Live data from Hacker News

Dark.fail: Is a darknet site online?

dark.fail

31–40 of 44 posts

Re: Dark.fail: Is a darknet site online?

#31

Is an illegal* site online? If I built this service I’d just log all the IPs from the requests and just hand them to the FBI.

Even if they had your IP address, they would not be able to track which sites you are visiting on the onion network anyway. You could just be visiting the CIA's Official Onion Site.

Re: Dark.fail: Is a darknet site online?

#32

Tor admins and cyber researchers rely heavily on this site to disseminate links in the wake of DeepDotWeb’s takedown. DDoS attackers seem to love it too as some sites change their .onion URLs ~hourly. Interesting how all sides of a battle can find a simple verified link so useful.

> some sites change their .onion URLs ~hourly. Not sure why you would do this? Do you have an example?

If DDoS traffic is aimed at domain1.onion, changing your site to donain2.onion would avoid that, wouldn't it?

Re: Dark.fail: Is a darknet site online?

#33
post #22

Earlier quoted context omitted.

I'm not trying to be a dick and you're obviously free to do what you wish (in case you wonder, I have not downvoted you). But this attitude has absolutely ruined the web. Despite all the improvements in web technologies, browsers and even bandwidth, I have noticeably more difficulty consuming good information today. This is 100% because of lax attitudes to user privacy. Please stop. :)

A few months ago, I had someone tell me on the programming subreddit that, while they were very concerned about privacy and Google Chrome, they tried Firefox but went back to Chrome because (and I am not making this up) the font kerning in Firefox was slightly suboptimal in certain situations. That's what we're fighting against. This was someone on a technical forum who understood the privacy issues at play. But they…

I think what you're really seeing is how much people value a good user experience, not how little they value privacy. Killing it on the UX end has always been a thing that OSS projects and software has struggled with and lack of growth there is, IMO, part of what has gotten us to where we are.

Re: Dark.fail: Is a darknet site online?

#35

Earlier quoted context omitted.

> some sites change their .onion URLs ~hourly. Not sure why you would do this? Do you have an example?

If DDoS traffic is aimed at domain1.onion, changing your site to donain2.onion would avoid that, wouldn't it?

Yeah, and nobody would know about the new URL, effectively having the same result as a successful DDoS. On the other hand, notifying your users of the URL change will also notify the attackers.

I've seen the response to DDoS mostly be a multiple public URLs, but it seems the results varied greatly, and since these operations are typically very secretive, they won't publish a lot of information (is the ddos still active but they are mitigating it? has the ddos stopped because they mitigated it? have they paid the attackers? etc).

Re: Dark.fail: Is a darknet site online?

#36
post #21

Earlier quoted context omitted.

You clearly visited that site, have you given your IP address to the FBI? why a throwaway account btw? I would really want to know you so I avoid anything you ever build.

And you might note the username plays on the name of a known admin.

Did not catch that, thanks for pointing out. Also got a bit emotional..

Re: Dark.fail: Is a darknet site online?

#37

Tor admins and cyber researchers rely heavily on this site to disseminate links in the wake of DeepDotWeb’s takedown. DDoS attackers seem to love it too as some sites change their .onion URLs ~hourly. Interesting how all sides of a battle can find a simple verified link so useful.

Does anyone know if there's any progress on finding a solution to the DDOS attacks that can run on tor?

Re: Dark.fail: Is a darknet site online?

#38

Tor admins and cyber researchers rely heavily on this site to disseminate links in the wake of DeepDotWeb’s takedown. DDoS attackers seem to love it too as some sites change their .onion URLs ~hourly. Interesting how all sides of a battle can find a simple verified link so useful.

Does anyone know if there's any progress on finding a solution to the DDOS attacks that can run on tor?

The v3 onion protocol [0] is supposed to provide better DDoS resistance than v2 [1] - haven't read up on the specifics though.

[0] https://www.jamieweb.net/blog/onionv3-hidden-service/

[1] https://darknetlive.com/post/cryptonia-market-countering-ddo...

Re: Dark.fail: Is a darknet site online?

#39

Tor admins and cyber researchers rely heavily on this site to disseminate links in the wake of DeepDotWeb’s takedown. DDoS attackers seem to love it too as some sites change their .onion URLs ~hourly. Interesting how all sides of a battle can find a simple verified link so useful.

> some sites change their .onion URLs ~hourly. Not sure why you would do this? Do you have an example?

Addresses are changed when the DDoS takes one down. This mean's the attacker's (usually automated) resources are wasted on a domain no one will ever visit again, while users will just visit dark.fail and get a new link 15 seconds after the site goes down.

At the beginning of the DNM large-scale DDoS attacks (Empire in particular), there was panic, confusion, and a whole lot of phishing. As another commenter noted, Empire users have now been trained (or learned the hard way) to visit dark.fail, copy/paste a mirror .onion address they've never seen before, verify it as legitimate through the various captchas/pgp/safeguards on the Empire login page, and then enter their username/password.

Sure, it's frustrating and complex the first time - a heck of a departure from cookies and 'sign in with google' buttons. But after five or ten times, it's just the way you log in to the website, and it takes an extra 60 seconds tops.

Not saying this is the only/best solution to a dedicated onion DDoS - just sharing that it's been working for Empire.

Post reply on HN