Live data from Hacker News

Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

wired.com

131–136 of 136 posts

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#131
post #48

Earlier quoted context omitted.

> Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website. This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic…

Knowing that Tor traffic comes and goes through a server isn't enough. Most data centers would not just hand over disk images just because a server is running Tor and a hidden service. You would need good evidence that the particular hidden service you seek is hosted at that particular data center. They can just enumerate every hidden service, figure out which ones are doing something obviously illegal, then once the…

> there aren't that many which yet accept Bitcoin for payment

FTFY

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#132
post #6

Earlier quoted context omitted.

Agreed. From this point forward Tor is considered harmful. But the same time, it seems like they're using workarounds, attacking the browser etc. I still believe the underlying network remains unbroken.

> Agreed. From this point forward Tor is considered harmful. Planting that seed in your mind was almost certainly one of the goals of this action. Mission accomplished, FBI.

Okay, let me put it this way:

Tor needs to be run from a live CD with an extended-hop circuit and a text only browser. TBB on regular box considered harmful.

We don't know the situation, so we have to assume that some part of the Tor stack is broken. It's likely to be the integrated web browser that's the weekend, but it could easily be higher or lower level.

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#133

Earlier quoted context omitted.

It looks like I was wrong about this. Will multiple datacenters allow you to continue setting up new accounts using nothing but bitcoin? If you don't need to provide identification, then this might be an interesting avenue to explore. Thank you for fact checking me. There's the chance that datacenters will be more inclined to image your server for authorities if you've set up a server using bitcoin and are hosting la…

>Will multiple datacenters allow you to continue setting up new accounts using nothing but bitcoin? I don't see how they could stop you. None of the btc hosting sites I've seen ask for real ID (passport, drivers license, etc..) They also allow you to rent by the year, though I suspect you would have to scale up fairly often. Overall though, I think anonymous hosting wouldn't be a problem (tor + ssh + tumbled btc). Th…

perhaps the darkmarket fork https://openbazaar.org/

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#134
post #41

Earlier quoted context omitted.

Requesting an image of a paranoid person's server isn't necessarily that great. When I worked for a run-of-the-mill cybersecurity firm, our simulator products were protected with full disk encryption using run-of-the-mill open-source software + light patches and keys bound to specific hardware, software, and configuration states via the TPM. This is for fully automated boot up. If you can accept the risk of needing t…

It's an interesting idea. I think physically shipping a server to a datacenter is precarious. Remember, it is known that your server is hosting a darknet website. You can't really hide this fact. Timing correlations make it possible to figure out which server is doing what. The reason that Tor users are generally safe from this is because they're not constantly connected, and an adversary generally can't cause a clie…

> You have to assume the worst: that authorities will take your box using a power adapter that lets them physically remove the computer from the datacenter without turning it off (such things exist), dump an image of your server while it's running (so that encryption keys won't help you)...

I believe they can keep my server powered on whilst they remove it from the DC (dual PSUs in enterprise servers would make this _extremely_ easy) but how exactly are they supposed to be "dumping an image of the server whilst it's running"?

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#135

Earlier quoted context omitted.

Then the authorities trace the server component to the person who sold it on Craigslist. And if your opsec isn't perfect, you're busted right there: Did you forget to set up a new email account for all of your craigslist transactions? Did you forget to set them up and connect to them only through Tor? Did the person you met with write down your license plate number? Seem unlikely? Think again. Cameras write down your…

you are probably going to be one of the few people to meet up and do a cash drop for the server. Which is automatically going to make you standout to the hosting guys. Thus, MUCH more identifiable.

'course. But how else are you going to pay? Stolen credit card?

Re: Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains

#136

Earlier quoted context omitted.

I'll have to take your word for it. I'm pretty sure you are overthinking this tho. What you are describing is basically: 1) They find the server [this likely takes months based on their performance so far]. 2) They get a copy of the paperwork & server [fake id, so useless information on it and a fake picture. That is assuming they keep a copy at all, they might not.]. Server is commodity and basically untraceable. Th…

>They find the server... I doubt you could host a large scale operation on a single server. Given the volume that SR1 && SR2 received, you would need more servers at some point. At that point you either need to hit up craigslist again or host via cloud providers. (of course all of this is assuming that the first guy you met on craigslist was not an undercover agent).

> I doubt you could host a large scale operation on a single server. Given the volume that SR1 && SR2 received, you would need more servers at some point. At that point you either need to hit up craigslist again or host via cloud providers. (of course all of this is assuming that the first guy you met on craigslist was not an undercover agent).

Given I've bought servers for cash on craigslist, I doubt this is really an issue.

You are making a large number of assumptions that in real world situations aren't likely.

They'd need to:

A) Locate you. Assuming good opsec, you'd move and so forth if they imaged/seized your servers and you were aware of it. B) Seed craigslist across a large enough area to catch you.

Hell, you could just move to Canada on "vacation" and pay cash to rent a room up there as well as buy servers in Vancouver or something.

Post reply on HN