Live data from Hacker News

Running a Dark Web pedophile honeypot

geekslop.com

1–10 of 185 posts

Re: Running a Dark Web pedophile honeypot

#2
Is it just me, or the rhetorical question in the title ("why I now think Tor is the devil") never got answered?

Also not clear whether the Dark Web spider project was just to later seed the honeypot sites to appear legit, or was it a project on its own? The quote "The reports are published nightly on a hacker-related Dark Web site that I am involved with" hints at the latter, and then I'd double don't understand why Tor would be the devil, if for other uses (hackers) the author is happy to take advantage of it?

I'm a bit confused about what good does it do to reveal the exit node addresses? It has nothing to do with the actual Tor user, and could be even considered "public info" the way Tor is used, doesn't it?

Re: Running a Dark Web pedophile honeypot

#3
post #2

Is it just me, or the rhetorical question in the title ("why I now think Tor is the devil") never got answered? Also not clear whether the Dark Web spider project was just to later seed the honeypot sites to appear legit, or was it a project on its own? The quote "The reports are published nightly on a hacker-related Dark Web site that I am involved with" hints at the latter, and then I'd double don't understand why…

Yeah this is clearly by someone who doesn't really understand how Tor works. Revealing exit node IP addresses is completely useless—this is a fundamental tenant of Tor's security. In fact, I believe that at any given time you can easily query the network for a list of all Tor exit nodes.

I think the "why I now think Tor is the devil" question is answered in the opening—because it has illegal/immoral stuff on it. I'm not sure why anyone would be surprised about this though...

EDIT: In fact, I don't think that the security scanner was even that effective: "around 5-10% of the registered users chose to run the scanner" (later, he changes this to 4-7%) and that "some of the users who opted to run the software appeared to be government or private researchers". I don't know what percentage of people using Tor for illegal activity would be incautious enough to run some random program on their computer, but I would be surprised if it was very high.

Re: Running a Dark Web pedophile honeypot

#4
post #2

Is it just me, or the rhetorical question in the title ("why I now think Tor is the devil") never got answered? Also not clear whether the Dark Web spider project was just to later seed the honeypot sites to appear legit, or was it a project on its own? The quote "The reports are published nightly on a hacker-related Dark Web site that I am involved with" hints at the latter, and then I'd double don't understand why…

I think the implication is its the devil because mostly Tor is used for pedophilic reasons - drugs, counterfeiting or political protest (I'd assume) are almost insignificant in comparison to pedophile traffic.

Re: Running a Dark Web pedophile honeypot

#6
post #2

Is it just me, or the rhetorical question in the title ("why I now think Tor is the devil") never got answered? Also not clear whether the Dark Web spider project was just to later seed the honeypot sites to appear legit, or was it a project on its own? The quote "The reports are published nightly on a hacker-related Dark Web site that I am involved with" hints at the latter, and then I'd double don't understand why…

I think the implication is its the devil because mostly Tor is used for pedophilic reasons - drugs, counterfeiting or political protest (I'd assume) are almost insignificant in comparison to pedophile traffic.

I don't think that's true. The darknet drug markets are insanely popular, just take a look at https://www.reddit.com/r/darknetmarkets for a small taste.

Re: Running a Dark Web pedophile honeypot

#7
Some of the technical points of this article are simply wrong...

> The exit node IP address of the user was easily obtained using the two different methods discussed briefly above.

This is really not a vulnerability but simply how tor, and the internet at large, works - hidden services by design protect the service not the user (the user is protected by tor by default) - what the author actually did here was "leak" their non-hidden services IP.

> and true external IP address (see partial data example to the above). And to answer the second question, “no”, this did not involve the placement of malicious malware. Read on…

The author then goes on to state that they gave the users malicious malware to run which revealed their ip address. They justify that this was not malware by stating:

> It should be noted that this was not malware per se. It did not replicate and was run voluntarily by the user. The user was notified that a “security scan” was going to be run on their machine and they freely chose to run the scan.

The author then goes on to publish a list of tor exit nodes with tor user agents...which they could have gotten directly from the tor directory services...

And, as pointed out by others, the author never really goes on to state why they think Tor is the devil - they built a honeypot and were disgusted by the flies it attracted....I'm not really sure what they were expecting...

Re: Running a Dark Web pedophile honeypot

#8
> On two different occasions I contacted the FBI about the project and offered to provide full sets of data that I had collected.

The FBI twice rejecting a set of information that could have reasonably led to the arrest of several pedophiles seems like a big mistake.

Re: Running a Dark Web pedophile honeypot

#9

Earlier quoted context omitted.

I think the implication is its the devil because mostly Tor is used for pedophilic reasons - drugs, counterfeiting or political protest (I'd assume) are almost insignificant in comparison to pedophile traffic.

I don't think that's true. The darknet drug markets are insanely popular, just take a look at https://www.reddit.com/r/darknetmarkets for a small taste.

This is just based on what he said, which was based on what he observed from the traffic to his honeypots. Understandably you probably cant create a honeypot to gauge political activism so that might be hard to measure :D

Re: Running a Dark Web pedophile honeypot

#10
post #7

Some of the technical points of this article are simply wrong... > The exit node IP address of the user was easily obtained using the two different methods discussed briefly above. This is really not a vulnerability but simply how tor, and the internet at large, works - hidden services by design protect the service not the user (the user is protected by tor by default) - what the author actually did here was "leak" t…

The author appears to believe that "Tor is the devil" because "4,000-5,000 hidden services are running at any given time. Secondly, the content served by these sites is almost universally illegal or immoral (by my definition anyway). A conservative estimate would be maybe 1 out of 200 or so hidden service websites contain content I would deem worthy of the protection an anonymous network provides. Sites featuring free speech dumps or libraries of hard-to-find underground literature are few and far between on the Dark Web."
Post reply on HN