Live data from Hacker News

A dark web tycoon pleads guilty, but how was he caught?

technologyreview.com

71–80 of 157 posts

Re: A dark web tycoon pleads guilty, but how was he caught?

#71
post #3

OTOH if these techniques and vulnerabilities were made public it would benefit cybercriminals as they could defend themselves better.

>if these techniques and vulnerabilities were made public[...] Should the government prove that it followed the law when investigating a criminal? Did they obtain the proper warrants that people recognize preserve stable law and order? It's unreasonable to assume that the vulnerability, that brought this case to justice, is the last one that could ever be used. More so, if you assume that most people are good and a h…

> Should the government prove that it followed the law when investigating a criminal?

They do, but only if the defendant requires them to do so.

What’s happening here is that the prosecutors told the defendant “look, we all know you did it, so plead guilty and we’ll recommend a light sentence. You have a right to make us reveal our tor backdoor, but if you do the plea offer is off and we will have the trial, and win, and ask the judge to send you to prison until you die.”

I’m sure the defendant is very interested in learning about the tor backdoor, but the idea of getting out of prison one day seems a little more compelling.

Re: A dark web tycoon pleads guilty, but how was he caught?

#72

Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long enough to become so notorious. Here's why: 1. Each hidden service chooses a "guard" relay to serve as the first hop for all connections. 2. A server running multiple hidden services…

That only leads you to the server though, not to the person managing it.

But that's all they need though.

A simple national security letter (NSL) without even needing to get a warrant and BOOM you can tap the server and get all info about the person running it.

Re: A dark web tycoon pleads guilty, but how was he caught?

#73
post #44

Earlier quoted context omitted.

Tor was created to help dissidents of other nations communicate. The military does not run on Tor.

> Tor was created to help dissidents of other nations communicate [1] Why would the US Navy develop something to help dissidents in other nations? [1] https://en.wikipedia.org/wiki/Tor_(anonymity_network)#Histor... > The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson, and computer scientists Michael G. Reed and D…

> Why would the US Navy develop something to help dissidents in other nations?

From their website: "The [Naval Research Laboratory] works closely with the National Security Agency (NSA), Space and Naval Warfare Systems Command (SPAWAR), Defense Advanced Research Projects Agency (DARPA), and Defense Information Systems Agency (DISA)."

Re: A dark web tycoon pleads guilty, but how was he caught?

#74

Earlier quoted context omitted.

>if these techniques and vulnerabilities were made public[...] Should the government prove that it followed the law when investigating a criminal? Did they obtain the proper warrants that people recognize preserve stable law and order? It's unreasonable to assume that the vulnerability, that brought this case to justice, is the last one that could ever be used. More so, if you assume that most people are good and a h…

>> Should the government prove that it followed the law when investigating a criminal? Did they obtain the proper warrants that people recognize preserve stable law and order? That is the concern. A lot of people say "you either did it or not" but the Fourth Amendment disagrees...any evidence must be obtained by following the law.

In theory, maybe. As in, I agree with you on principle, but if you do even a cursory read about recent abuses that include parallel construction, PATRIOT act and BSA, you may find that it is no longer the case.

Hell, during my last attended CAMS conference, FBI guy outright said said that if the new lawyer doesn't know how to play ball with those ( informatikn gathered by SARs ), he gets pulled to the side and told whats what.

Chilling. And no one questioned it. Including me.

Re: A dark web tycoon pleads guilty, but how was he caught?

#75

Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long enough to become so notorious. Here's why: 1. Each hidden service chooses a "guard" relay to serve as the first hop for all connections. 2. A server running multiple hidden services…

That only leads you to the server though, not to the person managing it.

In this case, the main question is how the server was discovered, not how the operator was then deanonymized. As the article describes, after the server was discovered to be in France and run by OVH, authorities used legal treaties ("MLATs") to obtain the subscriber information, leading them to the person that recently plead guilty in court.

Re: A dark web tycoon pleads guilty, but how was he caught?

#76
post #60

Earlier quoted context omitted.

The article explicitly does mention "EgotisticalGiraffe" (the Firefox TBB exploit). But the point is that the exploit was dropped on all websites that Freedom Hosting was running, which raises the question that the article is really about, "how did they know where the hidden services were?"

Could they not purchase some “Freedom hosting” and upload a website with backdoor?

How would they FBI know to purchase "Freedom hosting"?

Re: A dark web tycoon pleads guilty, but how was he caught?

#77

Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long enough to become so notorious. Here's why: 1. Each hidden service chooses a "guard" relay to serve as the first hop for all connections. 2. A server running multiple hidden services…

That's a very good explanation!

Re: A dark web tycoon pleads guilty, but how was he caught?

#78

If you're wondering why a web host, who could potentially be immune to prosecution under CDA 230, was charged with the distribution of child pornography, according to the warrant [1] an admin of one of the pedo sites claimed that Freedom Hosting had "full control" over the websites (well, he had root access to the servers, but so did OVH), was patching the websites, that the pedo site hosting was free, and that he as…

"According to the warrant". Take that with a grain of salt.

Re: A dark web tycoon pleads guilty, but how was he caught?

#79

Earlier quoted context omitted.

It is a bad idea to do illegal stuff.

Depends on your value system. Another perspective is that some laws ought to be broken, in spite of the potential consequences.

If the values of a person are "achieving personal power" in first position and "respect others" in last, that person may be ok to steal.

I hear some people arguing that in business "not breaking the laws" is not the problem unless they get caught and even in that case, it is a problem only if the consequences end up costing more than the gain they receive in doing it.

So a person with those value may end up breaking the law. Are you saying it is ok?

Re: A dark web tycoon pleads guilty, but how was he caught?

#80

Earlier quoted context omitted.

I am merely give my opinion, but a service created by the US government/Military is going to have undocumented "issues". I would not trust it one shred.

Tor is open source: https://www.torproject.org/download/tor/ So, no undocumented issues.

Issues can be undocumented if it is found by the 3 letter one, as pointed out in the article.
Post reply on HN