DEF CON 22 - Adrian Crenshaw- Dropping Docs on Darknets: How People Got Caught

Ғылым және технология

Presentation available here: www.defcon.org/images/defcon-...
Dropping Docs on Darknets: How People Got Caught
Adrian Crenshaw TRUSTEDSEC & IRONGEEK.COM
Most of you have probably used Tor before, but I2P may be unfamiliar. Both are anonymization networks that allow people to obfuscate where their traffic is coming from, and also host services (web sites for example) without it being tied back to them. This talk will give an overview of both, but will focus on real world stories of how people were deanonymized. Example cases like Eldo Kim & the Harvard Bomb Threat, Hector Xavier Monsegur (Sabu)/Jeremy Hammond (sup_g) & LulzSec, Freedom Hosting & Eric Eoin Marques and finally Ross William Ulbricht/“Dread Pirate Roberts” of the SilkRoad, will be used to explain how people have been caught and how it could have been avoided.
Adrian Crenshaw has worked in the IT industry for the last seventeen years. He runs the information security website Irongeek.com, which specializes in videos and articles that illustrate how to use various pen-testing and security tools. He did the cert chase for awhile (MCSE NT 4, CNE, A+, Network+. i-Net+) but stopped once he had to start paying for the tests himself. He holds a Master of Science in Security Informatics, works for TrustedSec as a Senior Security Consultant and is one of the co-founders of Derbycon.
Twitter: @irongeek_adc

Пікірлер: 143

  • @DigitalAbsence
    @DigitalAbsence9 жыл бұрын

    I love how if you pay attention from 49:30 and onward, his network slows down significantly and he checks the wifi. Suddenly you have people turning on their mobile hotspots haha

  • @neteheste3277

    @neteheste3277

    3 жыл бұрын

    defcon for ya

  • @apaskiewicz
    @apaskiewicz8 жыл бұрын

    +Adrian Crenshaw just wanted to say all the people making comments about your voice, I didn't even notice it. Great lecture. Thanks for the awesome information, keep it up.

  • @joshhutch3525

    @joshhutch3525

    2 жыл бұрын

    I get you’re trying to be nice, but cmon anyone with ears noticed.

  • @cyrilio
    @cyrilio3 жыл бұрын

    When this talk was given in 2014 ONE bitcoin was worth about 300 US dollars... Let that sink in.

  • @derschleichende

    @derschleichende

    3 жыл бұрын

    And DogeCoin wasn't being pumped by Elon Musk and was in fact called Doggycoin according to Crenshaw

  • @Slash27015

    @Slash27015

    2 жыл бұрын

    That's not even fat. There's older defcons where they discuss silkroad, and it's like "oh yeah 1 gram of weed is 1 btc".. i'm just sitting there nodding like "yes lol, good times"

  • @iskamag

    @iskamag

    2 жыл бұрын

    @@derschleichende and doge was seen as a joke with good intentions instead of a reddit asset

  • @iskamag

    @iskamag

    2 жыл бұрын

    And monero had just been created, only being worth ~30 cents each

  • @GeeqDoubt
    @GeeqDoubt10 ай бұрын

    Honestly “Polyester Road” sounds so dope I wish it was real not just an example

  • @ComputerAnarchy
    @ComputerAnarchy4 жыл бұрын

    Great talk! I'd like to attend one of these soon.

  • @jeremykurowski519
    @jeremykurowski5199 жыл бұрын

    Great talk!

  • @JayDascenzo
    @JayDascenzo3 жыл бұрын

    Great substance & energetic delivery.Thanks!.

  • @cristian5702
    @cristian57024 жыл бұрын

    Remeber ! Any legal advice I give is not legal advice in the legal advice definition of legal advice

  • @Rightly_Divided
    @Rightly_Divided9 жыл бұрын

    Very knowledgeable! Loved it.

  • @Lei_Wong
    @Lei_Wong9 жыл бұрын

    muy informativo, gracias

  • @TheEnmineer
    @TheEnmineer9 жыл бұрын

    IANAL... sounds like an apple device that you'd have to get off of some website on the deep web

  • @therealb888

    @therealb888

    3 жыл бұрын

    lol

  • @tubbalcain
    @tubbalcain3 жыл бұрын

    I love his nerdy jokes

  • @nikoladd
    @nikoladd4 жыл бұрын

    Marginot - a French firewall company..

  • @grilla6874
    @grilla68749 жыл бұрын

    this dude legit

  • @harryassenbach
    @harryassenbach9 жыл бұрын

    Layers like an Ogre. I like the Shrek reference.

  • @FultonLMiller
    @FultonLMiller8 жыл бұрын

    With the speech impediment, his summarizing notes that pop up in the video are really great. Here's a guy who understands his limits and how to solve problems.

  • @asexualprotonmail2726

    @asexualprotonmail2726

    8 жыл бұрын

    +FultonLMiller adrian is a great guy overlook his shitty disadvantage and focus on his knowledge and experience.

  • @erilgaz

    @erilgaz

    7 жыл бұрын

    What speech impediment? I don't see it. Just curious.

  • @iamnotaprogram

    @iamnotaprogram

    6 жыл бұрын

    ehh , i wanted to make an actualy funny (yet speechrelated) joke, but you calling it a disadvantage made me feel all sad inside...

  • @msardou3919

    @msardou3919

    4 жыл бұрын

    I legit don't know what speech impediment he has. English is not my first language and he is perfectly intelligible to me!

  • @user-lc8jd6sn2b

    @user-lc8jd6sn2b

    3 жыл бұрын

    @@msardou3919 It's a lisp. He mispronounces his s's and r's.

  • @alexlaroche7174
    @alexlaroche71749 жыл бұрын

    Lmao the great firewall of China hahahaha

  • @vincet9688
    @vincet96884 жыл бұрын

    AMAZBALLS I’M TUNED IN!!!!

  • @Crestoify
    @Crestoify9 жыл бұрын

    "Contact me at I'maDumbass @ gmail.com" LoL!

  • @marconius101
    @marconius1018 жыл бұрын

    i would like t use encryption but 90% of my friends can't use it. I set it up tor, veraCrypt tel them what to do and do not, they use it 2 days and stop. To slow, to hard, can't find my favorite porn site and what else. So what to do?

  • @Sawta

    @Sawta

    8 жыл бұрын

    +marconius101 The idea of using stuff like Tor is that you don't use it constantly, every single day. You use it when you need to use it, for whatever reason that might be. In a sense, your friends should think of it as having two persona's, the one's that they use when they're looking at porn or youtube videos or whatever, and the other persona that they use when they're using an encrypted service. That is, they should be using Tor when they are trying to accomplish something specific, not when they're just trying to surf the net casually. Surfing casually using encrypted services is generally bad practice and can lead to lax security precautions and a false sense of security. If you want a basic encrypted service that they could use with you on day-to-day stuff, look into PGP. I believe firefox has a plugin that can enable/disable it quickly for gmail accounts. Simple as a 5 minute setup, and clicking a button to turn it on or off.

  • @jameelahjohnson9683

    @jameelahjohnson9683

    4 жыл бұрын

    You must be one of those weirdo friends that secretly like cp ,I just want to be safe form pornhub viruses . Get a life bro .

  • @haonyoass9556
    @haonyoass9556Ай бұрын

    Great pres

  • @ronmeister9000
    @ronmeister900011 ай бұрын

    Smart dude i can listen to him forever😅😅😅😅

  • @topsecret4791
    @topsecret47913 жыл бұрын

    Someone screamed, and stretcher was brought in. Something bad happened in the background!!

  • @OnajTamo
    @OnajTamo8 жыл бұрын

    So the more people use tor, the stronger it is?

  • @DarkMichael89

    @DarkMichael89

    8 жыл бұрын

    +Blue Dragon (Onaj tamo) Not really

  • @OnajTamo

    @OnajTamo

    8 жыл бұрын

    ***** the way I understood it, it is. More users=more enthusiast users=more nodes.

  • @DarkMichael89

    @DarkMichael89

    8 жыл бұрын

    Blue Dragon That's truth but if the US government wants to track you down they can use a zero day exploit to attack your browser.

  • @OnajTamo

    @OnajTamo

    8 жыл бұрын

    ***** I know, but that as you have seen in the video is not a weakness in tor. That is also your fault for not hiding your browser signature.

  • @OnajTamo

    @OnajTamo

    8 жыл бұрын

    Eric Smith i guess...the last time I used it, it was turned on.

  • @daa3417
    @daa34179 жыл бұрын

    CWC got cleared to do a Defcon talk?

  • @allanpaiz3348
    @allanpaiz33487 жыл бұрын

    well that was entertaining.

  • @ERROR204.
    @ERROR204.3 жыл бұрын

    Great talk and despite the impediment comments I actually kinda like his voice

  • @cronicdee
    @cronicdee3 жыл бұрын

    Never use google! Location, location, location! lol

  • @Jzombi301

    @Jzombi301

    3 жыл бұрын

    KZread=Google

  • @Ryan-xq3kl

    @Ryan-xq3kl

    3 жыл бұрын

    I only use google when i want accurate geo lol

  • @casperghost1467
    @casperghost1467 Жыл бұрын

    Polyester road lmfao

  • @chovyfu
    @chovyfu8 жыл бұрын

    wtf is a "lemon wipe"? I couldn't find anything in Google.

  • @jurio3117

    @jurio3117

    4 жыл бұрын

    Basically you urinate on your device

  • @napalm3899

    @napalm3899

    3 жыл бұрын

    A "lemon wipe" is kind of like a "lemon party". Google "lemon party" for more info.

  • @neteheste3277
    @neteheste32773 жыл бұрын

    I wish the caption was a bit better

  • @fuckyoutube5033
    @fuckyoutube50338 жыл бұрын

    Curiosity something bad

  • @PaulChauvat
    @PaulChauvat Жыл бұрын

    Interesting

  • @theelastog1580
    @theelastog15802 жыл бұрын

    How does China block directory servers ?

  • @KenSherman

    @KenSherman

    Жыл бұрын

    I kid you not. I soon as I saw your comment, the speaker read it off. Talk about perfect timing @5:46! That actually happened twice today, tbh😄.

  • @mer_meh
    @mer_meh4 жыл бұрын

    How to never (no guarantees) get caught 1. Use tor 2. turn off java scripts 3. turn off images and media 4. switch accounts frequently Only reason to be _this_ anonymous is if you're doing highly illegal activities such as whistle blowing government documents or you run a site that generates a lot of untaxed profits. An extra step would be to live in a city where many people probably use tor. This makes it harder to narrow you down.

  • @trancetuberevived1131

    @trancetuberevived1131

    3 жыл бұрын

    Or - if you think privacy should be a foundational human right, you can claim it.

  • @karthikmishra3188

    @karthikmishra3188

    3 жыл бұрын

    @@trancetuberevived1131 But what if the government is involved for whatever reasons?

  • @trancetuberevived1131

    @trancetuberevived1131

    3 жыл бұрын

    @@karthikmishra3188 Well, then the government should uninvolve itself.. or, I am not sure what you are getting at.

  • @karthikmishra3188

    @karthikmishra3188

    3 жыл бұрын

    @@trancetuberevived1131 I mean, as u said to claim the privacy, but from whom? U don't have a chance if u r referring the hackers and u probably know y. Also if the govt it is, then no one could say for sure that they gonna stop track cuz they are authority. Either way we are doomed unless we care about our own privacy.

  • @trancetuberevived1131

    @trancetuberevived1131

    3 жыл бұрын

    @@karthikmishra3188 Claim your privacy from anyone who is trying to snoop on our personal stuff. From an OPSEC perspective I dont think it matters much. In my eyes cybersecurity/privacy is a gradient and we each can set our own level. You say "we have no chance against hackers or the authorities"! Why is that so? Set up a Libre booted computer with say OpenBSD and use gpg for encrypting your messaging. Sounds pretty solid to me.

  • @Zorn101
    @Zorn1018 жыл бұрын

    Dead man switches any one?

  • @maziku4749

    @maziku4749

    8 жыл бұрын

    Zorn101 hey i played shadowrun returns too :)

  • @Zorn101

    @Zorn101

    8 жыл бұрын

    maziku lol I never played shadow run. Just make a script that shuts your computer down if you do not type for 10 mins. dead man switch.

  • @kekistanimememan170

    @kekistanimememan170

    2 жыл бұрын

    @@Zorn101 wouldn’t that be more of a dooms-day switch? If that what you would call it.

  • @mkmike4903
    @mkmike49033 ай бұрын

    Wtf is "The Lemon Wipe?" Does he mean "LemonParty?"

  • @DrewWalton

    @DrewWalton

    Ай бұрын

    The lemon wipe literally refers to pissing on your phone to "wipe" it.

  • @thelemonking3288
    @thelemonking32889 жыл бұрын

    Dat hand tho 0:25

  • @edrutmayer6877

    @edrutmayer6877

    8 жыл бұрын

    The Lemon King ?

  • @Steven-wv3qm

    @Steven-wv3qm

    8 жыл бұрын

    +Ed Rutmayer He's talking about the audience member who briefly raised their hand at 0:28. Not sure why somebody took the time to type "dat hand tho" lol.

  • @xRIDExTHExSPIRALx
    @xRIDExTHExSPIRALx4 жыл бұрын

    i love you

  • @user-zm3wd6nj8l
    @user-zm3wd6nj8l Жыл бұрын

    They say there is no 100% inkognito. But there is.always the human fcck up sokething. Everytime somebody get caught its bcz of their fault. There is rules what you need to follow to be safe

  • @richymcbeath3238
    @richymcbeath32389 жыл бұрын

    You sound like Jimmy from South Park

  • @torbellinochacon9997

    @torbellinochacon9997

    9 жыл бұрын

    Richy McBeath hahahahaha

  • @grilla6874

    @grilla6874

    9 жыл бұрын

    Richy McBeath 100

  • @Ponder_the_Cross
    @Ponder_the_Cross4 ай бұрын

    Need anyone wonder why THIS GUY is worried about getting caught sharing files on the darknet. Very few pictures are illegal, bro.

  • @memegazer

    @memegazer

    4 ай бұрын

    My guy, he is giving a talk at defcon, a cybersecurity confrence.

  • @Ponder_the_Cross

    @Ponder_the_Cross

    4 ай бұрын

    @@memegazer Did you know that the bible is so true that archeologists use it to find lost cities? Also I'd bet a months wages that this guy is a pedo

  • @lisawood2340
    @lisawood23408 жыл бұрын

    21:05 FAIL. Uses PP on a Mac.....I lul

  • @root1657

    @root1657

    7 жыл бұрын

    PP on a VM on a Mac... you missed the rest of what he was doing...

  • @lometatron357
    @lometatron3573 жыл бұрын

    My question is,who are the people who spy on other people on the internet ? How the hell do you spy on someone on the internet if you are not physically with the person???🤷🏾‍♂️

  • @trancetuberevived1131

    @trancetuberevived1131

    3 жыл бұрын

    Watch the documentary called "Citizenfour"

  • @lometatron357

    @lometatron357

    3 жыл бұрын

    @@trancetuberevived1131 appreciate you

  • @armymobilityofficer9099
    @armymobilityofficer90998 жыл бұрын

    Adrian has no speech impediment or accent. He is a huge recurring character of "Barry Kripke" in The Big Bang Theory.

  • @ssneg
    @ssneg2 жыл бұрын

    If you are listening to this in 2014, go buy some Bitcoin.

  • @jay-ov6vh

    @jay-ov6vh

    Жыл бұрын

    if you are listening to this in 2022, go buy some eth

  • @casperghost1467

    @casperghost1467

    Жыл бұрын

    @@jay-ov6vh u mean monero

  • @drygordspellweaver8761
    @drygordspellweaver87613 жыл бұрын

    oWo i haw no secwecy whatsoewer

  • @KingsSlayerSportFishing
    @KingsSlayerSportFishing5 ай бұрын

    The information belongs in defcon the voice belongs at comicon 😂 so you dont want a fish[th] sandwhich? Sorry i have downs.

  • @N99622
    @N99622 Жыл бұрын

    I can't with the autism

  • @Ponder_the_Cross

    @Ponder_the_Cross

    4 ай бұрын

    It wasn't the red pedo flags for you?

  • @SaureHefePegorino
    @SaureHefePegorino8 жыл бұрын

    god hes nervous

  • @spatterlight7846
    @spatterlight7846 Жыл бұрын

    frequently too off topic

  • @ChaceBonanno
    @ChaceBonanno10 ай бұрын

    Something hilariously ironic about a genius with a speech impediment. It’s like hearing a 5 year old who somehow has vast knowledge.

  • @humbllbug
    @humbllbug3 жыл бұрын

    Jesus was born to a virgin, turned water to wine, taught, healed the sick, raised the dead, casted out demons, walked on water, and calmed the storm, among many other things. He was killed, and three days later He rose from the dead. Forty days later He ascended into heaven where He sits at the right hand of the Father. He is returning very soon, but before He does, Satan, the devil, is coming to pretend to be Jesus. Satan is an angel, and he will have certain supernatural powers with which to try to fool everyone. He will, for example, be able to make fire come down from heaven in the sight of men. He will only be on earth a short time before the real King of Kings, Jesus Christ, God in the flesh, returns. When the real Jesus comes we will all be transformed into our spiritual bodies at the same moment. Jesus came to offer forgiveness of sins and eternal life to anyone who believes and calls on His precious name. For all have sinned, and come short of the glory of God; - Romans 3:23 For the wages of sin is death; but the gift of God is eternal life through Jesus Christ our Lord. - Romans 6:23 For God so loved the world, that he gave his only begotten Son, that whosoever believeth in him should not perish, but have everlasting life. For God sent not his Son into the world to condemn the world; but that the world through him might be saved. He that believeth on him is not condemned: but he that believeth not is condemned already, because he hath not believed in the name of the only begotten Son of God. - John 3:16-18 The blessing of the LORD, it maketh rich, and he addeth no sorrow with it. - Proverbs 10:22

  • @lazarus8237

    @lazarus8237

    3 жыл бұрын

    Amen , but wrong audience . I became aware at 30 , beliver at 50 , born again ??? still praying for forgiveness .

  • @neilf335

    @neilf335

    2 жыл бұрын

    Does he use TOR?

  • @pimplepickerton

    @pimplepickerton

    Жыл бұрын

    @@neilf335 he actually uses a newer version of tails. It's called Nails.

  • @Ataraxia_Atom

    @Ataraxia_Atom

    11 ай бұрын

    ​@@pimplepickerton brutal

  • @l0k048

    @l0k048

    10 ай бұрын

    fun fact: you can read the bible on tor if you are in an country that makes bring christian illegal.

  • @rogerwilco2
    @rogerwilco28 жыл бұрын

    This guy sounds like he's tripping over his own tongue all the time.

  • @royalcrown7180

    @royalcrown7180

    8 жыл бұрын

    +robotic turdle Well said. I enjoyed his presentation!

  • @LTDanno360mods

    @LTDanno360mods

    8 жыл бұрын

    he is prolly hard of hearing

  • @Ryan-xq3kl

    @Ryan-xq3kl

    3 жыл бұрын

    Have you people never heard of speech impediment?

  • @Owyourhurtingme

    @Owyourhurtingme

    3 жыл бұрын

    Idiot. He has a lisp. You’re prob perfect, right?

  • @smisheski
    @smisheski9 жыл бұрын

    ppl with the speech impetiment drives me crazy, with the lazy R and L pronunciations. no offense to the speaker, but jeez this long of a speech with that? I'm sorry but just use R's normally

  • @montetown5741

    @montetown5741

    9 жыл бұрын

    Steven Misheski Did you have any trouble understanding him? I didnt at all. I think its your problem. What about ESL speakers? "English as a Second Language"? Depending on what their native language is there are dozens of pronounciations they cant get their tongue/mind around. Really man people like you should think about that. I was so fascinated in what he was talking about it just didnt even occur to me until I read some of these comments here.

  • @Rightly_Divided

    @Rightly_Divided

    9 жыл бұрын

    Steven Misheski Whatever you Justin Bieber wannabe.

  • @auscaliber1

    @auscaliber1

    8 жыл бұрын

    +Steven Misheski Awfully ironic to criticize someone's use of language and misspell "impediment".

  • @forevershampoo

    @forevershampoo

    6 жыл бұрын

    This dude is a G tho

  • @lazula

    @lazula

    6 жыл бұрын

    You probably also tell disabled people to "just use their legs normally" too, don't you?

Келесі