Post
Topic
Board Bitcoin Discussion
Re: SilkRoad domain Seized?
by
acoindr
on 02/10/2013, 19:24:36 UTC
pretty obvious TOR has a vulnerability that is being actively exploited ...

A prior comment of mine is relevant here:

So I just looked into this, not thoroughly so someone please correct me where wrong, but have the following assessment.

The FBI conducted a successful operation against a big person in the Tor world named Eric Eoin Marques who runs a company called Host Ultra Limited. They are trying to extradite Eric to the US to face charges. I'm guessing Eric either distributed directly, or hosted sites dealing in child pornography. Apparently he was conducting business as a Tor Hidden Service.

Now, Tor Hidden Services is different than using Tor normally. Tor Hidden Services is what allows Silk Road to operate because the server itself can gain anonymity while still handling incoming client requests.

What is not readily apparent (to me) is how the FBI found Eric's servers, and what was done with them. It could be that his servers were found with investigative methods outside Tor. However, there does appear to be a way to de-anonymize servers using Hidden Services revealed in the following paper at a security symposium in May 2013:

Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization

I only read the first couple pages but have no reason to doubt the claims. Whether or not the FBI used similar exploits for this case isn't apparent, but I'd say Silk Road looks vulnerable unless and until there is a patch or re-work of the Hidden Services protocol.