Showing posts with label Tor. Show all posts
Showing posts with label Tor. Show all posts

Thursday, August 15, 2013

"The age of narcotics e-commerce has arrived" says Andy Greenberg, demonstrates Silk Road online drug purchase in Forbes article

Andy Greenberg, a Forbes journalist focusing on technology, privacy, and information security topics, authored two startling articles about the online drug market. Both Justin and Jeffery have touched on the increased attention that online drug markets (like Silk Road, the focus of Greenberg's articles) have received over the past year. Greenberg's recent reports, however, provide a new look into the illicit trade, and both articles are a must read.

Meet the Dread Pirate Roberts, The Man Behind Booming Black Market Drug Website Silk Road, Forbes, August 14, 2012
Greenberg's first article provides a rare interview with the self-proclaimed "center of trust" for one of the web's most notorious online drug exchanges, Silk Road. Greenberg's interview with "Dread Pirate Roberts," the site's operator, details how Silk Road has amassed, according to Forbes' estimates, an "annual run-rate of $30 million to $45 million." The interview with Dread Pirate Roberts details how Silk Road uses anonymity software (such as Tor) and open-source cryptocurrency (such as BitCoin) to facilitate the purchases on the site. Even more interesting is Greenberg's take on how, "[a]s with physical drug dealing, a turf war has emerged" in the online drug trade. This article is also set to appear in the September 2, 2013 issue of Forbes.    

Here's What It's Like To Buy Drugs On Three Anonymous Online Black Markets,  Forbes, August 14, 2012
Taking his investigative report on the online drug trade a step further, Greenberg and the team at Forbes actually tested the drug-buying process. Using "the three most well-known online anonymous black markets: The Silk Road, Atlantis and Black Market Reloaded," Greenberg's article describes how he and his team "purchased  . . . small amounts of marijuana." Don't worry, as Greenberg's article explains, the team's lawyer insisted he destroy the "product." This video, released by Forbes, accompanied Greenberg's articles (and documents the "product's'" distruction)


These recent articles by Andy Greenberg and the Forbes team are quite compelling and demonstrate how the drug trade, unfortunately, has started to transform and grow in a digital age.

Monday, December 10, 2012

Austrian Tor node operator's home searched in child pornography investigation

An Austrian man's home was recently and his computers seized in an investigation related to child pornography distribution. His involvement concerned the operation of Tor on his computer, which allowed others to hide their Internet activity by having their data encrypted and transmitted through others' computers.  Mr. Weber, likely to be charged with child pornography crimes, never actively possessed such files if this is true, though they may have been sent through his computer.

In the Tor network, files are transferred along a randomized path, ultimately becoming unencrypted at the last node just before making it to the intended destination. As such, it would appear to investigators as though the files actually originate from that exit node though the computer operator has no knowledge of the files or their content.

In a blog post, Weber explained that he runs Tor in order "to make it possible for the not so privileged folks to have uncensored access to the internet, without fear of government prosecution."

Firearms and marijuana were also found and taken after Weber was asked to open his safe and he complied.

Tuesday, August 7, 2012

Carnegie Mellon study on Silk Road

You may recall that in May I wrote a post about what Bitcoins could buy you in the criminal underground, appropriately titled "What Bitcoins can buy you in the criminal underground."

In that post I mention Silk Road - a site that is pretty much an illicit drug bazaar. To follow up on that, I'd like to draw attention to a new study that has come out, authored by Nicolas Christin, which details the revenue made by the site, and other usage statistics - including a very high satisfaction rate with the transactions.

The study can be found here:

Traveling the Silk Road: A measurement analysis of a large anonymous online marketplace

H/T to Forbes: Black Market Drug Site 'Silk Road' Booming: $22 Million In Annual Sales

Tuesday, June 26, 2012

The illegality of striking back against hackers

It has been an emerging trend in recent security publications to highlight the interesting trend of companies "hacking back" against infiltrators and potential data exfiltrators. The concept sounds intriguing - if the internet is the wild wild west, then what better way to participate in it than to allow the tumbleweeds to shift in the wind as you and your foe see who can draw first, or, more accurately, get the last shot. However, the Computer Fraud and Abuse Act provides no escape hatch for such actions; there is no Castle Doctrine in federal statutes relating to hacking, and no such doctrine in state cybercrime laws, either. Any such activities are ill-advised, likely illegal, and do nothing but encourage the escalation of cybercrime.

It's certainly clear that this is a response to the plethora of attacks that have happened recently, but I think more tellingly, resonates from the clear embarrassment that permeates any large company's mea culpa when they admit a breach has occurred. In the article above, it notes that firms have popped up that are for-hire counter-strikers. While the notion fulfills the age-old revenge story meme, and could even make hackers think twice about striking your company (if they knew you would take such measures), the legal niceties are nothing even remotely so poetic. Here is a non-exclusive list of the problems I see with such a strategy:

1.  Such actions tread into legal no-mans-land - namely, that as far as I can tell, there is no legal precedent in support of such actions. Conversely, there's a ton of case law that is not on your side which states bluntly that unauthorized access is just that, unauthorized - no matter who the party "hacking" is.

2.  Any sophisticated hacker that would attack a semi-large or multi-national corporation isn't going to be hacking from their Dell PC at home, sitting behind a poorly secured Linksys router. They will be hitting through proxies, utilizing Tor, or more likely executing strikes through already compromised machines. The implication of this is three-fold - (a) in striking back, you may end up attacking an unwitting third-party who is likely also a victim of a computer crime - therefore, you will have even less sympathy if litigation arises; (b) if the originating host is an already compromised third-party, you could accidentally cause greater damage to hosts that are specifically enumerated in the CFAA, such as government computers, those containing national security information, or systems involved in medical care or public health/safety (See the DOJ's Prosecuting Computer Crimes manual) - and end up with a significant felony; or (c) (assuming a world where hacking-back becomes common), end up irritating a non-interested party, motivating them to also attack you.

3. While such actions may embolden or vindicate a hacked entity, they also put a larger target on your forehead. More specifically, if I were a hacker and my goal was simply to exfiltrate data, and you then attack me back, I am highly likely to escalate my attacks quid pro quo. Accordingly, what might have been simply a small case of data loss may turn into full scale damage to your systems; instead of sneaking in and out, you are now susceptible to much more malicious attacks - Denial of Service attempts, deletion of sensitive or irreplaceable data, actual hardware damage, or "doxing" of company executives. This undoubtedly will raise the price of the incident exponentially.

4.  It is unclear to me what an entity stands to gain by hacking back, other than the cathartic chest pounding that may occur when one can say that they "lost the battle, but won the war." Is that really worth a potential prison sentence?  Yes, your efforts could assist law enforcement in tracking down who hacked you, but it won't be so cathartic when the tables are turned, post investigation, to then investigate you for your actions.

5. Lastly, in 2008 the CFAA was amended to include a conspiracy offense, so you may not even need to actually breach an attacker to run afoul of the law. Could a corporate agreement with a strike-back contractor be sufficient to violate 18 U.S.C. 1030(b)?  That is not clear - but I'm betting we are going to find out if this trend evolves into the norm.

Tuesday, June 12, 2012

Tor prevents DOJ investigation of child pornography website

A recent Freedom of Information Act request has revealed that the Department of Justice was unable to investigate those involved in a child pornography website due to the use of Tor (read more about Tor here).
The website was not viewable through normal web browsers ... and [] the site and it's contents could only be viewed on the Tor Network....
[B]ecause everyone (all Internet traffic) connected to the TOR network is anonymous, there is not currently a way to trace the origin of the website. As such, no other investigative leads exist.
As Ars Technica reports, Tor has not always stopped law enforcement from investigating illegal activity including the April bust of the Farmer's Market.

Friday, April 27, 2012

Tech Watch: Onion Browser for iPhone allows encrypted browsing, Tor traffic tunneling

Onion Browser, an app just released for the iPhone and iPad, uses the Tor network to allow users to access the Internet with encryption and anonymity. The app, which is not made by the Tor Project, is available for $0.99 in the iTunes store.

The website lists the following features and benefits of the browser:
  • Internet access is tunneled through the Tor network: traffic is sent through an encrypted tunnel and over several "onion router" machines before reaching the destination.
    • Websites do not see your actual IP address.
    • Web browsing activities are protected from eavesdropping by ISPs or other users of your wireless or wired network
    • Freely access the entire internet from behind restrictive firewalls.
    • Access to the "dark net" of hidden services (".onion" web sites) not accessible via the regular internet
  • Ability to spoof HTTP User-Agent header.
  • Ability to change cookie storage policy (Allow All / Block Third Party / Block All)
  • “New Identity” button clears cookies, history, and cache and requests a new IP address in one quick step.
  • Startup page contains a list of well-known, stable .onion sites.
Tor software is, however, officially available for Android. According to Tor's website, the software, called Orbot, "allows mobile phone users to access the web, instant messaging and email without being monitored or blocked by their mobile internet service provider."

Thursday, November 3, 2011

Anonymous posts 190 IP addresses from child pornographers

This map shows the locations of those "caught" by Anonymous.
Anonymous, famous for their online protests and "hacktivism" has just released 190 IP addresses of child pornographers. The operation, called "Operation Paw Printing", was based around a Tor update released last week, and they knew that Tor users would want to immediately update their software. The group edited the code to allow them to track a user's online activity for 24 hours and posted the modified update on "Hard Candy", an underground child pornography forum on a website called The Hidden Wiki.

The administrator of "Hard Candy" added this note to the forum: "If you were stupid enough to install the recently linked Tor button 'update'... then your anonymity has no doubt been compromised. As a result you should consider running anti-virus/malware programs and/or fully wiping your hard drives."

Anonymous acknowledged their dedication to free speech, but noted: "Child Pornography is NOT FREE SPEECH.  We proved beyond doubt, that 70% of users to The Hidden Wiki access the HARD CANDY section, "a secret directory" used by the pedophiles to access sites like Lolita City and The Hurt Site, a site dedicated to trade of child rape."

The IP addresses and a more detailed explanation of Anonymous's operation can be found here.

RELATED NEWS: Anonymous has announced that they soon plan to release a list of at least 75 collaborators of a Mexican drug cartel after the group intercepted 25,000 e-mails from the Mexican government. According to a spokesperson, the list includes taxi drivers, public officials, and police officers.

Tuesday, October 18, 2011

French researchers claim to have compromised Tor network

The Onion Router (Tor), which has been providing online anonymity for almost a decade, may soon find its usefulness to be greatly diminished.

A French engineering school claims to have found a way to compromise a Tor network. The group claims that one-third of the Tor nodes are not properly secured, and hackers can "easily infect and obtain system privileges." From there, they use DOS attacks and packet spinning to ultimately decrypt each communication.

The claims can be viewed by clicking here (though the videos are in French). Tor plans to release a new version in late October, though it is uncertain if the updates will address these claims.

The Tor network has long been used to allow web surfers to hide their tracks while online. A user's online communications are sent through a multiple nodes, each carrying the data with multiple layers of encryption. The technique allows one to commit illegal activities while online without leaving a trail of evidence behind.

RELATED NEWS: In case you hadn't heard, Tor even has an app for Android phones called Orbot.