6 ms·
I'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to
by 46Bit 15y ago
I'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to get away with forever.
- redthrowaway 15y agoReally though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe. All of the people who were arrested for hacking the CIA or DoD were caught many years ago, when anonymization tools weren't nearly so well developed, and the need for anonymization wasn't so clearly recognized. I'd like to see a modern story of the authorities finding someone who was hidden by TOR + vpn. I just don't see it happening any time soon.
- ianterrell 15y agoJust like the low security systems they crack, the weakest link in their own chain is the human element. Think password reuse is a problem? So is screen name reuse. So is having the same friends over time. So is trusting people. A person's digital fingerprint is huge these days, and a human weakness can break the chain apart. And once one person's in custody? How much discipline do you think each member has to not snitch in the face of prison time?
- awakeasleep 15y agoExactly right. We have images of government forces tracing connections across a glowing map thanks to movies, but really they just tap their network of informants, or do personal research. In my imagination, they'll start with Aurenheimer's hdd. The world isn't that big. Think how the head of the CIA is probably 7 people away from anyone in luzsec.
- redthrowaway 15y agoThe human element is clearly the weak point, but it's also the easiest to overcome. The cracker who speaks to no one is secure beyond reproach. That they inevitably speak to others in search of recognition and respect is a flaw in the operators, not the system.
- shushan 15y agoEven if authorities were able to track down someone through TOR, I doubt they'd publish it. More easy to let black hats think they are safe.
- redthrowaway 15y agoRight, but then they'd be prosecuted, and the means would come out. You wouldn't be able to both put people in jail based upon evidence gained from compromising TOR, as well as keep secret the fact that TOR was compromised. Not for long, at any rate.
- 46Bit 15y agoPretty simple really, at least in the UK. Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. If the police just happen to discover a ton of other things they're really involved in whilst analysing them, there you go. If encrypted, under UK law you have to divulge the keys or go to jail, so you're guaranteed to get them some jail time.
- SwellJoe 15y agoJust get someone to make an allegation against them (underage porn, etc), and their computers get seized. Is that legal in the UK? Because in the US it'd be unconstitutional.
- glassx 15y agoI've seen news about child porn allegations in the UK that usually lead to nowhere in the latest years, mostly because of some credit card issues. I remember it happening with Pete Townshend (from The Who) and Robert Del Naja (from Massive Attack), plus some football player whose name I can't remember.
- redthrowaway 15y agoUnconstitutional doesn't mean it doesn't happen.
- suking 15y agoHow do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...
- aaronblohowiak 15y agohow much traffic does a terminal session really need?
- romland 15y agoWhat do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quickly if you (as in FBI et al) have to raid several companies to get your hands on machines to do forensics on. I doubt these files (or much of anything else) ever touched the criminal's physical machine. Unless, of course, they fucked up by, say, posting to pastebin or a tweet or something else that is seemingly insignificant (at the time) using their own IP. Most tend to.
- suking 15y agoAhhh, didn't know they went onto hacked machines. So - some people should be getting some knocks on their door soon?
- redthrowaway 15y agoThat's the unfortunate bit -- some innocent people are likely to get their dog shot as the FBI busts down their door with assault rifles to seize a laptop.
- getsat 15y agoYup, you use a compromised Windows machine or Linux server in a third world country as a proxy. When you're done, you wipe the disk.
- jeffreymcmanus 15y agoYou're assuming they're safe because their technology stack is safe, but there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Cops work like hackers in the sense that both groups attack vulnerabilities. The vulnerabilities here are clear: these guys have big mouths and they're overconfident. They'll talk to somebody someday, and when that happens, it will provide an opening for the fuzz.
- nodata 15y ago> there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Would be interesting to hear some of them.
- Hoff 15y agoMost any overlap between your "secret" identity and your "normal" identity can provide an opening. This might involve (erroneously) shared contacts. Shared VoIP numbers. Shared MAC addresses, or shared IP addresses. Shared passwords. IRC channels or web sites. Even what times you are active, what words and what phrases you use, and your browser strings can provide clues. A group within (IIRC) Lebanon was reportedly identified a while back because of an opsec error; one of the folks involved in the group used a "restricted" cellular phone to call his girlfriend, and that broke open the identities. The German Ultra encryption system was targeted and was sometimes vulnerable due to opsec errors. Opening such as key reuse, or sending duplicate messages, can provide openings that allowed decryption. This area is related to the classic "covert channels" discussions within information security; on the expected information leakage, and around how a "defender" wants to keep leakage at a minimum, and how an "attacker" is looking for clues and errors. This is also a corollary to the classic difficulties with maintaining server security; leave one sufficiently egregious opening in your security, and you can be toast.
- jeffreymcmanus 15y agoI just named one.
- lulzypop 15y agoWhat's the point of the VPN? A place to store data that is in a country that isn't US friendly?
- 5eruun 15y agoWell, I think its just a matter of the amount of pressure a group puts on the feds for finding them. TOR is not 100% percent, iirc there are some rather successfull attacks against it, so once a group like LulzSec starts releasing stuff that is really hot (millitary documents, e.g. US war logs or the nuclear weapon codes :D ) the feds or rather the nsa will think of something new. I guess they have the monetary means to setup a few TOR nodes...