Live data from Hacker News

Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

wired.com

61–70 of 136 posts

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#61
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

The DHS had an infiltrator in Silk Road 2.0:

http://building.liberty.me/2014/11/06/breaking-silk-road-2-0...

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#62

Earlier quoted context omitted.

It's an interesting idea. I think physically shipping a server to a datacenter is precarious. Remember, it is known that your server is hosting a darknet website. You can't really hide this fact. Timing correlations make it possible to figure out which server is doing what. The reason that Tor users are generally safe from this is because they're not constantly connected, and an adversary generally can't cause a clie…

I'm not sure this part is true. You can buy servers and server parts anonymously via places like Craigslist with cash. At which point, you just need a fake ID to trick the Colo and pre-pay them for 12 months in cash w/o being recorded. Its possible given I've run into colos that were run by college kids with just a single cage. I'm pretty sure they wouldn't turn the offer down and just say you were "too busy" to set…

Then the authorities trace the server component to the person who sold it on Craigslist. And if your opsec isn't perfect, you're busted right there: Did you forget to set up a new email account for all of your craigslist transactions? Did you forget to set them up and connect to them only through Tor?

Did the person you met with write down your license plate number? Seem unlikely? Think again. Cameras write down your license plate number as you drive. Constantly. So the authorities will simply look up where the person drove to meet you (parking lot, etc) and any cars that drove to the area at the time. You'll probably be on a highway at some point, which is a highway of data collection. There weren't that many people who drove a long distance to go to the meetup area. Now the authorities know which of 1,000 people you are. The more times you do this, the fewer the number of suspects there are, until they're down to a number that they can just investigate one by one. Then you're caught.

Or did you take your cell phone with you, and did the person who sold you components take their cell phone? Yes, you're caught. The operation in the previous paragraph, which assumes that you're just driving to meet someone and both parties are leaving their cell phones at home, is already busted. So if you've taken your cell phone on top of it, then it's even easier. Anything involving correlating cell phone movements is trivial for authorities. And if you don't take your cell phone, how are you going to let them know you've arrived? What if they're late? Or you're late? Now you have two problems: Set up a burner phone in an anonymous way (hello, in-store security cameras) and then never, ever use this cell phone in the same place as your main cell phone. Not a good position to be in.

I've ignored the whole "fake ID" aspect, because if you're in a position where someone is putting their face onto a forged legal document, that person is going to be persuaded by authorities to betray you. And if that person is you, then obviously you're caught at this point. Your face is probably on Facebook, and facial recognition software is getting pretty good nowadays.

In general, physical ops are the most dangerous of all ops, and should be avoided until every other avenue has been explored. Better to anonymize your cash (which is also a physical op) and then use that cash to rent a single remote server.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#63
post #5

I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.

This is a very hasty conclusion.

I think it's several orders of magnitude more probable that several greedy and half-intelligent people (intelligent enough to execute a darknet market and unintelligent enough that they aren't already well-compensated for their intelligence) saw a MASSIVE vacuum open up in the ecosystem when the Silk Road shut down. And they went for it, with varying degrees of success.

Tor is an anonymizing TCP overlay. That is all it is. It will make it so your TCP stream is not connected to your IP address.

But that's all.

I got asked a question, just two days ago, if Tor would make someone anonymous if they logged into their facebook account. Do you think it will? Do you think it's advertised that way?

Further, even the Tor developers acknowledge that hidden services are not a priority for them. Their priority is far and away client usage, because their largest userbase and their funders' priorities are bypassing Internet censorship, not running darknet marketplaces.

What was your reasoning process that lead you to discard the other explanations rather than Tor being weak?

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#64
post #20

“This is something we want to keep for ourselves,” he said. “The way we do this, we can’t share with the whole world, because we want to do it again and again and again.” That is so freaking evil.

They say this but why aren't they targetting the real evil shit on the dark web? Why the hell are they wasting their time and resources on drug busts when there are seriously sick dangerous people using those services, hunt them. They're the real dangers to society, not the ones selling weed and ecstasy. Makes me feel sick all the wasted talent that isn't being used to take down the dark dark corners of this world.

You say that as if organisations involved in the international drug trade are not engaging in "real evil shit". Not all cannabis sold in the United States is grown by long-haired Californians. Much of it is grown in Mexico by violent drug cartels that use slave labour and kill indiscriminately. They are practically the definition of evil, and sites like The Silk Road are pushing their product.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#65

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

0) Don't engage in business someone else has a large interest on the status quo (drug distribution and sales).

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#66
post #24

Earlier quoted context omitted.

You'd do well to just avoid the U.S. of A. (and friends, I guess). Take those profits and go somewhere safe and manage your newfound business from there. That could be one of the reasons some of the larger markets are still standing.

They catch Russian carding marketplace admins all the time so living in Brazil or Russia is no guarantee you won't end up in jail either. Just takes one mistake and you are on a plane in handcuffs to a federal court. They could bribe local police to pick you up for them too especially if you aren't politically connected in those countries.

And let's be honest, if one were to go to jail in the US, Brazil, or Russia, especially as a (formerly) wealthy American, the US is an order of magnitude better than the other two.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#67
Assuming TOR is compromised, what is to stop someone buying a vps (with fake/disposable credit card etc) hiding the main server behind this vps (with haproxy or stunnel)?

FBI come along and image the vps, but it wont be the main server, connection details could be stored in RAM and if server taken down to image no configs would be left.

Thoughts? obviously buying vps/servers in own name is dumb opsec. That way even if TOR is compromised you lose just a frontend point.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#68
post #48

Earlier quoted context omitted.

There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…

> Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website. This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic…

neither Europol nor the FBI can just walk into any data center and request images of any server that handles Tor traffic without a warrant, which would require some tangible evidence to support its release

What about with a data request by a judge in Italy, raising a sealed subpoena through a Texas court to get the FBI to physically remove a server from a datacenter in London belonging to a UK organisation, without informing them, the UK government or the UK police, all while keeping the original reasons for this under seal, and then suddenly returning the hardware just as mysteriously as it was first taken, without thinking you should have to explain a single thing?

That happened to Indymedia years ago. - https://www.eff.org/cases/indymedia-server-takedown

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#69
post #30

Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…

Just how law enforcement agents were able to locate the Dark Web sites despite their use of the Tor anonymity software remains a looming mystery. Do you happen to have a source for the "personal credit card" and "Tesla for BTC" lessons, or is this mere speculation? Edit: Tesla downpayment documented in Blake Benthall Criminal Complaint: http://www.scribd.com/doc/245744857/Blake-Benthall-Criminal-...

The Ars Technica article at http://arstechnica.com/tech-policy/2014/11/silk-road-2-0-inf... has the quote:

> "The server was controlled and maintained during the relevant time by an individual using the email account 'blake@benthall.net,'"

Since he used his personal e-mail for hosting, I would assume he used his personal credit card too.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#70
post #24

Earlier quoted context omitted.

You'd do well to just avoid the U.S. of A. (and friends, I guess). Take those profits and go somewhere safe and manage your newfound business from there. That could be one of the reasons some of the larger markets are still standing.

They catch Russian carding marketplace admins all the time so living in Brazil or Russia is no guarantee you won't end up in jail either. Just takes one mistake and you are on a plane in handcuffs to a federal court. They could bribe local police to pick you up for them too especially if you aren't politically connected in those countries.

Actually, Brazil has very tight control on financial transactions that take place in the country. Especially international transactions are closely monitored. I heard this is the reason why Paypal took so long to get here. In addition, I've read many news which point out close cooperation between Brazilian police and foreign agencies. I think a shady BTC millionaire would have a short run in here, unless he was very insightful of the local system, as well as extremely cautious and creative with the way he handled money.
Post reply on HN