5 ms·
As much as I hate to say this, we all knew it was happening, right? I'm still ninety percent sure they had to scramble to justify a non-tor-breaking reason the
by bin0 7y ago
As much as I hate to say this, we all knew it was happening, right? I'm still ninety percent sure they had to scramble to justify a non-tor-breaking reason they got Ulbricht. I don't know why people are still encouraging others to use it alone. You should also be using some kind of encryption of the content itself. Their goal is to figure out who you are and what you're saying; deny them either piece, and they're foiled (three-letters, that is).
- TazeTSchnitzel 7y agoUlbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.
- bin0 7y agoHe really did that? Jeez, you're right. Still, such attacks have doubtless been used before. Even if they haven't broken the core protocol, I'd assume they've got a few zero-days sitting around.
- TazeTSchnitzel 7y agoWe do know that the US government used a Flash applet to deanonymise a lot of Tor Browser users. It was revealed in some lawsuit I think.
- somethingnot 7y agoHe did a lot of stupid stuff. Like logging into SilkRoad from a public library. FBI agents were at the next table.
- dontbenebby 7y agoHe logged in in public a lot. They were able to correlate him opening laptop/joining wifi with their suspect account signing into Silk Road.
- stordoff 7y agoFreedom Hosting is a good example of using alternative attacks to sidestep Tor: > News reports linked a Firefox browser vulnerability to a United States Federal Bureau of Investigation (FBI) operation targeting Freedom Hosting's owner, Eric Eoin Marques. In August 2013, it was discovered that the Firefox browsers in many older versions of the Tor Browser Bundle were vulnerable to a JavaScript attack, as NoScript was not enabled by default. This attack was being exploited to send users' MAC and IP addresses and Windows computer names to the attackers. The FBI acknowledged they were responsible for the attack in a September 12, 2013 court filing in Dublin https://en.wikipedia.org/wiki/Freedom_Hosting https://en.wikipedia.org/wiki/Freedom_Hosting
- dontbenebby 7y agoI agree on the competency assessment, butI think the issue was plugging the service using his gmail IIRC. (Not just that he posted about Tor). IIRC they were able to track down the first mention of the site and it was from an account tied to Ross. Plenty of noncriminals are Tor users and post about Tor - myself included.
- eswat 7y agoFrom the news reports I’ve read, including Ulbricht's, it's enough for law enforcement to just find out who you are. They can then set up a sting operation where the target inadvertently leaves their laptop exposed with the keys to the castle available while being arrested.