Live data from Hacker News

A dark web tycoon pleads guilty, but how was he caught?

technologyreview.com

121–130 of 157 posts

Re: A dark web tycoon pleads guilty, but how was he caught?

#121
post #82

Earlier quoted context omitted.

Tor is open source: https://www.torproject.org/download/tor/ So, no undocumented issues.

I believe tor was researched designed and developed by the government

NRL (Naval Research Lab)

Re: A dark web tycoon pleads guilty, but how was he caught?

#122

Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long enough to become so notorious. Here's why: 1. Each hidden service chooses a "guard" relay to serve as the first hop for all connections. 2. A server running multiple hidden services…

There was a posts week or two ago from a person running a legit Tor service that was analyzing all of the attacks he received.

He said something seemed to be dos'ing the guard nodes, causing his service to automatically choose a new guard, in an attempt to get his service to connect to a guard node controlled by the adversary. He said in one case, they found his server's actual IP address and dos'd it.

Could that be what happened?

Re: A dark web tycoon pleads guilty, but how was he caught?

#123
post #122

Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long enough to become so notorious. Here's why: 1. Each hidden service chooses a "guard" relay to serve as the first hop for all connections. 2. A server running multiple hidden services…

There was a posts week or two ago from a person running a legit Tor service that was analyzing all of the attacks he received. He said something seemed to be dos'ing the guard nodes, causing his service to automatically choose a new guard, in an attempt to get his service to connect to a guard node controlled by the adversary. He said in one case, they found his server's actual IP address and dos'd it. Could that be…

I assume you refer to [0]. He says "If [the adversary] can knock me off enough guards, my tor daemon will eventually choose one of his guards. Then he can identify my actual network address and directly attack my server. (This happened to me once.)" I question how the author is sure this is what happened to him. But he may be right, and moreover that attack may have been performed against the "dark web tycoon" that is the subject of this post. However, it does seem to be somewhat challenging to perform, as Tor keeps trying to use all recent guards ever contacted, and so you'd have to simultaneously make all chosen guards unresponsive until a malicious guard is selected.

[0] http://www.hackerfactor.com/blog/index.php?/archives/868-Dea...

Re: A dark web tycoon pleads guilty, but how was he caught?

#124
post #72

Earlier quoted context omitted.

That only leads you to the server though, not to the person managing it.

But that's all they need though. A simple national security letter (NSL) without even needing to get a warrant and BOOM you can tap the server and get all info about the person running it.

Not if the server is paid for anonymously and you only connect to it over tor. That connection isn't through a hidden service and so isn't vulnerable to this attack.

Re: A dark web tycoon pleads guilty, but how was he caught?

#125
post #44

Earlier quoted context omitted.

Tor was created to help dissidents of other nations communicate. The military does not run on Tor.

> Tor was created to help dissidents of other nations communicate [1] Why would the US Navy develop something to help dissidents in other nations? [1] https://en.wikipedia.org/wiki/Tor_(anonymity_network)#Histor... > The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson, and computer scientists Michael G. Reed and D…

Congrats on pulling up a wikipedia article. You are now an expert.

Re: A dark web tycoon pleads guilty, but how was he caught?

#126

If you're wondering why a web host, who could potentially be immune to prosecution under CDA 230, was charged with the distribution of child pornography, according to the warrant [1] an admin of one of the pedo sites claimed that Freedom Hosting had "full control" over the websites (well, he had root access to the servers, but so did OVH), was patching the websites, that the pedo site hosting was free, and that he as…

"According to the warrant". Take that with a grain of salt.

"but he did plead guilty". Also take that with a grain of salt. Often plea deals create quite an incentive to plead guilt even when innocent. "Go to trial, risk 20 years in prison branded as a child porn purveyor. Or plead guilty, cooperate as a witness, we'll charge you with a lesser crime that will have you out of prison in 3 years"

Re: A dark web tycoon pleads guilty, but how was he caught?

#127

Earlier quoted context omitted.

That only leads you to the server though, not to the person managing it.

In this case, the main question is how the server was discovered, not how the operator was then deanonymized. As the article describes, after the server was discovered to be in France and run by OVH, authorities used legal treaties ("MLATs") to obtain the subscriber information, leading them to the person that recently plead guilty in court.

This seems incredibly naive. Who would register a VPS hosting different kinds of the most illegal content imaginable using their real name or IP address? Even if they thought hidden services were impenetrable, there are always other possible slip-ups you could make which could disclose the server's real IP, and of course they'd be ignorant to think any security measure is impenetrable, including Tor.

DPR made extremely careless mistakes, too, to the point that even a random amateur investigator could've identified him, using only Google.

It's shocking how many of these people aren't caught sooner when they don't even know OPSEC 101.

Re: A dark web tycoon pleads guilty, but how was he caught?

#128
post #86

Isn't it rather trivial to find who is accessing a website if you can manage to monitor tor nodes? Just do some heuristic, to see when traffic happens, and over time, narrow down users. If you're the FBI and have the authority to monitor the whole internet, isn't it trivial to catch any tor user? Tor is still secure, but of course if you are the government and have skilled engineers, time and admin access to the inte…

This would be more NSA jurisdiction and they do. The problem is most people's assumption is that if one part of the government has it, then everyone gets it. This is wildly false. Even within the FBI itself, different departments and cases get different tiers of access. Even when the case agents get access, policy dictates what evidence is allowed to be taken to a public trial. Otherwise you get repeats of the FBI/4c…

What FBI/4chan/8chan debacle? Are you referring to when an agent's search warrant evidence revealed their own 8chan posts? (https://ceinquiry.wordpress.com/2019/06/17/fbi-8chan/)

Re: A dark web tycoon pleads guilty, but how was he caught?

#129

This sounds fishy. He probably pleaded guilty as part of a plea deal, so law enforcement has a scapegoat and some meaningless "media success" in exchange for him getting a drastically reduced sentencing. They always do that, threaten people with insane penalties if they don't accept so shitty plea deal and if you are not super certain that you can win, you will likely accept that one, just because it seems "safer". T…

As a side note: Promise (YC startup) was also saying that 70% of people in jails are waiting for judgement or are in for a technical violation (ex: did not show up to a hearing). And being in jails they end up losing their job, eventually they lose their house etc. This is a space with a lot of low hanging fruits. And minor fixes may end up doing a lot of good.

Isn't that like, the purpose of jail vs. prison? Who else is in jail if not awaiting judgement or in on a technical violation?

Re: A dark web tycoon pleads guilty, but how was he caught?

#130
post #72

Earlier quoted context omitted.

That only leads you to the server though, not to the person managing it.

But that's all they need though. A simple national security letter (NSL) without even needing to get a warrant and BOOM you can tap the server and get all info about the person running it.

[deleted]
Post reply on HN