Live data from Hacker News

Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

wired.com

11–20 of 136 posts

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#11
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

Note that this is all about .onion hosted servers. Any flaws might be about locating the servers inside the TOR network and not about identifying individual users.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#12
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I sincerely hope this was done not through Tor backdoors but through traditional police techniques. It would be a great piece of evidence in support of anonymity if they were able to do all of this without finding/creating exploits.

Hopefully we'll eventually know the truth.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#14

I am curious how a .onion domain seizure works. Does this mean the various law enforcement agencies are in possession of the private keys of the services they shut down?

They somehow find the physical location of the hidden service and then are able to take control (e.g. via a letter to the webhost). After that they have full control over the server and thereby also the key behind the .onion address.

How do they find the physical location? This could be by plenty of technical methods, which is really too elaborate to expand on here, but it's almost certainly not a flaw in Tor itself. It's just very hard to do it all correctly from A through Z, one mistake and you're busted, so that's why so many services can be taken down.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#15
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I think that the feds having found and exploited a Tor vulnerability is much less likely than them having violated the law in the process of their investigation and then covered it up with parallel construction.

But Tor should protect against illegal actions as much as against legal ones. Unless, of course, they hacked into the servers (using flaws unrelated to Tor), but the problem is how these servers were even located!

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#16
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts.

If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots.

TOR is fine, but now that we know that the FBI has its tendrils everywhere perhaps we should be a lot more cautious about trusting people we meet online. At the very least we shouldn't be granting administrator privileges to people we don't know the identities of, which is a mistake some of these operators seemingly made.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#17
Lessons learned:

1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies.

2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card.

3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something.

4) When cashing in your ill-gotten gains, don't use your real name.

Seriously, if you're going to do this kind of stuff, paranoia is your friend. "They" probably are, indeed, following you.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#18
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I can think of at least one very easy way to break Tor, if you have access to a bunch of choke points however I'm nowhere near an expert in security so feel free to beat me to death over exceeding my area of expertise.

In a nutshell: assume that Tor hidden services are not amongst the highest traffic sites, that they still need to be hosted somewhere and that you can make your own traffic to such hosts stand out by sending alternate long-short sequences of packets to a hidden service by crafting requests simply inject a long sequence of such packets into Tor destined for the service you wish to unmask, then monitor your choke points to see where the sequence of long/short packets pops out last. That's the endpoint you're looking for. This undoes all the layers of the onion in one move. It will take some time before you have certainty because that same sequence will likely appear a number of times in a regular bunch of traffic as well but with increasing sequence length you should be able to get to good confidence that you have found the relevant host.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#19

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

This gives me an interesting thought for a startup. Provide training and testing for law enforcement for these scenarios. Would also give you the chance to outsmart law enforcement without getting arrested.
Post reply on HN