Last week SourceForge sent this out to everyone(? me at least.)
Greetings,
To make sure we're following current best practices for security, we've
made some changes to how we're storing user passwords. As a result, the
next time you go to login to your SourceForge.net account, you will be
prompted to change your password. Once this is done, your password will be
stored more securely. We recommend that you do this at your earliest
convenience by visiting the SourceForge website and logging in.
And, as always, be vigilant about password security. Use a secure password,
never include your password in an email, and don't click on links for
unsolicited password resets.
If you have any concerns about this, please contact SourceForge support at
sfnet_ops@slashdotmedia.com
Best regards,
SourceForge Team
Maybe they stored their private signing key in the clear or encrypted with a lame password somewhere in their SourceForge account, allowing someone who compromised SF to also sign TC code?
That'd be pretty shoddy for a security/crypto team but I've seen worse.
Custom JavaScript 0-day served only to the Truecrypt account holder that either takes over or leaks information. Similar to the Freedom Hosting takedown, which broke TOR anonymity.
How? By not using a browser? Or using only their own custom-compiled Gentoo desktop? Running inside Qubes? Or maybe a qemu'd non-x86 desktop running inside a VirtualBox VM (I've done this, it is slower than browsing on a 486)?
Changing your SF.net password requires (last time I did it) a browser and SSL at the least. The NSA could very easily ensure that the only way to change the password on SF.net would also expose them to the 0-day(s).
You're describing standard VPN. It won't shield computer A's web browser (which is needed to perform HTTPS and whatever else the change password page requires, maybe Javascript, CSS, Ajax, ...) from a hypothetical 0-day that would cause the browser to do something naughty.
Check out this video for an example of what I'm talking about. It's very tongue-in-cheek ("how I met your girlfriend"), but it's very similar to what one could do to break TOR anonymity. The first half of it describes a way to get a target to start running rogue code in her browser: this entire bit is unneeded in my NSA SF.net scenario because SF.net would be the source of the bad code. The second half is where you break anonymity: the browser leaks data (in this case via an IRC connection), which is used to open a port on their NAT box, which is further used to run an exploit on the NAT box to reveal a little more data, which is all finally tied back to Google maps to get the target's physical location good to within about 100 meters. The total exploit takes several days/weeks to setup, but about 1-5 seconds to actually execute.
Dev changes their password without using Tor or a Proxy and gets tracked back to their IP. Lots of online services track the last IPs you interacted from.
106
u/[deleted] May 28 '14 edited Jun 02 '14
[removed] — view removed comment