We know that Tor isn't resistant to state-based attackers, so my money is always on global surveillance networks picking up missteps by the operators.
"Whoops I forgot to turn my VPN on and SSH'ed into one of the servers they were already watching" -- this kind of thing.
Why would someone be using a VPN if they're using tor for the market? Why would a VPN offer any protection at all? If you're using a VPN and "SSH into one of the servers that they are already watching", then a VPN isn't going to provide anonymity.
User --> VPN --> Tor --> Market
Assuming the VPN is trustworthy and you don't connect to Tor without it, the VPN would cover up the fact that you used Tor at all.If you normally use the VPN, but forget it one time, you are now exposed.
What that means changes on the threat model, but for this scenario we'll say a hypothetical VPN provider in a different jurisdiction that takes Monero and has good OpSec.
The reason they can do the deanonymization attack on the Tor circuit is that they have basically unlimited resources to set up nodes, and Tor is built on the assumption that the nodes are all unrelated.
If a Tor session looks like:
User -> VPN -> Tor( A -> B -> C ) -> Market
then the government could have the advantage of owning both A and B, or any other combination. That is difficult (though not impossible) to do to a VPN that they do not have jurisdiction over.Anyone can set up a Tor node, but it's not possible to just randomly add nodes to a VPN's network, so they shouldn't be vulnerable to that (barring insecurity in other forms).
Plus, you can restrict what nodes are used. It's not like the public nodes are the only ones that exist.
Clearly I've got gaps in my understanding, any good resources you could point me towards to study up?
It'd also be helpful to first learn how routing works. Then check out different types of applications(Tor, AnoNet, ZeroNet, etc) and read up on how they implement their networks.
Also read up on how the people who ran the markets got caught (read up articles in addition to Wikipedia).
Be aware Wikipedia shouldn't be used as actual fact. Check the sources. Many editors misinterpret them, or don't even read them at all.
https://en.wikipedia.org/wiki/Category:Internet_privacy
https://en.wikipedia.org/wiki/Category:Anonymity_networks
https://en.wikipedia.org/wiki/Routing
Some keywords/concepts that may help:
I2P/Peer-to-peer/Friend-to-friend/
Onion routing
Garlic routing
Digital fingerprinting
https://en.wikipedia.org/wiki/Mix_network
https://en.wikipedia.org/wiki/Crowds_(anonymity_network)
https://en.wikipedia.org/wiki/ZeroNet
https://en.wikipedia.org/wiki/Anonymous_P2P
Tails/Whonix/QubeOS for system protection.
I'm not saying that this happened only that if you think that there is a global adversary that can break the Tor anonymity a VPN won't protect you.
[0] https://www.ohmygodel.com/publications/usersrouted-ccs13.pdf
On the other hand, if you normally do this but forget to one time, it doesn't mean you're automatically exposed. It simply means that if anyone is currently attempting to find you and have an exploit that will actually work on you, then they will be getting you directly instead of your VPN. However, even if you had a VPN, if it's a government agency then generally speaking they will be able to find you anyways. A VPN doesn't "hide" you. It's not meant to.
If you want to stay anonymous, there are several methods that can be utilized. The most obvious one is not connecting to the internet from your own home. Use the Starbucks WiFi. A more clever method would be buying slave bots and using poorly secured wifi netowrks around them to hop over one. Assume VPN connections are from companies based in countries not on friendly terms with yours. Like China/U.S.
User -> RandomWifi -> VPN/SSH -> Slave -> SecondSlave/WifiHop -> VPN/SSH 2.0 -> Tor -> Market
This is a very basic set up. I would personally add more to it with other stuff, but it all depends on your threat model.Small note. This assumes you're actually setting up your VPNs, not buying some "VPN service." I saw you wrote about being careful with VPNs and how "trustworthy" they are. I'm not sure why you would ever use a VPN service.
Geolocking. That seems to be the only 'accepted' technical answer.
One thing I would add to the RandomWifi at starbucks is to make sure not to bring your phone as they could detect you went there if they get to find your RandomWifi starbucks location. Also make sure to change starbucks/RandomWifi location every time and for extra-paranoid reasons, maybe wear some toupee and fake moustache in case they try to get camera recording from the starbucks. I would also do most of the work from home, just run all the db/code updates from home and then sync/push the update at RandomWifi so you just need to stay there a few seconds. You don't even need to get in, just stay outside walking and click the push button from your laptop quickly. Never do it on the same hours either.
It kinda seems like fees and taxes, but instead of paying them on every transaction the users gamble on whether they'll be the one stuck with the bill.
I'm also interested in the particular opsec failure for this iteration, I just think don't think it's the only factor.
The person running this site did not have anything near the technical skills required to operate a darknet market.
Instead of developing his own, he used a very clunky public script for his market https://github.com/5auth/eckmar-source
All of the early posts by /u/darkmarket on Dread were in /d/darknetmarketsAU. Very early on other users figured out his previous handle he used as a drug vendor.
DarkMarket was plagued by repeated IP leaks of its servers, and had its servers seized in the 2019 Cyberbunker raid.
https://twitter.com/SttyK/status/1349034993893265408
Dream market remained online for 7 years and shut down gracefully after the administrator got tired of dealing with DDoS attacks, odds are the site earned closer to $100M even if you ignore bitcoin appreciation.
>and he will be given long enough time and high enough incentives
You only have to last a couple of years to make tens of millions, Empire Market exited the business with over $30 million after two years.
If you were worried, you could evade capture forever by just moving around with a bunch of prepaid SIM cards and a 4G modem that lets you change your IMEI. Even if the police could somehow track down your Tor connections, they'd never be able to find you in a big city.
The risk of getting caught can be eliminated almost entirely without taking any unrealistic steps, an actual security pro would be able to get away with this with ease. Perhaps this is why we haven't seen any infosec people go to jail for operating darknet markets?
There's an opportunity. Marketplaces that will exist for X days only.