Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > News > Tech News > Child porn bust takes down half of Tor network; fed malware spotted

Child porn bust takes down half of Tor network; fed malware spotted
Thread Tools
NewsPoster
MacNN Staff
Join Date: Jul 2012
Status: Offline
Reply With Quote
Aug 5, 2013, 11:14 PM
 
Following the arrest of a Freedom Hosting service provider supervisor in Ireland, whom law enforcement has referred to as "the largest facilitator of child porn on the planet," some reports have surfaced of a JavaScript exploit of vulnerabilities in the anonymizing Tor Browser bundle. The exploit compromises Firefox, and forces the browser to send the computer's regular IP address to a Verizon IP address along with information on Tor sites visited to a data farm located in Reston, Virginia that is associated with US law enforcement.

According to security researcher Brian Krebs, "Tor software protects users by bouncing their communications across a distributed network of relays run by volunteers all around the world. As the Tor homepage notes, it prevents anyone who might be watching your Internet connection from learning what sites you visit, it prevents the sites you visit from learning your physical location, and it lets users access sites that are blocked by Internet censors."

Freedom Hosting, before its takedown, was the host for some of the Tor network's highest-traffic sites, including TorMail and the Hidden Wiki. Every site hosted by Freedom Hosting became inaccessible around 6:40AM EST on August 4.

Tor users are noting a "very large drop" in the number of 'onions,' or Tor-protected websites, due to the fall of Freedom Hosting. Other operators of Tor sites are finding JavaScript code embedded in sites, spreading the malware which sends identifying information to the Virginia data center. The center is managed by Science Applications International Corporation (SAIC), a US technology contractor known for doing work with the FBI. SAIC is headquartered not far away.

The Tor browser is based on Firefox 17. The current version of Firefox, version 22, is not susceptible to the vulnerability.
( Last edited by NewsPoster; Aug 6, 2013 at 03:33 AM. )
     
pairof9s
Senior User
Join Date: Jan 2008
Status: Offline
Reply With Quote
Aug 6, 2013, 08:02 AM
 
I'd say this malware is a good thing.
     
lkrupp
Forum Regular
Join Date: May 2001
Location: Collinsville, IL, USA
Status: Offline
Reply With Quote
Aug 6, 2013, 10:45 AM
 
A lot of pedophiles are looking over their shoulders I would expect. Another nail in the coffin of so-called "freedom" sites. They are nothing but fronts for criminal activity and always have been.
     
Grendelmon
Senior User
Join Date: Dec 2007
Location: Too F'ing Cold, USA
Status: Offline
Reply With Quote
Aug 6, 2013, 11:11 AM
 
This article completely misses the real story behind this:

http://arstechnica.com/tech-policy/2013/08/researchers-say-tor-targeted-malware-phoned-home-to-nsa/
     
Flying Meat
Senior User
Join Date: Jan 2007
Location: SF
Status: Offline
Reply With Quote
Aug 6, 2013, 01:19 PM
 
@Ikrupp,
I think that's an awfully wide brush your wielding there. "...nothing but fronts for criminal activity." You may be oversimplifying a little bit.
     
Makosuke
Dedicated MacNNer
Join Date: Aug 2001
Location: California
Status: Offline
Reply With Quote
Aug 6, 2013, 02:17 PM
 
Claiming that Tor and similar anonymizer services are "only for criminals" is a massive oversimplification--there are real implications for people in countries like China with repressive governments that monitor and/or block all internet traffic, people who would rather the Google Adsense network wasn't tracking their every move, and even in the US, where we've learned that your activity might not be so unmonitored by the government as you think.

That said, the potential for abuse is massive, and the sad fact is that you have things like Tor being used to distribute child porn and Bitcoin used to pay for hacking services on blackhat sites or drugs and counterfeit stuff on Silkroad. Criminals needed an equivalent of cash and a back alley instead of credit cards and phones, and these technologies provide that.

How to deal with this is a big and real question, and I don't think it's as simple as "information wants to be free, child porn is the cost thereof".
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 05:04 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,