#1 and #2 really should just be a part of #3: catastropic opsec. I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with…
De-anonymizing ransomware domains on the dark web
11–20 of 55 posts
Re: De-anonymizing ransomware domains on the dark web
#12Not sure why there's a mystique over the "dark web", they're all still just websites, and suffer the same types of vulnerabilities.
Re: De-anonymizing ransomware domains on the dark web
#13#1 and #2 really should just be a part of #3: catastropic opsec. I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with…
You only catch those who make those mistakes
My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.
Re: De-anonymizing ransomware domains on the dark web
#14So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.
Re: De-anonymizing ransomware domains on the dark web
#15Earlier quoted context omitted.
You only catch those who make those mistakes
Yes, thanks for that. My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.
Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.
Re: De-anonymizing ransomware domains on the dark web
#16Earlier quoted context omitted.
Yes, thanks for that. My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.
You only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.
AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn.
Freedom Hosting was taken down because the operators used outdated FF with javascript enabled.
Silk Road's Ross Ulbricht posted his personal Gmail address, linking the identities.
All of these are profound opsec failures, not just an oopsie that led to getting caught by talented LEOs.
Re: De-anonymizing ransomware domains on the dark web
#17So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.
For end-users TLS and Tor both provide privacy; since you don't need to identify yourself in order to use https. In fact, with ESNI and DoH the only thing anyone snooping wire traffic can see is that you're connecting to whatever data center is owned by the company hosting the website.
The sites in the original article are criminal enterprises, which means they have the unique problem of needing the origin server to remain anonymous so that their hosting provider can't find out what they are doing. This is the one thing Tor does that TLS doesn't; and they were deanonymized by them insisting on providing a self-signed cert anyway. However, this is a particularly unusual threat model that is far harder to maintain. Even the whole anticensorship thing is usually just hiding what sites you're visiting from, say, the Great Firewall - we don't care that China can also use Tor to learn where Google's servers are.
Re: De-anonymizing ransomware domains on the dark web
#18Not sure why there's a mystique over the "dark web", they're all still just websites, and suffer the same types of vulnerabilities.
Yea, it would be rather unfortunate terminology to call websites outside the realms of Google and bing as “dark web” as if somehow these services legitimize the internet itself.
as unfair as it may be, a huge part of the usefulness of information is its accessibility, and these search engines currently hold a near-monopoly on which sites can generally be considered readily accessible, ie the 'surface web' above the deep web
Re: De-anonymizing ransomware domains on the dark web
#19Not sure why there's a mystique over the "dark web", they're all still just websites, and suffer the same types of vulnerabilities.
Yea, it would be rather unfortunate terminology to call websites outside the realms of Google and bing as “dark web” as if somehow these services legitimize the internet itself.
Re: De-anonymizing ransomware domains on the dark web
#20Earlier quoted context omitted.
You only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.
Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the…
The tightest opsec I've ever seen is maintained by disability fraudsters. Privacy laws protect the evidence anybody would need to present against you, so as long as you keep doctor-hopping and never admit to anything, nobody can touch you. These people tend to be reclusive and not public-facing, but with such low risk comes low reward-- there's no real money to be made in it.
(...unless you're the doctor knowingly signing off on false diagnoses. This increases scale, at which point, the more of those you write, the greater the chances of some mistake made by you or any single one of your patients bringing the whole enterprise down.)