hack they did. by BitterOak · · Score: 1

      In a nutshell, they simply had any computer that contacted the web site send back the computer's real IP address and its MAC address. The actual security of the Tor wasn't affected.

      Ummm, the whole purpose of Tor is to make it impossible for the web host to determine your real IP address, so if it is so easy to get the browser to send that information back to the server then they've COMPLETELY disabled the security of the Tor network, so I really don't understand your statement that the "security of Tor wasn't affected."

      --
      If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    2. Re:Looks like a fairly simple hack they did. by SuricouRaven · · Score: 1

      TOR just anonymises transport. What goes over that transport is not part of the TOR system, it's just blind bytes being carried by it. So the attack, targetting the browser at the endpoint, didn't actually involve TOR - it just circumvented the need to break TOR by attacking another component instead.

    3. Re:Looks like a fairly simple hack they did. by fisted · · Score: 1

      TOR doesn't operate at the MAC level, your MAC address doesn't make it past your gateway.
      So the only way to leak your MAC address is actually transmitting it as whatever kind of application layer payload, or if your TOR entry node happens to be right on your local network...

    4. Re:Looks like a fairly simple hack they did. by Bite+The+Pillow · · Score: 1

      They only need the MAC address to confirm it was your computer in the event you use something like TAILS and profess to not have done anything wrong.

      Meanwhile, they have an IP address, a subscriber to John Doe, a correlated subscriber provided by the ISP, a commercial location to surveil, a video showing your vehicle, a warrant, and a full car/house search. And if they don't find anything, they start taking apart furniture and walls looking for the stuff they are convinced you have.

      If you saved anything, MAC is irrelevant and you're just as screwed. If you saved nothing, but they found your TAILS disc, a jury is going to convict you without a VERY good lawyer.

      Police are not there to find truth - they are there to find someone to arrest. The judge is not there to find truth - they are there to decide if applicable law finds you guilty.

      Your clever horseshit thought experiment is not going to save you when it matters. You have to avoid the same things that would get you into trouble if you ignored your MAC completely. And be assured that the judge and jury will not understand why everything but the MAC says you are guilty but you plead innocent. They will not go easy on you once the prosecution expert witness describes that MAC spoofing is "trivial".

      Were you expecting them to turn on the computer, see the MAC, decide that's clearly not the one they were looking for, then power it off without at least seeing what's in the CD tray?

    5. Re:Looks like a fairly simple hack they did. by gweihir · · Score: 1

      Tails routinely alters the computer's MAC address. At least the Freedom-Hosting malware was not able to detect that.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    6. Re:Looks like a fairly simple hack they did. by gweihir · · Score: 1

      When the Tor Browser Bundle runs on your system, it does not take over your system. It just establishes a canal over the Tor network, ordinary network access is still possible. So, what was affected is endpoint security, but not Tor security. The people not understanding Tor, that may sound the same, bit it is an important distinction. Security is not something you get if you do not understand the mechanisms used.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    7. Re:Looks like a fairly simple hack they did. by sjames · · Score: 1

      Because it's not Tor that failed, it was the browser that got exploited allowing an injected Windows program to bypass the Tor proxy.

    8. Re:Looks like a fairly simple hack they did. by linuxrocks123 · · Score: 1

      The way around this is Whonix. You can't be totally sure there are no zero-days in your web browser, so you browse in a VM that's only connected to the Internet through ANOTHER VM and THAT VM is running Tor. So, the VM the web browser is running in doesn't know your MAC address and doesn't know your IP and has no way to get it.

      Then, when you're done, you reset the entire VM to a known state ("snapshot") so that any virus they managed to installed can't stick around and probe for ways out of the VM jail.

      This isn't perfect. Nothing is. They could find a 0-day in the Tor project software, or they could find a way to break out of the VM after they compromised Firefox, but this is still REALLY good protection.

      And I have no problem with the FBI using malware to catch bad guys. Like others have said, the problem is (was?) with the Tor Browser, not with the FBI. They're just doing their job, and I applaud them for using all tools they have available.

      Now, they "blew their cover" with this tool by using it, so this particular vulnerability won't ever work again. I hope it was worth it.

      The endgame, of course, is going to be that the FBI doesn't have tools like this. Whonix, software like Whonix, and just plain better security practices in coding will make exploits like this rarer and rarer. Is that a good thing? I guess we'll see. If organized crime starts flourishing because of Internet anonymity, then I guess it's not a good thing. If not, it probably is. But, as long as law enforcement has a tool, it's their job to use it.

      --
      vi ~/.emacs # I'm probably going to Hell for this.
    9. Re:Looks like a fairly simple hack they did. by will_die · · Score: 0

      So what happens with those that change MAC address? I do that every few times a year with my wireless router, messes up some sites because for a few months sites that use MAC address for location through I was coming from Africa.

    10. Re:Looks like a fairly simple hack they did. by allo · · Score: 1

      You can change the MAC, so you cannot see the real one in your ethernet frames. But a software can read the real MAC from your NIC without any problem.

  22. Low standards by king+neckbeard · · Score: 2, Insightful

    They consider finding out about a dozen alleged USERS of child porn sites a big win?

    --
    This is my signature. There are many like it, but this one is mine.
    1. Re:Low standards by Anonymous Coward · · Score: 1

      Yes. More specifically, a big PR win.

    2. Re:Low standards by gweihir · · Score: 1

      Well, in comparison to the completely unimportant detail that they probably attacked millions of people with malware, sure these dozen users justify anything and everything!

      Seriously, they probably know what they are doing is deeply unethical, but it gets them more power, brings the surveillance and police state that they crave and the average person stops being rational when this type of material is mentioned. Most even think CP automatically means that children have been abused, completely ignoring drawings and pictures underage teenagers made of themselves.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  23. The FBI program sounds alot like this one at NSA by sasparillascott · · Score: 4, Interesting

    I wouldn't be surprised a bit to learn they are related:

    https://firstlook.org/theinter...

    Snowden docs, exceptional description of the Turbine program that seeds malware to non-targeted individuals - goal by the NSA (then) was millions of infections.

    The logical extension of this is, in the end, to compromise all personal and business computer systems - so anything is available when needed.

  24. Re:Shit software by Anonymous Coward · · Score: 0

    Wow. The NSA got here quick. They're on top of things today.

  25. Re:LOL by Zelucifer · · Score: 1

    What about I2P and Freenet. I haven't followed either in years, but AFAIK they're still around and used. Of course I believe both of them are darknet only.

    --
    The corner of a round room
  26. Re:LOL by Anonymous Coward · · Score: 0

    Got you to respond. Winning!

  27. Be a shame if drive by hacks of autopilot cars by WillAffleckUW · · Score: 2

    It would be a shame if hackers retaliated with drive by hacks of autopiloted cars using small RC vehicles mounting range extended telecom connectors.

    But, those who live by the unconstitutional spying on their own citizens deserve what blowback they get.

    If you don't have anything to hide, you don't understand what metadata is.

    --
    -- Tigger warning: This post may contain tiggers! --
  28. Re:LOL by Anonymous Coward · · Score: 0

    Modded you down. Loser!

  29. Re: Mostly harmless by Anonymous Coward · · Score: 0

    And you know this detailed information how?

  30. Re:Shit software by WillAffleckUW · · Score: 2

    Wow. The NSA got here quick. They're on top of things today.

    Probably has to do with them realizing there are two leakers in the NSA.

    I don't have the heart to tell them it's a Gang of Four.

    --
    -- Tigger warning: This post may contain tiggers! --
  31. Re:LOL by SumDog · · Score: 1

    There was a lot of stuff on the TOR mailing listing about how there were two Washington, DC nodes that couldn't be removed from your list of peers.

    Even if it's still somewhat anonymous, I wouldn't doubt the NSA has its hands in several of those exist nodes.

    Freenet serves a different purpose entirely, but it's also pretty good at what it does.

  32. Re:LOL by SuricouRaven · · Score: 5, Informative

    Freenet uses a very different model - it's basically a very elaborate distributed key-value store. It's good for dissemination and publication, but by design it can't be used for real-time communication - there's a delay of minutes to days for a message to become available to all nodes. It's all compromise: The same design that prevents real-time communication also makes Freenet a lot more resilient.

  33. Re:LOL by Anonymous Coward · · Score: 0

    All of the above, but use a burner laptop and a random open/hacked wifi access point for even better safety.

  34. Re: Mostly harmless by Anonymous Coward · · Score: 0

    Give me your gmail address and I'll email you a clue

  35. Re: obvious M$-fan troll by Anonymous Coward · · Score: 1

    More to the point, never trust the FBI.

    Yeah, because we know cyber criminals could do the same and already do hence the advice to NEVER run Java and Flash over Tor, and to even turn off Javascript.

  36. Re: LOL by Anonymous Coward · · Score: 1

    Talent?

  37. Re:the CP sites is one thing, Freedom Hosting anot by Carnildo · · Score: 2

    They did it to all sites hosted by Freedom Hosting. Most notably, they did it to Tormail -- not a kiddie porn site, a webmail provider.

    --
    "They redundantly repeated themselves over and over again incessantly without end ad infinitum" -- ibid.
  38. Re:LOL by BitZtream · · Score: 1

    Right, because they put data centers to handle Tor traffic ... in DC ...

    Instead of somewhere that doesn't cost some ridiculous sum of money per square foot of land and just provide a connection to the data center back to DC.

    Your theory is obviously stupid its makes you look silly for mentioning it.

    And the best part 'couldn't be removed' ... explain that one without sounding like you know nothing about OSS.

    --
    Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
  39. Re:LOL by Mister+Liberty · · Score: 1

    Not to worry.
    The Eff Bee Eye is just a giant set of Archie Bunkers, i.e. a conglomerate of fearful, nay paranoid
    panty sniffers, trying to prove mainly to themselves their worthliness in modern society.
    They prob. use buzzwords like 'terrorism' too.
    Pathetic old men, leave them alone.

  40. Re:Shit software by BitZtream · · Score: 1

    And you

    trustno1

    --Mulder

    --
    Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
  41. Re: Mostly harmless by Anonymous Coward · · Score: 0

    And you know this detailed information how?

    He... umm... heard it from a friend.

  42. Re: LOL by X0563511 · · Score: 1, Offtopic

    By replying to obvious trolls?

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
  43. Did you know? by Anonymous Coward · · Score: 0

    Did you know the FBI is primarily a mormon organization, ran by the mormons?

    I bet you didn't know that.

    1. Re:Did you know? by omnichad · · Score: 1

      The former polygamists known for taking underage brides? Do explain.

  44. Re:LOL by fisted · · Score: 1

    Son, are you even trying?

  45. Re:Mostly harmless by Anonymous Coward · · Score: 0

    Hey Roger . . . I see what you did.

  46. Re:Mostly harmless by Anonymous Coward · · Score: 0

    I have to say I'm a more than a little incredulous. This is the first time I've ever encountered someone like you. May I just simply ask what is it about pictures of exploited children you find so much more appealing than the plethora of normal legal smut the rest of us enjoy? I simply don't get it. What's the point?

  47. Re: the CP sites is one thing, Freedom Hosting ano by Anonymous Coward · · Score: 0

    Old Testament allows men to marry female children. America is a feminist police state. A woman's country. Men should not be loyal.

  48. Old stuff by Anonymous Coward · · Score: 0

    This is nothing new. I was with AnonOps where they posted a fake firefox TOR button which actually connected to a VPS and then to TOR while the VPS logged every connection, many many people downloaded it and many users of a certain large porn site were unmasked, sadly as well as users of TSR.

    It just shocks me the FBI uses such primitive and crude methods.

  49. Are any non Child Porn users using Tor? by mtthwbrnd · · Score: 1

    Are there any statistics about the usage or contents on TOR? It seems from all of the press that I have read that it is mainly a Child Porn network.

    Who else is actually using the technology? Please do not reply with "theoretical uses" such as "somebody in China *could* use it to communicate information which the government does not want to be transmitted", unless you can actually back it up with an actual occurrence of it.

    What I want is not really individual cases but to know if anybody has done a statistical analysis of the actual content types and usage.

    1. Re:Are any non Child Porn users using Tor? by Bite+The+Pillow · · Score: 1

      How would you conduct such a survey?

      And how can you gather statistics about usage when your source will never report anything about legit usage?

      "Utah man found using Tor to do his banking, film at 11."

      "Chinese dissident found using Tor, interview at.. oh wait he died mysteriously."

      "EFF representative uses TOR so he knows what he is talking about, film never because that's pretty damned boring"

      I suppose you could ask the NSA. Go ahead and file a FOIA request, we'll wait.

    2. Re:Are any non Child Porn users using Tor? by Anonymous Coward · · Score: 0

      I use TOR to read Slashdot, because I care about civil liberties and am afraid of exercising my liberty in front of the NSA secret police.

      No kidding, this is what it has come to in the United States. TOR just to be able to surf Slashdot and not be pegged on a watch list.

    3. Re:Are any non Child Porn users using Tor? by Anonymous Coward · · Score: 0

      Are there any statistics about the usage or contents on TOR? It seems from all of the press that I have read that it is mainly a Child Porn network.

      Who else is actually using the technology? Please do not reply with "theoretical uses" such as "somebody in China *could* use it to communicate information which the government does not want to be transmitted", unless you can actually back it up with an actual occurrence of it.

      Yes. I use it to surf adult porn when visiting countries for extended periods of time that block adult porn. I also use Tor when it's convenient to view material on subversive sites like the ACLU, Mother Earth, HuffPo, and Drudge. I've also downloaded all kinds of subversive content like "Unintended Consequences" using Tor.

      No reason to be tagged as anything outside of "CNN/CNBC/Fox" by them . I fly (out of necessity) too often.

      What I want is not really individual cases but to know if anybody has done a statistical analysis of the actual content types and usage.

      I'd guess that the only people doing true statistical analysis of traffic types and content at the exit-nodes are them . I find it unlikely that their research on the subject would be provided outside of their circles, until something drastically changes with our Government. I provide my usage as a poor example of what I believe is the majority of Tor usage, without any real proof of that fact.

      I expect a tremendous amount of Tor traffic is porn; I can't authoritatively comment on whether it's adult or child. Mine happens to be adult, but then I'd find a way to report a child-porn site to the FBI (using Tor) if I stumbled upon one. Not really surprisingly, my Tor searches usually result in exactly what I want to find - adult pron.

    4. Re:Are any non Child Porn users using Tor? by mtthwbrnd · · Score: 0

      I guess that some software could visit sites available on TOR and determine whether the site/content is Child Porn or not and in that way could gather some statistical estimate.

    5. Re:Are any non Child Porn users using Tor? by Fjandr · · Score: 1

      Tor does not host content, it simply disguises the source request for otherwise normal Internet content accessible by a normal browser.

    6. Re:Are any non Child Porn users using Tor? by Anonymous Coward · · Score: 0

      I'm using it to access TPB since a lawsuit forced my ISP to null-route its IP addresses.

      Yes, I suppose I could use a mirror but this way works, too. Much more reliable than a random proxy.

    7. Re:Are any non Child Porn users using Tor? by omnichad · · Score: 1

      You've really never heard of the Silk Road? It's been in the news quite a lot.

      But yes, there are actually people using it to circumvent government firewalls.

  50. Re:LOL by currently_awake · · Score: 1

    Those DC exit nodes probably connect directly to a secure government network, so CIA agents and spies can send reports and stuff without it ever going through insecure networks in plain.

  51. Re: LOL by slick7 · · Score: 1

    Pathetic old men, hah! These are the same people who create the terrorist scenarios that they then bust. We have met the enemy and they are U.S..

    --
    The mind conceives, the body achieves, the spirit manifests.
  52. Re: Shit software by slick7 · · Score: 1

    Where there is one cockroach, there are usually a hundred, go cockroaches!

    --
    The mind conceives, the body achieves, the spirit manifests.
  53. Of course this depends on who you're hiding from by Anonymous Coward · · Score: 0

    If just the MPAA/RIAA, you probably need much less - since those that can track tor traffic probably won't expose their hacks for movie piracy.

  54. Re: LOL by Anonymous Coward · · Score: 0

    "Cause Slashdot" is the only answer anyone needs, even if you don't like it.

  55. Re:Mostly harmless by Bite+The+Pillow · · Score: 1

    Because full disk encryption is a get out of jail free card?

    I don't see any Supreme Court rulings that support you. Depending on which circuit court you fall under, it may be an automatic jail sentence if you don't reveal the password.

    Assuming that, since you mentioned the FBI, you fall under US law, of course, and it would be silly to pretend otherwise at this point.

    It's a crap shoot basically, and if you go all the way to the Supremes, do you trust the current court to be on the side of privacy?

  56. Re:LOL by Anonymous Coward · · Score: 0

    Your UID isn't low enough to call anyone son, son.

  57. Absolutely wrong by s.petry · · Score: 3, Interesting

    On the surface this sounds valid, but you completely miss the obvious. The FBI, as well as other 3 letter agencies, are _creating_ software for the purpose of hacking into people's computers _illegally_. The FBI is not taking over some criminal botnet to harvest data, they are not intercepting malware C&C data to find things, they are creating their own malware for the purposes of performing illegal activities.

    That fact alone should exemplify how wrong this is, since they are not only breaking laws regarding Constitutional issues. They are also breaking US and International law covering hacking, wire tapping, and computer espionage. You know, the same shit they were trying to slap Aran Schwarts with 70 years in prison for laws.

    To use a drug analogy, the FBI can not start producing cocaine to find and arrest buyers. That is illegal, and repeatedly been reinforced as illegal.

    Computer vulnerabilities don't exist by nature, people must create methods of making computers vulnerable. A program with a buffer overflow exploit would not be vulnerable without the code to exploit the program deficiency. If you truly believe computers should be fair game, then you should also believe that it's perfectly fine for someone to steal your car because locks are imperfect and can be bypassed. (Had to throw in the tried and tested car analogy also..)

    --

    -The wise argue that there are few absolutes, the fool argues that there are no probabilities.

  58. Re:Catching a pedo by gweihir · · Score: 1

    You must be really sick to enjoy watching something like that. Seeing a human being destroyed is never anything to celebrate or even enjoy, unless you are a sadist and not one that has the urges under control. Are you jerking off to this? It sounds very much like you do.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  59. Re:LOL by fustakrakich · · Score: 1

    Why is this being modded down, aside from the overused "open sores" remark? More power to the FBI and all the other authorities to provide incentive to circumvent them in any way possible. There is no security in any electronic communication. That we must accept (Thank you, Mr. Smith). So let's do our best to deal with it and use it against them.

    And of course, it would be best for all if we can neutralize the weapons.

    Peace!

    --
    “He’s not deformed, he’s just drunk!”
  60. Catching a pedo by Anonymous Coward · · Score: 0

    The Old Testament agrees with the liberals. Read Deuteronomy 22 28-29 in hebrew. (Rape young girl, keep her, pay father) (and yea, real rape, seize and force)
    The Old Testament also says kill people who don't agree with the Old Testament.
    That would be people like you.

  61. Re:LOL by lister+king+of+smeg · · Score: 1

    But the freetards tell us that Tor is so secure!! Open sores fails again.

    Good thing that the proprietary vendor like Apple Microsoft don't just give TLA's back-door access to their products... oh wait they do just that. I would rather have bug that can be patched in a open project than backdoor in a product I can't patch and pay for.

    --
    ---Saying gnome 3 is better than windows 8 not so much a compliment as it is damning with light praise.
  62. Re:Mostly harmless by Sabriel · · Score: 1

    "What's the point?" Ironically, your question holds the answer - in pedophilia, the brain's sex drive is missing the point. An error in the genetic code, a bad evolutionary adaptation to population overpressure, excess or deficiency of required chemicals, damage due to stressful environment... whatever the actual cause, the end result is a human being placed in the nightmarish position of having a sex drive that finds children attractive.

    The trouble with biology is that it doesn't care, not about us having self-awareness nor our desire for a just world. After all, ask yourself: why do we find that "normal legal smut" so appealing? What's the point? Our "normal" sex drive is no more capable of recognizing that a photo can't reproduce any more than a pedophile's sex drive can.

  63. Re:Mostly harmless by LainTouko · · Score: 1

    Would you be able to answer the same question about your own personal porn preferences? I know I wouldn't be able to answer it about mine.

  64. Re:Mostly harmless by Anonymous Coward · · Score: 0

    Ummm... I believe there's a thing called the 5 amendment, and even the little letters know about it. Heck, even 1st year law grads know about it. So, no you don't have to surrender to search willingly. And they can't charge you for not being helpful, they only charge you with obstructing justice when performing an action that prevents them from doing their job.

    Unless of course you're in the UK...

      https://www.techdirt.com/articles/20140116/09195525902/uk-man-jailed-not-giving-police-thumbstick-password.shtml

  65. Wrong by Anonymous Coward · · Score: 0

    They also take over botnets and use them for all sorts of purposes, first of all for reconnaissance. There was a wired or SD article a couple of years ago.

  66. "Child Porn" and "Terror" by Anonymous Coward · · Score: 0

    Are their way of getting Absolute, Tyrannic Powers. Hail to the Absolutist King !

    And you know what ? Most of population falls for this shitty propaganda.

  67. YEAH ! by Anonymous Coward · · Score: 0

    Only Cockroaches need a constituion. Everybody else bows to the Neo-Cheka !

    http://en.wikipedia.org/wiki/Cheka

  68. In the eyes of the Rich&Powerful by Anonymous Coward · · Score: 0

    ...anonymity is evil. It kills their ability to

    A) set up a honey-trap for you

    B) send you the IRS

    C) Lock you up from some trumped-up-charges from B)

    D) spread lies in the circle of your friends, neighbours, acquiantances

    E) to make a special radio program "just for you"

    F) Have some dogs waiting for you behing the corner

    G) Use MK-1 Eyeball on you while you don't wear sunglasses

    In other words, anon threatens their corrupt ways of doing things. That's why they hate it

  69. the real enemy by ruir · · Score: 1

    Come again, what was that political propaganda posts about cyber attacks coming from China and the Middle east?

  70. Tor and social networks by ruir · · Score: 1

    It does not has any advantage to run Tor or Linux with Tor enabled if you then use it to access your personalised gmail or facebook account. No need for "hacking" by the FBI at ALL.

  71. Re:LOL by Brad+Eleven · · Score: 1

    The same design that prevents real-time communication also makes Freenet a lot more resilient.

    ... and durable.

    --
    "Press to test."
    (click)
    "Release to detonate."
  72. Grand Theft Auto 4 by Anonymous Coward · · Score: 0

    What about some almost left behind games, like Grand Theft Auto, or anything that doesn't have constant patches? As abandoned buildings, parasites will come to live in it. Every weekend, from Friday night to Sunday morning, self entitled hackers use other's players computers using games known vulnerabilities to host Tor sites, most of them containing sick content made by them raping their their breed.

    I which I was there to KILL every bastard who does that, instead of being run over by the wheel every time I have to format my PC to clean their mess.

  73. Re:LOL by Anonymous Coward · · Score: 1

    exit node, secure govt network, "reports and stuff", "insecure networks" "plain"

    This is a list of words I don't think you understand.

  74. Re: Catching a pedo by Anonymous Coward · · Score: 0

    Do you empathize with the particular type of human being we're talking about? Do you defend this kind of people? Ehy don't you take a seat over there?

  75. Criminal behaviour by Anonymous Coward · · Score: 1

    If the FBI ever infect a machine in my country, they will be committing a criminal offence. Of course, the whole US regime is now rogue, criminal, and corrupt, so I doubt that will bother them much.

  76. Re:Catching a pedo by mtthwbrnd · · Score: 0

    Not at all. I certainly do enjoy seeing a sick pedo getting caught and humiliated. I would enjoy even more if there was a public execution to follow!

  77. Re: LOL by ArcadeMan · · Score: 1

    It's a discussion about the FBI compromising TOR that turned into a flamewar between AAPL, MSFT and OSS fanboys because we all assume the malware probably only involved Microsoft's Windows OS.

    P.S.: I use Linux and OSS software for the server-side, I use OS X as my desktop with a mix of commercial and OSS software and I use Windows for both commercial and indie games. I'm a fanboy of using what I think works best for the task.

  78. Re:LOL by ArcadeMan · · Score: 1

    It's like some people who use TOR do this analogy: they wrap themselves in a full-body suit that can prevent face recognition, tracking, etc. But they walk around shouting their name, age, address,etc so that anyone within range can hear it.

    In other words, you can't fix stupid.

  79. Re:Catching a pedo by gweihir · · Score: 1

    That is extreme Sadeism. Deep in the pathological spectrum and far worse than a psychopath. This, incidentally, makes you far, far worse than the person that got caught.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  80. Re: Catching a pedo by gweihir · · Score: 1

    You share 99.9% of the genetic markup with this person. He still is human. The only thing your demonization of this person actually does show that you are very well aware of that and possibly are far closer to him than you want to admit. It seems pretty likely that you are a closet pedo.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  81. Re:LOL by SuricouRaven · · Score: 1

    There is a distinction - durable defines an ability to resist damage, resilient defines an ability to recover quickly from damage. Freenet posesses both.

  82. Not Bad? by LifesABeach · · Score: 1

    This could only be Intrapment?

  83. Re:LOL by Rich0 · · Score: 1

    One of the big advantages of freenet from this standpoint is that it doesn't support bidirectional communication. There are no "servers" on freenet. That means no search engines, or storefronts, or anything like that. You publish information, and you retrieve information.

    So, implementing something like silk road on freenet would be tricky. On the other hand, it would be harder to interfere with if you did.

  84. Re:Shit software by Reziac · · Score: 1

    "When three men sit down to discuss conspiracy, two are government agents and the third is a fool."
    -- Soviet proverb

    --
    ~REZ~ #43301. Who'd fake being me anyway?
  85. Re:Catching a pedo by mtthwbrnd · · Score: 0

    "That is extreme Sadeism."
    If a pedo does not want to be killed then they should refrain from raping our children.

    It is a simple formula:
          Rape our children = we will kill you.
          Don't rape our children = we will not kill you.

    "This, incidentally, makes you far, far worse than the person that got caught."
      Only in the opinion of the libtard mind. Only a libtard could possibly come out with such a warped and backwards interpretation of events.

    No sane person wants to allow an animal who rapes our children to live so that he can have the opportunity to repeat the offence and destroy another family - or even to remember with pleasure the harm he caused while he is enjoying the benefits of society after serving his puny sentence which the libtards have ensured has been reduced to almost nothing.

    The libtard position will not protect our children from becoming the next victim. Mine will.

    Some cowardly libtard marked my original comment as troll. This goes to prove the saying:
    If you want to know what a "liberal" thinks about freedom of speech, say something he disagrees with and you will find out from his lawyers.

  86. Re:Catching a pedo by mtthwbrnd · · Score: 0

    I never said I was Judaic. What on earth makes you think that I follow the Torah? But thanks for pointing out this element in the Jewish religion. You should also read the Talmud, in there you (the Anonymous Coward) will find all kinds of sick perversions.

  87. Re: Catching a pedo by mtthwbrnd · · Score: 0

    I think that you will find that the true differences between different people's are not determined by the fraction of "genetic markup" (as difficult as that is to quantify) that they share.

    Look at two vessels containing volumes of gas. One is Oxygen at STP and the other is Carbon Monoxide at STP. The vessels share more than 99.9% of similarity because they are mostly vacuum. But does that mean that the vessel of Oxygen is the same as the vessel of Carbon Monoxide? No.

    Compare the machine code generated by two different programs written in Java after the bytecode is JITed. Are they not very similar? Mostly it is house- keeping/framework related and that code is the same for all programs. But the tiny fraction of difference is what makes the programs do different things. I.e. the bit the programmer wrote.

    So comparing "genetic markup" and discovering that the code is 99.9% similar does not logically lead to the conclusion that "we are all the same". It is very conceivable that the important parts are the 0.1% of differences!

  88. Re: LOL by Anonymous Coward · · Score: 0

    The call and response here is too perfect, I suspect both posts by the same person, or mass posting script. I suspect some have too much time on their hands, I suspect others are paid by the post shills racking up the numbers.

    Either way its offtopic bait for other peoples karma. Hence....

  89. Re: LOL by Anonymous Coward · · Score: 0

    That's not really a good analogy. The article is about scripts being run through Tor; it's more like ... They were running a browser with a vulnerability, and got malware. There probably isn't a realworld analogy for iframes or JavaScript ... Or malware.

  90. Actually "the problem" is in accepting by ToddInSF · · Score: 1

    That it is OK, in ANY way, shape or form, for the police/law enforcement to be exempt from prosecution for violating laws which, when applied to anybody else, yield years in prison.

    I'm not OK with the activities of the criminals at the FBI.