Live data from Hacker News

Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

fbi.gov

211–220 of 264 posts

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#211

Earlier quoted context omitted.

>> made a down payment of approximately $70,000 in Bitcoins towards the purchase of a Tesla Model S Way to lay low.

This is a lot of major crimes investigations: if you want to participate in an organized criminal effort (which is what SR2.0 is), you're only as secure as the weakest link in that effort. Worth remembering when SR3.0 comes out. Is it being run by someone else who will put out a hit on a rival, or plow $70k of revenue into a Model S.

Silkroad 3.0 will probably be this: https://openbazaar.org/

Good luck in taking that down.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#213
post #205

I feel like this information might make some deviously smart individuals think they can get away with it by not screwing up where Benthall did.

Like he probably thought he would't screw up the same way Ulbricht did?

Yup, but the one takeaway I get from these court documents is the FBI needs someone to make some bone headed mistakes in order to bring them to justice.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#214
post #189
post #157

Earlier quoted context omitted.

He probably pays taxes on that money, too. Does that make the government an accomplice? Really, you just can't apply logic and consistency to laws across all members of society. On the one hand, they contradict themselves in application, and on the other hand you have special exceptions for state-actors among others.

He bought a top end tesla with a $70,000 down payment in bitcoin a few months after taking over. You really want to contend that he "probably pays taxes on that money, too."?

Sales tax in San Francisco is 8.75%, so, yeah.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#215

I think this is the money quote: "During the Government’s investigation, which was conducted jointly by the FBI and HSI, an HSI agent acting in an undercover capacity (the “HSI-UC”) successfully infiltrated the support staff involved in the administration of the Silk Road 2.0 website, and was given access to private, restricted areas of the site reserved for BENTHALL and his administrative staff. By doing so, the HSI…

This sounds no different than the undercover police, detective work the FBI has been doing since its establishment. Infiltrate the perp, take him down. They used the same tactics on gangs, mobs, etc. Now violent crime is slowing, but they have hoardes of agents trained in these protocols, so they're redirecting energy into catching so called "cybercriminals." A bunch of people who infiltrated the mob are now infitrat…

> A bunch of people who infiltrated the mob are now infitrating groups of nerds in basements. It's frustratingly hilarious.

I'm a little skeptical of this whole shtick that online criminals are just "nerds in basements." A nerd can do a lot more damage to your life with a computer than your average petty criminal.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#216

Earlier quoted context omitted.

yea, but, there is this tid-bit: "During the Government’s investigation, which was conducted jointly by the FBI and HSI, an HSI agent acting in an undercover capacity (the “HSI-UC”) successfully infiltrated the support staff involved in the administration of the Silk Road 2.0 website, and was given access to private, restricted areas of the site reserved for BENTHALL and his administrative staff. By doing so, the HSI…

But how could they know what support staff to infiltrate if they hadn't identified the server? The first step was locating the server. The second step was identifying the individuals and getting evidence against them. The undercover operation couldn't happen (except by accident) until step 2.

It seems you read this as support staff for the underlying webhost. However I get the impression the undercover agent had a role akin to an admin or moderator on other user content generated sites.

If that was the case, they didn't need to know where the server is hosted. And the "private" parts of the back end very likely opened up methods of code execution on the underlying host (eg. editing php templates, etc.)

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#217

Earlier quoted context omitted.

Interesting read, some highlights from the complaint: "40. Based on a review of records provided by the service provider for the Silk Road 2.0 Server (the “Provider”), I have discovered that the server was controlled and maintained during the relevant time by an individual using the email account “blake@benthall.net” (“Benthall Email Account-1")." "b. I have also reviewed a publicly available profile of “Blake Bentha…

> I have discovered that the server was controlled and maintained during the relevant time by an individual using the email account “blake@benthall.net” That's pretty f *ing retarded of him. No, I mean, what an idiot of epic proportions. Or he is just a fall guy. This is such a huge WTF to me. I mean, I can rent a server with Bitcoins completely anonymously right this moment from many providers.

But is the host reliable? Will the server be of decent quality? Does customer support exist?

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#218
post #217

Earlier quoted context omitted.

> I have discovered that the server was controlled and maintained during the relevant time by an individual using the email account “blake@benthall.net” That's pretty f *ing retarded of him. No, I mean, what an idiot of epic proportions. Or he is just a fall guy. This is such a huge WTF to me. I mean, I can rent a server with Bitcoins completely anonymously right this moment from many providers.

But is the host reliable? Will the server be of decent quality? Does customer support exist?

If it isn't reliable, there's plenty of competition.

I've been renting dirt-cheap VPSs recently and had zero problems with them.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#219
post #194

Earlier quoted context omitted.

I meant "power outage" as the pretext that would justify (to the HS owner) why the server has been power-cycled (assuming they decided to cooperate with the FBI/whoever). Here's how I would do it: - I assume that your hard drives are in RAID. I gamble that they're in RAID 1 - most typical - and strip one out while the server is still running. Some kernel messages are logged, whatever. - I start imaging the disk. If i…

> I patch both your boot loader and your kernel with a rootkit. This should be laughably easy for the level of adversary we're talking about. Well, you won't be getting the kernel, its on the drives. It would have to be in a separate partition so you can start it before mounting the sensitive filesystems, and you may have a key that the bootloader uses on it, but in either case if you are not present and a sever goes…

> Verify the ROMs integrity in that first stage (...) need open firmware or some mechanism to hash the ROM that is installed, you need to have a means to read it in its entirety"

Does such a mechanism exist? If you can do this[1] from BIOS, why is it safe to assume that the same can't be done for the dump-bios-image routine? AFAIK the BIOS handles this in real-mode [2] (overrides the OS), and "returns" the image by copying it somewhere in low memory. So, you're trusting the BIOS that it's copied the right data out for you. (goodguybios)

> I say open firmware because you need to be able to guarantee the FBI couldn't embed a backdoor firmware.

This reminds me of this NSA RAID controller rootkit for Dell Poweredge Servers [3]. Nuts. Every closed firmware on your servers is a potential hiding place to someone with (soldering-iron-to-the-motherboard) physical access.

In our Dread Pirate use case, you don't even have to think that far as you can't ensure your own BIOS. Who are you going to buy TPM servers [4] from, when you're defending against the FBI? Intel? HP?

The Rootkit wikipedia page is alarming, to say the least. [5]

--

[1] A Real SMM Rootkit: Reversing and Hooking BIOS SMI Handlers http://phrack.org/issues/66/11.html#article

[2] http://en.wikipedia.org/wiki/Real_mode

[3] http://resources.infosecinstitute.com/nsa-bios-backdoor-god-...

[4] http://en.wikipedia.org/wiki/Trusted_Platform_Module

[5] http://en.wikipedia.org/wiki/Rootkit#Bootkits ("Bootkits??")

[6] https://www.blackhat.com/presentations/bh-usa-07/Heasman/Pre...

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#220
post #192

Earlier quoted context omitted.

Perhaps, but that kind of joke gets made all the time on the Internet without bringing down black helicopters.

I made a joke like that on Slashdot once and the black helicopters did show up. Well, the Secret Service, anyway.

You satirically quoted an imaginary job posting and Secret Service showed up? That sucks, I guess we need to close down Duffel Blog and The Onion then.
Post reply on HN