[liberationtech] Freedom Hosting, Tormail Compromised // OnionCloud
R. Jason Cronk
rjc at privacymaverick.com
Tue Aug 6 12:28:35 PDT 2013
Plausible and clever in it's simplicity. Moral of the story: host your
own server. Anybody know what ever happened to Publius[1]? Did that
concept ever go anywhere?
1 http://www.cs.nyu.edu/waldman/publius/
On 8/6/2013 1:38 PM, The Doctor wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On 08/06/2013 10:18 AM, Pavol Luptak wrote:
>
>> The question is how FBI gained access to Freedom Hosting? What kind
>> of exploits did they use?
> Freedom Hosting offered web hosting services to people that asked for
> it, yes?
>
> A hypothesis I've seen floating around (without evidence, that's all
> it is) is this: The FBI asked for and received web space on Freedom
> Hosting. They uploaded an app that they knew had a couple of
> vulnerabilities that allowed for server side code execution and used
> them to compromise other sites on that machine. No need to send
> ninjas to raid the cookie jar when you can say, "Mother, may I?"
>
> - --
> The Doctor [412/724/301/703] [ZS]
> Developer, Project Byzantium: http://project-byzantium.org/
>
> PGP: 0x807B17C1 / 7960 1CDC 85C9 0B63 8D9F DD89 3BD8 FF2B 807B 17C1
> WWW: https://drwho.virtadpt.net/
>
> Livin' la vida alpha test.
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v2.0.20 (GNU/Linux)
> Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
>
> iEYEARECAAYFAlIBNJAACgkQO9j/K4B7F8GoOgCg6tLxg4LDf08CX64XsLTBQvlj
> kmQAn34OwraBqPwY8EH+rt2O1QLd6zC8
> =eZ9N
> -----END PGP SIGNATURE-----
> --
> Liberationtech list is public and archives are searchable on Google. Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at companys at stanford.edu or changing your settings at https://mailman.stanford.edu/mailman/listinfo/liberationtech
>
*R. Jason Cronk, Esq., CIPP/US*
/Privacy Engineering Consultant/, *Enterprivacy Consulting Group*
<enterprivacy.com>
* phone: (828) 4RJCESQ
* twitter: @privacymaverick.com
* blog: http://blog.privacymaverick.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.stanford.edu/pipermail/liberationtech/attachments/20130806/7bc02d11/attachment.html>
More information about the liberationtech
mailing list