Live data from Hacker News

Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

fbi.gov

151–160 of 264 posts

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#151

Earlier quoted context omitted.

A bunch of people who infiltrated the mob are now infitrating groups of nerds in basements. It's frustratingly hilarious. Why? Generally speaking, crime is crime, whether or not you wear a trenchcoat & fedora. There is perhaps some humor in operatives who went up against the mob now going after small fish which must seem like easy pickings to them, but it's the "frustrating" part that I don't follow.

Because basement nerd isn't violently murdering anyone. Basement nerd is making a violent drug market civil and non violent.

Except when basement nerd tries to take a hit out on someone.

Allegedly.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#152

What are the chances that the FBI set up a number of "copy-cat-silk-road" hidden services, immediately after seizing the original? That would provide them ample opportunity to 1) build a profile of everyone who used them, then 2) shut them down with an intimidating "sting," dampening the desire of potential copy-copy-cats.

Last I checked, the original Silkroad strongly enshrined PGP encrypted communication between seller & buyer into the way these marketplaces are run.

So theres no gain for them, as they can't get to whoever is selling/buying. They would just be facilitating the sales.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#154

They located Silk Road 2.0's server in an unspecified way, not directly related to their undercover agent on the support staff. Given that two other darknet markets (Black Market and Cloud9) have been shut down today, and they didn't specify how they located the SR2 server, it seems plausible that law enforcement have a vulnerability to locate servers over the Tor network. From the complaint: "In or about May 2014, t…

In this case it appears that they have an insider, however, given the ability to analyze internet traffic, and given the ability to DDOS a hidden service which apparently happens quite frequently when new sites appear, with sufficient network analysis it should be possible to determine the end point of the hidden service.

Understanding of Tor

  1. Hidden services can only exist on one node.
  2. That node has a single IP or few IP addresses.
  
How to locate a hidden service given understanding of Tor.

  1. Send pulses of traffic to the hidden service (DDOS)
  2. Comb through internet traffic logs to identify which IPs saw traffic pulses.
  3. Reduce to a few statistically probable nodes matching the pulsed traffic pattern
  4. Pulse hidden service again to see if it matches the probable nodes.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#155

I cannot imagine a way in which a single-server hidden service is safe from a global, active adversary like FBI, NSA & Friends. This [1] discusses passive analysis over time. Isn't it really easy to locate one if you can perform active attacks on the global infrastructure? (introduce latencies and/or break links temporarily) If your hidden service is served by a couple of mirrors on each continent, though... then may…

IIRC, Silk Road 1.0 (is this what we're calling it now?) had mirroring servers. As we know, somehow the IP of the main server was leaked, whether through the CAPTCHA or by other means. Security by obscurity always fails - especially against the FBI. Given that Tor is essentially an obscuring mechanism for servers that have to function to some degree on the clearnet, if the FBI really wants to find a hidden service th…

I'm not sure "security by obscurity" applies to Tor, even in the context that you mean (which I understood as the routing-to-hidden-services bit of it, rather than Tor in its entirety).

Based on the info and understanding I currently have, the only information that can be used to track a hidden service is, basically, uptime* . If you own a significant percentage of both the network (Tor), and its carrier (Internet), you can start introducing latencies at will to exclude routes. That will basically allow you to find the IP by elimination.

As a passive adversary, you have to do the above passively - meaning loads of accurate uptime/time data for the hidden service, which you'd then have to correlate with known outages in various sections of the internet, yada yada. Passively it could take forever.

Security by obscurity is when the process being kept secret is the duct tape making it "secure" (think XORing against a fixed key and calling it "encryption"). This clearly not the case here, but rather that the protocol cannot protect a single server hidden service on an adversarial carrier network.

I can't imagine a HS with mirrors in 10-20 different DCs would be susceptible even with active capabilities.

> have to function to some degree on the clearnet

How so? They certainly don't have to, and AFAIK "marketplaces" don't.

* I'm obviously not counting leaking the native IP through the app layer, which is what the FBI claims happened with "Silk Road 1.0" (yes, I think this is what it's called now. Who got dibs on the silk road 2.0 name, and how?)

If not eliminate to just one IP, at least eliminate to few enough that you can DDoS them and see what happens to the HS.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#156
post #134

Earlier quoted context omitted.

I'm not sure how this is a whack-a-mole game. If you run a single-server hidden service, the NSA can track it (unless you think otherwise - tried to initiate discussion here[1]). Once they track it, they will get your hosting provider to cooperate and before you know it, your server has been imaged and that irrevocable .onion private key is in the authorities' hands. The most you'll see from your end was some downtim…

> Once they track it, they will get your hosting provider to cooperate and before you know it, This is the whackamole I was talking about. The time between when they identify the server and getting the provider to comply is enough in certain countries to set up an alternative location. Hosting companies aren't gonna want to play this game forever, ESPECIALLY if they're getting good money out of it.

So you'd just move servers every X months no matter what, or would you be tipped off somehow during that time window? If it's the first, that's pretty hardcore. Migrations are a pain for most people. Unless the system was built to migrate painlessly... Hm.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#157
post #146

Earlier quoted context omitted.

> Nevertheless, selling illegal drugs on the internet is illegal. Apparently running a social media website where you don't sell drugs but other people do is also illegal. He committed the equivalent of putting up a bulletin board where drug dealers would pin instructions on how to buy from them.

Also he took a cut of every transaction

He probably pays taxes on that money, too. Does that make the government an accomplice? Really, you just can't apply logic and consistency to laws across all members of society. On the one hand, they contradict themselves in application, and on the other hand you have special exceptions for state-actors among others.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#158

Earlier quoted context omitted.

If Blake Benthall actually does prison time, I'd say that's extremely unlikely... I suppose the FBI could have been behind the original setup and then sold it to him...

Or he's a government agent. After all, who's really verifying he a) exists, b) goes to jail? Ok, that's enough fearmongering paranoia for me today. See you tomorrow hacker news! :)

[deleted]

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#159

They located Silk Road 2.0's server in an unspecified way, not directly related to their undercover agent on the support staff. Given that two other darknet markets (Black Market and Cloud9) have been shut down today, and they didn't specify how they located the SR2 server, it seems plausible that law enforcement have a vulnerability to locate servers over the Tor network. From the complaint: "In or about May 2014, t…

yea, but, there is this tid-bit: "During the Government’s investigation, which was conducted jointly by the FBI and HSI, an HSI agent acting in an undercover capacity (the “HSI-UC”) successfully infiltrated the support staff involved in the administration of the Silk Road 2.0 website, and was given access to private, restricted areas of the site reserved for BENTHALL and his administrative staff. By doing so, the HSI…

But how could they know what support staff to infiltrate if they hadn't identified the server? The first step was locating the server. The second step was identifying the individuals and getting evidence against them. The undercover operation couldn't happen (except by accident) until step 2.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#160
post #103

Earlier quoted context omitted.

So did the conformed slave.

Virtually everyone commenting here is at work and IMHO it is a lot more work to be a criminal.

Not if you operate for a year or two and manage to successfully exit. Then you'll be able to live without working for the rest of your life.
Post reply on HN