I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
11–20 of 136 posts
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#12I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
Hopefully we'll eventually know the truth.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#13Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#14I am curious how a .onion domain seizure works. Does this mean the various law enforcement agencies are in possession of the private keys of the services they shut down?
How do they find the physical location? This could be by plenty of technical methods, which is really too elaborate to expand on here, but it's almost certainly not a flaw in Tor itself. It's just very hard to do it all correctly from A through Z, one mistake and you're busted, so that's why so many services can be taken down.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#15I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
I think that the feds having found and exploited a Tor vulnerability is much less likely than them having violated the law in the process of their investigation and then covered it up with parallel construction.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#16I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots.
TOR is fine, but now that we know that the FBI has its tendrils everywhere perhaps we should be a lot more cautious about trusting people we meet online. At the very least we shouldn't be granting administrator privileges to people we don't know the identities of, which is a mistake some of these operators seemingly made.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#171) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies.
2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card.
3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something.
4) When cashing in your ill-gotten gains, don't use your real name.
Seriously, if you're going to do this kind of stuff, paranoia is your friend. "They" probably are, indeed, following you.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#18I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
In a nutshell: assume that Tor hidden services are not amongst the highest traffic sites, that they still need to be hosted somewhere and that you can make your own traffic to such hosts stand out by sending alternate long-short sequences of packets to a hidden service by crafting requests simply inject a long sequence of such packets into Tor destined for the service you wish to unmask, then monitor your choke points to see where the sequence of long/short packets pops out last. That's the endpoint you're looking for. This undoes all the layers of the onion in one move. It will take some time before you have certainty because that same sequence will likely appear a number of times in a regular bunch of traffic as well but with increasing sequence length you should be able to get to good confidence that you have found the relevant host.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#19Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#20That is so freaking evil.