Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
181–190 of 264 posts
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#182I think this may be his hn account. https://news.ycombinator.com/user?id=blakeeb
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#183Earlier quoted context omitted.
> I'm wondering why they would image the server. For offline analysis and to be used as evidence, presumably. > Did SR2 not use full disc encryption using LUKS? (...) longest private key ever So the process for you would be slightly different: There would be a "power outage" in your rack, your encrypted disk would be imaged and (unencrypted) bootloader would be bugged. Then they'd wait for you to see that your server…
It's not log bugging your bootloader can magically send your password for the key off the server. They would have to be watching and be very quick, but I'm sure they'd want to see the server start to boot to ensure they have it. I'd compare the bootloader to a known good image as an early boot step and if it isn't what you expect immediately start destroying data. :-)
Here's how I would do it:
- I assume that your hard drives are in RAID. I gamble that they're in RAID 1 - most typical - and strip one out while the server is still running. Some kernel messages are logged, whatever.
- I start imaging the disk. If it isn't a mirror of the other after all, I strip the remaining drive(s) out and start imaging them too.
- While the disk(s) is/are transferring, I patch both your boot loader and your kernel with a rootkit. This should be laughably easy for the level of adversary we're talking about.
- When the disk(s) are done, I power cycle your server. I may cold-boot your RAM and get the passphrases there if i'm lucky. The downtime was either seconds (if it kept going with one RAID 1 disk) or .
- When you realise your service is down you may contact customer support. In that case they will respond (with their usual timing) about something-something-blown-fuse-UPS in your rack.
- When you log onto your server, you will most likely be faced with the passphrase input and most likely will go for it, but even if you don't...
> I'd compare the bootloader to a known good image as an early boot step
If you do so after you've given away the passphrase, you've lost already. Destroying the data won't help, as they have the encrypted copy of it and you just gave them the key.
I don't think you could detect a good boot/OS rootkit remotely at all. One would cover for the other. You can't unplug the disk and examine it. You can't plug a read-only drive in and boot some forensic tool. All you have is your lying bootloader and your lying OS. Your encrypted partition doesn't protect the integrity of the binaries there either, as after it's been decrypted, the rootkit would happily intercept any values that would give it away.
I'm not sure how you could ensure hardware security without ensuring physical security. Usually, physical access == pwned. Maybe TPM changes/will change that, but I somehow doubt it. Some other routes not covered here (probably easier, heh): Getting host to decrypt your TLS/KVM session where you typed the passphrase in the first place, malware in firmware on misc devices, etc.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#184So what? 100 more will arise. And this time not US based. You close 1 100 more will appear.
Marketplaces work much better at scale. And entrepreneurs do better the more they are connected with their markets. So from the government perspective, 100 kittens is way better than 1 lion. The government doesn't have to make these disappear. They just have to increase the perceived risk and decrease their effectiveness until they're no better than buying on well-known corners or getting the phone number of that one…
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#185I think this may be his hn account. https://news.ycombinator.com/user?id=blakeeb
A software engineer at Space X [1] is also behind Silk Road 2.0? Crazy [1] https://news.ycombinator.com/item?id=7277371
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#186Earlier quoted context omitted.
Better watch out, law enforcement isn't exactly known for their sense of humour.
Yep, this is how you know you live in a -democracy- dictatorship.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#187I cannot imagine a way in which a single-server hidden service is safe from a global, active adversary like FBI, NSA & Friends. This [1] discusses passive analysis over time. Isn't it really easy to locate one if you can perform active attacks on the global infrastructure? (introduce latencies and/or break links temporarily) If your hidden service is served by a couple of mirrors on each continent, though... then may…
So, it seems possible to build a p2p based market. I'm pretty sure I read something about there already being one. Like, a distributed network based market where sales and buys are processed by users, much in the way bitcoin does, or torrenting. Then the network could be accessed by clients, even web based ones. Perhaps. Like i2p based markets? Which can even be accessed over tor?
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#188They located Silk Road 2.0's server in an unspecified way, not directly related to their undercover agent on the support staff. Given that two other darknet markets (Black Market and Cloud9) have been shut down today, and they didn't specify how they located the SR2 server, it seems plausible that law enforcement have a vulnerability to locate servers over the Tor network. From the complaint: "In or about May 2014, t…
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#189Earlier quoted context omitted.
Also he took a cut of every transaction
He probably pays taxes on that money, too. Does that make the government an accomplice? Really, you just can't apply logic and consistency to laws across all members of society. On the one hand, they contradict themselves in application, and on the other hand you have special exceptions for state-actors among others.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#190so, is everyone ready to ditch Tor for i2p yet?