Live data from Hacker News

De-anonymizing ransomware domains on the dark web

blog.talosintelligence.com

11–20 of 55 posts

Re: De-anonymizing ransomware domains on the dark web

#11
post #9

#1 and #2 really should just be a part of #3: catastropic opsec. I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with…

You only catch those who make those mistakes

Re: De-anonymizing ransomware domains on the dark web

#12
post #10

Not sure why there's a mystique over the "dark web", they're all still just websites, and suffer the same types of vulnerabilities.

Yea, it would be rather unfortunate terminology to call websites outside the realms of Google and bing as “dark web” as if somehow these services legitimize the internet itself.

Re: De-anonymizing ransomware domains on the dark web

#13
post #11
post #9

#1 and #2 really should just be a part of #3: catastropic opsec. I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with…

You only catch those who make those mistakes

Yes, thanks for that.

My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.

Re: De-anonymizing ransomware domains on the dark web

#14
post #4

So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.

If you follow the best practices and do not bind your onion service on 0.0.0.0 and use selfsign and don't reuse key, they do provide privacy against snooping exit node.

Re: De-anonymizing ransomware domains on the dark web

#15
post #13
post #11

Earlier quoted context omitted.

You only catch those who make those mistakes

Yes, thanks for that. My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.

You only have to slip up once to get caught.

Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.

Re: De-anonymizing ransomware domains on the dark web

#16
post #15
post #13

Earlier quoted context omitted.

Yes, thanks for that. My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.

You only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.

Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name:

AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn.

Freedom Hosting was taken down because the operators used outdated FF with javascript enabled.

Silk Road's Ross Ulbricht posted his personal Gmail address, linking the identities.

All of these are profound opsec failures, not just an oopsie that led to getting caught by talented LEOs.

Re: De-anonymizing ransomware domains on the dark web

#17
post #4

So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.

Anonymity of the origin server is not at all a design goal of SSL/TLS: in fact, the whole point is to tie a web host to a particular identity. Originally it was supposed to be legal identity, but that is actually fairly useless, so now it's just a domain name.

For end-users TLS and Tor both provide privacy; since you don't need to identify yourself in order to use https. In fact, with ESNI and DoH the only thing anyone snooping wire traffic can see is that you're connecting to whatever data center is owned by the company hosting the website.

The sites in the original article are criminal enterprises, which means they have the unique problem of needing the origin server to remain anonymous so that their hosting provider can't find out what they are doing. This is the one thing Tor does that TLS doesn't; and they were deanonymized by them insisting on providing a self-signed cert anyway. However, this is a particularly unusual threat model that is far harder to maintain. Even the whole anticensorship thing is usually just hiding what sites you're visiting from, say, the Great Firewall - we don't care that China can also use Tor to learn where Google's servers are.

Re: De-anonymizing ransomware domains on the dark web

#18
post #10

Not sure why there's a mystique over the "dark web", they're all still just websites, and suffer the same types of vulnerabilities.

Yea, it would be rather unfortunate terminology to call websites outside the realms of Google and bing as “dark web” as if somehow these services legitimize the internet itself.

the term 'deep web' refers to the subset of internet-connected information that is not widely published eg on search engines, where as the 'dark web' is specifically sites that hide their hosting information behind tor i2p etc

as unfair as it may be, a huge part of the usefulness of information is its accessibility, and these search engines currently hold a near-monopoly on which sites can generally be considered readily accessible, ie the 'surface web' above the deep web

Re: De-anonymizing ransomware domains on the dark web

#19
post #10

Not sure why there's a mystique over the "dark web", they're all still just websites, and suffer the same types of vulnerabilities.

Yea, it would be rather unfortunate terminology to call websites outside the realms of Google and bing as “dark web” as if somehow these services legitimize the internet itself.

I would personally call telegram/viber/whatsapp/et al. groups/chats/channels "dark web", since information is not indexed there and is basically decaying over time. In about a decade or decade and a half ago, forums flourished, it was really easy to find and share relevant information with relevant group of interested people. I particularly was interested in car's DIY service & retrofit topics. Unfortunately everything is mostly in messengers these days, which won users by offering real-time responses, but providing no real way of topic sorting or proper history. Duplicates of questions and answers of different topics and threads mixed together into an information garbage bin.

Re: De-anonymizing ransomware domains on the dark web

#20
post #16
post #15

Earlier quoted context omitted.

You only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.

Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the…

What sort of answer are you looking for? All of these proprietors are human. Humans make mistakes and act irrationally at times. Criminal enterprises are complex. Opportunity for mistakes increases with scale. The guy who ran Doxbin is the only high-profile case I can think of with apparent-flawless opsec, and that much only because he bailed before the long tail caught up to him.

The tightest opsec I've ever seen is maintained by disability fraudsters. Privacy laws protect the evidence anybody would need to present against you, so as long as you keep doctor-hopping and never admit to anything, nobody can touch you. These people tend to be reclusive and not public-facing, but with such low risk comes low reward-- there's no real money to be made in it.

(...unless you're the doctor knowingly signing off on false diagnoses. This increases scale, at which point, the more of those you write, the greater the chances of some mistake made by you or any single one of your patients bringing the whole enterprise down.)

Post reply on HN