   Indeed. There's a great quote from Eliot Spitzer, who used to be a 
prosecutor working on mafia cases in New York.  He said, "Never talk 
when you can nod.  And never nod when you can wink.  And never write an 
email because it's death.  You're giving prosecutors all the evidence we 

   Much of crime relies on face-to-face trust networks to plan and 
execute their projects (for lack of a better word).  This reduces the 
chance that there will be lasting evidence that investigators can use.  
Tor doesn't log connections, but that doesn't mean that a criminal 
wouldn't reveal themselves in other ways.  This is why I always tell 
activists and journalists that Tor can only be one part of their 
security plan.

   With online crime, botnets are de rigueur, since you can rent them or 
easily create them (or pay another criminal to create them).  Criminals 
use them as proxies to cast suspicion 1) away from themselves and 2) 
onto someone who is completely innocent.  Depending on how sophisticated 
a criminal is, they can connect to compromised machines in sequence, 
making their own pseudo-onion-routing-network.  They can also remove 
logs and most common botnet software can be configured to remove itself 
(!) after a certain amount of time or if it can't connect to the command 
& control platform.  Botnet-based crimes are the ultimate 
multi-jurisdictional problem, since known victims can be in dozens of 
countries, with dozens of investigations ongoing and many many victims 
trying to prove their innocence at once.

   But yeah, there's a lot going on in the world of crime, but the vast 
majority of it is offline.


