The FBI Is Infecting Tor Users With Malware With Drive-By Downloads
Advocatus Diaboli (1627651) writes For the last two years, the FBI has been quietly experimenting with drive-by hacks as a solution to one of law enforcement's knottiest Internet problems: how to identify and prosecute users of criminal websites hiding behind the powerful Tor anonymity system. The approach has borne fruit—over a dozen alleged users of Tor-based child porn sites are now headed for trial as a result. But it's also engendering controversy, with charges that the Justice Department has glossed over the bulk-hacking technique when describing it to judges, while concealing its use from defendants.
But the freetards tell us that Tor is so secure!! Open sores fails again.
Never trust open sores software written by amateurs.
What ever happened to not breaking the law to collect evidence?
Yeah, trust blackboxes made by Orwellian companies, where mediocrity is the norm, instead...
...and that's how and WHY they get away with this. This is against any human rights, but shout "won't anyone PLEASE think of the Children", and these agencies can get away with murder.
...without a harddisk! Use it to connect with TOR on a different network, preferably in a different city than where you live. You can't get much safer than that....IF...you apply the other 8 rules above.
So that said, to any whistleblower out there who doesn't have the tech savvy that we have, I'd offer a little bit of advice, read it - and don't forget it, you might just be next if you do:
1) Download Tails. Install it preferably on a CD.
2) Remove your hard disk connection (removing the power is enough) when you intend to boot from Tails.
3) Shut down your WiFi. And only use WIRED connections.
4) Boot tails, and when you start Iceweasel - make sure to turn NoScript ON for ALL sites. It's not on by default, when the SHIELD shows...it's on!
5) Never - ever use an acronym you'd use with your normal ISP (IP address), this WILL unmask you.
6) Do NOT use FLASH or JAVASCRIPT.
7) Do NOT do any banking business or anything that would identify the real you using TOR. Tor is like walking into an underworld of the worst place you could imagine in a bad movie (except Darknet is very real, and can be a VERY dark place, it has freedom...but freedom is precious there, and there's someone waiting on every corner to con you, and remember - this threat is VERY REAL!), so don't be a fool. Do what you have to, but stay safe.
8) Do NOT brag to friends that you're safe with Tor. As far as you know, you don't even know what Tor is.
9) If you can, use Tor with a laptop that has never been used on a wired or wireless KNOWN network with you, but only used for TOR
10) Don't SURF TOO LONG AT ONCE - People are working to unmask TOR users all the time with Injection attacts, and they succeed often! Notice that when the chain of relays break (refreshes)...always keep looking at the NETWORK MAP...ALWAYS, DISCONNECT LIKE THE WIND and find another time to connect short sessions. Keep things brief, and as many clusters as you can.
11) Always make sure that the TAILS CHECKSUM IS MATCHING! I've downloaded TAILS TWICE from their so called official server and had CHECKSUM MISMATCH, this could be as simple as a faulty packet...but it could also be much more serious than that, imagine the rest yourself - BE PARANOID! It's your life!
Information is the only power we have left!
What this world is coming to - is for you and me to decide.
- George Carlin
From the article, it sounds like we know they used it to identify computers browsing child porn sites. They had warrants. Okay, I'm not too upset about that. MAYBE they also did it to all sites hosted by Freedom Hosting. THAT would be a problem.
Problem5 with
So these people are so concerned about online privacy that they use Tor...on a proprietary OS!
Facepalm.
More to the point, never trust the FBI.
Free. The word is free, you hipster cunt.
Stop pretending you're a lawyer or Che T-shirtman. You're not fighting a good fight, you're fighting to keep cheetos from staining your beard.
Weren't you supposed to yell at some sheeple to "fucking flame away" or to "waste their goddamned mod points" or to "slit their fucking wrists"?
In the article, they mention that one of the drive by malware installations by the FBI hit the servers of a webmail service called Tormail in the process of going after a site that was believed to be hosting child porn. Presumably, they used the malware to search PCs, including those of Tormail users who had committed no crime. Wouldn't this be a massive violation of the fourth amendment?
I know this won't be a popular position here, but the problem here isn't with what the FBI is doing, but rather the fact that they can do it. The problem is with the technology: it just isn't as secure as it's supposed to be. When a hacker finds a vulnerability in a security system, most people on Slashdot say don't blame the hacker, but rather fix the underlying vulnerabilities in the system. Instead of pointing the finger at the FBI for using vulnerabilities in TOR, web browsers, and/or operating systems, we should be glad that they're making this public, so the vulnerabilities can be fixed. After all, if the FBI can do this, so can criminals, governments hostile to free speech, and many other malicious parties. Let's learn from what the FBI is doing and harden the systems, to make legitimate users of Tor and similar services safer.
If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
We are one slippery slide away from specifically targeting all users of TOR regardless of what services and sites they use.
At least this was a targeted attack against people actually breaking a law. Not as bad as the general fishing that the article explains. Still it is scary to think that thought crimes are being so focus'd on when we have more pressing issues as a society to deal with.
They also did it to all sites hosted by Freedom Hosting THAT would is a problem.
FTFY
I hate to say it, but this is pretty smart. They seem to have realized that using their new techniques against child porn is the best way forward for them because the issue has stigma to spare that can help quell dissent, then, once the practice is firmly established, they can quietly expand it to everything else they desire.
"I opened my eyes, and everything went dark again"
In a nutshell, they simply had any computer that contacted the web site send back the computer's real IP address and its MAC address. The actual security of the Tor wasn't affected. Just that compromising information was sent through the Tor network. Just as any other data would be sent through the Tor network.
Now I suspect the MAC address was sent so that they could identify the actual computer when they seized it via a warrant. That way the suspect couldn't claim that it wasn't their computer since the IP address was on the other side of a NAT and there were multiple computers using NAT. And the IP address was simply to make identifying the physical location easier.
Which raises an interesting question.... ... difficult ... without that MAC address.
What if someone alters their MAC address and then enters the Tor network via a public wifi hotspot?
The connection is encrypted so the fact that the hotspot is publicly accessible shouldn't be a problem.
And when the computer is turned off, the MAC spoofing goes away so even if the computer is seized, they don't have a matching MAC address to prove it's the computer they hacked. And of course, since access was via an open hot spot, there's plenty of computers that could have been connected. Proving which one would be rather
They consider finding out about a dozen alleged USERS of child porn sites a big win?
This is my signature. There are many like it, but this one is mine.
I wouldn't be surprised a bit to learn they are related:
https://firstlook.org/theinter...
Snowden docs, exceptional description of the Turbine program that seeds malware to non-targeted individuals - goal by the NSA (then) was millions of infections.
The logical extension of this is, in the end, to compromise all personal and business computer systems - so anything is available when needed.
If you had Javascript disabled, you were safe. Even though TOR has it enabled by default, almost all pedo sites has a javascript pop-up to tell you that you're not surfing safe and to turn it off. Also you had to turn TOR off and use the same browser on the regular web to deliver the data to the FBI, also not recommended. And if you'd set it to not store cache, history, cookies etc. as recommended you'd also be immune. They caught what, two dozen? There's literally thousands of active members on TLZ and *lol*IB, which is where everybody went after OPVA and Lolita City (both hosted on Freedom Hosting) went down. And smart people don't rely on TOR alone, always have at least two layers of defense. Well, three if you count my full disk crypto as a last resort if the police do knock down my door - there'll still be no proof to find here.
It would be a shame if hackers retaliated with drive by hacks of autopiloted cars using small RC vehicles mounting range extended telecom connectors.
But, those who live by the unconstitutional spying on their own citizens deserve what blowback they get.
If you don't have anything to hide, you don't understand what metadata is.
-- Tigger warning: This post may contain tiggers! --
More to the point, never trust the FBI.
Yeah, because we know cyber criminals could do the same and already do hence the advice to NEVER run Java and Flash over Tor, and to even turn off Javascript.
They did it to all sites hosted by Freedom Hosting. Most notably, they did it to Tormail -- not a kiddie porn site, a webmail provider.
"They redundantly repeated themselves over and over again incessantly without end ad infinitum" -- ibid.
Did you know the FBI is primarily a mormon organization, ran by the mormons?
I bet you didn't know that.
Old Testament allows men to marry female children. America is a feminist police state. A woman's country. Men should not be loyal.
This is nothing new. I was with AnonOps where they posted a fake firefox TOR button which actually connected to a VPS and then to TOR while the VPS logged every connection, many many people downloaded it and many users of a certain large porn site were unmasked, sadly as well as users of TSR.
It just shocks me the FBI uses such primitive and crude methods.
...who needs FSBs?
We seem to have this quaint notion that government abuses only happen in soviet bloc, or communist countries...the fact of the matter is that our oversized, powerful, and power hungry federal government has the same tendencies towards corruption and abuse. Hell, we seem to take for granted that oversized, powerful, and power hungry *companies* are corrupt and abusive, but never seem to apply the same strict scrutiny to our unaccountable government bureaucrats.
Are there any statistics about the usage or contents on TOR? It seems from all of the press that I have read that it is mainly a Child Porn network.
Who else is actually using the technology? Please do not reply with "theoretical uses" such as "somebody in China *could* use it to communicate information which the government does not want to be transmitted", unless you can actually back it up with an actual occurrence of it.
What I want is not really individual cases but to know if anybody has done a statistical analysis of the actual content types and usage.
There is a fantastic US TV show where the crew pose as children on the internet in order to catch pedo animals. So many of these sick animals are out there. They get them to meet up and when the animals enter the house they are greeted by a 6 foot Male who tells them to sit down and proceeds interrogates them about what the f*ck they think they are doing.
The police arrest them as they leave the house.
https://www.youtube.com/result...
Of course, every one of them, upon being caught red handed, say: "I have never done this before, this is my first time".
Unfortunately some of them are repeat offenders because the libtards have argued that pedo animals should be allowed to roam the streets even after they have been convicted of raping children. Personally I think we should just shoot them in the head and throw their bodies in a land fill.
If just the MPAA/RIAA, you probably need much less - since those that can track tor traffic probably won't expose their hacks for movie piracy.
On the surface this sounds valid, but you completely miss the obvious. The FBI, as well as other 3 letter agencies, are _creating_ software for the purpose of hacking into people's computers _illegally_. The FBI is not taking over some criminal botnet to harvest data, they are not intercepting malware C&C data to find things, they are creating their own malware for the purposes of performing illegal activities.
That fact alone should exemplify how wrong this is, since they are not only breaking laws regarding Constitutional issues. They are also breaking US and International law covering hacking, wire tapping, and computer espionage. You know, the same shit they were trying to slap Aran Schwarts with 70 years in prison for laws.
To use a drug analogy, the FBI can not start producing cocaine to find and arrest buyers. That is illegal, and repeatedly been reinforced as illegal.
Computer vulnerabilities don't exist by nature, people must create methods of making computers vulnerable. A program with a buffer overflow exploit would not be vulnerable without the code to exploit the program deficiency. If you truly believe computers should be fair game, then you should also believe that it's perfectly fine for someone to steal your car because locks are imperfect and can be bypassed. (Had to throw in the tried and tested car analogy also..)
-The wise argue that there are few absolutes, the fool argues that there are no probabilities.
The Old Testament agrees with the liberals. Read Deuteronomy 22 28-29 in hebrew. (Rape young girl, keep her, pay father) (and yea, real rape, seize and force)
The Old Testament also says kill people who don't agree with the Old Testament.
That would be people like you.
They also take over botnets and use them for all sorts of purposes, first of all for reconnaissance. There was a wired or SD article a couple of years ago.
Are their way of getting Absolute, Tyrannic Powers. Hail to the Absolutist King !
And you know what ? Most of population falls for this shitty propaganda.
Only Cockroaches need a constituion. Everybody else bows to the Neo-Cheka !
http://en.wikipedia.org/wiki/Cheka
...anonymity is evil. It kills their ability to
A) set up a honey-trap for you
B) send you the IRS
C) Lock you up from some trumped-up-charges from B)
D) spread lies in the circle of your friends, neighbours, acquiantances
E) to make a special radio program "just for you"
F) Have some dogs waiting for you behing the corner
G) Use MK-1 Eyeball on you while you don't wear sunglasses
In other words, anon threatens their corrupt ways of doing things. That's why they hate it
Come again, what was that political propaganda posts about cyber attacks coming from China and the Middle east?
It does not has any advantage to run Tor or Linux with Tor enabled if you then use it to access your personalised gmail or facebook account. No need for "hacking" by the FBI at ALL.
What about some almost left behind games, like Grand Theft Auto, or anything that doesn't have constant patches? As abandoned buildings, parasites will come to live in it. Every weekend, from Friday night to Sunday morning, self entitled hackers use other's players computers using games known vulnerabilities to host Tor sites, most of them containing sick content made by them raping their their breed.
I which I was there to KILL every bastard who does that, instead of being run over by the wheel every time I have to format my PC to clean their mess.
If the FBI ever infect a machine in my country, they will be committing a criminal offence. Of course, the whole US regime is now rogue, criminal, and corrupt, so I doubt that will bother them much.
This could only be Intrapment?
That it is OK, in ANY way, shape or form, for the police/law enforcement to be exempt from prosecution for violating laws which, when applied to anybody else, yield years in prison.
I'm not OK with the activities of the criminals at the FBI.