Live data from Hacker News

De-anonymizing ransomware domains on the dark web

blog.talosintelligence.com

21–30 of 55 posts

Re: De-anonymizing ransomware domains on the dark web

#21
post #19

Earlier quoted context omitted.

Yea, it would be rather unfortunate terminology to call websites outside the realms of Google and bing as “dark web” as if somehow these services legitimize the internet itself.

I would personally call telegram/viber/whatsapp/et al. groups/chats/channels "dark web", since information is not indexed there and is basically decaying over time. In about a decade or decade and a half ago, forums flourished, it was really easy to find and share relevant information with relevant group of interested people. I particularly was interested in car's DIY service & retrofit topics. Unfortunately everythi…

> I would personally call telegram/viber/whatsapp/et al. groups/chats/channels "dark web", since information is not indexed

That's a really odd way of naming thing.

They are not web, and "not indexed" usually is referred to as "deep web", not "dark web".

Re: De-anonymizing ransomware domains on the dark web

#22
post #16

Earlier quoted context omitted.

Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the…

What sort of answer are you looking for? All of these proprietors are human. Humans make mistakes and act irrationally at times. Criminal enterprises are complex. Opportunity for mistakes increases with scale. The guy who ran Doxbin is the only high-profile case I can think of with apparent-flawless opsec, and that much only because he bailed before the long tail caught up to him. The tightest opsec I've ever seen is…

>What sort of answer are you looking for?

They said that some of the 3 I listed by name had "great opsec". I am curious which one of those they thought was great, and laid out why I think the opsec in these cases was really far from "great".

Maybe when they said "those listed", they were referring to the list on the website and not my list. In that case, I misunderstood and obviously my comment doesn't make much sense. But I presumed they were referring to my list.

>Humans make mistakes and act irrationally at times. Criminal enterprises are complex.

Agreed on both fronts.

But I think that the severity of mistakes is a scale, and some of the really big players on the darknet have made mistakes that I argue is much closer to the "really dumb mistake, trivially avoided" end of the scale, such as using your LinkedIn email to run your multi-million dollar black market.

>Opportunity for mistakes increases with scale.

Agreed. But none of the three examples I listed by name were affected by scale. Using outdated software with known vulnerabilities, posting your own email, and using an email connected to your LinkedIn are all not issues of scale.

Edit to clarify, as I think people may be misunderstanding me (maybe? hard to tell from just downvotes and no replies):

Opsec is hard. 100%. You have to maintain it basically forever, which makes it really hard.

But, if I walk into a bank intending to rob it and start shouting out my full name and address (or, say, left my drivers license at the scene), people would have a jolly laugh at how bad of a robber I was. This is analogous to using the same email to run your multi-million dollar black market as well as sign up for a LinkedIn account. Most people would agree that in my hypothetical, the robber made some really trivial mistakes. I'm not sure why it's so hard to say that for these darknet operators that basically did the same thing, but in computer form.

Re: De-anonymizing ransomware domains on the dark web

#23
post #16
post #15

Earlier quoted context omitted.

You only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.

Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the…

Maybe the dark web makes people feel safe and they let their guard down? I cannot imagine why else someone would use their own email address in any transaction or operation.

Re: De-anonymizing ransomware domains on the dark web

#24
post #9

#1 and #2 really should just be a part of #3: catastropic opsec. I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with…

The genius is the one selling the shovels to the gold diggers

Re: De-anonymizing ransomware domains on the dark web

#25
post #16
post #15

Earlier quoted context omitted.

You only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.

Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the…

It sounds pretty easy to inadvertently visit a site on an old laptop with javascript enabled. Is this what counts as a profound opsec failure these days?

Remembering that you only have to make an error like that once.

And if all these high-profile people manage to get caught (It seems like pretty much everyone that isn't a nation state ends up getting found eventually!) then maybe it's not that these people are terrible at Opsec, it's maybe that it's much harder than it looks, especially when the government has access to tools that you have no idea about, and maybe it's inevitable that you make an error if you are a human operating for a long time, regardless of 'opsec' skillz.

Re: De-anonymizing ransomware domains on the dark web

#26
post #16
post #15

Earlier quoted context omitted.

You only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.

Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the…

The original Silk Road supposedly had amazing opsec but they caught him because one time he used the same, oblique username to register something many years previous IIRC.

Re: De-anonymizing ransomware domains on the dark web

#27
post #16

Earlier quoted context omitted.

Which ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the…

What sort of answer are you looking for? All of these proprietors are human. Humans make mistakes and act irrationally at times. Criminal enterprises are complex. Opportunity for mistakes increases with scale. The guy who ran Doxbin is the only high-profile case I can think of with apparent-flawless opsec, and that much only because he bailed before the long tail caught up to him. The tightest opsec I've ever seen is…

Compartmentation is the bedrock of good op-sec. Throwaway identities that are single use and then forgotten about.

Dwell time is important too. The longer you stay in the game, the greater chance you’ll slip up.

Re: De-anonymizing ransomware domains on the dark web

#29
post #14
post #4

So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.

If you follow the best practices and do not bind your onion service on 0.0.0.0 and use selfsign and don't reuse key, they do provide privacy against snooping exit node.

>do not bind your onion service on 0.0.0.0

Good advice

>they do provide privacy against snooping exit node

onion services don't use exit nodes. Your client and the service build circuits to nominated middle relays so https only offers very marginal increases in privacy. However, you are right to assume than any exit node may (or probably is) monitored.

Re: De-anonymizing ransomware domains on the dark web

#30
post #13
post #11

Earlier quoted context omitted.

You only catch those who make those mistakes

Yes, thanks for that. My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.

You have to be a certain level of stupid to attempt these crimes, especially when you're up against such powerful nation-state adversaries. Stupid probably isn't the right word though. Lazy and arrogant might be more accurate.
Post reply on HN