Earlier quoted context omitted.
People under influence do indeed pose danger to other people. Even the influence of alcohol is potentially dangerous in certain situations leading to incidents ranging from hit and run to domestic violence.
Even alcohol? Alcohol is the most endangering drug. Because of wide spread use (no competition because in many places it's the only legal drug), addictiveness, toxicity and intrinsic nastiness of influence it has on some users.
Underground Hansa Market taken over and shut down
161–170 of 381 posts
Re: Underground Hansa Market taken over and shut down
#162Earlier quoted context omitted.
When laws are bad, its bad when people face the repercussions of those laws.
Yeah but debating whether the law itself is bad is a separate discussion. Until the laws change people can't be outraged or surprised when they got caught up in them... Besides, it's possible that many of the users live in countries where _buying_ drugs isn't a crime, or where circumstantial evidence like this isn't enough to warrant opening an investigation. So it's possible that most of these users won't even face…
Re: Underground Hansa Market taken over and shut down
#163> Some 10,000 foreign addresses of Hansa Market buyers were passed on to Europol. That's really bad, because not all countries are Holland, which is famous for its 'relaxed' attitude towards drugs in general, so some users might have their lives turned around by this - followed, arrested, jailed, extorted, etc.
There's still no proof of payment. How could you win the case? I could easily order drugs to someone I don't like.
http://www.sandia.gov/news/publications/labnews/articles/201...
https://motherboard.vice.com/en_us/article/7xz35e/us-law-enf...
http://www.coindesk.com/elliptic-partners-with-risk-controls...
Re: Underground Hansa Market taken over and shut down
#164Earlier quoted context omitted.
Law enforcement could have easily MITM'd the PGP. They replace the public key of a vendor with their own public key (on the vendors's page, without the vendor's/buyer's knowledge), then the buyer address gets encrypted with that public key. Then they decrypt and resend the message using the sellers original public key. I really wonder if this happened at all
They can't MITM secure email from buyers to vendors (the direction with actual physical addresses) unless they subvert either the buyers or vendors email server. The actual email does not go through the site.
Re: Underground Hansa Market taken over and shut down
#165I would love to know how they got caught. There is probably something to learn about opsec from this. The paranoid side of me says Tor is unsafe (due to whatever - the authorities having backdoors on most hosting services, on your PC, due to the encryption being cracked by some unknown breakthrough or due to 90% of entry nodes being controlled by NSA). And NSA and FBI and co just have hundreds of people working on "p…
Every time a market has been taken down it's been due to OPSEC failure and other information leaks (e.g. Silk Road captcha IP leak, DPR's advertising of market being linked to his personal email address). AlphaBay Which got taken down first in this operation was due to a personal email being included in the header of the welcome email sent out to new users 3 years ago [1] [1] https://www.justice.gov/opa/press-release…
1) They were investigating AlphaBay for nearly 3 years 2) They came upon somehow control of an email address which contained 3 year old mail that contained the password reset email 3) They are capturing and storing large amounts of tor traffic much like the NSA does on clearnet see: xkeyscore
This isn't really explained in the indictment
Re: Underground Hansa Market taken over and shut down
#166The clever thing is that they took it over and for one month monitored it without the users knowing. Everyone on obfuscating their persona with Tor and bitcoins, still had to enter their postal addresses on the website, to receive the goodies. That database must be a wet dream for law enforcement.
From what I remember poking around at Hansa that's not true. Each vendor / user had a public key associated with their account. All text communication through the website was supposed to be with GPG encrypted text secured by private keys unavailable to website. So law enforcement has lots of encrypted text along with some clear text from users not informed enough to follow any kind of opsec.
Re: Underground Hansa Market taken over and shut down
#167Earlier quoted context omitted.
Not everything that is illegal is wrong. E.g. being gay is illegal in many places.
Buying drugs can fund actions far worse than just creating drugs. From human slavery (drug mules) to murder. Some of the other things on that list are bad not because the actual item being traded is bad, but because of what the trade enables. I'm not seeing a significant difference between the markets in this regard, except for popularity. Compared to the example you gave, where no one is harmed and no further harm i…
I buy my marijuana from a friend who grows a few plants in his basement. How exactly is that funding slavery and murder?
Re: Underground Hansa Market taken over and shut down
#168Earlier quoted context omitted.
Law enforcement could have easily MITM'd the PGP. They replace the public key of a vendor with their own public key (on the vendors's page, without the vendor's/buyer's knowledge), then the buyer address gets encrypted with that public key. Then they decrypt and resend the message using the sellers original public key. I really wonder if this happened at all
This has me curious (as a complete crypto noob): how would one defend against such a MITM attack in general? Only send messages to vendors with known "trusted" keys and don't trust new keys? So in general, use a trusted channel for key exchange separate from the communication channel so that a MITM needs to control both channels?
Re: Underground Hansa Market taken over and shut down
#169Earlier quoted context omitted.
good argument for legalisation....
The counterargument is that if drugs are legalized then the crime syndicates will need to find a new line of work. It's possible they'll go "legit" like the mob did after prohibition and get into the Casino business, but it's also possible they'll switch to human trafficking or gun running or some other harmful trade. This is an especially big danger if you're talking about a gang that currently deals mostly drugs bu…
Re: Underground Hansa Market taken over and shut down
#170I would love to know how they got caught. There is probably something to learn about opsec from this. The paranoid side of me says Tor is unsafe (due to whatever - the authorities having backdoors on most hosting services, on your PC, due to the encryption being cracked by some unknown breakthrough or due to 90% of entry nodes being controlled by NSA). And NSA and FBI and co just have hundreds of people working on "p…
Every time a market has been taken down it's been due to OPSEC failure and other information leaks (e.g. Silk Road captcha IP leak, DPR's advertising of market being linked to his personal email address). AlphaBay Which got taken down first in this operation was due to a personal email being included in the header of the welcome email sent out to new users 3 years ago [1] [1] https://www.justice.gov/opa/press-release…
This is true, but it dangerously misses the point. Every time someone gets taken down, the know-it-alls on various fora sneer and go "Ha! What terrible opsec! I wouldn't have made that mistake!" No, you would've made some other mistake.
To run a darknet market and not get caught, your opsec has to be perfect. Every second, every minute, every day, every person involved, forever. That is simply not possible once an operation exceeds a certain size. Like the IRA once said: "We only need to be lucky once. You need to be lucky every time". This is the "defender's dilemma" that guarantees you will be caught as t goes to infinity: sooner or later, you'll make some mistake that burns you.
Focusing on the specific mistakes made by bust-ees only boosts your confidence and ignores that you, in their situation, would've leaked information somewhere else.