10 ms·
Global Web Crackdown Arrests 17, Seizes Hundreds Of Dark Net Domains
- higherpurpose 12y agoI think Wired was the first with the first Silk Road bust, too, or in similar FBI operations. Does the Wired have FBI "sources" or FBI PR contacts that give them these almost-exclusives?
- rjaco31 12y agoMaybe they're just buying drugs on those websites
- krapp 12y agoIt's a high profile tech magazine with mainstream credibility. It would be silly for them not to have FBI sources.
- marianminds 12y agoSome guy in a fedora and freebsd t-shirt hanging around sleazy bars downtown waiting for his flipped FBI agent to come around and drop him some new juicy goss on the latest... TF2 hat update? Sounds legit
- krapp 12y agoWell, Wired is a business, and cybercrime stories are pretty good business, and a lot of people the FBI might want to reach (and let know that they're on to your games, criminal scum) probably read Wired. It would be a mutually beneficial relationship, and this isn't exactly bad press for the government, so it might be more legit than it sounds at first glance.
- higherpurpose 12y agoIt just doesn't seem right for media sites to "partner" with FBI/the government for a story like this, and give them a platform to spread its propaganda. For the record I'm one of the people who believe what the FBI did here is wrong. I imagine if they had know what it is and what it can do early on, they would've shut down Bittorrent Inc, too, for "facilitating piracy", "conspiracy to create piracy", "money laundering" (by making money as a company that creates torrent technology), and some other CFAA charges, for good measure - all of them bullshit.
- krapp 12y agoThis isn't entirely propaganda, though. Sure, the government's version of events is, but it's also a newsworthy event that Wired's readership would be interested in. Why would they not cover it, or foster partnerships that make it easier to get access to stories like this? It is literally their job.
- celticninja 12y agobut this happened yesterday and there were lots of posts from various sites about it, the criminal complaint has been posted online, I dont see how wired were frist with anything here.
- userbinator 12y agoI wonder if these attacks, along with some clever fingerprinting of the server host, and advanced techniques on traffic correlation, were enough to determine the whereabouts of the servers: http://www.ieee-security.org/TC/SP2013/papers/4977a080.pdf http://www.ieee-security.org/TC/SP2013/papers/4977a080.pdf http://www.cl.cam.ac.uk/~sjm217/papers/ccs06hotornot.pdf http://www.cl.cam.ac.uk/~sjm217/papers/ccs06hotornot.pdf
- bhouston 12y agoI think that TOR should no longer be considered secure in the wake of so many busts. Either it isn't secure by some flaw, or it is too easy to fingerprint visitors, or some other work around.
- s_q_b 12y agoAgreed. From this point forward Tor is considered harmful. But the same time, it seems like they're using workarounds, attacking the browser etc. I still believe the underlying network remains unbroken.
- owenmarshall 12y ago> Agreed. From this point forward Tor is considered harmful. Planting that seed in your mind was almost certainly one of the goals of this action. Mission accomplished, FBI.
- s_q_b 12y agoOkay, let me put it this way: Tor needs to be run from a live CD with an extended-hop circuit and a text only browser. TBB on regular box considered harmful. We don't know the situation, so we have to assume that some part of the Tor stack is broken. It's likely to be the integrated web browser that's the weekend, but it could easily be higher or lower level.
- w1ntermute 12y agoI think that the feds having found and exploited a Tor vulnerability is much less likely than them having violated the law in the process of their investigation and then covered it up with parallel construction.
- privong 12y agoThat may very well be true, but in the absence of supporting evidence, prudence would suggest caution (with respect to tor) is not a bad idea.
- diyorgasms 12y agoI am curious how a .onion domain seizure works. Does this mean the various law enforcement agencies are in possession of the private keys of the services they shut down?
- lucb1e 12y agoThey somehow find the physical location of the hidden service and then are able to take control (e.g. via a letter to the webhost). After that they have full control over the server and thereby also the key behind the .onion address. How do they find the physical location? This could be by plenty of technical methods, which is really too elaborate to expand on here, but it's almost certainly not a flaw in Tor itself. It's just very hard to do it all correctly from A through Z, one mistake and you're busted, so that's why so many services can be taken down.
- downandout 12y agoLessons learned: 1) Don't engage in businesses that make you a target of the world's best-funded law enforcement agencies. 2) If ignoring lesson 1, don't access servers directly, from home, and don't pay for said servers with personal credit card. 3) Don't pay for your $130K Tesla using BTC a month after you open up a massive illegal drug marketplace that runs exclusively on BTC. Someone may suspect something. 4) When cashing in your ill-gotten gains, don't use your real name. Seriously, if you're going to do this kind of stuff, paranoia is your friend. "They" probably are, indeed, following you.
- deleted 12y ago[deleted]
- 67726e 12y agoThis gives me an interesting thought for a startup. Provide training and testing for law enforcement for these scenarios. Would also give you the chance to outsmart law enforcement without getting arrested.
- longlivegnu 12y agoDoesn't palantir basically just do this for them?
- ddoolin 12y agoYou'd do well to just avoid the U.S. of A. (and friends, I guess). Take those profits and go somewhere safe and manage your newfound business from there. That could be one of the reasons some of the larger markets are still standing.
- dobbsbob 12y agoThey catch Russian carding marketplace admins all the time so living in Brazil or Russia is no guarantee you won't end up in jail either. Just takes one mistake and you are on a plane in handcuffs to a federal court. They could bribe local police to pick you up for them too especially if you aren't politically connected in those countries.
- rglover 12y ago“This is something we want to keep for ourselves,” he said. “The way we do this, we can’t share with the whole world, because we want to do it again and again and again.” That is so freaking evil.
- waterlesscloud 12y agoSo much for responsible disclosure.
- Lrigikithumer 12y agoThey say this but why aren't they targetting the real evil shit on the dark web? Why the hell are they wasting their time and resources on drug busts when there are seriously sick dangerous people using those services, hunt them. They're the real dangers to society, not the ones selling weed and ecstasy. Makes me feel sick all the wasted talent that isn't being used to take down the dark dark corners of this world.
- oftenwrong 12y agoYou say that as if organisations involved in the international drug trade are not engaging in "real evil shit". Not all cannabis sold in the United States is grown by long-haired Californians. Much of it is grown in Mexico by violent drug cartels that use slave labour and kill indiscriminately. They are practically the definition of evil, and sites like The Silk Road are pushing their product.
- benajnim 12y agoOf course, the ideal way of sucking out the oxygen from these entities is to legalize the product they're pushing. Perpetuating the drug war is some "real evil shit" when you consider the police unions are among the biggest lobbying groups fighting to keep these substances in question illegal..
- charonn0 12y agoProhibition drives prices sky-high, drives out law-abiding brokers, but doesn't affect demand. The Mexican cartels are yet another bad consequence of the war on drugs.
- dobbsbob 12y agoThey probably just use the tried and true method of exploiting flaws in the server, then helpfully offering to fix it. Repeat until trust builds and eventually a fed agent is the Sr technical lead with access to everything.
- jordanbaucke 12y agoI think it will be very interesting to see the correlation of "discovery vectors" these LE's purport to have used in locating these services.
- angch 12y agoI wonder how hard it is to cause a very spiky, targeted temporary network outage (DDoS, etc) and use it to correlate with which Dark web sites relies on which physical network. With enough random events, it's probably possible to pin down the location, unless you have more than a host or move around a bit.
- gnu8 12y agoThe only criminals here are the feds. Each and every one of them belong in a cage.
- zurn 12y agoEuropol took over the .onion domains? How does that work technically? And doesn't it sound a little brusque considering Europol doesn't have authority to do anything on the field?
- CmdrKrool 12y ago"When WIRED spoke Thursday night with Troels Oerting, head of the European Cybercrime Center, he said his staff hadn’t even had time to assemble the full list of sites it’s pulled down in the sprawling operation." That sounds a bit cavalier. Are they actually checking whether the sites are involved in illegal activity before they pull them down? Or is merely hosting a website on Tor illegal nowadays?
- atwebb 12y agoA less ominous interpretation could be that they pulled some servers and aren't sure how many sites were hosted on them.
- yc1010 12y agoAssuming TOR is compromised, what is to stop someone buying a vps (with fake/disposable credit card etc) hiding the main server behind this vps (with haproxy or stunnel)? FBI come along and image the vps, but it wont be the main server, connection details could be stored in RAM and if server taken down to image no configs would be left. Thoughts? obviously buying vps/servers in own name is dumb opsec. That way even if TOR is compromised you lose just a frontend point.
- knyt 12y agoDon't think that'd add anything. The people investigating you would presumably look at your network traffic and see all of the non-anonymized TLS packets traveling between your VPS and the real server. And they shouldn't need to bring the VPS down to get an image of its disk (or its RAM).
- yc1010 12y agoOf course tho' I doubt it be enough for evidence in court especially if everything is bought with fake aliases. And the saving memory contents (could hold config files on tmpfs for example) seems to be a difficult process, from wikipedia "Holding unpowered RAM below −60 °C helps preserve residual data by an order of magnitude, improving the chances of successful recovery. However, it can be impractical to do this during a field examination." It would be interesting to get perspective from any forensic experts. The key imho is to put as many hoops in attackers path.
- knyt 12y agoThey could just write the memory to disk. https://www.suse.com/documentation/sles11/book_kvm/data/sec_libvirt_manage_save.html https://www.suse.com/documentation/sles11/book_kvm/data/sec_...
- psykovsky 12y agoIt doesn't need to be like that. You can have a frontend server with a public .onion domain that just pulls everything from a different remote and private .onion domain. Yes, the latency will suck.
- fixermark 12y agoAh, good. Now if only they can snag people who send anonymous death threats too.
- logfromblammo 12y agoAs much as this story interests me on deeper levels, my brain keeps wanting to think of it as a misspelled or mispronounced "Operation Ominous" rather than subtracting the "an-" prefix to negate "anonymous" (which they undoubtedly thought was very clever). And I do find it very ominous that apparently the only way that I can speak and act freely over the Internet is to maintain absolutely perfect operational security across an entire group of individuals that I already know enough to trust, thanks to out-of-band signaling. While I don't really have anything to plan or discuss that would be considered threatening to any current regime, I also know that regimes change and evolve, and the Internet is rather capricious with regard to what it forgets. I have to wonder if someday even my posts on HN will be used against me at a time when prison, or execution, or even just denial of a benefit is a possibility. Right now, they are busting folks for trading contraband and criminal services. But it somehow feels like the evidence of massive surveillance and interdiction is more threatening to me personally than the existence of the online black markets. Perhaps I'd just like to pretend that in theory, I could defy an objectionable government edict and not get squashed like a bug. I'd like to believe that the spirit of rebellion still lives among the people, and that the underdog can still put up a good fight, even if they can't actually win.
- thesis 12y agoCouldn't they just be monitoring these sites for uptime? When datacenters have a network event and the sites go offline it would seem like a fairly easy correlation.
- nickthemagicman 12y agoCommenting to save this post. Downvote away.
- lotharbot 12y agoAny post you upvote is saved in your "saved stories" link (https://news.ycombinator.com/saved?id=[your https://news.ycombinator.com/saved?id=[your id] -- you can find it in your profile. No, it won't display other peoples' saved stories for you.) If you must comment, try to at least include something other people will want to read. (And then you can stick a keyword like "saved" or "fleezblort" into your post to make it easy for you to search for.)
- nickthemagicman 12y agoBrilliant! Thanks, did know know that.
- vuldin 12y agoMaybe a decentralized market server approach is better: https://openbazaar.org/ https://openbazaar.org/ Edit: I should say that openbazaar hasn't been released, and very little work has gone into allowing for anonymous nodes on the market. The idea is that once openbazaar is released then people can apply Tor anonymity to connecting their market node to the database of all nodes where things are available for purchase.