Earlier quoted context omitted.
I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts. If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots. TOR is fine, but now that we know that the FBI has its tendrils everywhere pe…
> I refuse to believe that the FBI is privy to a funamental TOR break[...] and they're risking revealing it with some darknet busts. This is probably the best analysis I've heard. If the Tor protocol was broken in some way, agencies would be sitting on it to vacuum up as much information as possible. If the underlying cryptographic primitives were broken in any way, that information would be restricted to the highest…
Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
101–110 of 136 posts
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#102Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#103Earlier quoted context omitted.
> Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website. This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic…
>This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic and all of them could be hosting hidden services as well. The total traffic in itself doesn't necessarily show that a server hosts hidden services. It could also me masked by generating fake traffic to/from the server. Relays (exit and non-exit relays) are listed in the consensus, so you can…
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#104Earlier quoted context omitted.
There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…
> Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website. This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic…
They can just enumerate every hidden service, figure out which ones are doing something obviously illegal, then once they locate a datacenter that is likely to be hosting hidden services e.g. accepts payment in Bitcoin, get netflow data and pump traffic at each hidden service in turn. When a synchronised block of encrypted traffic turns up at a host, there's your probable cause to go image the server: it's practically bulletproof evidence that the hidden service corresponding to some black market is running on that machine.
The only bottleneck to this approach is finding the datacenters, but there aren't that many which accept Bitcoin for payment, and I bet intelligence agencies can easily provide a list of every colocation facility that is running long term connections to the Tor network. Heck they can probably identify the precise machines by doing traffic correlation automatically - it's the sort of task they'd be good at, and they have the infrastructure.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#105Earlier quoted context omitted.
There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…
One potential long term outcome of these highly publicized fed / darknet busts is that future operators will learn from the opsec mistakes of Dread Pirate Roberts, Blake Benthall, Sanu, Lulzsec, Anonsec, etc. Theoretically after enough people cock up, the 'playbook' on how to run a dark service / h4x0r group should be sufficiently fleshed out and there will be fewer and fewer busts.
Remember, the FBI's story about a leaky captcha only came out very recently. SR2 had been running for a long time by then. And there's currently no info about how they found the servers for 414 different onion sites: seems most likely they have beaten hidden service security and can now find most or all of the ones they want. No opsec gonna save you from that.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#106Earlier quoted context omitted.
I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts. If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots. TOR is fine, but now that we know that the FBI has its tendrils everywhere pe…
They don't have to break Tors crypto to figure out where hidden services are. They just need to identify which IPs are consistantly connected to the Tor network, and then prod them and see if the hidden service goes offline. That is one of the reasons why you're absolutely not supposed to run a relay from the same IP that you run a hidden service from. Because your IP is published if you do that. If I were to run suc…
QUANTUM + XKEYSCORE + some MapReductions would make mincemeat of this problem.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#107I think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
There are some interesting theories being tossed around. I'd like to add one more. The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence. Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocatin…
Why not? A google search for this reveals several companies who offer this.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#108Earlier quoted context omitted.
The whole idea of a centralized market, with someone syphoning off large amounts of money and being the major legal target, sets it up for failing. Once it becomes a distributed marketplace with all services replicated it becomes much more secure.
So like the distributed tracker system in bittorrent I guess: http://en.wikipedia.org/wiki/BitTorrent#Distributed_trackers Some background research on a distributed key/value system that this could serve as a basis for a peer-to-peer distributed marketplace: http://www.cs.rice.edu/Conferences/IPTPS02/109.pdf
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#109Edit: I should say that openbazaar hasn't been released, and very little work has gone into allowing for anonymous nodes on the market. The idea is that once openbazaar is released then people can apply Tor anonymity to connecting their market node to the database of all nodes where things are available for purchase.
Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
#110“This is something we want to keep for ourselves,” he said. “The way we do this, we can’t share with the whole world, because we want to do it again and again and again.” That is so freaking evil.
They say this but why aren't they targetting the real evil shit on the dark web? Why the hell are they wasting their time and resources on drug busts when there are seriously sick dangerous people using those services, hunt them. They're the real dangers to society, not the ones selling weed and ecstasy. Makes me feel sick all the wasted talent that isn't being used to take down the dark dark corners of this world.