Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
91–100 of 264 posts
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#92"On or about October 7, 2013, the HSI-UC [the undercover agent] was invited to join a newly created discussion forum on the Tor network, concerning the potential creation of a replacement for the Silk Road 1.0 website. The next day, on or about October 8, 2013, the persons operating the forum gave the HSI-UC moderator privileges, enabling the HSI-UC to access areas of the forum available only to forum staff." They we…
That sounds like the FBI had already infiltrated the Silk Road 1.0 community so they were invited into 2.0 at the beginning.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#93Earlier quoted context omitted.
I'm not sure how this is a whack-a-mole game. If you run a single-server hidden service, the NSA can track it (unless you think otherwise - tried to initiate discussion here[1]). Once they track it, they will get your hosting provider to cooperate and before you know it, your server has been imaged and that irrevocable .onion private key is in the authorities' hands. The most you'll see from your end was some downtim…
I'm wondering why they would image the server. Did SR2 not use full disc encryption using LUKS? How would they be able to access anything on it, I know if I were running SR2 I'd have the longest private key ever stored in my brain to decrypt the drives.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#94Earlier quoted context omitted.
I'm not sure how this is a whack-a-mole game. If you run a single-server hidden service, the NSA can track it (unless you think otherwise - tried to initiate discussion here[1]). Once they track it, they will get your hosting provider to cooperate and before you know it, your server has been imaged and that irrevocable .onion private key is in the authorities' hands. The most you'll see from your end was some downtim…
I'm wondering why they would image the server. Did SR2 not use full disc encryption using LUKS? How would they be able to access anything on it, I know if I were running SR2 I'd have the longest private key ever stored in my brain to decrypt the drives.
For offline analysis and to be used as evidence, presumably.
> Did SR2 not use full disc encryption using LUKS? (...) longest private key ever
So the process for you would be slightly different: There would be a "power outage" in your rack, your encrypted disk would be imaged and (unencrypted) bootloader would be bugged.
Then they'd wait for you to see that your server had some issues, upon which time you'd have two choices:
-enter your private key to resume the service.
-abandon the server.
The correct choice would be (2), but you don't have enough information to make that call.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#95Earlier quoted context omitted.
I'm wondering why they would image the server. Did SR2 not use full disc encryption using LUKS? How would they be able to access anything on it, I know if I were running SR2 I'd have the longest private key ever stored in my brain to decrypt the drives.
If you're in San Francisco, how do you type the disk password into a server in Iceland? Through a BMC with clownshoes security?
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#96I think this is the money quote: "During the Government’s investigation, which was conducted jointly by the FBI and HSI, an HSI agent acting in an undercover capacity (the “HSI-UC”) successfully infiltrated the support staff involved in the administration of the Silk Road 2.0 website, and was given access to private, restricted areas of the site reserved for BENTHALL and his administrative staff. By doing so, the HSI…
Its been hinted that they'll be busting other Tor marketplaces in the next day or so. I wonder if they were similarly infiltrated and what effect that will have on the community.
Seriously, if you were running a Tor marketplace and one of your competitors goes down, it is a perfect cover for running away with everyone's bitcoins and disappearing.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#97http://instagram.com/p/uyqRk1CXWk/
Prophetic.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#98Earlier quoted context omitted.
...when it consistently and unfairly places itself and its cronies above said laws.
Nevertheless, selling illegal drugs on the internet is illegal. I don't think you can say that attempting to bring down darknets is an example of government corruption in this case, notwithstanding the inevitable argument that the government is corrupt in any case.
There's a much higher beneficial payoff that can come from arresting bankers (like Iceland did), and at much less effort, than trying to make sure anonymous people don't put silly substances in their mouths.
So yes, attempting to close down darknets is a shining example of our government's corruption, today, with everything that is happening with the economy, courtesy of the bankers.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#99They located Silk Road 2.0's server in an unspecified way, not directly related to their undercover agent on the support staff. Given that two other darknet markets (Black Market and Cloud9) have been shut down today, and they didn't specify how they located the SR2 server, it seems plausible that law enforcement have a vulnerability to locate servers over the Tor network. From the complaint: "In or about May 2014, t…
They've bugged nearly all of the entrance and exit nodes. This allows them to do trivial traffic analysis. Parallel construction hides the method from the courts which would be reluctant to rule against anyway.
Re: Operator of Silk Road 2.0 Website Charged in Manhattan Federal Court
#100I cannot imagine a way in which a single-server hidden service is safe from a global, active adversary like FBI, NSA & Friends. This [1] discusses passive analysis over time. Isn't it really easy to locate one if you can perform active attacks on the global infrastructure? (introduce latencies and/or break links temporarily) If your hidden service is served by a couple of mirrors on each continent, though... then may…
Security by obscurity always fails - especially against the FBI. Given that Tor is essentially an obscuring mechanism for servers that have to function to some degree on the clearnet, if the FBI really wants to find a hidden service there are apparently many points of failure to exploit.
However, given that Ulbricht and now Benthall both had poor OpSec, criminals on the internet have as a last resort the ability to have no identifying information on their servers, even if their servers get owned.