Users of hidden net advised to ditch Windows
bbc.co.uk
bbc.co.uk
I agree that switching away from Windows is generally a good idea, but only a hardware-based router, or a software based VM isolation solution like Whonix or Qubes OS would have defended the user in this case. Even Tails, the Tor live USB distribution could have gotten owned by this exploit, had the NSA/FBI/hackers chosen to target them.
Wouldn't disabling JavaScript have also prevented this exploit? I don't know if FireFox still runs JavaScript through an interpreter if the user has disabled it; I'd assume not, but it wouldn't come as a shock to me if it did.
Before this issue they even advised _not_ to disable javascript, since that would make you stand out more amongst Tor users.
https://www.torproject.org/docs/faq.html.en#TBBJavaScriptEna...
I believe this issue has caused the Tor people to realize this more than ever, and think/hope that some priorities and tools within the project will change as a result.
I guess you could do this with TAILS and a usb stick though.
It's possible to virtualize Tor (without running a dedicated router) so that it, too, doesn't know the external IP address. You can do this, as an example, in FreeBSD jails, and instruct the firewall to NAT all connections from/to the jail in which Tor is running. Of course, having a dedicated hardware router running Tor is even safer.
Now, would the world be a better or worse place if someone got SCOTUS to agree that DC v Heller applied to 0-day exploits? Personally, I don't know if I could answer that.
I'll take a liberal, CATO-Institute-on-2nd-amendment stance on the concept of what is considered "Well-Regulated" in the eyes of the Law [1].