Dark Web Price Index 2020
privacyaffairs.com
privacyaffairs.com
For the hitman, it's much safer to just take the down payment / etc and not do anything. That's just way more cost effective / lower risk to do that over and over again.
For the person hiring them... no reason to think the hitman won't do the logical thing and not do the hit / walk with the up front cash.... and probably limited no incentive to pay after the deed is done if in fact everyone is anonymous.
Historically speaking hitmen seem to be tied to organizations who the hitman and the employer more or less can trust / provide some level of protection / regular work / other work or at least the promise of it. And generally the the professional hitmen eventually tend to be disposed of by the next hitman after their usefulness to their employer fades...
A system where nobody trusts anyone would seem to only attract scammers and some random idiots.
Hard to imagine it working out any other way.
Beyond that though a hitman seems to assume some level of proximity to the target that authorities could use. Mailing drugs much less so.
And its partially a true story:
https://www.insidehook.com/article/military/real-life-jackal...
Plus you order your goods to the wrong address or use a fake name, and when the heat comes around you say "it wasn't me" and flush your drugs -- they're not going to chase you for months the way they might a murder case.
Obviously exceptions for the guys ordering kilos of coke every quarter, but as long as you put a little bit of effort into CYA no one is going to kick down your door for $80 worth of Molly.
It's trivially easy to create new accounts and maintain parallel alternate accounts on dark net marketplaces, even going so far as giving yourself fake reviews to pump up reputations.
This is such a common scam on dark net markets that it has a name, known as exit scamming. A vendor will build themselves up a good reputation (usually fake) and then scam everyone who transacts with them, cashing out on the reputation. Wash, rinse, repeat with new accounts.
You also run a risk when leaving a bad review. Even if you never buy from that vendor again, you could buy from one of their alternate accounts, and they'll send you fentanyl in your product as retaliation.
It's all turtles it seems ;)
I think all dark markets to date had some escrow systems in place eventually.
In Finland, last year, young man offered his hitman services on dark web and eventually murdered another. Trial started in the beginning of June 2020.
Of course, he was not a professional hitman and outcome very scam'ish.
(Assume the prediction market is completely decentralized and untraceable. Assume there is an accurate way to determine the outcomes of the events in a manner compatible with being untraceable and decentralized.)
If Joe dies and someone gets $500,000 richer I'm sure the police would be very interested to investigate the transaction, but would the bet itself actually violate any laws?
My question is whether it's actually illegal to take this bet, since it doesn't really prove that you're the hitman.
Anyway, in real life a hit costs about $50K.
Basically, jury nullification is a thing, and this is the same principle backward.
Some people seem to think "beyond a reasonable doubt" means the same as "beyond any shadow of a doubt" - but they are very different standards!
Please see people who are convicted on limited or circumstantial evidence because everyone is pretty sure they did it. Example Hans Reiser.
I understand that HN and Reddit like to repeat this fact, but it's really not a useful answer to the question I asked. I think you're saying "no, it's not illegal", but you've masked that opinion with trivia.
> limited or circumstantial evidence [...] Hans Reiser
Reiser plead guilty to murdering his wife and disclosed the location of her shallow grave. I'm not sure how limited or circumstantial that is.
I don't think it's masking the issue with trivia at all. If you conspire to kill someone or indeed to commit any crime and your defense rests on a cute use of the law to remain technically on the side of the law while obviously trespassing beyond it you are only as safe as you can convince the jury you are.
If you are more interested in the actual law we could look at justice.gov
https://www.justice.gov/archives/jm/criminal-resource-manual...
Section 1958 renders it illegal: 1) to travel or use facilities of interstate or foreign commerce; 2) with intent that a murder in violation of State or Federal law be committed;
Looking at my state WA states law
RCW 9A.32.030 Murder in the first degree. (1) A person is guilty of murder in the first degree when: (a) With a premeditated intent to cause the death of another person, he or she causes the death of such person or of a third person;
If you in effect arranged for someone to die by betting a large sum of money on a prediction market no judge or jury will pick nits and disregard your intent while placing such a bet.
Hacked websites, bribed operators etc.
Someone with half a million to squander already has the means to disperse of others. Whereas an enemy of the people may have 10,000 detractors, who while otherwise wouldn’t have the means, can pool together a seven figure bounty for $100 each.
Credit cards and bank credentials being worth comparatively much less means that hackers don't have easy ways to secure the funds - either there's a high risk that the transaction is reverted, or there's a high risk that the hacker gets caught and goes to jail. You can tell it's not just an effort issue because the value of the accounts barely scale as the amounts in the accounts increase.
Considering there are ~325 million active paypal accounts, wouldn't there be a huge supply if their security, overall, was lax?
And furthermore, isn't the security of a criminal getting money out of the system only equivalent to getting the money through banks?
I'll try to re-word the GP, thanks for highlighting your confusion.
i don't think normal demand curve applies to stolen bank accounts. the value of a stolen account would be the average amount of money you can expect to get out of it, regardless of how many stolen accounts are available. An increase in supply wouldn't make that any different.
So if you were to gain access to a stranger's account, you'd have to transfer the money to an existing, old and actively used account. Which is likely to be your own or your friend's.
Seems like a huge risk, so the hackers just sell the account to some idiot willing to try it.
I browsed Tor regularly between 2011 and 2013. Late 2012 and early 2013 brought the most precipitous drop in deviant material. Before then, you couldn't throw a stone without coming upon CP(I avoided it like the plague but knew it was there), you could buy literally any drug on the Silk Road safely, and you could easily find bomb-making and asymmetric warfare information. Nowadays? Not so much.
I'm sure CP existed and exists on the dark web, but I think it's an exaggeration to say "you couldn't throw a stone without coming upon CP". A few years back I spent quite a bit of time on tor (research purposes), and thankfully never once just stumbled upon CP - I'm sure it's there, but you're going to have to go looking for it.
While Silk Road isn't around any more, other drug marketplaces pop up as soon as one dissappears - it's still very, very easy to buy any drug you want. Next day delivery of heroism? Easy. You've 3 big threats with buying drugs on the darkweb though:
1) The site pulling an exit scam, dissappearing with all the escrowed funds 2) Your seller pulling an exit scam, taking money for as long as possible without sending any drugs, then leaving the market 3) The site being compromised by the feds - it's actually quite difficult to run a watertight site on the darkweb, so this does happen
It was on every single Hidden Wiki at the time.. it _was_ everywhere, and commonly linked to from sites like 4chan.
other drug marketplaces pop up
Sure, but nothing like the Silk Road. In a winner-take-all market like the online marketplace market, you would expect a top dog to emerge.
When did you do your research? The difference I noticed began late 2012.
There were huge markets after Silk Road, though admittedly I don't know how size compared to Silk Road (e.g. AlphaBay, Agora, Nucleus, Hansa).
DNM's haven't been the same since the busts of AlphaBay and Hansa in close succession.
I'm sure any operators that didn't get busted realized the heat had showed up and chose to shut down. When you are facing 20 years in jail you don't need hard evidence that Tor is broken to decide to walk away.
Scrubbed my drives, poured bleach in my eyes and swore off TOR forever. I'd agree that at the time, it was rampant.
However, it was during the same time that the FBI had set up their Operation Torpedo so it's quite possible those were heavily advertised on purpose as a trap.
Either way, it's sickening and another proof that we can't have nice things. Give a dark-web to mankind and the first thing they do is upload disgusting illegal porn to it (I am not talking about kinks but actual criminal activity).
Damn, screw my "hero's journey," this sounds way more straightforward. :P
There's a lot of evidence to the contrary. I don't mean to be rude, but your assertion sounds quite hollow and baseless. I'm certainly interested in any evidence you would have that shows tor is compromised.
It's nothing now like it was then.
If I was a Dark Web Drug Kingpin, I would want to lessen the stigma of using the Dark Web, and that means trying to DDoS unsavory sites, convince other sites not to link to it, and the like.
I think we should stop fear mongering over shady wifi. In a world with HSTS and CT, these types of attacks ars incredibly difficult to pull off.
Google is HSTS. The bank may or may not be (what a sad state of affairs, but i digress) but the link from google will at least be https.
What websites do you have in mind that are not https and that average users enter personal information that could lead to identity theft on?
> having information about general activity can in itself be a privacy concern, whether or not that information is readable.
It definitely can be in some threat models. In the context of average user being the target of drive-by identity theft, i struggle to see a realistic threat model for traffic-analysis of encrypted network traffic.
The rest of it seems fairly accurate based on jstash/unicc/etc.
Doesn't seem easy at all. ATMs have cameras and are monitored for abnormal transactions (stolen cards, unusual withdrawal patterns, etc).
Unusual patterns and stolen cards are one of the primary reasons that they will rarely ever leave a team. It takes a great deal of work to gather stripe data + PIN. It's much easier to look for a website without PCI compliance. In-person carding is going by the wayside, but is much easier to accomplish if you have good data. You can buy dumps, but no one is turning over a PIN.
Cameras can’t tell you the name and address of the pixel blob that is committing the crime. Cameras as a security device are overrated. My building had countless footage of people entering the bike room or parking and stealing bicycles. Resident makes a complaint to the police, proudly says “we have cctv footage!”, police shrugs and looks at cctv footage, and nothing happens because what do you do with the video of a thief stealing your bike..?
https://www.theguardian.com/uk-news/2018/nov/11/super-recogn...
Given sufficient resolution, software, and access to data they can with some degree of accuracy.
>My building had countless footage of people entering the bike room or parking and stealing bicycles
With bicycle theft you have an individual with an incentive to recover the bike approximately equal to the retail value of the bike, and few resources at their disposal. Law enforcement is not going to pay much more than lip service to a stolen bike, because they don't have any tangible incentive to recover it, while it's probably a lot of work to even try. Depending on the building, it's possible the landlord is sufficiently incentivized to increase security to mitigate tenant complaints, but that won't extend to the search for a bike that has already been stolen.
By contrast, with bank fraud you have, for example, a $300 bn company like JPM with a strong incentive to protect their network's security and consumer trust, cameras everywhere, and good working relationships with law enforcement at many levels of government. It is much more likely to be taken seriously and acted upon, and is therefore riskier than bike theft.
Banks seems to have lots of influence and move things around. Bank thefts (where I live) net for thieves around 10-20k USD. They get lots of police action. Other thefts with even higher amounts go unnoticed.
The hacker doesn't hack, but sells the information to be weaponized.
The person that weaponizes only does that to get a giant leak of data, that they sell in pieces.
The person that buys a few cards, gets 1 that works, and now we are talking about a few thousand dollars. Almost too small to care for a big investigation.
And so on and so forth.
There is rarely anyone to levy the whole force of the RICO act + CFAA + Wire Fraud + Conspiracy + Using a fake ID + etc etc
Because there's almost no risk associated with it. You don't have to get a team together to hit up ATMs and extract money from those cards, which requires trust and increases complexity, you just mount a few skimmers, collect the data, remove the skimmers, and then sell it online and let someone else take the risk.
If you're the police and you have the option of spending resources on burglary or muggings (which cost an absolute fortune in police time, generally low value, but in the public's eye very important) or payment fraud, the police will put time into "in person" crime every time.
It’s really not a lot of extra risk, it’s not like the authorities could respond at the ATM in a timely manner. All the thief needs to do is cover their face.
Given that, I assume it's a very risky thing.
In most places finding an ATM that still uses the magnetic stripe is certainly not easy.
(Some chips aren't actually signing anything, they're just another way of reading the same info that's on the strip. It depends on the company issuing the card. This isn't covered in the video, but it's true.)
As the video shows, there are other vectors of extraction than ATMs.
Some time ago I accidentally stumbled upon how some organized crime ring determined which credit cards worked. Someone in my party asked the Uber driver one night what other gigs they do for money. He said he uses this one card to get 40% cash back. Of course I asked more questions being the only one in security at this party:
He starts talking saying he goes around to different, small, local businesses - but never visiting the same place twice - and uses this card to pay for his friends' food, splitting the bill, but keeping the cash back rewards. Sometimes the card is rejected and he has to keep trying until it works finally. The actual credit card has to frequently connect to his phone by pushing a button on the card to sync with his phone to make purchases. Of course what his phone is doing is downloading a backlog of CCN's which then is sent to the credit card to change the magnetic strip dynamically - completely unknown to him he's testing if credit card numbers are working and getting paid for it. Genius scam, but that's what this one specific crime ring has to pay in order to check the availability of stolen credit card numbers.
But if he isn't in on the scam and does pay off his card, funny enough, that must mean all of his money is going directly to the crime ring. Two birds with one stone!
Why not? ATMs work at 3AM.
> but you also have to test what credit cards work and what don't
Not really, if it’s data you skimmed yourself odds are they’ll work more than half the time.
If I was in fraud detection there would be fraud flag contagion: If 25% of them started out as blocked and you tested them all, afterwards 100% would be blocked.
I can think of ways around it myself but I don't think they're realistic for the number of times this would actually happen.
If within X minutes you see Y cards and Z of them are known to be stolen, you set the soft fraud flag on all of them. Values of X, Y and Z would be set based on historical data.
You could still test your stolen cards, of course - but 5 at a time, not 50 at a time.
Then repeat for each block of 25%.
In short, Domino’s across the US regularly receive strange orders for $2 Coke (and nothing else), which then no one ever picks up. The theory is, if a card doesn’t work, an automated script detects that as online order form switches to cash—and if it works, given the popularity of Domino’s this transaction might just slip by the cardholder’s attention.
My parents' experience suggests donating to charity probably isn't as effective any more.
Because now you have $25, and you don't have your face on video using a stolen debit card?
The links can be dead by the time you get to them. You don't know if it's just another honeypot. You don't know if you'll get what you pay for.
I bought an expensive T-shirt a long time ago from a rather legit looking apparel company (nice website, LTD company/bank account).
Learned the right words on Reddit, hit up Instagram and started looking for and messaging people. Got a few replies, went with the one who had the most legit looking photos.
After a few questions on WhatsApp (yeah, really, lol) got directed to the website and bought the right item... via direct debit because their payment processor was "down".
Big risk on my part, I guess, my plan if popo called was to just say "hey I only ordered a t-shirt!"... I did not think it through very well.
Got it pretty fast (Royal Mail tracked and signed) and found a gift pack of "Revels" inside. How nice of them!
It seems rather risky for them, wouldn't it take just one guy to talk? Or maybe the seller was new to the business.
Tbf, setting up a company, bank account and shipping, all while staying anonymous is extremely easy (but not legal) in the UK compared to the rest of EU.
Joking appart, my question wasn't to learn about drug prices for "practical use". I just think it's an interesting subject: how the web changes underground/illegal markets, what impact it has, etc.
There are lots of counterintuitive things in that field (look at how Portugal handles it), which makes it even more interesting to me. "war on drugs vs war on drug users".
So what it can do is as limited as it's hardware and connectivity?
Paid malware isn't all necessarily low quality, but most of it out there is. If you want something high quality I'd imagine you wouldn't see the listing for a particular malware that is high quality, but for someone who can write something high quality. Something custom developed will always be less detected than something being traded around.
Why would this be so valuable? Stealing somebody else’s free emergency tow? Isn’t a membership itself only like $120 a year?
https://www.cnet.com/news/your-hacked-facebook-account-may-b...
Of course nothing stops an anonymous seller from defrauding an anonymous buyer in a one-off transaction. But sellers operate under some kind of semi-stable pseudonym, so they do care about their reputations. They might also be selling on a market where some third party would look at the goods provided and adjudicate a dispute.
This was the most surprising to me. Seems like it’s extremely high priced. You get a 30% discount for using counterfeits and potentially getting the secret service on you? Maybe that is a reflection of its quality but... Yea, no thanks.
Edit: Ohhhh My bad read it wrong. 70% off... better but these would have to be amazing quality.
So $6 actual for a $20 bill. I see how that could be tempting to someone but I’m pretty sure it would have to be somewhere outside the US, you don’t mess with fake money here.
Perhaps because they don't matter, but perhaps because they are more difficult to create or Google is better at spotting fakes.
I think the renewal for my AAA membership was $74. Why would anyone pay for a fake membership for $70?
Did they scrape data from various black market sites naively?
If you're in a "law enforcement free-zone" and can bank a recurring service fee versus a one-time scam running these kind of services, why not engage in such behaviour?
There are career criminals with reputations also.
If you become familiar and known in the scene the risk of being scammed is very low and if it happens it's more like a "one last money grab and I am done thing" where the person offering the service will disappear. But since this works once per online persona this really doesn't happen that often.
Not that I'm planning to purchase any of those services of course, I'm just curious because it sounds like there's no possible starting point, unless by pure chance one of your personal friends happens to be already involved in the area and lets you know.
Use the phrase "darknet" then just apply the word "markets" and you'll already started the jump down the rabbit hole.
https://www.usenix.org/system/files/conference/woot16/woot16...
It uses the outputs of the key exchanges as proof that the attack was carried out. I doubt anyone uses it in practice though.
For more mundane services, though, most 'darknet markets' like Silk Road have a seller account reputation system, like ebay; and a payment escrow system. So you can choose a seller who has 100 previous transactions and a 99.5% positive reputation. And if they don't deliver, they don't get paid.
You can also ramp your purchases up gradually, buying the $10 1-hour DDOS and the $60 1-day DDOS, thus confirming the supplier can deliver before spending more than you can afford to lose.
And of course it's traditional for every bitcoin/darknet service to eventually fold with some insider making off with everyone's money. For that, I don't know what the common mitigations are, apart from not carrying an account balance larger than you can afford to lose.
[1] https://www.theguardian.com/technology/2013/nov/21/silk-road...
From forgers to illegal sex workers. Even the rationales are flimsy.
there are easy rebuttals to help justify why different kinds of service providers discriminate in those specific trades if I elaborated at all, but the rationales behind them still don't make sense.
I only posted as it might be a shared experience for some people passing through here, and insightful to people that haven't experienced it. If you are in the habit of questioning the validity of a reality you personally haven't perceived, then this comment just isn't for you.
these are not merchant consumer relationships, these are service providers that have to follow instructions with clients and deliver the service requested.
- That adds extra risk, so you might have to pay someone to scare that mule into doing their part.
- You'll want to get that laundered somehow, so you'll want to arrange some nice path that leaves no trail to you, maybe through Western Union?
And so the costs keep increasing and your margin goes down. The key of the game is to setup this kind of stuff at scale. Then it doesn't really matter if you're making only 60$ from each card, as long as it covers the cost.
I've never tried it, but I'm almost certain my bank would block the transaction -- either for authorization by SMS (if the Bitcoin-selling site supports this), or by denying it until I phone the bank myself.
I think this would be normal for most European cards. I was surprised not to see a separate price for EMV / no-EMV cards in the table.
Because of more prison time. The moment you start pulling money off of someone else's card either an automated system will trigger an alert or the owner of the card will get a push notification about a withdrawal and the authorities will get alerted.
Just skimming can remain undetected for quite a while, but the moment you start stealing money, your risk will go up dramatically.
$9-$25 each and depending on provider you get discounts based on number of pieces purchased at once & possibly historical spend.