Skip to content

Comment on Another Security Blunder Takes Down Another Dark Web Drug Emporium

Comments

Seems a few comments here are pointing to the VPS provider being the ones who might have leaked the source code. I don't think that was the concern, but hopefully somebody more in the know can elaborate.

From what I understand, once a portion of the source code was in the open, a match could be made (not easily like a google search) to that server's index.php page, pointing to exactly which server is running the code, and can then be back traced to who the account was registered under.

What I don't understand (and I've never used any of these sites) is how do they have a DNS registration and ip look-up without that being connected to an individual. I know you can make your DNS details private, but I would have assumed that was only 'private' from public view and that most of the DNS companies would have cooperated with law enforcement.

Unlike general snooping, I think I'd be fine with Law Enforcement getting a warrant to find who registered a particular domain, and back trace from there. They would still need to make a case of illegal activity, so should this be protected information?

These sites don't participate in the DNS. They (theoretically, at least) keep their IP addresses secret by sending and receiving traffic only through the Tor onion routing network.

http://en.wikipedia.org/wiki/Tor_(anonymity_network)#Hidden_...

.onion sites are not part of the DNS but are resolved by a DNS equivalent based on public/private key encryption and directory servers thus revealing neither IP# nor hoster.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.