Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - kmfkewm

Pages: 1 ... 41 42 [43] 44 45 ... 249
631
kmfkewm mentioned that having iframe enabled might be enough for the exploit to work.

Fuck me but I did try to access bud porn on servers that were probably targeted by the feds  (I got the server maintenance page).

I don't view cp and never have but am screwed here because I tried to access one of the targeted servers?

I mean I've probably accessed nug porn images on any of those servers dozens of times.  Since the feds won't have access to my Tor browsing history, how will they differentiate between those that viewed cp and those that didn't?

I can imagine that them having a record of someone accessing the server (through the js exploit) would be enough probably cause for warrants but I would have to have them seize my computers for them to do forensic analysis to determine that I, indeed, don't and never had cp?

wtf???

They can probably differentiate between those who attempted to view CP and those who attempted to view drug images.

632
Showing my ignorance, what is iframe?

An embedded frame that loads remote HTML, kind of like a hotlinked image but a hotlinked website instead.

633
I hate that all of the tech stuff flies over my head for the most part. Should I be worried if all I use is a thumb drive with Liberte? I had two tormail accounts that I had never used to send anything. Nor have I logged into them for many months. I never reused passwords but had a tormail matching my sr username.

I don't think Liberte users are vulnerable because it doesn't use Firefox or Iceweasel does it?

Quote
Is there any information on how he was tracked down and arrested?

No I don't think there is. I don't think there is even any proof yet that this is actually him, although circumstantial evidence strongly suggests that it is. I do know that he used virtual machines to isolate his web servers though, that means if he was hacked the hackers had to break out of a virtual machine, which is pretty advanced compared to everything we have thus far witnessed LE hackers do. Another possibility is that his server was traced to its entry guards and then LE got a court order to tap an identified entry guard in order to locate his hidden service. Another possibility is that he fucked up in some other way, maybe social engineering got him or maybe the datacenter his server was at noticed he had 24/7 terabytes a day of Tor traffic.

Quote
It APPEARS that anyone using a non-windows system has nothing to worry about.  This includes tails and any other linux-based, or mac osx systems.  The exploit has been reported to only work on the windows OS.  While we cannot be sure this is the case, it does seem plausible.  However, if the exploit does work on non-windows systems then using tails, etc. would likely not protect you from having your IP address discovered, as the IP provided by your ISP would be the same whether you use tails or not.

The exploit only targets what looks like Windows OS, but Tor Button makes all Tor users look like they are using Windows. So it is not certain that it wont work against Linux users, it will try to exploit them anyway due to the fact that Tor Button spoofs user agent to look like Windows. I have seen a few peoples opinions on this exploit code so far, and nobody is yet willing to say if it works against Linux or not. So far I have not heard much that sounds very solid.

Quote
I have done quite a bit of research on javascript and IP address discovery.  There is no way that I have discovered to obtain your location's public IP address from javascript.  All that (non-hacked) javascript has the capacity to do is report the private IP address of the local computer it is running on, which is useless to LE.  Its clear that the FBI, or someone the FBI bought the exploit from (yes, the FBI buys shit off the black market too), has a way to do this.

Javascript directly cannot obtain IP address, but it can be used to take full remote control of a persons computer, because it can be used to exploit security vulnerabilities in firefox or whatever, and that is what people think has happened.

Quote

Was the Freedom Hosting owner even keeping his identity secret?  I assume he didn't provide free hosting services.  Perhaps he only allowed anonymous currency payments.  Its not clear from any of the reports I've read.  Its also not clear whether he was responsible for the child porn directly or his company hosted a hidden service that was responsible.

He kept his identity a secret and he did offer free hosting services.

Quote
Alright, so they got freedom hosting. The owner apparently had a history with child pornography. Illegal photographs were being hosted on freedom hosting's servers.. but they can't necessarily use that same tactic to shut SR down.. am I right? Yes, drugs are being sold here, but that doesn't give them any more than they already have to go after the company that hosts SR. Am I the only one who doesn't believe SR is next?

Of course they could use the same tactic to shut SR down.

Quote
Does anyone have any guess as to whether deleted messages on Tormail would be recoverable by an agency? Im thinking specifically ones that I deleted a year or so ago.

It may be possible, or it may not be, it depends on too many variables that we do not know. You should have used GPG.

Quote
I'm not entirely clear on what is/has happened here, are people saying the java script exploit was up and running before the FH sites went down or after?

The claim is that the exploit was injected during the down time, and during the time when the server is down message was coming up.

Quote
I think that FH was just allowing .onion sites to be hosted, I dont know if he directly was involved in CP or if it was just more of a "He allowed them to be hosted , Hes as guilty as the people downloading them"

He didn't host CP himself and he actually said in the rules that he wouldn't allow CP to be hosted, but he also turned a complete blind eye to it and obviously was fine with people using his server to host CP.

Quote
None concrete yet.

I am beginning to believe it was his own negligence that lead to his identification and arrest. He also ran a clearnet host (hostultra.com) and didn't seem too concerned about keeping his identity a secret (clearnet - http://www.webhostingtalk.com/showthread.php?t=157698). Freedom Hosting apparently had quite a lot in common with Host Ultra which, while circumstantial, could raise suspicion.

Also, Anonymous leaked specific software information about the Freedom Hosting server in fall of 2011. He was the wrong guy in their witch hunt but the information they collected I'm sure was filed by the FBI.

There is speculation of him running other deepweb services (I've read he ran OnionBank? any confirmations on that?) and there is also mention of large amounts of money running through his own bank account which is unlikely to be from Freedom Hosting as his plans were all unmetered. He could have been taking under-the-table payments to keep CP sites online above normal fees, and that would leave a paper trail if the client had been caught or was under investigation - or if a client that paid him under the table was actually law enforcement. There's also a bit of focus on a transaction to Romania (6000 euros) from his own bank account, which he claims is investment in another business. It's been mentioned in a couple of threads the possibility of "real life" social engineering.

It says the FBI has been investigating him for a year. He is also a US citizen, though living in Ireland since age 5 and the warrant is issued from Maryland.

Sorry I can't provide more info.

ER.

I don't think he was too stupid or anything, he had some of the best technical security of anyone in onionland and he has been running Freedom Hosting for quite a lot of years now with no issues. He also didn't charge anything for hosting anything. Also the person who is busted used his credit card to withdraw 6,000 Euro in romania but also sent about half a million dollars worth of Euros to Romania through his bank account.






634
First of all, yes all of the Tor Project software, from Tor Browser to Tails, ships with javascript enabled by default. If you didn't turn it off, then it is on. I always thought it was stupid for them to ship with javascript enabled by default, and maybe now they will wake up to this fact.

Second of all, nobody has actually shown any proof that this guy who got busted is the owner of Freedom Hosting. It does look like he probably is, since he was busted running multiple websites hosting more than a million images of CP. On the other hand, there are busts of people running large websites with many images of CP on a fairly regular basis, just a few years ago there was a bust in Ukraine of people running dozens of CP pay sites with millions of images on them, but nobody jumped to the conclusion that it was freedom hosting at the time. On the other hand, in this case we just don't know the details of the operation, in the Ukraine case they talked about pay walls and paypal and etc, in this case we only know the very basic facts. Also it is a bit weird that the busted guy had funneled like half a million dollars through his bank account, that makes it sound like perhaps he was operating a for pay CP network, or maybe he is just some rich fuck who owns his own hosting company. Running a site like Freedom Hosting would probably require at least five hundred bucks a month, so since he did it for free he obviously was pretty well to do. So yeah it looks like Freedom Hosting admin was busted, but I have not seen any concrete evidence on this yet, and a lot of the stuff I am seeing about it looks like it is fresh from the asshole of Anonymous trying to scare everybody. Nobody in the news has linked Freedom Hosting to this busted guy, it has all been random fucks who seem to have no solid evidence that the person busted is freedom hosting admin. On the other hand, it looks like at least one person running a CP site on Freedom Hosting claims that they had javascript exploits injected into their site content, so that is certainly not a good sign.

Also No Script shipped with Tor Browser has iframe enabled by default so I don't think it is going to protect anyone from this if it turns out to actually be real.

635
Security / Re: Tormail founder arrested
« on: August 04, 2013, 12:22 pm »
I always thought it was stupid that Tor Project left javascript on by default in Tor Browser. I really question a lot of choices that they make in the name of making their software more user friendly. Leaving javascript on to "hide your browser fingerprint in a larger crowd" might turn out to be about the same as wrapping a rope around your neck , tying it to a fan, and jumping off a chair, because you don't want to step on a tack on the floor.

636
Legal / Re: Countries where some drugs are legal
« on: August 04, 2013, 08:21 am »
I think also in Spain all personal use is legal, but correct me if I am wrong.

637
Legal / Re: Countries where some drugs are legal
« on: August 04, 2013, 08:05 am »
I heard somewhere that Uraguay is going to legalize Cannabis for personal recreational usage.

All drugs are already legal for personal use in Uraguay, they are making cannabis legal to produce and sell (legal for anybody to grow, legal for the government to sell).

Czech Republic has similar laws, personal use amounts of all drugs are completely legal, you cannot even get a ticket for them or have them seized from you.

Portugal has also decriminalized personal use amounts of all drugs but it isn't quite to the same degree as Czech Republic for example. If you get caught with personal use drugs you can still have them seized from you, and you can still be taken to court. If the Judge at court determines you are an addict they can sentence you to drug treatment, otherwise they can give you a small fine, or they can just let you off. So it isn't really like drugs are decriminalized in Portugal it is just that for personal use amounts of anything the worst sentence you can get is outpatient drug treatment and a small fine.

638
Security / Re: Tormail founder arrested
« on: August 04, 2013, 04:23 am »
Yikes I wonder how they traced somebody who used virtual machine isolation plus Tor. It seems that either they broke Tor to trace him or they hacked into his server and busted out of layers of virtual machines. In either case that is fucking scary.

639
Drug safety / Re: DMT, What did I do wrong?
« on: August 03, 2013, 02:29 pm »
Here is the thing about DMT. 50% of the time it will have no effect or very little effect. 50% of the time you will massively overdose on it and feel like you just smoked ten tons of crack. I have not been able to find the mystical in between place for DMT, and I know a lot of other people who have similar things to say about it.

640
Drug safety / Re: Ketamine, what the hell?
« on: August 03, 2013, 02:26 pm »
IMO with K you have to decide: or you use it as a recreational drug or you use it as you would a strong psychedelic.

If you go with the recreational route then stick to low doses (naturally taking care of tolerance that increase quite fast). If you go for the psychedelic one instead go for a k-hole. The space in-between the two is usually uncomfortable in both cases because it's not one nor the other and it gives no benefits for what you want to do. If you want a recreational feeling then a too high dose will just make you feel sort of drunk and not able to do what you want to do and if you want a mystical or psychedelic experience everything lower than a k-hole is a waste and  will not give what you search.

Pretty much this. 100mg is likely either too little or too much, depending on what you are aiming for. Either about double the dose (to 1mg per lb you weigh) or cut it in half.

641
Drug safety / Re: Ketamine, what the hell?
« on: August 03, 2013, 02:22 pm »
100mg is a bad dose imo, you want to either k hole or do nothing is my opinion. Some people like low dose ketamine but for me it just feels uncomfortable. Unless you only weigh 100 pounds 100mg is a low dose. Try taking 1mg per lb that you weigh and see how you like it. I like it a lot more at that dose than something like 100mg, which isn't enough to k hole and just makes me feel kind of woozy.

642
Security / Re: FBI Taps Hacker Tactics to Spy on Suspects
« on: August 03, 2013, 10:02 am »
Or they could hack into the SR server and then hack into you when you load a page hosted on it.

643



Actually in a libertarian world this would be much less likely to happen. Libertarians are more in favor of gold standard, and most are very against fiat money. One of the main things the banks do is fractional reserve banking, where they can loan out more money than they actually have. This is only made possible because of the government, and the only reason fiat currency has any value at all is because the government demands that taxes are paid in it. Libertarians are generally against the idea of taxation, which means they generally view fiat currency as being inherently worthless. In a libertarian society, a bank that loaned out more gold than it has would be considered to be engaging in fraud, and all of the fiat currencies in the world would be seen as about as valuable as toilet paper.

Just to be clear, are you proposing a strict gold standard? Where banks can literally only issue paper to the value of gold they hold?  Surely not? Fractional reserve banking came about because it is extremely useful. It is possible for a bank to engage in it entirely alone, based on its customers confidence in its ability to meet its obligations. It is not inherently fraudulent. Nor does it need government backed fiat currency to work. Banks have been issuing many times more currency than holdings since the 17th century. Its something they can do completely independent of government backing.
         Of course, at various points in history governments or more usually monarchs have become enraptured by the seemingly magical ability to print money to pay their debts and this is where many of the problems begin.

I am proposing a strict whatever the hell people want standard. People don't want money that has value because it is used to pay off the mafia. The dollar is only worth anything because taxes are paid in it. Fractional reserve banking is pretty close to inherently fraudulent. If you have 10 bars of gold how can you loan out 80 bars of gold? Banks have pretend money and it is used for them to make real money. If I write a check to the bank for 10 times more money than I have, and then I use the cash for investments, it is considered fraud right? So why can the bank give out 10 times more money than it actually has? The only reason it can is because the government says that it can. The bank makes money out of nothing and then gets rich from it. That wouldn't happen in a libertarian world, because nobody really wants pretend money, and you can't really loan out 80 bars of gold when you only have 10.

644
Security / Re: FBI Taps Hacker Tactics to Spy on Suspects
« on: August 03, 2013, 05:06 am »
Moral of the story: Don't be dumb. Don't share your 'business' laptop, don't download anything 'unknown'. don't leave your computer unattended, etc etc. The whole Tails usb setup would seem to counteract against the possibilities outline in the article.

Tails does little to stop this sort of attack. You really need things like isolation, memory randomization and highly audited or better yet formally verified software to counteract the risk of hacking techniques. Tails doesn't use any of these things really. Qubes uses sophisticated isolation techniques, OpenBSD has full memory address space randomization and there are a few formally verified kernels but I think none of them are available to the public. LE with hacking tools is actually really bad news.

Or just don't click random links...

Not clicking random links works great until the server you are visiting is hacked and then you are hacked through it.

645
Security / Re: Freedom Hosting down?
« on: August 03, 2013, 04:49 am »
I didn't know you double posted I was just trying to start a pattern :).

Pages: 1 ... 41 42 [43] 44 45 ... 249