Facebook Helped Develop a Tails Exploit
vice.com
vice.com
https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fb...
As does a company like Facebook spending large sums of money to narrow down on specific people, it could be someone you hate today and an activist the next.
Facebook has teams of people whose entire job is covering Facebook's ass. Before Facebook even does something bad, they already figured out an excuse for it before they even started doing it. If they didn't have an alibi, they wouldn't even do the crime. That's the kind of operation they run. They preemptively create the narrative, then they act. Why do people treat Facebook as if it were a conscientious person?
This is great PR for themm to say that both privacy and encryption are bad and should be outlawed.
Wouldn't be surprising at all if that's how they spin it.
Source? I know FB is pretty bad with the privacy of users of it's own services, but I'd be curious to see how they've campaigned against privacy.
For a for-profit company spending millions needs a justifications stronger than a penchant for vigilante justice.
A lot of big companies have a proven history of quietly cooperating with cops, three letter agencies and military.
That type of cooperation often leads to multi-million, even billion $ contracts and special favors from political power.
What is facebook trying to achieve?
Good PR for stopping predators.
Flexing their power in front the FBI and other tech firms.
Trying to demonstrate how obliterating privacy can sometimes have upsides.
Plus, it's clear that Brian Kil was a particularly bad actor and worthy of taking down.
For example, there's a reason most justifications we've seen regarding mass surveillance or automatic recognition systems are boiled down to two things:
stopping harmful material
terrorism
Of course, they take a topic that you wouldn't even dream or arguing against and using that against you.
If they wanted to erode our freedoms to stop harmful material I'm sure most would likely accept that outcome as I feel they have done (AI/facial tech)
The only reason the world isn't hating on them as much is because people need the platform to stay in touch during covid.
They carry far less info about people than google, google literally are funnelling data to all sorts of shady companies, and yet people trust google more.
Google literally tracks you across all of the internet, meatspace and beyond. Facebook can't do anywhere near as much (yet, ar glasses might change that)
Zuckerburg's utter inability to deal with trump effectively is symptomatic of the PR incompetence at the top. They have no idea that the outside world might think ill of actions. They are continually surprised when shit blows up in thier faces.
In short, no, FB are utterly terrible at controlling the narrative.
> This guy deserves what was coming to him,
I agree.
And on the scale of users FB has, he is most assuredly not the only one like him on Facebook.
I wonder how many there are that the company has no idea about, that perhaps are in countries that are not so well connected that they will get a dedicated FB employee to look into, who frankly FB does not and will not give a shit about.
I am therefore having some trouble believing they did this entirely in good faith. How many others are there that they will do absolutely nothing about?
- It makes their platform more secure. - Good PR - Assisting LEO prevents future problems with new laws etc. - It is good faith
In general decisions like this, always have multiple dimensions. Always it is calculated decision.
Facebook had no control over the exploit once it was handed over to the FBI. It could have been simultaneously used on the child predator and 100 activists at the same time.
Which is why Apple didn't help the FBI break iOS.
They did choose to not provide true E2E encryption for iCloud, however :(
https://threatpost.com/android-zero-days-worth-more-iphone-e....
This sounds like they describe the well-known WebRTC leak: https://restoreprivacy.com/webrtc-leaks/
0) https://securityaffairs.co/wordpress/43442/cyber-crime/fbi-u...
> and tails uses tor browser which doesn't support webrtc.
and how (in other instances than the situation in the article) the WebRTC flaw could be used. I wasn't specific enough.
1) escape from browser into VM
2) escape from VM into host
3) run exploit on host
And yes, vulnerabilities in Tor have been exploited. So it's prudent to hit Tor via nested VPN chains, just in case.
https://www.schneier.com/blog/archives/2017/03/fbis_exploit_...
From Engadget coverage [1], I feel a bit of context is missing in TFA.
[1] https://www.engadget.com/facebook-fbi-hacking-tool-targeted-...
Then I understood that "developing" an exploit means taking advantage of existing properties/vulnerabilities.
Is this standard wording in security circles?
Yes. There is a large industry that develops products for law enforcement and intelligence agencies focused on "exploit development," which is largely focused on developing exploits for zero day vulnerabilities in widely used software.
The process of discovering a vulnerability is called 'vulnerability research'.
So when Schneier says Facebook paid for an exploit to be developed, it means they paid for software that exploits a vulnerability.
In the case of paying for such exploits, it's not always clear who exactly did the research. Often the research comes from a third party who put together a simple proof of concept that demonstrates only that the security control can be breached (the PoC) -- then, a contractor may buy this vulnerability ('0day') from e.g. zerodium and develop an exploit for it, which will usually be pretty much point and shoot so you don't need an exploit dev team to leverage it.
Hope that makes sense.
" A factor that convinced Facebook’s security team that this was appropriate, sources said, was that there was an upcoming release of Tails where the vulnerable code had been removed. Effectively, this put an expiration date on the exploit, according to two sources with knowledge of the tool.
As far as the Facebook team knew, Tails developers were not aware of the flaw, despite removing the affected code. One of the former Facebook employees who worked on this project said the plan was to eventually report the zero-day flaw to Tails, but they realized there was no need to because the code was naturally patched out. "
[1] https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fb...
But then, this also can't be used against every other human being who needs privacy either. E.g.: Journalists, activists, anyone who disagrees with a large government, etc,
As an aside, I believe everyone needs privacy, so I'd rather say that everyone benefits from it, not just the usual journalists, activists, whistleblowers, etc...
Not saying that’s what is happening here, but it’s not like Facebook has a glowing reputation to begin with. Telling the vendor that a future release will patch the bug gets everyone to stop asking questions without really knowing if it’s true.
By telling Tails that the vulnerability will be patched in a future release without disclosing the details of the vulnerability, Tails has no way of knowing if this is actually true.
It’s easy to be a little skeptical when a company spends 6 figures to develop an exploit and then state publicly “we can verify that the issue will be patched in a future Tails release, but we’re not going to tell them or anyone else what the exploit was in the first place.”
If you wanted to keep using that exploit, or sell it, the easiest way to do so would be to tell Tails that it’s going to be fixed without actually giving them any details about it.
So there's no way for anybody to verify that the code is actually being removed, or that the exploit won't crop up again in the future. I don't trust them or the FBI at all in this.
You frequently get people on the internet saying "Your IP address doesn't prove anything", but I was always curious how that worked in the real world.
IP only tells the investigator whose name is on the ISP account, not which person was at the keyboard. Your recommendation only helps the police know where to set up the surveillance, not who to bring charges against.
Even if we do decide on some kind of ban, we need to assume facial recognition will always be used by someone, somewhere, and design our social systems to account for that fact.
Think this is less about Tails and more about this "video-tagging" tech.
At some point you have to wrestle with the fact that law enforcement is predicated upon having strong tools with which to deal with law breakers of all kinds, not just the few you find particularly onerous. They're going to need to perform ethical hacking to prosecute people under laws or circumstances you disagree with. And it would probably be better for us if they didn't always have to hack to get the information.
I think we need to work much more closely with law enforcement, not just technically on being able to lawfully intercept private communications, but in what laws and what cases its use is allowed. Nobody trusts the government in this age, but I think that needs to change, and it's the people that need to step up to reign in their government, not vice versa. That means more oversight, restrictions on when and how powerful tools can be used, periodic review, input into the design phase of new technologies, and so on.
We can use our brains to both make it more difficult for them to abuse advanced tools, and also make it more convenient to use them to solve serious crimes. We don't have to live in a black and white world where we either allow everything or allow nothing. We can live in a world of gray, but we have to step up to create that world; we can't just expect to keep saying 'no' to law enforcement and them being able to do their jobs, which is keeping our people safe.
You must assume this is the case. The FBI isn't going to stop using a tool just because they caught one suspect in once case.
Similar to what happen to Jeff Bezos.
The point of that is to say that "only allowing the machine to talk to Tor nodes" wouldn't stop an exploit from effectively bypassing Tor—by talking in a slightly unusual way to an adversary-controlled Tor node!
If they're not already doing it, it might be safer for Tails to learn the specific guard that its copy of Tor is using at a particular time, and only allow outbound traffic to that guard rather than to any Tor node. (Another precaution which they might already be taking: only the Tor daemon process should be able to open remote sockets at all.)
1. Since you share your vpn exit IP with several users, sometimes hundreds, it becomes harder for any website or service you use to track you by IP alone.
2. My ISP is mandated by law to save all my browsing data (germany here, this law changes every two month but you can assume they all log anyway). My VPN Provider is not mandated and has at least some incentive to not log any data. Cost and Reputation beeing the main ones.
3. I can for example have all my torrents exit in a country where filesharing is not illegal, making any persecution much less likely, same for other laws that are not the same everywhere.
That is why I say rotating botnet, because there is nobody to subpoena and it would require even more $$$. When your that level of criminal, might as well go all the way.
In both cases you need the tor daemon or the VPN software to be outside of the host running Tails.
How would they know he was running tails particularly?
And what a happy coincidence that the 0day was patched before they even had a moral obligation to notify anyone about it. Quelle chance!
Doesn't Tails route all traffic through Tor by default?
Seriously, Vice, “booby-trapped”..? It’d be funny if it wasn’t minors. Actually, it’s still kind of funny.
That’s one of the issues an aggregate system (which describes any system of meaningful size, these days) has to deal with.
How many of the massive breaches we hear about, originate with dependencies or subcontractors?
But there was a Windows password hash method in the early 2000s that could be brute forced on a single consumer grade CPU in less than 24 hours on their current-at-the-time flagship network server OS. So there's that...
Disclosure/ad: I work on Whonix, which is, uh, tails in VM essentially (to the person who only knows tails and not whonix). In Whonix, the desktop is in an VM, separate from another OS in another VM running the networking. No program in the desktop VM can reveal the public IP. On top of that, for advanced users, the desktop hardware itself might be separate from the hardware connected to the public internet.
The VM (virtualbox, kvm, whatever) is the single (practical) attack service, which is safer than ensuring every program the user may run is patched. Excuse the rant/ad/competition-bashing.
> Facebook had tasked a dedicated employee to unmasking Hernandez
If the government couldn't break in to Tails and required the outside help of two well-resourced organisations to find (and burn) a single exploit then overall that seems a pretty good endorsement of the security of a volunteer open-source project.
Or they didn't want to. Now we all know it costs a measly "six figures" (100k??) to zero day a system used by journalists and activists.
I would assume a huge, IT-focused org like FB already has 3-4 high-end security orgs doing pen-testing and digging for zero-days in their code; they just poured a little sugar on top of an existing contract to help squash this one online predator douche.
They previously worked with the FBI to try and trap this malicious user with a TOR exploit that didn't work against Tails where the malicious user saw the effect and mocked his investigators.
The $0.5million reportedly spent for the Tails 0day seems like it might actually be proportionate (perhaps even affordable) to the costs they incurred. I'm typically pretty skeptical of the costs the FBI and large corporations assign to corporate hacks or copyright theft, but this seems like it carries legit risk if FB doesn't try to do a lot to disable these malicious actions on their platform.
> Several FBI field offices were involved in the hunt, and the FBI made a first attempt to hack and deanonymize him, but failed, as the hacking tool they used was not tailored for Tails. Hernandez noticed the attempted hack and taunted the FBI about it, according to the two former employees.
No evidence that it was a TOR exploit, but I interpreted it that way because they FBI and Facebook would most certainly have known he was using TOR from his exit IP rotating frequently and FB explicitly supports a TOR server hostname.
But it doesn't seem to me that the FBI put much effort into this whole thing, maybe it was more a concern for Facebook than for them.
As I understand it knowing that someone is using Tor is usually trivial, the exit nodes normally set a reverse DNS record that signals it and there are exit nodes blacklists
Yeah, Facebook almost certainly receives a lot of attempted traffic from those relatively few TOR exit node IPs, so I'm sure part of their system is aware that they are effectively proxy IPs.
The FBI blew a TOR 0day on this user, it just didn't work against his Tails OS. It's possible that the 0day was sourced from another 3-letter agency.
Anyway, of course it isn't proven, but I would be extremely surprised if said 3-letter agencies even needed a 0-day exploit to identify a Tor user...
Needing Facebook and a consulting firm to find a vulnerability in a video player? Come on, I would find more credible that they used a consulting firm to choose which exploit to use, if they could use all those available to the various agencies... :)
I think I inferred what I said from this quote:
> Several FBI field offices were involved in the hunt, and the FBI made a first attempt to hack and deanonymize him, but failed, as the hacking tool they used was not tailored for Tails. Hernandez noticed the attempted hack and taunted the FBI about it, according to the two former employees.
And everyone else.
Facebook is a honeypot.