So law enforcement has lots of encrypted text along with some clear text from users not informed enough to follow any kind of opsec.
So law enforcement has lots of encrypted text along with some clear text from users not informed enough to follow any kind of opsec.
I really wonder if this happened at all
Furthermore, in order to lower the risk of anyone detecting this here's something the LEO could do:
1. They seize control of the servers.
2. They make note of who is an existing user and keep serving them the real PGP keys of other pre-existing users.
3. For anyone who registers after the point in time where LEO controls the servers, replace the PGP keys of sellers and also the keys of these new users with MITM key pairs.
Then when they run the site for a month as they did and they have the influx of users they got from AlphaBay, they will have plenty of evidence on all of the sellers that are active during that period of time due to there being so many new users all of whom you are MITMing, regardless of whether the sellers are new or old because the old sellers are also being MITMed in all exchanges they have with new users.
The sellers were the primary target of interest, so the LEO got what they wanted.
All of what I said is just something they could have done though. Not saying that it's what they actually did.
Of course, I know nothing and have just heard of either of those sites this morning.
Only send messages to vendors with known "trusted" keys and don't trust new keys? So in general, use a trusted channel for key exchange separate from the communication channel so that a MITM needs to control both channels?
Yes, this is how PGP verification is supposed to take place.
Someone sends you their public key, and then you meet them in person to verify it.
Of course, nothing stops the government from sending an agent to meet you, but it does raise the effort required to MITM substantially.
In short, I doubt the police did this kind of thing because they risked blowing their cover for the sake of getting some buyers' addresses.
Also, these sites tend to have a big button labelled 'encrypt my message' - which ostensibly does all the PGP for you. I'd guess that most people are lazy and just press this instead of running PGP/GPG manually. It would be trivial for the police to capture the unencrypted messages just by subverting the auto-PGP.
Dutch Police released a statement claiming as much http://politiepcvh42eav.onion/hansafaq.html
PS. OpenBazaar seems to have received $3M funding. Interesting about change for a project started by Amir Taaki given his very anarchist professions.
PPS. Desktop client seems a bad thing to develop first (in the true tradition of Bitcoin!). Perhaps you guys could have stuck with network client daemon + API for starters. Anyway, good luck.
Maybe this was done on a case-by-case basis or Grams updated their keys to the new LE keys.
The size of the grid makes encryption work.