Reading the Silk Road configuration
blog.erratasec.com
blog.erratasec.com
As for the backend servers - if all machines are connected through OpenVPN with TLS-Auth they can use private IP space and are not accessible from outside. The OpenVPN tunnels are configured outside of the onion VM and Tor VM and the backend machines are also in a VM that pipes all outgoing traffic (except OpenVPN traffic) to the internet through Tor.
This setup should at least omit the problem of leaking public IP addresses on compromise or did I overlook something? Let's ignore VM outbreak exploits (ksplice/unattenend-upgrades should help here if it's not the NSA).
With TLS-Auth and a default DROP firewall rule all machines should not even appear in scans on the internet. So any outside contact to any machines is only possible if you know the OpenVPN TLS-Key + Certificates. An intruder would only see local IP addresses even if he manages to compromise a backend server. All created outgoing traffic to find the machines would be routed through Tor.
As the Tor onion VM is separate from the webserver only a Tor remote exploit or a VM outbreak exploit would be critical. Maybe encryption can help here.
Another point is using dedicated hardware with Full Disk Encryption and just enter the passphrase via the provider console. There are cold boot attacks but VPS servers allow to dump a memory image while running - that's not so easy with dedicated hardware.
1) Full Disk Encryption
2) Two physical machines owned by you, perhaps stored in some basement
3) Be able to boot them back on without physical access (perhaps this is simply a Bad Idea?)
4) One machine with two NICs running Tor, exposing only Tor to one of the NICs
5) The other machine running a VM host with 1 VM for each of your services. The host is connected to the NIC of the first machine, thus only has access to the internet through Tor
[…]
> Be able to boot them back on without physical access (perhaps this is simply a Bad Idea?)
This is exactly the problem which our project solves:
http://www.recompile.se/mandos
Introduction:
http://www.recompile.se/mandos/man/intro.8mandos
Summary:
The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key; each client has one unique to it. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system, whereupon the computers can continue booting normally.
You also need to adjust the “approval_delay” setting.
https://en.wikipedia.org/wiki/KVM_switch#KVM_over_IP_.28IPKV...
I may be overly pedantic here but it should be "public IP address" as there is no TCP/IP without an IP address. The address may be in the private ranges, though.
There are always going to be bugs, but this would very strongly isolate each of the risky components. Feeling even more paranoid? Put a strong network filter in place between each of the components to make sure that only the specific subset of TCP that's actually in use makes it through; that'll prevent network stack-level issues.
If the nginx configuration for port 443 did indeed not restrict access to [star].php, then that means that index.php would have been accessible to the Internet at large (although HTML elements with other suffixes - e.g. .jpg, .css, .js - would not have been served).
If the CAPTCHA element's URL also ended in .php, then it's not beyond the realms of possibility that Tarbell could type the IP address, followed by /index.php and end up seeing a screwed-up version of the SR home page, with the CAPTCHA as he describes in his testimony.
The log file entries cited are for port 80, whereas the SR webserver ran on port 443.
If the defence already have all the log files, they should grep for 199.170.71.133 in the 443 logs and/or search for a group of log file entries with simultaneous successful serves of anything ending in .php, with "permission denied" failures for things not ending in .php
Incidentally, the May 3, 2013 webserver IP leak referred to in footnote 5 to Tarbell's testimony syncs up nicely with the date of this thread on Reddit: https://www.reddit.com/r/SilkRoad/comments/1dmznd/should_we_...
Credit to Michael Koziarski for the Reddit link: http://krebsonsecurity.com/2014/10/silk-road-lawyers-poke-ho...
The evidence submitted by the FBI [1] shows the phpmyadmin page running on address 192.168.1.24. Are they claiming to have connected over the internet to a public facing RFC1918 address and it was routable?
(Saying that, I'm now realising that I could knock up a similar screenshot showing me connecting to any "real-world" IP address anyway; it seems to prove nothing.
[1] http://krebsonsecurity.com/wp-content/uploads/2014/10/70-8.p...
If he's right that the quoted configuration file doesn't do what the defense said it did as part of their accusations of lying, they've seriously messed up, no matter what the truth is.
If the frontend server in Germany is reverse proxying through to the backend server in Iceland, then sure, a user is not going to see the Icelandic server's IP in the source IP field of the packets. But I don't see this as definitive proof of the FBI's assertion being a flat out lie. The IP could easily have been exposed in the packet body.
What happens if you visited the captcha URL with a HTTP/1.0 request without Host header? If the resulting URL generated any self-referential links, what did they use as the hostname? If the Host header is available the norm is to use this, but if not then the script may use the server's FQDN or IP address. If it sent a 301/302 redirect in the HTTP response headers, then that _must_ contain a hostname according to the RFC (it shouldn't be relative), so what was used there? There's nothing in the nginx config that rewrote such response headers.
What happens if you make malformed requests to the captcha URL? Do you get an error page with the IP address embedded, or something that references an object hosted on the IP?
These are just two possibilities, and yes, neither would lead to the IP being exposed in the 'packet headers'. But it's very feasible for it to be exposed in the packet body, so it seems silly to hang the entire argument on the basis that one word is correct, without considering the alternatives.
But you're right, I'd expect that whatever tactic they used, the prosecution should be able to demonstrate in far more depth how the IP leaked.
Which would make the FBI's assertion that they found the IP address in the packet headers a flat out lie...
There was also other MySQL Injection bugs. You could even look through the SR forum archive and find people talking about how the search field at one point was exploitable by the standard "' or 'a'='a" and was disclosing customer's names and addresses.
Given this, the odds of DPR ever seeing the light of day, even if they win this suppression motion, are quite small. He is looking at multiple life sentences even without Silk Road specific charges. But his lawyers are going through piece by piece, hoping to convince prosecutors that it will be difficult enough to get convictions that they offer him a substantial, but less than life, prison sentence in exchange for a plea. Even then we're talking about decades in prison.
Nope, most were dropped before the indictment. Only one (in Maryland) remains: http://freeross.org/correction-of-our-report-on-the-indictme...
lololol. They'll just smooth the practice over with some new laws which, like every other blatantly unconstitutional law currently in effect, won't be overturned by the courts because doing so would upset the status quo.
The only way it'll ever stop is when the fuckers are finally bankrupt, both economically and socially.
http://msansnom.tumblr.com/post/63069733245/fruit-of-the-poi...
What we're seeing here is called "parallel construction". The FBI was given this illegally obtained surveillance data, made the arrest, and then needed to make up a lie as to how they really found him.
[0] http://computersweden.idg.se/polopoly_fs/1.526338.1380735946...
¹) Not an exact quote, I know, I glued two sentences together and cut some parts.
I wonder if they just said here you go? It sure seems like it.
[1] http://krebsonsecurity.com/wp-content/uploads/2014/10/70-4.p...
To date, engineers have not been given similar consideration, probably because they're not independent and their employers would force them to abuse the privilege. E.g. automotive engineers would say "oh, it's totally acceptable to have that exploding gas tank" and software engineers would say "oh, it's totally okay for that to lose all your data."
Barring special consideration like that, it comes down to the expert witnesses. The jury will decide based on which expert they find more credible / whose lawyers do the best job of presenting their expert.
> BTW: one plausible way of having discovered the server is to scan the entire Internet for SSL certificates, then correlate information in those certificates with the information found going across the Tor onion connection.
Would this be considered parallel construction, or would this be a legitimate way to attempt to figure out who was involved in the Silk Road, and is it plausibly the way the FBI might have zeroed in on the server?
You don't have to be the NSA to make a database like that, but it helps. I could build a database broadly like that for certificates/ciphersuites/other metadata myself with active scanning and zmap (and it might make a good weekend project, to examine and contrast RC4 proliferation amongst TLS-encrypted web and mail servers) - but they have a near-realtime-updating passively-constructed one. If the FBI asked them for help, they'd definitely use that.
https://www.reddit.com/r/SilkRoad/comments/1dmznd/should_we_...
But he managed to map a lot of secret Trojan servers used by govs.
(Would be nice if there was a gallery, as infinite scrolling uses a ton of browser memory, but I'm not aware of one...)
before the mods changed the link. Here's a vote for changing the HN code so it says "link changed from $X to $Y" at the top of the page when they do that.
We found them by simple looking at the IP that the packets of the captcha were served from. The captcha was served over tor, based on the evidence that's impossible. Either you lied or you need to add further evidence. If you can't/won't add further evidence then as the court sees it you lied and are in contempt and will be punished in line with minimum sentencing??
This is of the order of a "he robbed me at home at exactly 2pm", "your submitted cell-phone evidence says you were at work from 1pm until 4pm".
If the defendant is convicted on some other counts can they, or anyone else, do anything or is the allowance of officers of the FBI to lie in open court somehow embedded in the USA constitution.
As a foreigner to the USA this sort of thing just undermines the entire foreign policy rhetoric of bringing democracy to the world. Bring some damned democracy to the USA first: government by the people for the people, my arse.
Most voters don't have information about such incidents or enough time to crawl through court records looking for that information. Actually, in judicial elections, most voters don't even have anyone else to vote for.
If you can't tell the truth in court then keep your mouth shut or you'll be punished accordingly seems like the exact message a country intending to operate under the rule-of-law should be promoting.
This case is being heard by a federal court, the United States District Court for the Southern District of New York. Federal judges are appointed by the president with the consent of the Senate.
IMO electing judges and sheriffs makes negative sense, but that's what we have going on here.
I don't do forensics. But I am a reverse-engineer and I am familiar with the techniques: more familiar than Tarbell, it seems. (That's really his name? Tarballs from Tarbell? My goodness.) Tarbell's declaration reads to me more like a textbook demonstration of (bad) parallel construction in action.
They could have done it legitimately, without compromising the server and potentially tainting the evidence any way they wanted: DPR indeed made a few rookie mistakes that would potentially provide for that. But the logs don't seem to actually have evidence supporting that, which is very unusual and at this time not explained? The declarations filed so far do not really seem to support that either, which is very odd and strongly suggests that we don't have the whole picture here: and we really should.
(Of course, we don't have the whole image, so we don't have the whole picture here. BTW: They used tar, not dd or ddfldd? Boo.)
http://www.collegehumor.com/video/6905757/the-worst-hacking-...
...I've got to be honest, a few of those are better than the FBI story!
HackerNews, you frustrate me.
HA!
Which has since been changed to http://krebsonsecurity.com/2014/10/silk-road-lawyers-poke-ho...
These are all questions of basic fact and they are all easily testable.
What do courts do when this situation comes up? Do they play warring experts, when (at least) one side definitely wants to perform a test, because they are confident that their interpretation is correct?
(ed: 'questions of basic fact' like, whether a server with this configuration is hittable from non-allowed IPs)