top | item 6166302

Users of hidden net advised to ditch Windows

33 points| timetraveler | 12 years ago |bbc.co.uk | reply

26 comments

order
[+] computer|12 years ago|reply
That [title] is a weird thing to take as main message from that advisory. The Firefox exploit that was used would have worked on Linux just as well; it was simply only targeted at Windows this time.

I agree that switching away from Windows is generally a good idea, but only a hardware-based router, or a software based VM isolation solution like Whonix or Qubes OS would have defended the user in this case. Even Tails, the Tor live USB distribution could have gotten owned by this exploit, had the NSA/FBI/hackers chosen to target them.

[+] doctorfoo|12 years ago|reply
How exactly does a hardware based router help? Is the idea that TOR is running on separate hardware, and despite the local system being compromised, the attacker can't "phone out" to find the real IP address?
[+] rmrfrmrf|12 years ago|reply
I was surprised that Windows was the target OS -- I had figured that most Tor users were using Tails at this point. I'm sure that whoever targeted the user group they meant to capture, though, had a good idea of their general usage patterns.

Wouldn't disabling JavaScript have also prevented this exploit? I don't know if FireFox still runs JavaScript through an interpreter if the user has disabled it; I'd assume not, but it wouldn't come as a shock to me if it did.

[+] Torgo|12 years ago|reply
Does the Qubes Tor container egress filter non-Tor traffic? If it does not, it would still be susceptible to a linux-specific version of this same attack.
[+] negativity|12 years ago|reply
Does this mean that Linux, and other Unix variants (but not Mac OS of course, because Apple plays ball), will be classified as a "Hacker Tool" in the eyes of the law?
[+] sobkas|12 years ago|reply
In the "eyes of the law" wget is a "Hacker Tool".
[+] pessimizer|12 years ago|reply
Anything without a well-regulated "app store" will be classified as a hacker tool in the eyes of the law.
[+] shmerl|12 years ago|reply
Windows should be ditched by any user who cares about privacy. This has nothing to do with Tor specifically.