Live data from Hacker News

Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

fbi.gov

221–230 of 264 posts

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#221
post #140

Earlier quoted context omitted.

You can buy a Tesla with Bitcoins?

Sure, you could theoretically buy a used Tesla with Bitcoins. But it may be hard to find a dealer willing to do that. There was a story a while ago about someone buying a Tesla with Bitcoins, but it ended up being incorrect. The Bitcoins were exchanged for US Dollars which were then used to buy the car: http://www.cnbc.com/id/101258152

You can't buy a Tesla from a dealer. There are no Tesla dealers.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#222
>>> and Peter Edge, Executive Associate Director of Homeland Security Investigations (“HSI”),

I wonder how is it "Homeland Security". Looks like this confirms "Homeland Security" is completely coopted into War on Drugs. Not that after this: https://www.eff.org/deeplinks/2014/10/peekaboo-i-see-you-gov... there was any doubt, but basically every time they talk about doing something to fight terrorism, it's probably means drug enforcement.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#223
post #204
post #191

Earlier quoted context omitted.

> By the way: If the FBI is so successful using traditional police tactics to infiltrate "cybercrime syndicates," why do they need a "front door" to our devices? Just like the old-fashioned police work they did here which you mentioned, the FBI in the past has been able to use warrants to obtain unilateral access to safe deposit boxes, drill open personal safes stored at home, search through a person's desks, closets…

> The cryptographic technology necessary to do so already exists, in a way that would limit access to the manufacturer, so that's not the issue. This is a genuine question: Does it really? Everything I've read on the topic has shown that that's not really the case, at least not without implementing it in such a way that it has some rather serious human weaknesses anyway. However, I'm rather ignorant on the topic, so…

Easy mode is to encrypt the device key for each individual device, store it only with the manufacturer. Make it more difficult by requiring m-of-n agreement (probably via a parity block scheme) between HSMs to derive the key if you wish (with the key material being guarded on separate stores so that an insider can't simply hack into access), but that's not that difficult in comparison to what we're talking about.

Even easier might be to have the device itself store an encrypted version of the data storage key, encrypted to a PKI private key that only the manufacturer controls (i.e. leave a GPG-encrypted file accessible in an unencrypted partition that unlocks the rest of the storage). Since we're assuming that skilled hackers will forcibly encrypt sensitive data anyways by jailbreaking if needed, it's not that much of an additional stretch to leave the key on the device itself, and FBI can still get warrants served on the 99.9% of accused criminals who can't be arsed to figure out that their iPhone can be unlocked.

I'm not even close to a crypto expert either, someone with deep insight into the crypto literature (I hear NSA has a few of those...) could undoubtedly point to more applicable research that would be useful here.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#224
post #134

Earlier quoted context omitted.

> Once they track it, they will get your hosting provider to cooperate and before you know it, This is the whackamole I was talking about. The time between when they identify the server and getting the provider to comply is enough in certain countries to set up an alternative location. Hosting companies aren't gonna want to play this game forever, ESPECIALLY if they're getting good money out of it.

So you'd just move servers every X months no matter what, or would you be tipped off somehow during that time window? If it's the first, that's pretty hardcore. Migrations are a pain for most people. Unless the system was built to migrate painlessly... Hm.

Set up the site so all the database transactions take place in memcache or redis and every 10 minutes it's written into encrypted entries on some kind of distributed blockchain (Datacoin, Namecoin, etc).

Use Docker to wrap up the front-end and make it easy and portable. You can then spin up a new iteration of the site on a new VPS in a matter of moments. It can download the DB entries from that blockchain, decrypt, and then keep the DB in memcache/redis. To speed things up, you can also do daily encrypted DB dumps to a DHT address and write the DHT address into the blockchain to bootstrap the service restart.

Once the DB is bootstrapped and caught up, the site can register itself on the Onion network and since it'll be the newest entry, traffic will start ending up at the new site pretty quickly.

Such a system could be automated pretty quickly where a person could register VPS's at Linode, Digital Ocean, AWS, etc. Then write some kind of encrypted config file into a blockchain so the site software would pull down the config and make the transition to the new provider automatically. Could be an automated daily move and by using a blockchain as an intermediary for communications it prevents worries about making mistakes with accidentally leaking IP addresses at each new service provider.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#225

They located Silk Road 2.0's server in an unspecified way, not directly related to their undercover agent on the support staff. Given that two other darknet markets (Black Market and Cloud9) have been shut down today, and they didn't specify how they located the SR2 server, it seems plausible that law enforcement have a vulnerability to locate servers over the Tor network. From the complaint: "In or about May 2014, t…

Interesting read, some highlights from the complaint: "40. Based on a review of records provided by the service provider for the Silk Road 2.0 Server (the “Provider”), I have discovered that the server was controlled and maintained during the relevant time by an individual using the email account “blake@benthall.net” (“Benthall Email Account-1")." "b. I have also reviewed a publicly available profile of “Blake Bentha…

>>> Google Chrome web browser version 35.0-1910.3 and the Apple OS X operating system, version 10.9.0

Hello browser fingerprinting, not a theoretical concern anymore I guess.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#226
post #222

>>> and Peter Edge, Executive Associate Director of Homeland Security Investigations (“HSI”), I wonder how is it "Homeland Security". Looks like this confirms "Homeland Security" is completely coopted into War on Drugs. Not that after this: https://www.eff.org/deeplinks/2014/10/peekaboo-i-see-you-gov... there was any doubt, but basically every time they talk about doing something to fight terrorism, it's probably mea…

ICE (Immigration and Customs Enforcement) is responsible for controlling the import of goods (such as counterfeit Dutch passports and ID cards, but probably including drugs too) into the country, and they're a part of DHS.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#227

Earlier quoted context omitted.

Sure, you could theoretically buy a used Tesla with Bitcoins. But it may be hard to find a dealer willing to do that. There was a story a while ago about someone buying a Tesla with Bitcoins, but it ended up being incorrect. The Bitcoins were exchanged for US Dollars which were then used to buy the car: http://www.cnbc.com/id/101258152

You can't buy a Tesla from a dealer. There are no Tesla dealers.

Dealers can sell a used Tesla.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#228
post #193

Earlier quoted context omitted.

I'm not sure if they did, "in this investigation". I was commenting more on the general tone of US agencies, since the PATRIOT ACT, and their contradictions of what is breaking the law when it applies to them vs. whomever they are investigating.

Commenting more on the general tone of US agencies, since changing the law to specifically allow an expanded set of investigatory techniques , is them "breaking the law"? What? You can argue they shouldn't have such authorities, but when the law explicitly gives them authority it's foolish to then claim they're breaking the law when using those same authorities.

It can still be breaking the law if they: a) exceed even the authority granted to them explicitly by the Patriot Act or b) the contents or interpretation of the Patriot Act violate the letter (and possibly the spirit/interpretation) of a higher law, namely the Constitution. IANAL so I don't know whether either of those are true, but is something that has been called into question (beyond the ethical or social-impact concerns over the laws and practices enabled by the act). I don't feel shutting down a black market is illegal (or unethical) unless the means to do so were illegal (or unethical). However, saying that US agencies violate the law more often after being given more powers within the law is not necessarily a self-contradictory or strange notion.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#229

Earlier quoted context omitted.

This sounds no different than the undercover police, detective work the FBI has been doing since its establishment. Infiltrate the perp, take him down. They used the same tactics on gangs, mobs, etc. Now violent crime is slowing, but they have hoardes of agents trained in these protocols, so they're redirecting energy into catching so called "cybercriminals." A bunch of people who infiltrated the mob are now infitrat…

> A bunch of people who infiltrated the mob are now infitrating groups of nerds in basements. It's frustratingly hilarious. I'm a little skeptical of this whole shtick that online criminals are just "nerds in basements." A nerd can do a lot more damage to your life with a computer than your average petty criminal.

True, but that doesn't necessarily mean they will. One of the smarter things about Silk Road in my view was the nominal policy of disallowing trade in child pornography, criminal services, stolen credit card data and so on, ie illicit things that also have (or are intended to have) victims who are necessarily injured as a condition of production. There's no economic tipping point at which the consumption of child pornography could justify the abuse perpetuated in its production, for example.

While the drug trade can cause people to become victims (just as the legal trade in alcohol or cigarettes or many other commodities), such victimhood is incidental to the production and consumption of the illicit good rather than inherent to it. I think this distinction between what sorts of contraband could be traded on Silk Road (even if it was not adhered to in practice) is a big part of why many people were/are sympathetic towards Silk Road.

Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court

#230
post #32

Earlier quoted context omitted.

On the community I have no idea, but I imagine the next reincarnation of these type of markets will have to be managed by lone wolfs out of a cave in Afghanistan.

in all seriousness perhaps iranian hosts would be a viable route

You'd probably fall afoul of sanctions law if you tried that.
Post reply on HN