Various well documented analysis have linked this incident to "EgotisticalGiraffe", a well known -- and since fixed vulnerability.
FUD or lazy journalism? I mean, at least read the subjects Wikipedia page before publishing something..
Various well documented analysis have linked this incident to "EgotisticalGiraffe", a well known -- and since fixed vulnerability.
FUD or lazy journalism? I mean, at least read the subjects Wikipedia page before publishing something..
A Wired article on it:
https://www.wired.com/2013/09/freedom-hosting-fbi/
Slides:
https://web.archive.org/web/20140413004837/http://cryptome.o...
A breakdown of the malware:
https://web.archive.org/web/20140417081750/http://ghowen.me/...
Of course, I would still assume that other ways of discovering the location of hidden services have been found. I'm not convinced that onions can be hidden from an adversary with the resources of a US government agency, particularly in light of some of the posts that appeared on Hacker Factor recently.
I know in some computer forensics work it is important to be able to prove evidence has not been tampered with.
So for example, cracking hashes instead of working with encrypted data can create safe space for non-leo to work without undermining an investigation.
For example, a case of illegal doping, the accused Pearson’s samples must be able to be shown to not have been tampered with.
It seems being able to prove the source of evidence would be the first step of this process.
This only is meaningful in a courtroom situation, a lot of "evidence" never sees the courtroom and is merely used as information to help the investigation.