Live data from Hacker News

Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

wired.com

21–30 of 136 posts

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#21
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I sincerely hope this was done not through Tor backdoors but through traditional police techniques. It would be a great piece of evidence in support of anonymity if they were able to do all of this without finding/creating exploits. Hopefully we'll eventually know the truth.

I've heard reports that Feds were actually moderators of SR2 from the very start. So from the beginning they were actively building a case against the other owners.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#22
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I can think of at least one very easy way to break Tor, if you have access to a bunch of choke points however I'm nowhere near an expert in security so feel free to beat me to death over exceeding my area of expertise. In a nutshell: assume that Tor hidden services are not amongst the highest traffic sites, that they still need to be hosted somewhere and that you can make your own traffic to such hosts stand out by s…

I believe this has been a well known underlying problem with Tor for a long time as it only really provides anonymity. If you control enough exit nodes, or alternatively, control the means of transmission in enough places, you can narrow the net and get closer to finding things. At the very least, one could get close enough to allow one to focus more traditional investigatory techniques. The problem is this is a fairly large scale problem. Now any organizations with the capacity to do something like that? I seem to recall lots of speculation around the time Snowden came out.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#24

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

You'd do well to just avoid the U.S. of A. (and friends, I guess). Take those profits and go somewhere safe and manage your newfound business from there. That could be one of the reasons some of the larger markets are still standing.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#26
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I can think of at least one very easy way to break Tor, if you have access to a bunch of choke points however I'm nowhere near an expert in security so feel free to beat me to death over exceeding my area of expertise. In a nutshell: assume that Tor hidden services are not amongst the highest traffic sites, that they still need to be hosted somewhere and that you can make your own traffic to such hosts stand out by s…

That type of traffic correlation attack is pretty well known and understood. The problem is that Tor simply isn't designed to protect against a global adversary.

If you're the NSA, you can inject traffic through, bisect the network by forcing certain nodes offline, ...

Tor can't defend against that. But we don't have anything right now that would.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#27
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

It is much, much more likely that law enforcement hacked onion domains because of their improper implementations of TOR procedures and/or general shitty security than it is that they discovered a fundamental security vulnerability in TOR.

The weak link here isn't TOR, it's the doofus who bought the Tesla with $130k worth of BTC.

Which is why I would never mess with darknet sites. I trust the TOR network, but I don't at all trust the individual domain owners.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#28
post #6
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

Agreed. From this point forward Tor is considered harmful. But the same time, it seems like they're using workarounds, attacking the browser etc. I still believe the underlying network remains unbroken.

> Agreed. From this point forward Tor is considered harmful.

Planting that seed in your mind was almost certainly one of the goals of this action. Mission accomplished, FBI.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#29
post #8

I think Wired was the first with the first Silk Road bust, too, or in similar FBI operations. Does the Wired have FBI "sources" or FBI PR contacts that give them these almost-exclusives?

It's a high profile tech magazine with mainstream credibility. It would be silly for them not to have FBI sources.

Some guy in a fedora and freebsd t-shirt hanging around sleazy bars downtown waiting for his flipped FBI agent to come around and drop him some new juicy goss on the latest... TF2 hat update? Sounds legit

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#30

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

Just how law enforcement agents were able to locate the Dark Web sites despite their use of the Tor anonymity software remains a looming mystery.

Do you happen to have a source for the "personal credit card" and "Tesla for BTC" lessons, or is this mere speculation?

Edit: Tesla downpayment documented in Blake Benthall Criminal Complaint: http://www.scribd.com/doc/245744857/Blake-Benthall-Criminal-...

Post reply on HN