Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To summarize your comment:

* attacks are hard to predict

* law enforcement is interested in attacking

* being hosted on a single server is just one way to make something attackable

* the proposal needs more work

* whether this actually works is an open question

* the real question is whether law enforcement will be able to attack

In a nutshell, this is circular logic that ends where it begins, and makes no journeys elsewhere. It makes no technical criticism of DarkMarket, references no historical or similar examples, and offers no extra information from other sources (such as the source code).

So, I down-voted, and wonder why all the up-votes.



I think the summary is: It's premature to call this 'a Silk Road the FBI Can Never Seize' until it has withstood a few years of determined attacks.

If you look at a lot of the best practices documentation for Tor it makes everything sound like a huge hassle [1] so I can believe making a system secure against the concerted efforts of law enforcement is complicated.

[1] http://lifehacker.com/how-can-i-stay-anonymous-with-tor-1498...


I don't think you are getting the point of the article or the comment above.

This is a p2p system meaning that by definition you cannot take the market down by arresting a single person. It doesn't say it is secure against everything. It just says that as long as the source code/binary is somehow available, it will not be possible to completely shutdown.

The beauty is security vulnerabilities come and go (as in gets patched) so those are not the main concerns here. Even if they decide to tap every communication to identify the transactions and manage to decrypt it, it is going to help for a single raid and then it will get patched.


Sure, maybe you can make entry nodes discoverable by users without them being discoverable by the feds. And maybe new users can get the software without going to a central location. And maybe you can distribute bug fixes securely without a central server, and without the people with the keys to sign the bug fixes getting compromised. And maybe you can deal with 90% of the peers being created and controlled by the feds. And maybe you're secure against any and all types of DOS. Maybe you're undetectable by deep packet inspection if every ISP was forced to perform it. And maybe there's no way to grief or spam the network into being useless. And maybe you can tolerate coordinated police operations, where a single bug in the software gets a hundred of your best sellers carted off to jail. And maybe the market will still be going strong after that's happened 5 or 6 times.

But I'm going to reserve judgement until I've seen it working.


The most effective attack is the easiest to predict.

It is human intelligence or infiltration by actors with a hidden loyalty. This has worked since the time immemorial for all sorts of security systems.

For FBI to bring it down they'll just need to repeat what they've done with Silk Road - pose as a straw buyers, get everyone they touch on record and use them to identify/arrest the users. Put out a request for a contract killing and arrest all responders. Bonus for putting a bounty on members turning in other members.

Even if this won't "shut down" the system itself, it would make it impossible to use safely.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: