Funnily enough the IP address in the iframe location is in a /11 formerly belonging to D.C.-headquartered MCI Communications, now under Verizon, and traceroute points to it being in D.C. as well.
This could be faked, but it's interesting on its own.
So the founder of Tor Freedom is arrested and now this. Quite a coincidence. Maybe not NSA, but probably some kind of government agency. I think the best bet people can make these days is to assume that government is guilty and means to do nasty things - until proven otherwise.
Probably because they have a hard-on for snooping and TOR, by design, makes it extremely hard to correlate usage with a person without owning exit nodes and/or social engineering.
Realistically though, if the NSA were going to penetrate TOR, they would just own exit nodes and do social engineering. Bear in mind that the American government had a hand in building TOR to begin with.
That this appears to be so blatant suggests to me that it has nothing to do with surveillance at a state level.
Realistically they'd probably use a variety of approaches. Each approach could have its own limitations or be closed off without much notice. Wouldn't you want to hedge your bets?
Even if it isn't outside the realm of possibility, I don't think it's plausible for an organization that's supposedly powerful enough to monitor and archive all domestic and incoming electronic communication, when there's an entire ecosystem of hackers and skiddies out there anyway who do this kind of thing elsewhere all the time. JS in an iframe? XSS? Why would they even bother?
It is NSA[1]. No implication needed. FBI nabs host owner and suddenly code is injected to exploit all end users? Rather tired of people downplaying these events at every attempt. What does your comment add? At least the parent comment you are responding hinted at a potential suspect.
Perhaps he doesn't want to be hunted either directly implicating the US for the US's work.
Seriously, bring something to the discussion if you are going to be asking others to do the same.
By the way the person who started the site linked is being prosecuted by the DoJ[2], no doubt with others involved being hunted down as well. I'm sure there is no implications to any of this.
FBI, who happens to work as a conduit for the NSA, along with any number of the other acronym boys? Or the corporations they hire while handing out legal immunity for the actions they are hired for? Or Google and others who also accept payoffs and immunity for helping monitor the acronym boy's targets?
How is the various crony corporations publicizing these deeds as services not relevant? This is the subject of exploits being used on users of a host whose owner was arrested, correct?
I am readily awaiting a more logical answer than another contracted service like Endgame and their pool of exploits they are so ready to use on the non legally immune citizens of the world. Or companies like Google for going along with the dragnet monitoring and exploitation of dissidents.
All of them are connected by virtue of payoffs, insider trading, market manipulation. None of it is irrelevant.