LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Friday, October 4th, 2013

    Time Event
    2:18p
    Friday's security updates

    Fedora has updated icedtea-web (F18; code execution) and rubygems (F18; F19: denial of service).

    Gentoo has updated perl-Module-Signature (code execution).

    openSUSE has updated boost (input validation bypass).

    11:39p
    Attacking Tor: how the NSA targets users' online anonymity (The Guardian)

    Writing at The Guardian, Bruce Schneier explains in his latest Edward Snowden–related piece that the US National Security Agency (NSA) had tried unsuccessfully to mount an attack against the Tor network, in hopes of bypassing the service's anonymity protections. Nevertheless, the NSA is still able to identify Tor traffic and track individual Tor users (despite not knowing their identities), which can lead to further surveillance. "After identifying an individual Tor user on the internet, the NSA uses its network of secret internet servers to redirect those users to another set of secret internet servers, with the codename FoxAcid, to infect the user's computer. FoxAcid is an NSA system designed to act as a matchmaker between potential targets and attacks developed by the NSA, giving the agency opportunity to launch prepared attacks against their systems." By targeting a Tor user, the agency could then leverage attacks like browser exploits to get into the user's system; nevertheless, so far the design of Tor itself seems to be functioning as planned.

    << Previous Day 2013/10/04
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org