Silk Road forums

Discussion => Security => Topic started by: BlarghRawr on July 29, 2012, 08:17 am

Title: I just found Silk Road Forum Posts by searching google.
Post by: BlarghRawr on July 29, 2012, 08:17 am
I searched for kmfkewm(Because I think he's an idiotic motherfucker) and I got tor2web and onion.to results. Is this a good thing?
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: vlad1m1r on July 29, 2012, 08:23 am
I searched for kmfkewm(Because I think he's an idiotic motherfucker) and I got tor2web and onion.to results. Is this a good thing?

One of the many advantages of Tor hidden services is we're not indexed by search engines - I've never really seen the point of onion.to and tor2web as why not simply use the Tor browser? Perhaps they're trying to open up SR to the non IT literate masses? :-)

V.
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: BlarghRawr on July 29, 2012, 08:25 am
I searched for kmfkewm(Because I think he's an idiotic motherfucker) and I got tor2web and onion.to results. Is this a good thing?

One of the many advantages of Tor hidden services is we're not indexed by search engines - I've never really seen the point of onion.to and tor2web as why not simply use the Tor browser? Perhaps they're trying to open up SR to the non IT literate masses? :-)

V.
Seems like the reason for those services, yeah. But hey, now we ARE being indexed by google. Fuckin' imagine that, eh?
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: dzlrv on July 29, 2012, 11:52 am
What is disadvantages of that? It's just some kinda proxy-service making the forums more available, we're still just as safe and all?
If its unwanted Im sure they'll block it with a simple robots.txt file or something to deny Google/outside access.. 
maybe its a good thing, bringing more attention and eventually a bigger stronger userbase..=)?
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: Oompaloompa on July 29, 2012, 01:25 pm
I'm uneasy at the possibility of forum posts here coming up in a google search. Sounds like a massive attention getter - the wrong type of attention.
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: digitbh on July 29, 2012, 01:38 pm
I searched for kmfkewm(Because I think he's an idiotic motherfucker) and I got tor2web and onion.to results. Is this a good thing?

Why's he an idiot?
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: mybodymychoice on July 29, 2012, 03:42 pm
kmfkewm is not an idiot. he seems to be a very intelligent, security and IT minded individual. not going to judge you but if i had to pick you or him to help me it'd be him.
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: Looker on July 29, 2012, 04:42 pm
I won't claim kmfkewm is an idiot as I don't believe he is unintelligent. However his views related to security and IT are more academic than practical and why I disagree with many of his particular views.

Let me sum it up like this. There are many 'types' of security professionals in the IT business. I've worked in highly secure places, both private sector and govt. So I'd like to think I have a unique perspective on this topic. There are some that would only consider a computer in a warehouse surrounded by a faraday cage running a heavily customized and hardened copy of openbsd 'secure' and anything else is a joke and completely insecure. This is the type of view that kmfkewm commonly expresses. This is often the view of someone who is likely young, inexperienced in the practical application and management of secure networks but is well educated in them in the academic and/or classical sense. It's and argument like this:

Using a 2048 bit PGP key is completely insecure because a 4096 bit key is stronger.

So this statement is half true, in so much as the 4096 bit key is more secure (this is of course assuming all other variables are unchanged, like password length type etc) however the ideal that 2048 bits is not secure is false and reflects a failure to apply the security principles in a practical fashion.

There are other security minded folks/professionals (I don't really do as much with security specifically now as I do with virtualization although I did author some hardening documentation) like myself that have a more targeted approach to security which is to say to identify your attackers, or who you are concerned about obtaining your data for whatever reason and focus on eliminating the gaps that exist and make those attackers job easier.

This is to say that some believe (like kmfkewm appears to) that security is an 'all or nothing' sort of deal and anyone doing less than them are fools and are largely unprotected. He may have a fair amount of knowledge on securing computing platforms and where vulnerabilities exist but I'm of the opinion he is lacking in actual 'seat time' managing such things and understanding what a reasonable application of security principles is and when you are simply applying restrictions for the sake of applying them and really not increasing your security in a useful fashion (read: you've gone significantly beyond the point of diminishing returns).
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: vlad1m1r on July 29, 2012, 06:03 pm
kmfkewm is not an idiot. he seems to be a very intelligent, security and IT minded individual. not going to judge you but if i had to pick you or him to help me it'd be him.

He also wants to murder Police officers and legalise kiddy porn - as such I have been giving him a wide berth! I'm sure his technical knowledge is sound...

V.
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: digitbh on July 30, 2012, 05:19 pm
kmfkewm is not an idiot. he seems to be a very intelligent, security and IT minded individual. not going to judge you but if i had to pick you or him to help me it'd be him.

He also wants to murder Police officers and legalise kiddy porn - as such I have been giving him a wide berth! I'm sure his technical knowledge is sound...

V.

I'll never understand the "Fuck the police" mentality. I've never had a bad time with a cop, but maybe that's because I'm white.
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: jeffsandwich on July 30, 2012, 06:18 pm
I'm uneasy at the possibility of forum posts here coming up in a google search. Sounds like a massive attention getter - the wrong type of attention.

On one hand, you should already expect LE etc to be reading / able to read, don't put it on the forums if you don't want it to be public knowledge.

On the other hand, I agree that this sounds like the wrong kind of attention overall and the fewer laymen idiots on here the better for us all.  I wouldn't mind seeing a robots.txt set to disallow all pages from being indexed.
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: jeffsandwich on July 30, 2012, 06:48 pm
I'm uneasy at the possibility of forum posts here coming up in a google search. Sounds like a massive attention getter - the wrong type of attention.

On one hand, you should already expect LE etc to be reading / able to read, don't put it on the forums if you don't want it to be public knowledge.

On the other hand, I agree that this sounds like the wrong kind of attention overall and the fewer laymen idiots on here the better for us all.  I wouldn't mind seeing a robots.txt set to disallow all pages from being indexed.

I agree -- a robots.txt file would be an excellent idea. It's just that I don't want people to be getting the wrong idea by thinking that stuff they post here is private.

Guru

Totally.  But this is the internet, you should assume that EVERYTHING you do is somewhat public.  Thinking that a small layer like Tor protects you from yourself is ill conceived.  Always use vague terminology, never own up to quantity and never give too much personally identifiable information away - then if it's blown up on the projector in your court case, you haven't fucked yourself nearly as badly as you could have.
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: Boris Badenov on July 30, 2012, 08:37 pm
I'm uneasy at the possibility of forum posts here coming up in a google search. Sounds like a massive attention getter - the wrong type of attention.
We need much less attention from the world at large, not more.

BB
Title: Re: I just found Silk Road Forum Posts by searching google.
Post by: Vinnyg007 on July 30, 2012, 09:31 pm
Rape fantasies, wanting child pornography legalized and wanting to mail bombs is a pretty fucked up world view. I don't think he is unintelligent, just completely warped in the head with hardcore libertarian beliefs.