The developers of a privacy-focused operating system championed by Edward Snowden are scrambling to find out the details of a hack that the FBI usedand Facebook paid forto unmask a child predator.
Last week, Motherboard revealed that Facebook had paid six figures to a cybersecurity firm to develop a hacking tool that the company then handed to the FBI in 2017. At the time, Facebook and law enforcement had spent years tracking a California man, who went by the name of Brian Kil online. The man, whose real name was Buster Hernandez, was using Facebook to harass and extort teenage girls, forcing them to send nude pictures of themselves, threatening to kill them and murder their friends.
The hacking tool relied on an unknown flawalso called a zero-day in hacker lingoin the default video player included in Tails, a well-known Linux-based operating system thats used by journalists, dissidents, human rights activists, and security-focused users all over the world. For example, Tails is part of the anonymous tip submission system SecureDrop, which is used by dozens of newsrooms all over the world, including VICE.
Tails key feature is that all internet traffic gets routed through Tor, a network that encrypts and anonymizes connections, masking the users real IP address.
They should have been notified.
The exploit funded by Facebook allowed FBI agents to identify the user's real IP address, which then allowed them to identify Brian Kil as Hernandez. Technically speaking, this hack could have been used against activists and other sensitive people by law enforcement or authoritarian governments. Motherboard reported that Facebook did not inform Tails of the exploit, and decided it was OK to use it because Tails was incidentally patching out the exploit as part of an unrelated update.
But Tails developers, as well as privacy and security experts, agree that, update or not, Facebook should have alerted Tails once the FBI operation was over. Three years later, that has not happened yet, and the Tails developers, as well as the makers of the popular media player, called GNOME Videos, said they found out about all this through Motherboards article.
The only way for Tails to be sure that every single aspect of the zero-day is indeed fixed already is to learn about the full details of the zero-day, a Tails spokesperson said in an email, arguing that its possible that the flaw relied on a chain of other flaws that may still be partially unpatched. Without these full details, we cannot have a strong guarantee that our current users are 100 percent safe from this zero-day as of today.
Tails said that neither Facebook, the FBI, nor the cybersecurity firm hired by Facebook, has reached out to the developerseven after they reached out asking for an explanation.
Do you work or did you use to work at Facebook? Do you work for the FBI or develop hacking tools for law enforcement? Wed love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, OTR chat at lorenzofb@jabber.ccc.de, or email lorenzofb@vice.com
The developers of the targeted video player said they havent heard from anybody either.
GNOME was not previously aware of this story, and is not able to guess which vulnerability might have been exploited, a spokesperson for the GNOME Project, the developers of a free and open source desktop environment and the GNOME Videos player, which are both included in several Linux distributions such as Ubuntu, told Motherboard in an email.
The GNOME spokesperson said that they appreciated Facebook planning to report the vulnerability before discovering it was apparently already fixed, but many people who use their software may still be running an unpatched version. Thats why they expect the FBI or Facebook to contact them to make sure they can alert all users.
The security of law-abiding users is jeopardized when such vulnerabilities are not disclosed to us in a timely manner, the spokesperson wrote.
Facebook said they made an effort to reach out to Tails in the last week, and had confirmation from the FBI that this technique would be used for this case only. (The Tails spokesperson said that, as of Thursday, they had not heard from Facebook.)
I asked an FBI spokesperson whether the FBI used the hacking tool funded by Facebook in other cases, whether it still is in possession of it, and whether it submitted it to a government process that determines whether agencies should keep the flaw secret or notify the software makers, technically known as the Vulnerabilities Equities Process or VEP.
Appreciate you following up, but we still don't have a comment for you, the FBI spokesperson said.
Its unclear whether the zero-day flaw that the exploit relied on has been fixed. When they helped develop and paid for it, Facebook realized it was going to be fixed in an upcoming release, so they decided not to alert Tails developers, according to a former Facebook employee who worked on the project.
Thats perhaps beside the point. Should Facebook, the FBI, of the cybersecurity firm, have alerted Tails or GNOME after Buster Hernandez was safely behind bars?
They should have been notified, a current Facebook employee, who asked to remain anonymous because they were not allowed to speak to the press, told Motherboard.
According to several privacy and security experts, the answer is a resounding yes as well. In fact, many think Facebook should not have gotten involved in making and paying for the hacking tool in the first place.
Facebook is out of control at best and is making the world less safe for people who need anonymity to survive.
The fact that Facebook or any private company would think they had the right to commission the creation of malware against another software entity is so incredibly arrogant, said Katie Mossouris, who used to lead the vulnerability research teams at Microsoft and Symantec and is one of the worlds most well-known experts on coordinated disclosure. Security professionals worth their salt are worried about governments not making the right call when it comes to making decisions in the Vulnerability Equities Process, and were all supposed to be fine with that kind of decision resting in Facebooks hands?
According to Moussouris, what Facebook did in this case is more evidence that Facebook is out of control at best and is making the world less safe for people who need anonymity to survive.
Moussouris used the facepalm emoji when describing how she felt when she read the Motherboard story that revealed Facebooks role in the hacking of Hernandez.
I didnt think a vulnerability disclosure story could possibly horrify me after all these years, but here we are, she said in an online chat.
Harlo Holmes has been developing tools for journalists and activists for years, and now helps media organizations set up SecureDrop and trains their journalists to use tools such as Tails. Holmes said that Facebook needs to be more transparent as to what the vulnerability was exactly, and what the agreement with the FBI was.
"What was in that contract? Was it a one time use license against this one actor? Or did they just hand it over to the FBI and be like 'now this is in your arsenal now'?" Holmes said in a phone call. Those are very, very key questions.
Moreover, she said that its hard to understand how Facebook thought it would be OK to help the FBI hack a child molester, while the company is also suing the spyware maker NSO Group for using WhatsApp to help their customers hack targets.
"The hypocrisy is absolutely wild," she said. More hackers should learn about the ethics of what we do, and this is a textbook example.
Subscribe to our new cybersecurity podcast, CYBER.
Follow this link:
Privacy-Focused OS Wants to Know How Facebook and the FBI Hacked it - VICE
- New York Times pushes clemency for Edward Snowden. Justified? (+video) [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Napolitano Says No Clemency for Edward Snowden [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Hero Edward Snowden? [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- What to do about Snowden: The NY Times gets it right [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Snowden 'an aberration': Booz Allen CEO [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Edward Snowden - Wikipedia, the free encyclopedia [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Will Obama Help Edward Snowden? - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- 2 Newspapers Call For Clemency For Edward Snowden - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Editorials Argue Why Edward Snowden Should Get Clemency - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- EDWARD Snowden - IS HE A HERO OR A TRAITOR??? - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Snowden seeks extra Russian protection after U.S. threats [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Edward Snowden denies that he's a Russian spy [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Snowden Denies Working as Foreign Spy, New Yorker Reports [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Glenn Greenwald I Defend Edward Snowden Like MSNBC Defends Obama "24 Hours A Day" - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Former CIA insider on Sochi Olympics security, Edward Snowden - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Airdate : January 4, 2014 : Clemency for Edward Snowden - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- #10 Edward Snowden a Hoax?? Rockefeller: Human Cloning in Film Documentary Series Jan 20 2014 - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Double Standards - Edward Snowden: Traitor or hero - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Edward Snowden NSA Spying HOAX BUSTED fraud Jan 19 2014 Rockefeller net Ron Rand Paul Breaking News - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Philip and Edward Snowden. - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Did Snowden Act Alone? - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Edward Snowden Denies Russian Spy Theory - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Coastal Today Show, January 20 - 26, 2014 | Full Episode - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- BREAKING! Edward Snowden LIVE in New York Snowed-in Snowden Blizzard Snow Storm - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- New York Times editorial defends Edward Snowden - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- The People's Republic of Edward Snowden - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Snowden says mass collection must end [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Russian lawmaker says Snowden asylum period to be extended [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Snowden Says Whistle-Blower Law Gaps Preclude His Return [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden Denies 'Stealing' NSA Co-Workers' Passwords [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden's Asylum in Russia Extended [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden: 'Not Possible' to Return to U.S. Now [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- What Do We Know About Edward Snowden? Webster G. Tarpley - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- On Edward Snowden, Privacy, NSA, and Accountability - Quick Thought #632 - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden is a SPY? How do you kill a spy? - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Scooter and Snowden [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Edward Snowden: Did the American whistleblower act alone? [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Snowden Says Whistle-Blower Law Gaps Preclude Return [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Hükümete protesto, Snowden'e destek - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Edward Snowden NSA leaker asks for extra security after receiving death threats from US officials !! - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Snowden says officials want to kill him [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- edward_snowden_portrait_twitter_reuters.JPG [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Edward Snowden: There Are 'Significant Threats' To My Life [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Snowden Says ‘No Doubt’ NSA Engages in Industrial Spying [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Edward Snowden Biography - Facts, Birthday, Life Story ... [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Alex Jones Show Friday 1 24 14 Piers Corbin - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- The People's Republic of Edward Snowden part 2 - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Snowden interview turns up few key revelations [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- edward-snowden-reuters-120313.JPG [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Edward Snowden - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- German Television To Air NEW Edward Snowden Interview TONIGHT - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Edward Snowden is nominated for the 2014 Nobel Peace Prize [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Snowden Nominated by Norwegian Lawmakers for Nobel Peace Prize [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Snowden nominated for Nobel Prize [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Snowden Gets Nobel Peace Prize Nomination From Norwegian MP - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- BREAKING: Edward Snowden Nomination For Nobel Peace Prize! - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Edward Snowden's Psychic Human ETs - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Report puts Snowden-like leaks as No. 2 threat to US security [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Why Silicon Valley sticks up for Snowden [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Snowden nominated for Peace Prize [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Edward Snowden Nominated For Nobel Peace Prize - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- UK spy chief to step down: GCHQ boss Iain Lobban leaves in wake of Edward Snowden NSA leaks - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Is Edward Snowden Behind Target Hacking? - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Snowden: NSA Mining App Data to Track Targets - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Snowden nominated for Nobel Peace Prize [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- [CCTV FOOTAGE]Edward Snowden Gunshot January 31, 2014 - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Obama administration nominates new NSA director - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden nominated for Nobel Peace Prize: NSA whistleblower has exposed US spying - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden's Norwegian Nobel nomination called into question - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden the Peace Prize Winner? - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden, a Party to Subverting Nations in Latin America [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Edward Snowden: World's most wanted man [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Politicians attack Great Barrier Reef, Edward Snowden and TV Reporter - TFU Friday - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- WikiLeaks, Greenwald Blast Guardian Journalist’s Book On ‘FSB Prisoner’ Snowden [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Killing Edward Snowden on Occupy The Microphone - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Edward Snowden January 25, 2014 Interview Links - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Edward Snowden Documents reveal Canadian Spies Exist! - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- 20140203 - Barking at the moon - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Snowden aftermath: Defense contractors revamp policies, practices [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Booz Allen Exec Describes How Snowden Stole Millions of Documents [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]