3 ms·
I was once approached to develop a darknet market. I spent a few weeks scoping out the work, unpaid, before I turned down the opportunity due to the legal and e
by deftnerd 6y ago
I was once approached to develop a darknet market. I spent a few weeks scoping out the work, unpaid, before I turned down the opportunity due to the legal and ethical problems.
I did spend that time pondering and scoping out the work because I found it a fascinating challenge to design an ecommerce platform with very heavy requirements for user privacy and anonymity.
The source code for an existing platform that I was granted access to view showed me that a lot of encryption techniques were just smoke and mirrors. Mostly, everything was stored unencrypted or using symmetric encryption with the encryption key stored on the same filesystem as the server generating the pages.
It was fun designing an asymetric multi-key encryption system, where a user's "second password" with a hash (stored with a microservice API on another server in another data center) generated one of the multiple keys required. Even server seizure wouldn't result in anything usable.
Another challenge was how to prevent servers from being overwhelmed with DDoS attacks. That would have been achieved by using the Tor API to generate custom onion addresses for each user and vendor that they could bookmark. The only site that could be DDoS'd would be the landing page. It also allowed for an easy route to horizontal scaling.
The old system also didn't properly delete stuff, it just flipped a boolean "deleted" field to prevent it from being visible anymore... Not very smart for data hygiene.
I've been wanting to use what I planned out to build a product for the last few years, but I can't think of anything legal & legitimate that would have such strict security requirements that also has potential for profitability.
- qvrjuec 6y ago> Another challenge was how to prevent servers from being overwhelmed with DDoS attacks. That would have been achieved by using the Tor API to generate custom onion addresses for each user and vendor that they could bookmark. The only site that could be DDoS'd would be the landing page. It also allowed for an easy route to horizontal scaling. If the market were compromised and the URLs exposed, this would make it easier for a bad actor to connect a user to the URL, right?