Live data from Hacker News

Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

wired.com

31–40 of 136 posts

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#32
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

There are some interesting theories being tossed around. I'd like to add one more.

The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence.

Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocating is also compromised.

I'd like to posit the following law of nature: You can't run a darknet website from a datacenter and think you've hidden the location of the server, regardless of whether it's using Tor or other anonymity software.

Why not? Because the datacenter has the ability to image servers, along with the ability to notice that you're generating large amounts of outgoing Tor traffic (or other anonymity software).

Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website.

Remember, the point of Tor is to hide the final IP address of a web request or web service. It does not hide the total volume of traffic that must be delivered. And it can't. If you operate a darknet marketplace, you're probably serving a large volume of traffic. Guess who notices? ISPs and datacenters. Guess which datacenters can be trusted not to divulge an image of your server to authorities? None of them.

What do I think the future of darknet opsec will look like? Well, if you're reading this, and you're an individual or group interested in pursuing your ideology through a darknet website, you will need to run your website from a datacenter and not rent your server in your name. In fact, your opsec needs to be so good that there's no way to trace the account back to you. This sounds hard, and it is, but it's possible. Secondly, you must assume at all times that the server you're using is compromised. Assume that aurhorities can access the contents of the server, can manipulate it, and can subvert anything you put on it.

This is a grim situation, to be sure. The above assumption is that you are never safe from authorities gaining a copy of the contents of your datacenter-hosted darknet website (including any databases), and from a takedown of the service whenever authorities deem to do so.

Here's the ray of hope: Just because they takedown your website doesn't mean they take you down. This is where opsec comes into play, and it's our last hope. Every other link in the chain of trust for darknet websites has been broken. The one and only chance is that you can figure out a way to create accounts at datacenters without authorities being able to trace them back to you.

Authorities takedown your service? Okay, start it again at some other datacenter. Authorities get a copy of what's on your server? Okay, no problem: you were assuming it was compromised anyway, right? Authorities install a program to make your software malfunction? That's unfortunate, and will shake the trust in your website, but it's possible to recover from this.

Do your best, and do not get caught. The rest follows from this.

At a minimum, you need to research opsec. Read history of how groups have evaded detection. Do your research using Tor, because associating such Google searches with your home account is a terrible mistake.

One of your biggest problems is going to be anonymous money. No, bitcoin won't help you. You can't rent a server from a datacenter using bitcoin. But you can anonymize your money and then use that money to rent your server.

It's a long shot, but it's all we've got left. Be perfect. There's no room for error. Or realize the truth: If you can't be perfect, you will get caught. And you may get caught anyway. Being perfect sounds impossible, but human history has shown that there are situations in which no or few mistakes are made. I would recommend you research those situations and how to minimize the total number of mistakes you make. Use software to help you do this, while realizing that clever software alone won't be enough. For example, if you're configuring an individual piece of software on your personal computer to connect to your darknet website, even through Tor, you're doing it wrong. You need to isolate yourself from this equation at all times. Sound hard? Oh, it's hard. It will slowly dawn on you how hard this method of operating is. Convenience? No. You don't get to enjoy the benefits of convenience. Convenience is the opposite of security.

Oh, and if you do happen to somehow make a lot of money, you should keep it as bitcoin for the forseeable future. What good is it? Maybe converting small amounts won't be noticed. On the other hand, converting large amounts of bitcoin to dollars will be noticed, and it's extraordinarily dangerous to your opsec.

I'll be around to answer questions if you have them. If you'd like to ask a question anonymously using Tor, create a new HN account and post your question. I'll see it, but it will show up as dead on HN, so I won't be able to reply to it directly. So I'll reply to my own comment with a copy of your question, along with a response. Then you can reply to that, and I'll repeat the process.

HN is one of the few websites that we can even have these kinds of conversations on using Tor. Everything on Reddit is autokilled. 4chan doesn't let you use Tor. Maybe we should work on this problem first: How to make the equivalent of unlisted Tor exit nodes so that Tor isn't so trivially blocked?

There are a lot of ideas in my comment, and some of them are better than others. I hope that the bad ideas can be discarded and the good ones refined until we have someting workable.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#33
post #16
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts. If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots. TOR is fine, but now that we know that the FBI has its tendrils everywhere pe…

> I refuse to believe that the FBI is privy to a funamental TOR break[...] and they're risking revealing it with some darknet busts.

This is probably the best analysis I've heard.

If the Tor protocol was broken in some way, agencies would be sitting on it to vacuum up as much information as possible. If the underlying cryptographic primitives were broken in any way, that information would be restricted to the highest levels of government and used against state actors.

Darknet busts mean JS browser injection attacks, poor development practices on the server side, or bad human factors (probably this one, from what we're hearing).

But more importantly, increasing the frequency of darknet busts gives a hint of what the authorities think about Tor: they don't have fundamental attacks, so it's best to scare people away as much as possible to discourage use.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#34
post #16
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts. If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots. TOR is fine, but now that we know that the FBI has its tendrils everywhere pe…

I would caution against drawing arbitrary lines between agencies like FBA and NSA or GCHQ or the "cryptographic community" in terms of information/skills, e.g. http://www.foreignpolicy.com/articles/2013/11/21/the_obscure...

It might be more accurate to conclude that information is a currency in an unregulated market: GCHQ shares with NSA who shares with FBI DITU amongst many other public and private sector customers.

In a world of parallel construction, the most reasonable assumption is that anyone can be privy to anything, or at least information derived from it.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#35
post #30

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

Just how law enforcement agents were able to locate the Dark Web sites despite their use of the Tor anonymity software remains a looming mystery. Do you happen to have a source for the "personal credit card" and "Tesla for BTC" lessons, or is this mere speculation? Edit: Tesla downpayment documented in Blake Benthall Criminal Complaint: http://www.scribd.com/doc/245744857/Blake-Benthall-Criminal-...

[deleted]

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#37
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…

The whole idea of a centralized market, with someone syphoning off large amounts of money and being the major legal target, sets it up for failing. Once it becomes a distributed marketplace with all services replicated it becomes much more secure.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#38
post #24

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

You'd do well to just avoid the U.S. of A. (and friends, I guess). Take those profits and go somewhere safe and manage your newfound business from there. That could be one of the reasons some of the larger markets are still standing.

Ignore the fact that the entire West is working together at your peril.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#39
post #19

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

This gives me an interesting thought for a startup. Provide training and testing for law enforcement for these scenarios. Would also give you the chance to outsmart law enforcement without getting arrested.

Doesn't palantir basically just do this for them?

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#40
post #24

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

You'd do well to just avoid the U.S. of A. (and friends, I guess). Take those profits and go somewhere safe and manage your newfound business from there. That could be one of the reasons some of the larger markets are still standing.

They catch Russian carding marketplace admins all the time so living in Brazil or Russia is no guarantee you won't end up in jail either. Just takes one mistake and you are on a plane in handcuffs to a federal court. They could bribe local police to pick you up for them too especially if you aren't politically connected in those countries.
Post reply on HN