Live data from Hacker News

De-anonymizing ransomware domains on the dark web

blog.talosintelligence.com

1–10 of 55 posts

Re: De-anonymizing ransomware domains on the dark web

#5
post #4

So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.

This is not a big deal really. Getting an SSL cert only requires you provide proof of ownership of your domain and has no KYC. You can get as many certs as you want, or sign it yourself.

Right now, SSL(or PKI to be precise) is a very privacy respecting technology. For both the server and the client.

Re: De-anonymizing ransomware domains on the dark web

#6
post #4

So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.

Certificates enable privacy for the user - fundamentally, they are about proving the identity of the server, which is at least somewhat at odds with privacy of the server.

Anyway, these all seem like pretty obvious opsec fails where the darknet website is also served over the regular internet, which is just atrocious.

Re: De-anonymizing ransomware domains on the dark web

#7
post #5
post #4

So certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.

This is not a big deal really. Getting an SSL cert only requires you provide proof of ownership of your domain and has no KYC. You can get as many certs as you want, or sign it yourself. Right now, SSL(or PKI to be precise) is a very privacy respecting technology. For both the server and the client.

[deleted]

Re: De-anonymizing ransomware domains on the dark web

#9
#1 and #2 really should just be a part of #3: catastropic opsec.

I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with metadata), etc. I mean it's nice that they are making it easier to catch themselves, but at the same time I can only wonder how some genius can invent some novel and complex ransomware operation just to turn around and use the email they've had since they were 13 to register the services that operate it.

Post reply on HN