Live data from Hacker News

A dark web tycoon pleads guilty, but how was he caught?

technologyreview.com

51–60 of 157 posts

Re: A dark web tycoon pleads guilty, but how was he caught?

#51

It's strange to me that people who make a habit of doing fantastically illegal things on the internet are always so sloppy about it. Even if they don't have the technical ability to break into their neighbor's wifi or set up a long range antenna to connect to an open access point they can still get a burner smartphone and drive to a Starbucks. Back when I used to torrent my TV shows I didn't even let my piracy laptop…

>or set up a long range antenna to connect to an open access point

Sure, this works for torrenting TV shows. If you are the number one peddler of child porn on the planet however, this won't help you for very long. The FBI (or whatever national police force is trying to find you) will just go to the access point, realize you're connected remotely and triangulate your position with (essentially) some signal-strength meters in much the same way the FCC tracks down particularly disruptive unlicensed broadcasters.

Re: A dark web tycoon pleads guilty, but how was he caught?

#52

Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long enough to become so notorious. Here's why: 1. Each hidden service chooses a "guard" relay to serve as the first hop for all connections. 2. A server running multiple hidden services…

This is some great info for the less technically knowledgeable about Tor (like me!). However, I think your math in #3 is wrong.

Assuming random assignment/selection of the guards, each time one is chosen it has a 98% chance of not being "caught" by choosing an adversary's guard. Going with 50 services as you said would be .98^50=.364, meaning the chance of getting caught is 1-.364=.635 - 63.5%. This is vastly different than being nearly 100%.

Re: A dark web tycoon pleads guilty, but how was he caught?

#53

Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long enough to become so notorious. Here's why: 1. Each hidden service chooses a "guard" relay to serve as the first hop for all connections. 2. A server running multiple hidden services…

This is some great info for the less technically knowledgeable about Tor (like me!). However, I think your math in #3 is wrong. Assuming random assignment/selection of the guards, each time one is chosen it has a 98% chance of not being "caught" by choosing an adversary's guard. Going with 50 services as you said would be .98^50=.364, meaning the chance of getting caught is 1-.364=.635 - 63.5%. This is vastly differe…

Fair enough! I was using as a heuristic the expected number of compromised guards, which would be 0.02*50 = 1. Moreover, things degrade exponentially over time. If half the guards rotate every month, the chance of choosing a bad guard is after 2 months is >86%, after 4 months is >95%, after 6 months is >98%.

Re: A dark web tycoon pleads guilty, but how was he caught?

#54

This report came out only a few months before he was caught: https://www.reddit.com/r/onions/comments/1guiav/we_have_anal... He was likely de-anonymized through this technique or similar. The issue was that he trusted the Tor network to keep him anonymous and paid for the servers with his real identity.

Just to be clear: The v3 onion services fix that weakness, right?

Re: A dark web tycoon pleads guilty, but how was he caught?

#55
This sounds fishy. He probably pleaded guilty as part of a plea deal, so law enforcement has a scapegoat and some meaningless "media success" in exchange for him getting a drastically reduced sentencing. They always do that, threaten people with insane penalties if they don't accept so shitty plea deal and if you are not super certain that you can win, you will likely accept that one, just because it seems "safer".

There are a LOT of cases like this, just most of them don't gain this publicity. Actually, 95% of court cases never reach court because of this. Innocent people plead guilty because they don't have the wealth and resources to win in court. USA is a shithole when it comes to law enforcement. Medieval and sad. Land of the free (as long as you are rich, that is).

Re: A dark web tycoon pleads guilty, but how was he caught?

#56
post #44

Earlier quoted context omitted.

Tor was created to help dissidents of other nations communicate. The military does not run on Tor.

> Tor was created to help dissidents of other nations communicate [1] Why would the US Navy develop something to help dissidents in other nations? [1] https://en.wikipedia.org/wiki/Tor_(anonymity_network)#Histor... > The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson, and computer scientists Michael G. Reed and D…

It's also designed for dissidents in countries that are either opponents or rivals of the US: Russia, China, Iran, North Korea, Brazil, and Venezuela. It allowed for pro-US dissidents and agents to stay unidentifiable to these nations while distributing pro-US messages.

Re: A dark web tycoon pleads guilty, but how was he caught?

#57

Hacker Factor has a series of articles about various attacks on Tor: https://www.hackerfactor.com/blog/index.php?/archives/868-De... The tor daemon really needs to be re-written and audited. Apparently the codebase right now is a huge mess.

You can make a mistake in your code and end up causing someone to go to prison. What a time to be alive.

Re: A dark web tycoon pleads guilty, but how was he caught?

#58
post #3

OTOH if these techniques and vulnerabilities were made public it would benefit cybercriminals as they could defend themselves better.

I was going to write that the world is moving toward hiding some technologies from the public domain and facts are also hidden. And that requires a very high trust in those that manage these secrets.

In reality I realized that this has always been the case in the last 100 years.

Re: A dark web tycoon pleads guilty, but how was he caught?

#59
post #49

Earlier quoted context omitted.

The concern seems to be more of a legal one than a technical one. Law enforcement in theory should always disclose how they collect evidence.

Should they? I know of no such law or theory. They have a burden of proof regarding the correctness of evidence and the defence can question the legality of collection methods if the evidence gets used in court. As far as I know, that's about it.

Does chain of custody have anything to do with this?

I know in some computer forensics work it is important to be able to prove evidence has not been tampered with.

So for example, cracking hashes instead of working with encrypted data can create safe space for non-leo to work without undermining an investigation.

For example, a case of illegal doping, the accused Pearson’s samples must be able to be shown to not have been tampered with.

It seems being able to prove the source of evidence would be the first step of this process.

Re: A dark web tycoon pleads guilty, but how was he caught?

#60
post #24

The central premise of the article is that there is no disclosure regarding the vulnerability used, suggesting the existence of some unknown zero-day exploit.. Various well documented analysis have linked this incident to "EgotisticalGiraffe", a well known -- and since fixed vulnerability. FUD or lazy journalism? I mean, at least read the subjects Wikipedia page before publishing something..

The article explicitly does mention "EgotisticalGiraffe" (the Firefox TBB exploit). But the point is that the exploit was dropped on all websites that Freedom Hosting was running, which raises the question that the article is really about, "how did they know where the hidden services were?"

Could they not purchase some “Freedom hosting” and upload a website with backdoor?
Post reply on HN