Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - astor

Pages: 1 ... 45 46 [47] 48 49 ... 208
691
Off topic / Re: Hey, come chat with us!
« on: July 14, 2013, 01:15 pm »
donatto,

In Pidgin, open Help -> Debug Window. When I connect to the silcroad server, I see these lines (with some omitted):

account: Connecting to account astor@silcroadg3c3mtu6.onion.

dnsquery: Performing DNS lookup for 127.0.0.1
dnsquery: IP resolved for 127.0.0.1

proxy: Attempting connection to 127.0.0.1
proxy: Connecting to silcroadg3c3mtu6.onion:6667 via 127.0.0.1:9150 using SOCKS5

socks5 proxy: Connection in progress
socks5 proxy: Connected.
socks5 proxy: Able to read.

proxy: Connected to silcroadg3c3mtu6.onion:6667


You should see a similar sequence of events. At which step does it fail?

692
Security / Re: DBAN laptop HDD Questions
« on: July 14, 2013, 12:43 pm »
Will DBAN completely wipe the HDD including the BIOS? If so, will I need a secondary computer to re-install BIOS/drivers etc?

The BIOS isn't part of the hard drive. No, it won't wipe the BIOS, but it will wipe the entire hard drive.

Quote
Also, will running DBAN need to be done from a secondary computer? Some help or a link to a guide would be appreciated.

No, you burn it to a CD and boot it. That's why it's called Darik's Boot and Nuke. :)

693
Off topic / Re: Atlantis is shady as hell
« on: July 14, 2013, 11:31 am »
A lot of FUD in here. :P

Differentiating a proxy from the real site is difficult. The real site and the phishing site have the same time stamp, exactly 12 seconds ahead of real time, but a good proxy simply forwards the main site and MITMs the connection. Access times to hidden services can be variable, but taking averages over many access attempts might yield some fruitful results. I've discovered that TTLs are useless. They are reset along the circuit, so you always get 64.

This is of course great for plausible deniability, if they are behind it.

The thing is, Jack, it's not a single data point, but the aggregate of facts. Atlantis has been on an aggressive marketing campaign for some time now, and it's clear they want to steal SR users. They tried creating forum accounts and advertising here, but those accounts and posts were deleted. They tried drawing vendors to their market by waiving the vendor fee and 3 months of commission. They tried luring more vendors with these "buyer" shills with gift codes. They created an AMA on on the Silk Road subreddit, for Christ's sake. Is it really hard to believe they would engage in underhanded tactics to steal SR users?

Do you believe those were real buyers with gift codes? I can't prove they weren't, but the aggregate of facts convinces me they were Atlantis shills.

694
Off topic / Re: Atlantis is shady as hell
« on: July 14, 2013, 11:16 am »
I actually think that someone in Atlantis (maybe the admins themselves, but I have no proof of this) create accounts with well known user names here is SR.

Well, SR vendors have been PMed by "buyers" with Atlantis gift codes, asking them to create an account on Atlantis and sell to them there. Certainly their shadiness extends far beyond this issue here.

695
Security / Re: What email website to use?
« on: July 14, 2013, 05:19 am »
If you MUST use a service like Safe-Mail, then you must ensure to use Tor to keep them from harvesting your IP addresses, and you also must ensure that all your email is PGP-encrypted BEFORE it ever hits the Safe-Mail servers.

That's a given for any clearnet email provider. You'd be an idiot to do anything criminal with a clearnet email account and not use Tor + PGP.

They can still get metadata, like the email addresses you were communicating with and the dates / times of the emails, but the NSA probably already has that data.

The issue is, some services won't communicate with you when you have a Tormail address, or it might look suspicious if they know what it is. There are use cases for clearnet email providers, and Safe Mail is one of the few that allows you to register over Tor.

696
Off topic / Re: Atlantis is shady as hell
« on: July 14, 2013, 04:34 am »
Uh huh. Because I have never seen a onion.to link to SR... wait, hold on a minute...

I remain unconvinced. I don't see how I am at risk. I don't see how vendors are at risk. It seems like a bunch of hyperbole.

You must be extremely dense if you don't understand the difference between users posting onion.to links and the admins posting onion.to links. They can't account for what 77,000 people do, but they've never posted links through third party proxies themselves.

The fact that the Atlantis admins have repeatedly done that is one way they have shown a flagrant disregard for their users' security.

697
Silk Road discussion / Re: Never mind.
« on: July 14, 2013, 02:44 am »
Thanks DPR for clarifying things.

698
Silk Road discussion / Re: Never mind.
« on: July 14, 2013, 01:40 am »
If you are worried about your old info being saved, I strongly suggest you create a new account every once in a while. It's the only way to be sure.

Yeah, it sucks having to start over with fewer than 10 purchases and many vendors requiring FE, but if you have purchased multiple times from some trusted vendors, you can send them an encrypted messaging, telling them you are going to start buying from a new account, and let them know which one. If they're cool, they will waive the FE requirement.

699
Silk Road discussion / Re: Never mind.
« on: July 14, 2013, 12:42 am »
The All Time column is gone now, when did you last see it, SS?

700
Off topic / Re: Atlantis is shady as hell
« on: July 14, 2013, 12:29 am »
Nice way to limit the response. This isn't just about you.

As I wrote before, the admins have posted onion.to links to their site on clearnet.

If the phishing site is a proxy that MITMs connections to steal account credentials, then an *official* approved method of accessing the site, promoted by the admins themselves, opens their users to the exact same threat. You never know when onion.to or onion.sh might start doing that.

That is a flagrant disregard for their users' security. That combined with the in-browser PGP feature breeds laziness and insecurity among their users.

701
Off topic / Re: Atlantis is shady as hell
« on: July 14, 2013, 12:04 am »
I still wouldn't buy anything on Atlantis, given their blatant disregard for their users' security.

702
Off topic / Re: Atlantis is shady as hell
« on: July 14, 2013, 12:03 am »
Quote
That is one huge non sequitur. A phishing site is capable of doing that. It is a relatively unsophisticated MitM strategy exploiting the ignorant. Where you go off the rails and into tin-foil hat territory is when you say that you are 95% sure that it is Atlantis admins doing it, and giving only 5% chance to conceding that it is what it is - a phishing site.

Yeah, the theory is that they are phishing for people who use the same info on SR to create accounts on Atlantis, then they clean out the SR accounts. Some people on the forum have claimed this happened to them.

I'm testing that theory now, and I'm willing to accept it if it turns out to be true.


703
Silk Road discussion / Re: Never mind.
« on: July 13, 2013, 10:19 pm »
Interesting Frank. Thanks for the info. Maybe they have been keeping monthly totals all along.

704
Silk Road discussion / Re: Never mind.
« on: July 13, 2013, 10:10 pm »
Actually, they didn't subtract the 3 month stats, they just used the old total purchasing stats as the 1 year stats, derp.

705
Silk Road discussion / Re: Never mind.
« on: July 13, 2013, 10:07 pm »
Although, in order to calculate the 1 year stats, they will have to keep records of number of purchases, amount spent, auto-finalize rate, and refund rate on a monthly basis, which is presumably more info than they kept before.

Pages: 1 ... 45 46 [47] 48 49 ... 208