6 ms·
I had wondered what would happen to the DEA agent mentioned in the big Wired stories[0][1]. As a Bitcoin novice, I was left wondering: is it a common misconcep
by DaveWalk 11y ago
I had wondered what would happen to the DEA agent mentioned in the big Wired stories[0][1].
As a Bitcoin novice, I was left wondering: is it a common misconception that Bitcoin is anonymous? Or rather, just how easy is it to trace someone's transactions if you know their wallet ID?
[0] http://www.wired.com/2015/04/silk-road-1/ http://www.wired.com/2015/04/silk-road-1/
[1] http://www.wired.com/2015/05/silk-road-2/ http://www.wired.com/2015/05/silk-road-2/
- kilovoltaire 11y agoBitcoin transactions are stored in the public Blockchain, so if you know a wallet ID then you can see every transaction it's ever been involved in. So if you want anonymity you have to be careful that no one can connect you to a wallet ID.
- Vexs 11y agoYou can also use a tumbler, which is basically where you and several other people all run your coins into one wallet, and then withdraw random amounts up to the amount you put in. Obviously the issue there is someone needs to keep track of who has how much in the tumbler, but I imagine there's services out there.
- glomph 11y agoThat would be a bad tumbler design. A better design pays you out in bitcoins that have no connection to the bitcoins you paid in. Say you pay into wallet A and someone else pays into wallet B then you could get paid entierly out of wallet B. Then the only person who could follow the path would be the owner of wallets A and B.
- DaveWalk 11y agoI see -- I think the above argument is that the tumbling service, i.e. owner of wallets A and B, has the evidence of laundering. Concentrated in one place it's easier to protect, and easier to attack, I guess?
- kerkeslager 11y agoNo, it has nothing to do with where it's concentrated; I don't know of any tumbler designs that aren't concentrated in one place. It has to do with that if Alice gets a Bitcoin by selling uncensored newspapers in China, transfers it to wallet A in the tumbler, and then the tumbler transfers that to Alice's Coinbase account, Alice is going to jail. The transaction record tells us that Alice's Bitcoin came from the uncensored newspaper through an intermediary. The Chinese government can then arrest Alice on suspicion of selling illegal newspapers. At that point Alice must either prove somehow that wallet A in the tumbler is owned by the person who really sold the newspapers (which will be impossible), or admit that she sold the newspapers and used a (bad) tumbler in an attempt to hide her transaction. That is to say, if there's a chain of transactions connecting Alice to the newspaper sale, the tumbler has provided Alice no anonymity. Contrast this with a more realistic tumbler design: the tumbler owner (let's call him Troy) deposits a bitcoin from Coinbase in wallet A. Alice is the first user of the tumbler, so she gets a bitcoin selling uncensored newspapers in China and deposits it in wallet B. The tumbler owner then forwards the coin from wallet A (minus a fee) into Alice's Coinbase account. Now Bob, as the second user of the tumbler, comes along and deposits a coin he got from selling LSD on the Silk Road into wallet C. Troy then sends the coin Alice got from selling uncensored newspapers (minus a fee) to Bob's Coinbase account. Alice now has a coin from Coinbase, Bob has a coin from Alice's sale of an uncensored newspaper in China, and Troy the tumbler operator has a coin sitting in wallet C waiting for the next person to use the tumbler. The Chinese government has no way to track the transactions to Alice. IF Bob lives in China the Chinese government could come and accuse him of selling uncensored newspapers, but the accusation would make no sense; he has alibis for some of the days newspapers were sold, he's not educated enough to write, etc., because he didn't sell the newspapers. Bob can even say he used a tumbler, but he used it because he purchased a lot of bondage pornography: embarrassing, but not illegal. But more likely than not, Bob won't even be accused of Alice's crimes, either because he lives in a different country or because the accusations won't make any sense. Both Alice and Bob's anonymity has been protected.
- DaveWalk 11y agoGreat explanation, I understand it better from a technical perspective. I assume Troy is hidden to the authorities, who only have the Blockchain ledger and no other information to go on? That's waht I meant by "concentrated" above -- how likely is it that the Chinese government would find Troy and extract the information out of him with legal threats or with a heavy wrench?
- TomGullen 11y agoIf you're guaranteed to not get any BTC back you put in, then that seems like it could reveal information in itself. Perhaps a better design would be it totally randomly redistributes.
- tedunangst 11y agoSounds like Mt. Gox. You deposited your coins, then withdrew a "random" amount.
- jerf 11y agoIt seems to be a very popular de facto design in the BitCoin world, yes.
- jnbiche 11y agoThere is no concept of "wallet ID" in Bitcoin transactions as transmitted over the wire. There are only input and output values in transactions (which do have an ID number). If you know someone is connected to a given input, then you can trace them through any outputs to other parties. So it's not quite as simple as a "wallet ID". The transactions in given Bitcoin wallet software may be connected to each other (by the mechanism I describe above), but are not necessarily connected, particularly if you generate a new address for each transaction for which you are the receiving party (and/or take additional precautionary measures). It's entirely possible to have a wallet full of untraceable transactions.
- danielbln 11y agoThe bitcoin blockchain is a public ledger. Unless a mixing service is involved, you can trace back each transaction to an origin easily. If that origin can be linked to a person (e.g. through a trade service that knows bank details and other personal data) then you are no longer anonymous. Moving coins around a few times to different wallets/addresses makes plausible deniability easier and the trace harder, but if you are a high profile target, you probably want to be more thorough with obfuscating and/or outright disrupting the path through the blockchain that eventually leads back to you. A mixing service will basically perform money laundering for you, disrupting the direct path back to your initial transaction. tl;dr: It can be anonymous, but by default it's not really.
- DaveWalk 11y agoThanks for the detailed followup. Is there any case precedent for prosecuting money laundering like this? It seems to me that the path can still be rebuilt. I guess the criminality depends on the crime and the jurisdiction? (And the law. Obviously I'm not a lawyer, lol.)
- itake 11y agodon't know about the legal side, but from a technical side, the laundering services pool all of their client's money together in one churning pot. Which makes it very difficult to see whose money is actually going where.
- emergentcypher 11y agoEspecially if you move your coins through different wallets a few times to obfuscate, and then consolidate them back into the same wallet where you attempt to convert it into cash... obfuscating the intermediary wallets isn't going to do you much good if it can be shown you control the starting and ending wallets. headdesk
- navait 11y agobitcoin is pseudo-anynomous, since the blockchain is a public ledger of all transactions. Mixing services exist to help anonymize transactions, for example. For a technical solution on bitcoin privacy and providing anonymous bitcoin transactions, see: http://zerocoin.org/ http://zerocoin.org/
- drzaiusapelord 11y ago> is it a common misconception that Bitcoin is anonymous? On a practical level its anonymous. Its trivial to move coins around to various exchanges that makes it difficult or impossible to trace. Jurisdictions come into play here as well. If I steal some coins in the US and move them to a Latvian exchange, then a Russian one, then a Swiss one, then finally cash out in a Chinese one, who will be even able to track me down? Who will respect all these warrants? A real life example is what's going on with cryptolocker-like malware. People are paying hundreds of dollars in bitcoins to these ransomwares for almost two years now, yet there have been zero arrests. I imagine laundering bitcoins is easy to do as well by trading value in a shared pot. Hell, you could just trade one 'hot' wallet for another and again and again. Now the path is even more obfuscated.
- DaveWalk 11y agoThat cryptolocker-like malware was particularly terrifying...is it still around? I wonder why it hasn't become more or less famous? Reminds me of ATM skimmers, also particularly terrifying. I imagine they are kept at a certain degree of popularity for the same reasons.
- drzaiusapelord 11y agoYes, I read /r/sysadmin, Brian Krebs, /r/netsec, etc everyday (Sysadmining and securing our environment is one of my job responsibilities) and its not only out there, its gotten bigger. I see it blocked on my firewall, filtered out in our mail, etc. More players have entered the market (there are several active variants now) and the malware is smarter. The malware uses new tricks to infect (html file in a zip file that just does a redirect to a exe hosted on the web), bundled with 'crimepacks' that perform multiple exploits at once (java, flash, etc), running as a word macro, running fully in memory to avoid disk write restrictions, etc. We've shored up our defenses significantly but unless we move to a whitelisted-only executable environment, then it will probably get through eventually. One of my chief complaints about Windows 10 is that it does absolutely nothing to solve the "download invoice.pdf.exe" problem Windows suffers from. At least in Linux that file needs to be given a +x and in OSX non-Apple signed executable need to be approved in the system settings. Windows is still the wild west. Its a shame MS didn't use Win10 as a way to lock things down to address today's threats. Signature based AV cannot move faster than a certain speed and malware like Cryptovariants move much, much faster than that. Heuristics are terrible for some reason on popular AV's and everyone is constantly getting infected. Yeah, leave exceptions for power users and enterprise, but by default it should not allow untrusted unsigned content to run by default. I told myself that if I ever start my own company that actually allows me to quit my dayjob it would be 100% OSX environment on the client-side. MS just doesn't take security very seriously, its targeted badly, and even the pro-netsec people at MS that want to be better with security are knocked down by the other politics of having 20-30 years of legacy support for ancient apps and not breaking anything. Its just not able to keep up with modern threats. Its a shame Win10 isn't shipping with a Windows store only policy for installs and some kind of OSX-like exception in the control panel for whitelisting. Devs would hate, IT departments would lose their shit, but in a few months we'd all be used to it and the internet would be much safer.
- joering2 11y agoThis entire story was very weird, if you give Wired 100% credibility. It felt to me like Feds wanted to do everything in their power to put him down for lifetime, and I wouldn't be surprise if more skeletons come to the light. Namely, the part about him hiring a hit man was very fishy. First it was his coworker that agreed to helped Feds to play dead, but then you had some bikers performing multiple hits (supposedly all successful) on people Ross wanted dead. Uhm, so basically a motorbike gang agreed to play along with Feds, plus many "victims" agreed to disappear and play dead for months so that Ross is convinced all that money he paid the gang were for successful hits. Maybe in a Grisham book, but in real life things like that don't line up this good. Then Feds didn't hesitate to tell judge about all this, but then they decided not to use "evidence" of Ross ordering hits, and focus only on his drug business. So basically you have a judge that looks at a person that supposedly order multiple hits, who also created website to exchange some drugs. No wonder he got lifetime behind bars. I don't think drug dealers go to jail for lifetime. Another thing that struck me was allowing testimony of parents of a teen that drug himself to dead. Seriously? Sure, had not SR, he probably would have never found access to drugs somewhere else.. NOT. How about looking into the quality of their parenthood? Environment he lived in? His school and friends problems? etc etc. But no! Just exactly when was the last time you seen a family trying to shut down Ford car company and put the CEO behind bars because their two young children burnt to death in a car accident caused by a Ford vehicle?? EDIT: my point about Ford was that when did you see last time a car company CEO being found guilty and put in jail for lifetime because his company's vehicles are responsible for tens of thousands of deaths, including young children. (never)
- tedunangst 11y agoPeople sue Ford and other car companies on a somewhat regular basis.
- emodendroket 11y ago> Just exactly when was the last time you seen a family trying to shut down Ford car company and put the CEO behind bars because their two young children burnt to death in a car accident caused by a Ford vehicle?? Are you joking?
- 11y ago
- jimbobimbo 11y agoThere's a conclusion of that story: http://www.wired.com/2015/05/silk-road-2/ http://www.wired.com/2015/05/silk-road-2/
- DaveWalk 11y agoOh yes -- weird it's not prominent on the initial story. I've edited myself.
- chejazi 11y agoA Bitcoin transaction between two parties is itself pretty obscure. As others have said, "mixing" techniques like CoinJoin [0] allow for much greater obscurity. The big misunderstanding is with services that use Bitcoin; for example, the agreement to send $50k in Bitcoin was probably in a message log in a Silk Road database. [0] https://en.wikipedia.org/wiki/CoinJoin https://en.wikipedia.org/wiki/CoinJoin
- ocb 11y agoAs far as I know, all dark net markets (including Silk Road when it was around) strongly recommend that you encrypt all text containing sensitive information using PGP. They don't force you to, though.
- chejazi 11y agoIf PGP was used, I wonder with what security each party guarded their PGP key. I could imagine DPR's PGP key getting compromised following his arrest. This would reveal half of the conversation -- likely enough to spawn an investigation of the DEA agent.
- granfalloon 11y agoAt the time his transactions may have been difficult to trace, but now we have tools like Wallet Explorer, which make his wrongdoing pretty clear: https://www.walletexplorer.com/wallet/08363b86122e340c https://www.walletexplorer.com/wallet/08363b86122e340c (That's the 770 BTC payment references in this article: http://motherboard.vice.com/read/how-a-two-timing-dea-agent-got-busted-for-making-money-off-the-silk-road http://motherboard.vice.com/read/how-a-two-timing-dea-agent-...)