De-anonymizing ransomware domains on the dark web
blog.talosintelligence.com
De-anonymizing ransomware domains on the dark web
1–10 of 55 posts
Re: De-anonymizing ransomware domains on the dark web
#2Re: De-anonymizing ransomware domains on the dark web
#3Re: De-anonymizing ransomware domains on the dark web
#4SSL may stop your roommate or isp but they provide another vector for linking to other entities.
I wonder how many are using this technique to link web properties together.
Re: De-anonymizing ransomware domains on the dark web
#5So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.
Right now, SSL(or PKI to be precise) is a very privacy respecting technology. For both the server and the client.
Re: De-anonymizing ransomware domains on the dark web
#6So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.
Anyway, these all seem like pretty obvious opsec fails where the darknet website is also served over the regular internet, which is just atrocious.
Re: De-anonymizing ransomware domains on the dark web
#7So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.
This is not a big deal really. Getting an SSL cert only requires you provide proof of ownership of your domain and has no KYC. You can get as many certs as you want, or sign it yourself. Right now, SSL(or PKI to be precise) is a very privacy respecting technology. For both the server and the client.
Re: De-anonymizing ransomware domains on the dark web
#8This should come in handy if I ever have to run a website on the dark web
Re: De-anonymizing ransomware domains on the dark web
#9I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with metadata), etc. I mean it's nice that they are making it easier to catch themselves, but at the same time I can only wonder how some genius can invent some novel and complex ransomware operation just to turn around and use the email they've had since they were 13 to register the services that operate it.