Live data from Hacker News

A dark web tycoon pleads guilty, but how was he caught?

technologyreview.com

31–40 of 157 posts

Re: A dark web tycoon pleads guilty, but how was he caught?

#31
post #24

The central premise of the article is that there is no disclosure regarding the vulnerability used, suggesting the existence of some unknown zero-day exploit.. Various well documented analysis have linked this incident to "EgotisticalGiraffe", a well known -- and since fixed vulnerability. FUD or lazy journalism? I mean, at least read the subjects Wikipedia page before publishing something..

EgotisticalGiraffe was the JS embedded in Freedom Hosting's web pages, which is mentioned by the article. Are you saying they hacked the site and inserted the JS? I assumed that was inserted after de-anonymizing the server and seizing it.

A Wired article on it:

https://www.wired.com/2013/09/freedom-hosting-fbi/

Slides:

https://web.archive.org/web/20140413004837/http://cryptome.o...

A breakdown of the malware:

https://web.archive.org/web/20140417081750/http://ghowen.me/...

Re: A dark web tycoon pleads guilty, but how was he caught?

#32
post #24

The central premise of the article is that there is no disclosure regarding the vulnerability used, suggesting the existence of some unknown zero-day exploit.. Various well documented analysis have linked this incident to "EgotisticalGiraffe", a well known -- and since fixed vulnerability. FUD or lazy journalism? I mean, at least read the subjects Wikipedia page before publishing something..

The article explicitly does mention "EgotisticalGiraffe" (the Firefox TBB exploit). But the point is that the exploit was dropped on all websites that Freedom Hosting was running, which raises the question that the article is really about, "how did they know where the hidden services were?"

Re: A dark web tycoon pleads guilty, but how was he caught?

#33
post #4
post #3

OTOH if these techniques and vulnerabilities were made public it would benefit cybercriminals as they could defend themselves better.

It would also benefit whistleblowers, investigative journalists and other groups who routinely use Tor...

Good point

Re: A dark web tycoon pleads guilty, but how was he caught?

#34
post #7

The military needs, or needed, Tor to be functioning and anonymous for their own use, correct?

The military and intelligence needs use of Tor to be functioning and anonymous more than they need hidden services to be functioning and anonymous. The unknown "investigation" technique in this article is about deanonymizing hidden services, not individual Tor users (at least not directly, they used the discovery of the hidden services to send an exploit which has been publicly identified to individual users).

Re: A dark web tycoon pleads guilty, but how was he caught?

#35
post #29

It's strange to me that people who make a habit of doing fantastically illegal things on the internet are always so sloppy about it. Even if they don't have the technical ability to break into their neighbor's wifi or set up a long range antenna to connect to an open access point they can still get a burner smartphone and drive to a Starbucks. Back when I used to torrent my TV shows I didn't even let my piracy laptop…

Where there's a will, there's a way. The internet is designed to send data from point A to point B. Keeping point A and point B truly anonymous means that the internet won't work. Tools like Tor don't really protect you, it's more like they make it hard enough to figure out who you are that only people with strong incentives will track you down.

> Keeping point A and point B truly anonymous

Read and write encrypted packets to alt.anon ?

Re: A dark web tycoon pleads guilty, but how was he caught?

#36
post #3

OTOH if these techniques and vulnerabilities were made public it would benefit cybercriminals as they could defend themselves better.

>if these techniques and vulnerabilities were made public[...] Should the government prove that it followed the law when investigating a criminal? Did they obtain the proper warrants that people recognize preserve stable law and order? It's unreasonable to assume that the vulnerability, that brought this case to justice, is the last one that could ever be used. More so, if you assume that most people are good and a h…

I'm not saying the authorities would not have to describe its investigative methods to a judge. What I'm saying is making them available to the general public.

Re: A dark web tycoon pleads guilty, but how was he caught?

#37
post #24

The central premise of the article is that there is no disclosure regarding the vulnerability used, suggesting the existence of some unknown zero-day exploit.. Various well documented analysis have linked this incident to "EgotisticalGiraffe", a well known -- and since fixed vulnerability. FUD or lazy journalism? I mean, at least read the subjects Wikipedia page before publishing something..

The concern seems to be more of a legal one than a technical one. Law enforcement in theory should always disclose how they collect evidence.

Re: A dark web tycoon pleads guilty, but how was he caught?

#38

It's strange to me that people who make a habit of doing fantastically illegal things on the internet are always so sloppy about it. Even if they don't have the technical ability to break into their neighbor's wifi or set up a long range antenna to connect to an open access point they can still get a burner smartphone and drive to a Starbucks. Back when I used to torrent my TV shows I didn't even let my piracy laptop…

We don't actually know for sure that he was doing "illegal things". He was running a hosting company ("Ultra Host") on the public facing web and later launched Freedom Host as a side business, or perhaps better described as a charitable hosting service to contribute to the Tor network. Freedom Host offered FREE hosting to people on the Tor network. What liability does he have if other people use his host for illegal things? From what I understand he was never personally involved in any of these activities.

One can argue that he had to know about it, perhaps so, but the way he's being portrayed by LE and media is as if he was the kingpin of child porn. That's far from the truth. Freedom host served half of the Tor network, including perfectly legitimate services like Tormail, wikis etc.

I think his mistake in not cloaking the identity used to purchase servers can be explained this way: He was never planning to host CP starting out (or do anything else illegal for that matter). He probably thought universally recognized no-liability laws would apply to Freedom Host just as any other hosting business. Perhaps he later went down a darker path, but at that point it was too late.

The fact that he now pleads guilty means absolutely nothing however. Remember, he was extradited from his country to USA, and while he should never have been sent there, he now have to adapt to the way the "justice system" works over there and it works kind of like this: 5000 years in jail or take a plea deal and get away with 15-30 years. Even if he is innocent, you need to realize that when you're facing a kangaroo court and subsequent rotting away in jail for life it might be better to pick the lesser evil.

Re: A dark web tycoon pleads guilty, but how was he caught?

#39
post #20

It's strange to me that people who make a habit of doing fantastically illegal things on the internet are always so sloppy about it. Even if they don't have the technical ability to break into their neighbor's wifi or set up a long range antenna to connect to an open access point they can still get a burner smartphone and drive to a Starbucks. Back when I used to torrent my TV shows I didn't even let my piracy laptop…

> drive to a Starbucks Didn't help Ross. It's a bad idea to do illegal stuff in public.

It is a bad idea to do illegal stuff.

Re: A dark web tycoon pleads guilty, but how was he caught?

#40
post #24

The central premise of the article is that there is no disclosure regarding the vulnerability used, suggesting the existence of some unknown zero-day exploit.. Various well documented analysis have linked this incident to "EgotisticalGiraffe", a well known -- and since fixed vulnerability. FUD or lazy journalism? I mean, at least read the subjects Wikipedia page before publishing something..

The article explicitly does mention "EgotisticalGiraffe" (the Firefox TBB exploit). But the point is that the exploit was dropped on all websites that Freedom Hosting was running, which raises the question that the article is really about, "how did they know where the hidden services were?"

[deleted]
Post reply on HN