Live data from Hacker News

Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

wired.com

51–60 of 136 posts

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#51
post #24

Earlier quoted context omitted.

You'd do well to just avoid the U.S. of A. (and friends, I guess). Take those profits and go somewhere safe and manage your newfound business from there. That could be one of the reasons some of the larger markets are still standing.

They catch Russian carding marketplace admins all the time so living in Brazil or Russia is no guarantee you won't end up in jail either. Just takes one mistake and you are on a plane in handcuffs to a federal court. They could bribe local police to pick you up for them too especially if you aren't politically connected in those countries.

if you are russian and living in russia they will not extradite you and as long as you are not targeting russians the police will not care that is why many of these carders dont get arrested and if they do it is usually when they leave russia.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#52
post #16

Earlier quoted context omitted.

I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts. If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots. TOR is fine, but now that we know that the FBI has its tendrils everywhere pe…

They don't have to break Tors crypto to figure out where hidden services are. They just need to identify which IPs are consistantly connected to the Tor network, and then prod them and see if the hidden service goes offline. That is one of the reasons why you're absolutely not supposed to run a relay from the same IP that you run a hidden service from. Because your IP is published if you do that. If I were to run suc…

Actually a relay will be awesome way to mask a hidden service, if TOR encryption holds.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#53
post #20

“This is something we want to keep for ourselves,” he said. “The way we do this, we can’t share with the whole world, because we want to do it again and again and again.” That is so freaking evil.

They say this but why aren't they targetting the real evil shit on the dark web? Why the hell are they wasting their time and resources on drug busts when there are seriously sick dangerous people using those services, hunt them. They're the real dangers to society, not the ones selling weed and ecstasy.

Makes me feel sick all the wasted talent that isn't being used to take down the dark dark corners of this world.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#54
post #41

Earlier quoted context omitted.

Requesting an image of a paranoid person's server isn't necessarily that great. When I worked for a run-of-the-mill cybersecurity firm, our simulator products were protected with full disk encryption using run-of-the-mill open-source software + light patches and keys bound to specific hardware, software, and configuration states via the TPM. This is for fully automated boot up. If you can accept the risk of needing t…

It's an interesting idea. I think physically shipping a server to a datacenter is precarious. Remember, it is known that your server is hosting a darknet website. You can't really hide this fact. Timing correlations make it possible to figure out which server is doing what. The reason that Tor users are generally safe from this is because they're not constantly connected, and an adversary generally can't cause a clie…

How about hosting your website on a botnet? Using infected machines to handle requests and sending the compressed order info over TOR to suppliers?

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#55
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…

To be honest, I don't think it is possible to evade the authorities and run a profitable business on BTC.

I think that is really where these markets are running into trouble. They need to spend the BTC they earn to cover their costs and lifestyle, at which point it becomes pretty obvious given I doubt there are many people converting BTC to cash in 6 figure quantities per year. Given the blockchain isn't anonymous, every 3rd party you move your BTC through can receive a warrant until they find the name you withdrew the cash under. They all want your bank account information which means you'd need a fake bank account.

Once you hit the "I need a fake second identity for financial information, etc." you are going to throw up all kinds of red flags.

Yes the banks break the rules [e.g. HSBC]:

http://www.reuters.com/article/2013/07/02/us-hsbc-settlement...

But they do eventually get caught.

I think Tor and the Darknet is great when you need to start a revolution or other non-profit-activity. The moment you try to make money you can live off of and cover your costs is the moment you accept you will get caught eventually.

> How to make the equivalent of unlisted Tor exit nodes so that Tor isn't so trivially blocked?

Run a VPN connection through TOR via a service that lets you pay anonymously. [e.g. gift cards you can buy with cash]

Of course, then the VPN can snoop all your traffic but given you are using TOR...you should be expecting that anyway. TOR guarantees technical anonymity, not privacy. You screw up your OpSec and you are screwed anyway. ~

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#56
"When WIRED spoke Thursday night with Troels Oerting, head of the European Cybercrime Center, he said his staff hadn’t even had time to assemble the full list of sites it’s pulled down in the sprawling operation."

That sounds a bit cavalier. Are they actually checking whether the sites are involved in illegal activity before they pull them down? Or is merely hosting a website on Tor illegal nowadays?

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#57
post #41

Earlier quoted context omitted.

Requesting an image of a paranoid person's server isn't necessarily that great. When I worked for a run-of-the-mill cybersecurity firm, our simulator products were protected with full disk encryption using run-of-the-mill open-source software + light patches and keys bound to specific hardware, software, and configuration states via the TPM. This is for fully automated boot up. If you can accept the risk of needing t…

It's an interesting idea. I think physically shipping a server to a datacenter is precarious. Remember, it is known that your server is hosting a darknet website. You can't really hide this fact. Timing correlations make it possible to figure out which server is doing what. The reason that Tor users are generally safe from this is because they're not constantly connected, and an adversary generally can't cause a clie…

I'm not sure this part is true.

You can buy servers and server parts anonymously via places like Craigslist with cash. At which point, you just need a fake ID to trick the Colo and pre-pay them for 12 months in cash w/o being recorded. Its possible given I've run into colos that were run by college kids with just a single cage. I'm pretty sure they wouldn't turn the offer down and just say you were "too busy" to set it up yourself due to work.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#58
post #54

Earlier quoted context omitted.

It's an interesting idea. I think physically shipping a server to a datacenter is precarious. Remember, it is known that your server is hosting a darknet website. You can't really hide this fact. Timing correlations make it possible to figure out which server is doing what. The reason that Tor users are generally safe from this is because they're not constantly connected, and an adversary generally can't cause a clie…

How about hosting your website on a botnet? Using infected machines to handle requests and sending the compressed order info over TOR to suppliers?

Not a bad idea, assuming you don't care about taking other people's property and using it in ways they don't expect for personal gain. But it's difficult. Once you no longer control the underlying hardware guarantees, availability chief among them, it's hard to design a reliable webservice. There has been some research in this area, though I'm not intimately familiar with it. Find it and read up on it. In general, the problem is how to organize some kind of store of data across multiple unreliable machines. That sounds like a solved problem (bigtable et al) until you realize it also needs to be secure, and you're running on an unsecure network of infected computers. At some point, some computer needs to access the secure info. If you're letting infected computers do that, then that means its operator can also do that. Though, in fairness, maybe you don't need to care about that threat. A bigger threat is that the operator would also have write access: they could corrupt your data or forge transactions in your system.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#59

"When WIRED spoke Thursday night with Troels Oerting, head of the European Cybercrime Center, he said his staff hadn’t even had time to assemble the full list of sites it’s pulled down in the sprawling operation." That sounds a bit cavalier. Are they actually checking whether the sites are involved in illegal activity before they pull them down? Or is merely hosting a website on Tor illegal nowadays?

A less ominous interpretation could be that they pulled some servers and aren't sure how many sites were hosted on them.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#60
post #48

Earlier quoted context omitted.

There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…

> Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website. This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic…

>This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic and all of them could be hosting hidden services as well. The total traffic in itself doesn't necessarily show that a server hosts hidden services. It could also me masked by generating fake traffic to/from the server.

Relays (exit and non-exit relays) are listed in the consensus, so you can easily rule them out, or just watch the hidden service and the relay and correlate downtime.

Bridges are not listed in the consensus, but they also don't survive very long, and don't carry very much traffic, since they tend to be used by a small number of individuals. So bridges will naturally churn out of your target set.

>neither Europol nor the FBI can just walk into any data center and request images of any server that handles Tor traffic without a warrant,

This seems optimistic at best. They could certainly ask to install a wiretap, or just threaten their way into installing a wiretap (i.e., install this wiretap or my buddy at the EPA is going to be allllll over you for how bad your parking lot is drained, etc). They could just ask and say they suspect the computer is involved in child pornography, which will probably override most people's objections.

But beyond that, people tend to cooperate with authorities. It's either a natural state of humans to be subservient, or we've been indoctrinated through eons of hierarchy, but now, the only thing necessary to get someone to kill someone else is a stern command. If you don't believe me, look up the Milgram experiments.

Post reply on HN