3 ms·
I'm guessing they do not -- that would be inconvenient, expensive, unreliable, insecure, and/or conspicuous. Some do run their own platforms or share a self ho
by LinuxBender 2y ago
I'm guessing they do not -- that would be inconvenient, expensive, unreliable, insecure, and/or conspicuous.
Some do run their own platforms or share a self hosted platform set up by people in a non cooperating country. Sometimes the platform admins find out they were being MitM by mistake tech or law enforcement make. [1] Or not using the MitM detection Jabber is capable of. Jabber scales to millions of users per cluster, big enough for probably most criminal organizations. I doubt the cluster in question was specifically meant for criminals, but the smart criminals will find solutions best suited for their needs. In this case I think they chose poorly given VM's can be live migrated and snapshot including memory contents without interrupting the platform or raising suspicion.
In my humble opinion the big shared corporate platforms will attract the ultra-lazy arrogant and cavalier criminals and I'm sure law enforcement are fine with it. Easy busts still look good to justify big budgets. There are probably people that say they don't know anyone that's been busted on those platforms but they are probably not moving enough volume of illicit goods to warrant immediate attention. That information would be quite useful for getting a warrant however if the target was suspected of something else or if they were an influencer thinking or saying the wrong thing in public.
[Edit] Updated link to the snapshot describing potential mitigations including SCRAM PLUS which was not configured in this incident.
[1] - https://archive.ph/4wi5t https://archive.ph/4wi5t