6 ms·
With good opsec (i.e. only PGP-encrypted messages) sellers should still be able to operate safely. Buyers slightly less, considering that the sellers might be
by computer 13y ago
With good opsec (i.e. only PGP-encrypted messages) sellers should still be able to operate safely.
Buyers slightly less, considering that the sellers might be cops (which is also the case on a non-honeypot site), or because the PGP-keys of the sellers might be fake (for MITM).
But considering that feds generally seem to target sellers, I don't think the usefulness of this as a honeypot would be huge. But it's definitely possible, especially given that the feds have the source code and all.
- Touche 13y agoWouldn't it be a great honeypot for one big bust? Delay the launch as long as possible due to "load issues" to bring in as many sellers as possible and then take them all down after their first transaction.
- computer 13y agoHow are you going to find a seller? They use Tor, don't need to enter their details anywhere; they just send packages to addresses they receive in encrypted form.
- stcredzero 13y agoMost sellers are too lazy/cheap to properly set-up their fulfillment operation with good enough security. If you read accounts of the seller busts from Silk Road 1.0, the authorities can trace where your packages have been sent from and where you bought the postage from. If you don't operate as if the police are actively using this information to track you down, they will be able to.
- corin_ 13y agoSellers don't reveal their personal details to the site - maybe having a honeypot site would make it easier to track them down, but it wouldn't be simple.
- jarrett 13y ago> considering that the sellers might be cops Why wouldn't law enforcement pose as buyers, as well? This is a common tactic in narcotics enforcement. Entrapment often isn't an issue, as the seller took the first step of advertising the drugs for sale. Are you getting at the fact that the buyer must have a receiving address, while the seller can ship anonymously? I would be skeptical of that. If I were attempting to track the source of a package, and I had the full force of warrants behind me, I bet I could track down most shippers. Every shipping company has its own tracking information. Much of this may be opaque to the end user. The tracking might be much more detailed than what you can see as an end user with a tracking number. Assuming the carrier cooperates with law enforcement, tracking could (presumably) be further enhanced for targeted post offices, routes, etc.. For example, suppose I, as a law enforcement agent, receive an order from a Silk Road seller. Let's say it was shipped in an envelope, dropped off at a USPS street-corner box. From the tracking info, I identify which post office first handled the envelope. Thus I narrow my search to a few possible mailboxes served by that post office. I instruct the carriers at that post office to assist me. As they follow their routes, emptying mailboxes, I have them sort outgoing mail into separate bags, one per box. I have the post office flag any mail going to my address. I place another order from the same seller. When it hits the post office, it gets flagged, and because of the per-box sorting, I know which mailbox was used. For round three, I place yet another order, this time with the mailbox under surveillance. I also install a camera inside the mailbox that sees the destination address of every envelope deposited. When the seller drops his shipment, my surveillance team detects it. They then follow the person who dropped the letter. Now I have the shipper's identity. Can these measures be defeated with appropriate opsec? Maybe, if you know exactly what tactics law enforcement will employ. But you don't. You could spend all your time defending against the tactics I just described, only to get caught because law enforcement came up with a totally different strategy. My point is, opsec is really, really hard.
- deleted 13y ago[deleted]
- ye 13y ago> Why wouldn't law enforcement pose as buyers, as well? Because as a buyer you don't know who the seller is. You just receive your package. But as a seller, you know your buyer's mailing address. It becomes trivial to catch the buyer.
- eurleif 13y agoIf this is a honeypot, couldn't they conceivably deanonymize users based on timing, using either ISP data or data from honeypotted Tor relays?
- ZoFreX 13y agoYes: https://www.torproject.org/docs/faq.html.en#AttacksOnOnionRouting https://www.torproject.org/docs/faq.html.en#AttacksOnOnionRo...