Earlier quoted context omitted.
They say this but why aren't they targetting the real evil shit on the dark web? Why the hell are they wasting their time and resources on drug busts when there are seriously sick dangerous people using those services, hunt them. They're the real dangers to society, not the ones selling weed and ecstasy. Makes me feel sick all the wasted talent that isn't being used to take down the dark dark corners of this world.
You say that as if organisations involved in the international drug trade are not engaging in "real evil shit". Not all cannabis sold in the United States is grown by long-haired Californians. Much of it is grown in Mexico by violent drug cartels that use slave labour and kill indiscriminately. They are practically the definition of evil, and sites like The Silk Road are pushing their product.
Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
71–80 of 136 posts
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#72Assuming TOR is compromised, what is to stop someone buying a vps (with fake/disposable credit card etc) hiding the main server behind this vps (with haproxy or stunnel)? FBI come along and image the vps, but it wont be the main server, connection details could be stored in RAM and if server taken down to image no configs would be left. Thoughts? obviously buying vps/servers in own name is dumb opsec. That way even i…
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#73“This is something we want to keep for ourselves,” he said. “The way we do this, we can’t share with the whole world, because we want to do it again and again and again.” That is so freaking evil.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#74Earlier quoted context omitted.
There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…
The whole idea of a centralized market, with someone syphoning off large amounts of money and being the major legal target, sets it up for failing. Once it becomes a distributed marketplace with all services replicated it becomes much more secure.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#75Now if only they can snag people who send anonymous death threats too.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#76Earlier quoted context omitted.
I'm not sure this part is true. You can buy servers and server parts anonymously via places like Craigslist with cash. At which point, you just need a fake ID to trick the Colo and pre-pay them for 12 months in cash w/o being recorded. Its possible given I've run into colos that were run by college kids with just a single cage. I'm pretty sure they wouldn't turn the offer down and just say you were "too busy" to set…
Then the authorities trace the server component to the person who sold it on Craigslist. And if your opsec isn't perfect, you're busted right there: Did you forget to set up a new email account for all of your craigslist transactions? Did you forget to set them up and connect to them only through Tor? Did the person you met with write down your license plate number? Seem unlikely? Think again. Cameras write down your…
If your opsec isn't perfect you are busted anyway. You already said that in the OP. ;)
> Did the person you met with write down your license plate number? Seem unlikely? Think again. Cameras write down your license plate number as you drive. Constantly. So the authorities will simply look up where the person drove to meet you (parking lot, etc) and any cars that drove to the area at the time. You'll probably be on a highway at some point, which is a highway of data collection. There weren't that many people who drove a long distance to go to the meetup area. Now the authorities know which of 1,000 people you are. The more times you do this, the fewer the number of suspects there are, until they're down to a number that they can just investigate one by one. Then you're caught.
We are assuming a criminal here. You use a fake license plate that you change regularly. You also move regularly and pay cash. Once again, your OpSec needs to be perfect but it is the only real obstacle. If they know which cluster of 1,000 people you are, your license plate gets changed, and you leave at the end of the month forever...they'd have to investigate all 1,000 people to maybe-possibly-id-you then try to figure out who and where you changed your license plate. But you are assuming they can trace the hardware of an anonymous cash transaction on craigslist again. I highly doubt that.
> Or did you take your cell phone with you, and did the person who sold you components take their cell phone? Yes, you're caught. The operation in the previous paragraph, which assumes that you're just driving to meet someone and both parties are leaving their cell phones at home, is already busted. So if you've taken your cell phone on top of it, then it's even easier. Anything involving correlating cell phone movements is trivial for authorities. And if you don't take your cell phone, how are you going to let them know you've arrived? What if they're late? Or you're late? Now you have two problems: Set up a burner phone in an anonymous way (hello, in-store security cameras) and then never, ever use this cell phone in the same place as your main cell phone. Not a good position to be in.
The last time I bought one, I met them at their house and rung the door bell. No phone required. You can also pay a bum to go in and buy the burners for you. Admittedly, I was just buying something to experiment with on the cheap so I didn't really care about anonymity.
However, you are making the assumption these components are easily traced in after market cash sales. I doubt strongly that they are that easy. And given you are trying to be anonymous, you don't care if either party is late since you'd wait a reasonable amount of time and if that failed, setup a new transaction elsewhere.
> I've ignored the whole "fake ID" aspect, because if you're in a position where someone is putting their face onto a forged legal document, that person is going to be persuaded by authorities to betray you. And if that person is you, then obviously you're caught at this point. Your face is probably on Facebook, and facial recognition software is getting pretty good nowadays. In general, physical ops are the most dangerous of all ops, and should be avoided until every other avenue has been explored. Better to anonymize your cash (which is also a physical op) and then use that cash to rent a single remote server.
You can't anonymize your cash for digital transactions given sufficient effort being expended to find you. If you don't do physical ops, you aren't paying cash. If you aren't paying cash, they will find you because the banks [which are intentionally letting things slide to increase business] can't hide it from the regulators forever. They've proven that repeatedly with billion+ dollar fines.
Honestly, it doesn't matter tho. I have no real interest in hiding to that degree. Everything I do is legal. :P Its just a fun mental exercise to me.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#77Assuming TOR is compromised, what is to stop someone buying a vps (with fake/disposable credit card etc) hiding the main server behind this vps (with haproxy or stunnel)? FBI come along and image the vps, but it wont be the main server, connection details could be stored in RAM and if server taken down to image no configs would be left. Thoughts? obviously buying vps/servers in own name is dumb opsec. That way even i…
Don't think that'd add anything. The people investigating you would presumably look at your network traffic and see all of the non-anonymized TLS packets traveling between your VPS and the real server. And they shouldn't need to bring the VPS down to get an image of its disk (or its RAM).
And the saving memory contents (could hold config files on tmpfs for example) seems to be a difficult process, from wikipedia "Holding unpowered RAM below −60 °C helps preserve residual data by an order of magnitude, improving the chances of successful recovery. However, it can be impractical to do this during a field examination."
It would be interesting to get perspective from any forensic experts.
The key imho is to put as many hoops in attackers path.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#78I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts. If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots. TOR is fine, but now that we know that the FBI has its tendrils everywhere pe…
TOR has always been traceable to anyone with enough resources as it makes no attempt to guard against timing attacks.
TOR has never been a secure defense against a collaboration between rich states, especially if you are running permanent services with lots of users.
Also, I do not quite see the intelligence benefits of trying to hide something that is mentioned in the TOR faq, this is not a secret weakness, but something that has been a known weakness since the project's inception.
The only secret revealed here is that the security services have been busy tapping lots of stuff, but that cat has been firmly out of the bag for a while and has since had kittens.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#79Lessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) Whe…
0) Don't engage in business someone else has a large interest on the status quo (drug distribution and sales).
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#80I think Wired was the first with the first Silk Road bust, too, or in similar FBI operations. Does the Wired have FBI "sources" or FBI PR contacts that give them these almost-exclusives?
It's a high profile tech magazine with mainstream credibility. It would be silly for them not to have FBI sources.
For the record I'm one of the people who believe what the FBI did here is wrong. I imagine if they had know what it is and what it can do early on, they would've shut down Bittorrent Inc, too, for "facilitating piracy", "conspiracy to create piracy", "money laundering" (by making money as a company that creates torrent technology), and some other CFAA charges, for good measure - all of them bullshit.