The FBI Is Classifying Its Tor Browser Exploit
motherboard.vice.com
motherboard.vice.com
If you can't make a case against someone without classified information, decide which you care more about: the classification of the information, or the conviction.
Somebody high-up in the CIA is secretly working for the USSR. They are passing everything to the USSR. Over in the USSR there is a similar situation, with somebody passing KGB things to the CIA. The guy secretly working for us is able to reveal the person secretly working for the USSR.
Now we grab the person. If we reveal the evidence to him and everybody in unclassified court proceedings, it will get back to the USSR. Our agent in Moscow will be caught. Even if we black out his name, he will be caught. It's a scary enough risk just acting on the info he supplied.
Your way of doing things gives us 3 terrible choices:
a. Evacuate our super-valuable guy from Moscow. b. Get our guy in Moscow killed. c. Let the spy go unpunished, thus encouraging others.
Exactly the problem. "People with security clearances" seems like a set of people more likely on average to favor the government point of view, to the point that a defense attorney that allowed twelve people with security clearances to form a jury has utterly failed at voir dire.
For sure, it's a more caring and accurate group of people than the usual collection of students, old ladies, and unemployed people.
It'd work fine.
It's not perfect, but it balances the conflicting needs better than any alternative I've ever seen.
Note that this isn't 1-sided in favor of the government. Consider what happens today. People working at Area 51 tried to sue over being exposed to toxins, but were stopped by the state secrets privilege. That privilege would die if we had classified courts.
Damn you and your impossible standards, you commie terrorist!!
After-the-fact law enforcement is secondary. It may be this is a tool they intend to use to attack spy and terrorist networks where breaking up the network is more important than getting prosecutions.
I'm not sure that's true. Where do you get that?
That's an interesting claim, but utterly untrue: "The mission of the FBI is to protect and defend the United States against terrorist and foreign intelligence threats, to uphold and enforce the criminal laws of the United States, and to provide leadership and criminal justice services to federal, state, municipal, and international agencies and partners; and to perform these responsibilities in a manner that is responsive to the needs of the public and is faithful to the Constitution of the United States."
https://www.justice.gov/jmd/organization-mission-and-functio...
If I'm allowed to use a classified system to extract information (say from an encrypted drive) I could really just be creating that information instead. The defendant can't or won't decrypt the drive so they can't dispute the claim.
But if there's a classified evidence-gathering program it can be upgraded to "find" whatever they want at any date.
http://motherboard.vice.com/read/fbi-our-malware-sends-unenc...
Without that evidence is literally worthless.
Yes, the exclusionary rule means the bad guys win when the good guys can't prove they followed the rules. That's how the exclusionary rule gets the good guys to follow the rules.
You can verify that:
1) Drugs were present at the location at the time of the arrest.
2) They are in fact drugs.
3) That a chain of custody exists.
4) The people involved in the arrest and the person arrested.
With "classified, closed source software" you can verify:
1) The people involved in the arrest and the person arrested.
You cannot verify:
1) If the software works as explained/intended.
2) You cannot verify the person was present at the time of the crime.
3) You cannot verify the chain of custody because you have no idea. ( http://legal-dictionary.thefreedictionary.com/chain+of+custo... )
"Your Honor, the new version of the program found kiddyporn that we missed before."
And even if you decrypted the drive you wouldn't be able to prove you didn't have the data steganographically hidden, so there's no possible way you could refute the claim.
"never attribute to malice that which can be attributed to incompetence." -Some Smart Guy IDK...Google it.
They are like your annoying needy friend. Always asking you for stuff but never bothering to return the favor.
No they don't. Assistance that industry would provide would also be classified and honestly a penalty would probably be levied if the found issues were ever fixed.
So they found it on their own, results classified so they can't be fixed.
Needed help finding it, threaten penalties if the issue is ever fixed.
They're not trying to build bridges, they're trying to gain control of another source of information.
A sandbox is necessary, and I'm 100% sure there are a ton of 0-days in all browsers.
>Our efforts to work with the Chrome team to add missing APIs were unsuccessful, unfortunately. Currently, it is impossible to use other browsers and get the same level of protections as when using the Tor Browser.
https://blog.torproject.org/blog/google-chrome-incognito-mod...
If you're referring to Chromium, well, what makes you think it's more secure than Firefox?
Also, don't you think that the developers of the Tor browser are pretty security-aware? That they might make very well informed decisions?
Firefox has zero additional layers of security. Chromium has a battle-tested sandbox which kills 99% of all exploits in the absence of an additional kernel exploit.
Also note how none of the recent Flash 0days was exploitable on Chrome.
Reminder, this isn't a vulnerability in Tor, but an IP leak in Firefox, or at least the way it's configured in TBB.
Maybe a sandbox is irrelevant to an IP leak though, idk.
[0] https://www.reddit.com/r/linux/comments/3a0rz0/chromium_unco...
Certainly there are other higher level data exposure problems that could manifest, but I'm so utterly sick of C-level security exploits that I'm ready to throw everything out with the bathwater.
I'd rather that fewer people understand how to break tor, as opposed to more. There's a middle ground which may be better, but on the open-source/classified spectrum I'm a little right-leaning on this one. Thoughts?
The entire reasoning behind using tor is for anonymity, and we don't know what this exploit is exactly or how serious it is.
If that's the case the exploit is intrinsically linked to the way tor works, and there may be no patching possible.
I'ma need someone to fact-check me because I'm semi-busy right now and I don't have the article on-hand.
Then you should be opposed to this! If the fbi shares the exploit, tor will patch it. As is, this vulnerability in tor puts its users at risk, both from the fbi and from anyone else who has found the exploit.
The FBI doesn't want the vulnerability to be fixed though, which is why they classified it.
If the exploit were in the protocol itself then that might not have been viable, but the facts of the case suggest it's an implementation level exploit, in which case the FBI choosing to hoard it actually does increase the chance of more people (even outside of the American intel community) gaining access to the exploit.
Releasing it would almost certainly lead to it being fixed very soon.
That is ridiculous. The more people who try to break Tor, succeed and tell the Tor Project how they did it, the safer Tor (and Firefox) become. The Tor Project relies on the security research community to find attacks on Tor so that they can be fixed. Same goes for all software in general.