'Silk Road Reloaded' Launches On a Network More Secret Than Tor
rossgneumann writes A new anonymous online drug market has emerged, but instead of using the now infamous Tor network, it uses the lesser known "I2P" alternative. "Silk Road Reloaded" launched yesterday, and is only accessible by downloading the special I2P software, or by configuring your computer in a certain way to connect to I2P web pages, called 'eepsites', and which end in the suffix .i2p. The I2P project site is informative, as is the Wikipedia entry.
Honeypot???
have you seen my sig? there are many others like it but none that are the same
One crappy drug site and the whole Tor network is now infamous.
You know, tweaking would explain a lot ...
Lost at C:>. Found at C.
It's the idiot paying for the servers processing the drug transactions in the backend with credit cards in his own name.
Two people can keep a secret, but only if one of them is dead
But then, from the I2P page
I2P is beta software since 2003. Developers emphasize that there are likely to be bugs in the software and that there has been insufficient peer review to date. However, they believe the code is now reasonably stable and well-developed, and more exposure can help development of I2P.
So while "More secret than TOR", may be true, actually being secret is unknown by the users. But I bet the TLA LEAs will be keeping an eye on it and directing resources to test I2P limits (if they already haven't - they kinda don't like communications they can't tap)
I am Slashdot. Are you Slashdot as well?
'Silk Road Reloaded' Launches On a Network More Secret Than Tor
*sigh* Sure was a nice secret network we had going up until five minutes ago. Thanks a bunch, timothy!
TL;DR - shut uuuuuuup!
systemd is Roko's Basilisk.
So, does this provide any actual additional security, or is is just security by obscurity because nobody is using it?
If it's just security by obscurity ... well, good luck with that.
Lost at C:>. Found at C.
I2P has been the successor to Tor for more than a decade, but people continue using Tor thanks to a successful campaign by media/state to maintain the protocols use in an effort to continue exploiting it and avoid having to deal with more secure alternatives. Check out fdroid.org for open source apps that enable i2p on android as well, and expect a wholesale ban on i2p traffic in the near future.
Good people go to bed earlier.
Can't you just cop dope on the street corner in the hood like the rest of us joes? I suppose thats harder if you live in a really rural area though...
Is it really needed to make it sound as if something magical needs to be done?
I am sure that some technical information about what this "certain way" is would be understood by the readers of /.
(perhaps not the moderators, but that is something else altogether.)
And in what way is it more secure then Tor? It uses something lesser known? That is security through obscurity.
Using something less known by configuring my PC in a certain way does convince me this will be more secure. I can buy most drugs legally if I want to, so I am interested in the technical aspect. This sounds as if was written by somebody at the FBI to use entrapment to get their quota in arrests.
Don't fight for your country, if your country does not fight for you.
"You want to go to Silk Road 2.0? You're either nuts or on drugs."
"Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
I have tried I2P several times for torrent and iMule to avoid university anti piracy regulations and it was ridiculously slow, download times were about 10KB/sec and that is not good for movies. EEpsites are also quite slow first time they are loaded. Most nodes were in Russia, some were also in Romania and similar east european countries, also some in India and Brazilia. If it is a honeypot, it is most probably Russian honeypot as there are many Russian IPs. Not good for political activism, good enough for Silk Road I suppose...
Given that size is a fairly useful attribute for an 'anonymous' network(if the system is so small that a little traffic analysis can identify the 10 cypherpunks and couple of dozen kiddie porn enthusiasts that actually use it, it isn't too useful no matter how elegant the design), what does i2P fix about TOR to be worth the greater obscurity?
People have been designing virtual networks for decades. I2P is well advertised on Freenet, itself a well-known secure network.
Nothing new here. The security and reliability of none of this software is proven, it may not even be provable due to the distributed nature. That reduces the problem to one of how many people you're ok with knowing what you're doing.
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
I mean, advertising an illegal drug market in a public place makes so much sense, right?
Let's just re-use this one...
If we are discussing it on Slashdot, it's not secret.
I2P's real technical advantage over Tor is : I2P supports UDP. I'm unsure if that's relevant to a market site.
I'm doubtful about I2P claims that they're better designed for hidden services, since the Tor folks are redesigning their hidden services now.
If you made a P2P market application that used small XML UDP packets as opposed to huge ass webpages, then you'd maybe benefit from using I2P over Tor. In practice, you'd still benefit more from the sheer size of the Tor network.
I have been mildly curious about i2p for quite some time, but never found anything that really describes how it works, how people have tried to attack it, and how it has resisted attack better than Tor. And since I'm only "mildly curious," I never dived into the code to study it (and honestly, I'm hardly the most qualified to analyze its strength, anyway). Maybe having some famous/infamous parties involved, will get it some more exposure and analysis.
I downloaded it from www.fbi.gov/downloads/i2p.exe and it looks okay. Why do you think it is a honeypot?
You should download the source code and compile it yourself. Be sure to use the compiler that is supplied as part of the package.
www.fbi.gov/downloads/i2p/sources/WindowsFullPackage.zip .
Did you really just creepily read through all of OPs comments?
Calm down, it's an internet comment board.
I heard apk likes to suck his daddy's dick.
APK, thank you for your interest in joining the Gay Wigger Association of DICE* (GayWAD)! GayWADs worldwide are happy that you'd like to become part of our
constantly enlarging member ship (come sail away 8====D~)
Unlike other geek fraternities that you might have heard about, GayWAD accepts members of all races, creeds, and colors. We don't even have a technical inclination requirement. As our founders stated in the Annals of GayWAD, Chapter 1: "You don't have to be a geek, as long as you like it Greek." They were, of course, referring to the penis in anus style of sexual relations. Don't despair, as attaining full fabulous lifetime status in GayWAD is easy. The only prerequisites for membership in Gay Wigger Association of DICE* are that you meet all of the following conditions:
To submit your Gay Wigger Association of DICE* Membership Application, simply do nothing. Congratulations, you're now a GayWAD!
If you require a specific membership number for purposes such as framing, docking, or prestigious inclusion upon your business cards and resume, please take down this number: 69.
Optionally, you may complete the following survey by replying to this post, indicating affirmative responses with an X in each appropriate box:
GayWAD Membership Survey (OPTIONAL)
[ ] I am gay
[ ] I am a wigger
[ ] I have used SLASHDOT BETA to find a sex partner
After completion of this optional survey, your Slashdot post ID shall serve as your unique Gay Wigger Association of DICE* membership ID.
Your GayWAD membership kit** is on its way.
* GayWAD is neither affiliated with nor endorsed by DICE.
** GayWAD membership kit no longer includes HIV self-test catheter.
Let BarbaraHudson speak vs. this http://slashdot.org/comments.p... or are you BarbaraHudson stalking apk by ac posts as she said she does http://slashdot.org/comments.p... ? Most likely based on BarbaraHudson's own words quoted there.
In the past, some Slashdot users have responded to a request for clarification or citation by trying to shift the burden of proof: "This isn't Wikipedia; if you want a citation, do your own search. It's not my job to teach you how to choose and use a search engine."
BarbaraHudson stalked me by ac posts & that's quoted in her words (due to posts like the one you've replied to that I confronted him/her with) - result?
Her "points" (in a 'journal' - not publicly since she KNOWS they're bullshit) were as follows:
"We don't need to use a hosts file to block ads (adblock does it better)" - by BarbaraHudson (3785311) on Sunday September 21, 2014 @02:09PM
FROM-> http://slashdot.org/comments.p...
To THAT b.s., I merely point out how NOT BETTER it is, tearing up 4++gb of RAM & flooring CPU too -> https://blog.mozilla.org/nneth...)
AND?
By default (since advertisers KNOW most folks using "Almost ALL Ads Blocked" won't change that either) adblock's PAID OFF NOT TO DO ITS JOB FULLY -> http://techcrunch.com/2013/07/...
ClarityRay is also DESTROYING AdBlock but it's NOT ABLE TO DO THAT to custom hosts files...
BarbaraHudson's *trying* to tell us that Adblock's vastly inferior in abilities + chews up resources LIKE MAD is "superior" to hosts that do all of what adblock does, and FAR more - with less? Please... lol!
You decide on that note - me? I am simply confronting the dolt BarbaraHudson directly (despite her constant trollings of myself, that I do *NOT* start 1st, until she pulls her crap on me like usual... that's all!) for closure of this, publicly so she can "eat her words" in front of you all!
APK
P.S.=> Facts vs. BarbaraHudson's fictions & the FACT BarbaraHudson CANNOT DISPROVE that hosts do more with LESS, & far, Far, FAR MORE for added speed, security, reliability, + even anonymity (to an extent) than adblock AND that hosts fix DNS security issues like DNS amplification attacks, DNS being downed, DNS being redirect poisoned etc. - et al as well: NO SINGLE SOLUTION can do more & with less, period/fact, for all those points of mine here she downmodded & RAN from -> http://slashdot.org/comments.p... like the troll & multiple account using sockpuppeteer she is... apk
Twerking? Please no.
I tried I2P once but I couldn't connect to any eepsites. My I2P connection was fine but the sites were down.
Not trying to launch a debate here. I do like Java for a LOT of things. But a software router needs to be lightweight so it can run in very low-overhead environments. Tor runs nicely on settop boxes and many SOC hardware opportunities like RaspberryPI or low-end VPSs.
The memory footprint of a JVM is going to keep a java-based software router like i2p off those devices.
$5 / month hosted VPS on linux = awesome!
why would you feel the need to roll your R's?
The main weakness is the floodfills, which are a DHT storing all the information about how to contact each destination (like tor's directory authorities). They're self-selected from around 1000 of the fastest routers, but their DHT key changes daily in a predictable way. If someone can control enough fast i2p routers, the other floodfills will churn and de-floodfill themselves, resulting in 100% of leaseset lookups going to the attacker.
In terms of tunnels, that's well researched, they work similar to tor. There are a much greater number of routers to build tunnels through though, tens of thousands, most with only a couple of tunnels but many with thousands at any one time.
It's been growing slowly for years, without to much pushing at attempting to grow it, in case a sudden influx of users causes instability. That was decided almost 10 years ago now though, but it still seems to be semi-official 'policy', despite its probable irrelevance
what was that supposed to mean?
"I tore apart your stupid hosts file crapola." - by BarbaraHudson (3785311) on Tuesday August 19, 2014 @10:46AM (#47703255)
Where? You RAN from trying recently -> http://slashdot.org/comments.p... & you're FAIRLY given the opportunity to make good on those words of yours - you downmodded (via your many sockpuppets) & ran, lol, after your wise-ass comment on hosts here JUST before that challenge -> http://tech.slashdot.org/comme... quoted next below:
---
"scans multiple forums repeatedly to troll his crappy HOSTS file " - by BarbaraHudson (3785311) on Sunday January 04, 2015 @11:58AM (#48730581) from http://tech.slashdot.org/comme...
I only post on them where they apply (or confronting naysayers like you). Prove otherwise!
(Oh, that's right - you're NOT BIG ON PROOF, are you? See below next...)
---
"His only "legend in his own mind" was that he claimed that "his" hosts file could completely secure a windows computer. " - by tomhudson (43916) on Saturday February 12, @11:19AM (#35186644)
Where did I even *once* claim hosts completely secure a computer?
Putting words in my mouth I never stated != truth, or a good argument on YOUR part. You RAN from that too!
---
"Who has independently vetted it?" - by BarbaraHudson (3785311) on Tuesday August 19, 2014 @10:46AM (#47703255)
You tried to say it's malware/spyware too - guess what:
Answer = The BEST in the security antimalware & antispyware business currently, http://www.av-test.org/en/news... per that VERY recent test's results, who also host & RECOMMEND my program for hosts, is who -> http://hosts-file.net/?s=Downl... (Malwarebytes' hpHosts)
* You've done better? No... lol!
APK
P.S.=> You fail: "Eat your words, Forrest" & you told others to stalk/harass me by ac posts as YOU YOURSELF do, unceasingly, for years http://slashdot.org/comments.p...
... apk
BarbaraHudson stalks me by ac posts & that's quoted in her words http://slashdot.org/comments.p... & her "points" vs. hosts = b.s. (in a 'journal' - not publicly since she KNOWS they're bullshit):
"We don't need to use a hosts file to block ads (adblock does it better)" - by BarbaraHudson (3785311) on Sunday September 21, 2014 @02:09PM
FROM-> http://slashdot.org/comments.p...
To THAT b.s. I point out how NOT BETTER it is, tearing up 4++gb of RAM & flooring CPU too -> https://blog.mozilla.org/nneth...
+
By default (since advertisers KNOW most folks using "Almost ALL Ads Blocked" won't change that) adblock's PAID OFF NOT TO DO ITS JOB FULLY -> http://techcrunch.com/2013/07/...
ClarityRay's also DESTROYING AdBlock but it's NOT ABLE TO DO THAT to custom hosts files.
Barb's *trying* to tell us that Adblock's vastly inferior in abilities + chews up resources LIKE MAD is "superior" to hosts that do all of what adblock does, and FAR more - with less? Please... lol!
* I'm confronting BarbaraHudson directly (despite her constant trollings of myself often behind my back that I do *NOT* start 1st, until she pulls her crap on me like usual: That's all!) for closure of this publicly so BarbaraHudson can "eat her words" in front of us all!
APK
P.S.=> Facts above vs. BarbaraHudson's fictions & the FACT BarbaraHudson CANNOT DISPROVE that hosts do more w/ LESS, & far, Far, FAR MORE for added speed, security, reliability, + even anonymity (to an extent) vs. adblock & that hosts fix DNS security issues in DNS amplification attacks, DNS being downed, DNS being redirect poisoned etc. - et al as well: NO SINGLE SOLUTION does more & w/ less, period/fact, for all those points of mine here Barb sockpuppet downmodded & RAN from -> http://slashdot.org/comments.p... like the troll & multiple account using sockpuppeteer she is... apkcid=47960059
To THAT b.s.