[tor-talk] Silk Road taken down by FBI

The Doctor drwho at virtadpt.net
Thu Oct 3 19:25:23 UTC 2013

Hash: SHA1

On 10/03/2013 01:49 PM, Ahmed Hassan wrote:
> One question is still remain unanswered. How did they locate
> Silkroad server before locating him? They had full image of the
> server before his arrest.

Not sure.  One hypothesis (and that's all it is - a hypothesis) is
this: The Silk Road may have been running on the same machine as a Tor
router and not a client.  Finding the set of all Tor routers is
trivial.  So, hammer on the hidden service while watching for
bandwidth utilization to go up on the Tor routers that you can surveil
to see which ones seem to respond appropriately.  Pick away the
rendezvous nodes because they don't originate tunnels (they're not
clients).  If the Tor router is running on a server or in a VM hosted
at a provider that could be subpoena'd or strongarmed, forensic images
of same could be acquired.

