Did Stack Exchange staff members assist in the apprehension of Ross Ulbricht?
meta.stackoverflow.com
meta.stackoverflow.com
I know the evidence has presented to make us think they found him via a series of mistakes, but the existence of parallel construction makes me question everything.
Why don't we deal with the widespread corruption and overreach of power on all levels, from blue-clad street thugs, through federal prosecutors who see nothing wrong with pre-trial asset forfeiture, all the way up to and including the military-surveillance complex?
Plan accordingly.
On the other hand, we have recently seen much greater evidence about the wholesale surveillance of society under secret law and apparently not accountable in any practical sense to oversight.
The first is normal and appropriate and well within the bounds of civil liberties guaranteed by Fourth Amendment. The second is highly problematic - but one doesn't necessarily lead to the other. Our civil liberties and civil rights have always been subject to appropriate exceptions. The problem is when those exceptions become so broad as to render the freedoms ineffective, not that they exist at all.
[1] Well, obviously one can disagree about the criminalisation of recreational drugs, but they are, so the cops are working within their brief.
Not all of us, gold/bitcoin stash or no, accept that police are a necessary part of society.
Given that one part of society (the state) has historically demonstrated that it will expand to fill any and all available opportunities to exert destructive power over others, it doesn't make much sense to grant them a monopoly on the opportunity to use violence to uphold the law.
Laws, we need. Cops, we don't. The NSA has nothing to do with it.
TL;DR: Fuck the police.
Anyone care to speculate how they found him?
Specifically to your question, I'd guess they run a large number of Tor exit nodes and from there it was fairly simple to see exactly who was doing what.
Also it's come out recently in the Guardian, the NSA can backdoor machines through special servers running man-in-the-middle attacks.
Basically, the Internet (and planet Earth too) is not secure, so trying to pull off a large-scale crime is kind of foolish.
Parallel construction doesn't actually imply that the NSA is omniscient and that the entire rest of the American justice system is a charade meant to mask its power from the muggles. The NSA doesn't know everything. They don't see everything. They don't whisper words of power into the ears of every prosecutor, and a dark man smoking a cigarette doesn't appear from out of the shadows with fabricated evidence for the Department of Justice and a dossier from ten minutes into the future every time a hacker opens their browser.
It gets mentioned every time a post comes up involving court case or arrest, and it's quite honestly as useless a form of speculation as suggesting divine intervention as a first cause in science. Assuming too much power on the part of the NSA (and by extension, that no other methods used by any other bureau or department are effective except as a smokescreen) is as dangerous as dismissing them entirely.
You have a good point though that maybe my comment is not constructive. I don't wish for this to become a cliche response on HN that it 'must have been the NSA' but we must acknowledge that they posses powers of surveillance the world has never before seen (except if you believe in God... however, we actually have architecture diagrams and proof of the NSA technology... not just 'The Book of Edward').
But yeah, it's dangerous to dismiss the NSA entirely and dangerous to make it a given they're more powerful than they are. However, given their secrecy, that's all a fairly expected situation for us.
Its awful to say, but do you think a murder in Detroit gets the same attention this guy or Snowden does/did?
They implied this was the first thing they did. The interception of the fake IDs may have occurred before or after he was already under heavy suspicion of being Dread Pirate Roberts. I also believe there was some discussion that the fake IDs might've actually sent by an undercover agent.
Either way, I think it's very likely that they already had the idea that Ross Ulbricht == DPR before finding his Stack Overflow post.
I thought this part was the dumbest aspect of the whole arrangement, but then I heard about posting on Stack Overflow to get your bugs fixed, and "contact me at rossulbricht@gmail.com kthxbye", and I begin to think that "criminal mastermind" is not exactly an apt description of this guy. I find it hard to contain my laughter at this.
I would have thought the server seizure demonstrated exactly why you would go to this bother: when you encrypt your address to the seller's public key, and send the encrypted address rather than the plaintext address, now all the FBI gets is an encrypted message they can't read. And the Tor connections means that they can't look up your IP in the logs, and so on and so forth.
And how can I trust that the seller isn't an FBI agent? Still seems kind of risky. Even if they aren't an FBI agent, they're going to decrypt the address, and who knows what they'll do with it in plaintext? For one, they will write it on an envelope, leaving open the potential for exactly what happened with the fake IDs.
If not these scenarios involving law enforcement, there's also the risk that the seller, who has my address, will extort me for cash or whatever.
Just as with buying drugs face to face you have to trust that the dealer is not malicious, is there a risk? definitely. But just as in the real world law enforcement have little interest in wasting their time on buyers.
It seems to me if you go out of your way to hide your identity you should, um, hide your identity. That would mean not trusting the post office just as you would not trust a sniffable network. Arrange a drop in a public place or some such. (Or do I see too many movies?)
And it may seem risky, but that doesn't matter: we have the numbers. We have the statistics. The FBI has kindly told us exact numbers based on the SR database they seized. You can calculate the risk pretty easily. Take the number of sellers and/or transactions, get an estimate of number of buyers busted (for example, count instances in http://www.gwern.net/Silk%20Road#safe ), divide. This is like worrying that flying on an airliner might be really risky since the plane could fall out of the sky or be hijacked - certainly, but the worry is wrong, and you can go to faa.gov and look up the exact numbers and see for yourself how risky flying on an airplane is.
And it seems that I am not the only one who sees something there, as according to media reports DPR himself was extorted over the question of revealing the street addresses of users.
You're probably right that the average Joe doesn't have to worry. But for specific individuals like DPR, they should know that being involved in facilitating a large number of illegal transactions, there is much more likelihood that they specifically will be targeted by law enforcement. I would expect then that they would do more to guard access to their address.
(Even if most people are OK, that doesn't mean it's not still a weakness. In the days before SSH became common, I used to log in over telnet all the time and never once to my knowledge got compromised. I suspect many had the same experience. Does that mean I was safe? Of course not.)
I agree, it does sound absurd. And yet...
> And it seems that I am not the only one who sees something there, as according to media reports DPR himself was extorted over the question of revealing the street addresses of users.
DPR was worried (assuming, as usual, that the indictments are reasonably accurate here and their lies, omissions, and insinuations affect only other things) about the reputation of SR as a whole: SR as a viable business was being held hostage. This is not something relevant to an individual buyer being blackmailed one on one, which was the scenario you were asking about.
> But for specific individuals like DPR, they should know that being involved in facilitating a large number of illegal transactions, there is much more likelihood that they specifically will be targeted by law enforcement. I would expect then that they would do more to guard access to their address.
Yep. The ID stuff was remarkably careless. We don't know that it was fatal - I personally suspect the Australia wire transfer may have revealed everything - but it obviously could have been.
Why did he even need the fake IDs? They claimed it was to rent servers, which makes zero sense I've never been asked for ID when renting dedicated servers they just ask for money. PRQ certainly doesn't ask for anything except email address and payment.
I guess he didn't read that story about the secret service running a sting operation for years posing as an ID vendor on fraud forums.
[1]: http://www1.icsi.berkeley.edu/~nweaver/UlbrichtCriminalCompl...
Freedom Hosting was likely a NSA op to get a hold of tormail.org messages and history because Snowden was either using it or emailing somebody using it. The FBI will use parallel construction to cover that one.
SR I suspect they simply watched him sitting at cafes and libraries and logging into his virtual cartel. There were also numerous people who had discovered leakage and were able to find the server many of whom ended up working for DPR. Either way it wasn't set up very well, who knows maybe the FBI uploads spyware.js as an image while posting a new order or broke through the php5-mysql plugin. I'm sure they will discover that half his inner circle of close associates were informants too maybe they leaked the address. Remember he once put out applications for database administrators you can guarantee dozens of agents signed up for the job.
I do not know why any judge would issue one of those searches + gag included orders based on a random code fragment, but then of course I know that judges just robosign these things from the FBI turned intelligence agency.
http://arstechnica.com/security/2013/10/silk-road-mastermind...
From that account, it looks like the key break was likely that the first alias to promote Silk Road (altoid) was at one later point also linked to a real-name gmail address (rossulbrecht@gmail).
Even if that association was brief, plenty of people (and even law enforcement researchers) are likely scraping/archiving or email-subscribed to the bitcoin forum where the association appeared. The same goes for 'tor' forums or tags elsewhere... so an actual law-enforcement approach to StackOverflow/Bitcointalk/Gmail/etc may not have even been necessary.
(OTOH, Bitcointalk.org is currently down after an attack that may have resulted in the leak of username/hashed-password/email records. User altoid's email address there could have been obtained by law enforcement, by subpoena or hack, and also pointed towards Ulbrecht.)
I don't know about you, but I'm pretty sure any half-decent cop would be using the logs of that conversation to convert that person into a witness.
I'm not sure that I would call multiple times a year "very, very rarely".
Every service loves to use their total number of members and say that requests are very rare--relative to their number of users.
But honestly not sure what they could have done, if FBI comes in with a legal request for a specific user's data, what are your options?
I'd agree that that's very, very rarely.
Why do sites like StackOverflow keep audit logs of your account information?
When I built a site that existed for a very long time, was very popular, and involved monetary transactions, I had to track nearly everything. IP addresses, address changes, email changes. Everything I could think of. This was then utilized when I suspected someone of fraudulent behavior. I could pull up an administrative screen that compared data in an archive copy (where I dumped the older information for just this purpose and to specifically keep it inaccessible to the outside world for user security purposes). With that, I could see whether several users were actually the SAME user. I even tracked things like user-agent string and detected screen resolution.
A lot of pieces of data can come together to provide more than circumstantial evidence that someone is shilling, trying to feedback-bomb another user, and so on. Enough correlated points of data can confirm suspicions like this. You'd be surprised how many people use an email address for one account, change that address, then create a second account with the email address they used to have on the first account and then use the second address to drive up the value of their stuff by shill-bidding against another user on their own item.
There are also errors on our end like account merge bugs, moderation mistakes, dropped/flagged/whatever recovery emails, and so on. Keeping additional historical data can help us recover in those cases.
If you're smart about what you track it's not that much data; we record most changes to user records into a history table (likewise, and for the same reasons on post records). Keeping traffic logs around and queryable forever would be really, really expensive though. We keep some around, but only really recent stuff is easy to query (about 2 days) since that tends to be what's needed when reproducing bugs. I don't even think we have all traffic history, and old stuff would require digging a tape out (if we even move those to tape like we do with DB backups, I honestly don't know; it's never come up).
Moderation is a good reason to keep lots of data around, you're right, but it's not the only one.
Disclaimer: Stack Exchange, Inc. employee.
Pfft, he's counting in ternary.
My guess is they've gotten one request from the NSA ('give us all your data for everyone... otherwise we will just tap into your fiber lines at ISPs') and one from the FBI ('we are doing some parallel re-construction and it says here we have a warrant for a user by the name of Frosty').
I'm just surprised an admin on the site didn't close the Q&A as non-constructive and speculative :)
The only question is whether they pay someone to do it manually or they paid someone like a SO user to automate it.
National security letters are only supposed to be used for national security, not random drug busts. If they used an NSL it was unlawful.
If this was just a sealed request it should be open now that the indictment has been handed down. If it was reasonable and lawful they should be asking for it to be unsealed and the request should be granted.