DEF CON 22 - Adrian Crenshaw- Dropping Docs on Darknets: How People Got Caught

  Рет қаралды 203,221

DEFCONConference

DEFCONConference

9 жыл бұрын

Presentation available here: www.defcon.org/images/defcon-...
Dropping Docs on Darknets: How People Got Caught
Adrian Crenshaw TRUSTEDSEC & IRONGEEK.COM
Most of you have probably used Tor before, but I2P may be unfamiliar. Both are anonymization networks that allow people to obfuscate where their traffic is coming from, and also host services (web sites for example) without it being tied back to them. This talk will give an overview of both, but will focus on real world stories of how people were deanonymized. Example cases like Eldo Kim & the Harvard Bomb Threat, Hector Xavier Monsegur (Sabu)/Jeremy Hammond (sup_g) & LulzSec, Freedom Hosting & Eric Eoin Marques and finally Ross William Ulbricht/“Dread Pirate Roberts” of the SilkRoad, will be used to explain how people have been caught and how it could have been avoided.
Adrian Crenshaw has worked in the IT industry for the last seventeen years. He runs the information security website Irongeek.com, which specializes in videos and articles that illustrate how to use various pen-testing and security tools. He did the cert chase for awhile (MCSE NT 4, CNE, A+, Network+. i-Net+) but stopped once he had to start paying for the tests himself. He holds a Master of Science in Security Informatics, works for TrustedSec as a Senior Security Consultant and is one of the co-founders of Derbycon.
Twitter: @irongeek_adc

Пікірлер: 143
@DigitalAbsence
@DigitalAbsence 9 жыл бұрын
I love how if you pay attention from 49:30 and onward, his network slows down significantly and he checks the wifi. Suddenly you have people turning on their mobile hotspots haha
@neteheste3277
@neteheste3277 3 жыл бұрын
defcon for ya
@apaskiewicz
@apaskiewicz 8 жыл бұрын
+Adrian Crenshaw just wanted to say all the people making comments about your voice, I didn't even notice it. Great lecture. Thanks for the awesome information, keep it up.
@joshhutch3525
@joshhutch3525 2 жыл бұрын
I get you’re trying to be nice, but cmon anyone with ears noticed.
@GeeqDoubt
@GeeqDoubt 9 ай бұрын
Honestly “Polyester Road” sounds so dope I wish it was real not just an example
@cyrilio
@cyrilio 3 жыл бұрын
When this talk was given in 2014 ONE bitcoin was worth about 300 US dollars... Let that sink in.
@derschleichende
@derschleichende 2 жыл бұрын
And DogeCoin wasn't being pumped by Elon Musk and was in fact called Doggycoin according to Crenshaw
@Slash27015
@Slash27015 2 жыл бұрын
That's not even fat. There's older defcons where they discuss silkroad, and it's like "oh yeah 1 gram of weed is 1 btc".. i'm just sitting there nodding like "yes lol, good times"
@iskamag
@iskamag 2 жыл бұрын
@@derschleichende and doge was seen as a joke with good intentions instead of a reddit asset
@iskamag
@iskamag 2 жыл бұрын
And monero had just been created, only being worth ~30 cents each
@JayDascenzo
@JayDascenzo 3 жыл бұрын
Great substance & energetic delivery.Thanks!.
@jeremykurowski519
@jeremykurowski519 9 жыл бұрын
Great talk!
@ComputerAnarchy
@ComputerAnarchy 4 жыл бұрын
Great talk! I'd like to attend one of these soon.
@Rightly_Divided
@Rightly_Divided 9 жыл бұрын
Very knowledgeable! Loved it.
@cristian5702
@cristian5702 4 жыл бұрын
Remeber ! Any legal advice I give is not legal advice in the legal advice definition of legal advice
@TheEnmineer
@TheEnmineer 9 жыл бұрын
IANAL... sounds like an apple device that you'd have to get off of some website on the deep web
@therealb888
@therealb888 3 жыл бұрын
lol
@Lei_Wong
@Lei_Wong 9 жыл бұрын
muy informativo, gracias
@harryassenbach
@harryassenbach 9 жыл бұрын
Layers like an Ogre. I like the Shrek reference.
@nikoladd
@nikoladd 4 жыл бұрын
Marginot - a French firewall company..
@FultonLMiller
@FultonLMiller 8 жыл бұрын
With the speech impediment, his summarizing notes that pop up in the video are really great. Here's a guy who understands his limits and how to solve problems.
@asexualprotonmail2726
@asexualprotonmail2726 8 жыл бұрын
+FultonLMiller adrian is a great guy overlook his shitty disadvantage and focus on his knowledge and experience.
@erilgaz
@erilgaz 7 жыл бұрын
What speech impediment? I don't see it. Just curious.
@iamnotaprogram
@iamnotaprogram 6 жыл бұрын
ehh , i wanted to make an actualy funny (yet speechrelated) joke, but you calling it a disadvantage made me feel all sad inside...
@msardou3919
@msardou3919 4 жыл бұрын
I legit don't know what speech impediment he has. English is not my first language and he is perfectly intelligible to me!
@user-lc8jd6sn2b
@user-lc8jd6sn2b 3 жыл бұрын
@@msardou3919 It's a lisp. He mispronounces his s's and r's.
@tubbalcain
@tubbalcain 3 жыл бұрын
I love his nerdy jokes
@grilla6874
@grilla6874 9 жыл бұрын
this dude legit
@vincet9688
@vincet9688 4 жыл бұрын
AMAZBALLS I’M TUNED IN!!!!
@alexlaroche7174
@alexlaroche7174 9 жыл бұрын
Lmao the great firewall of China hahahaha
@haonyoass9556
@haonyoass9556 Ай бұрын
Great pres
@Crestoify
@Crestoify 8 жыл бұрын
"Contact me at I'maDumbass @ gmail.com" LoL!
@OnajTamo
@OnajTamo 8 жыл бұрын
So the more people use tor, the stronger it is?
@DarkMichael89
@DarkMichael89 8 жыл бұрын
+Blue Dragon (Onaj tamo) Not really
@OnajTamo
@OnajTamo 8 жыл бұрын
***** the way I understood it, it is. More users=more enthusiast users=more nodes.
@DarkMichael89
@DarkMichael89 8 жыл бұрын
Blue Dragon That's truth but if the US government wants to track you down they can use a zero day exploit to attack your browser.
@OnajTamo
@OnajTamo 8 жыл бұрын
***** I know, but that as you have seen in the video is not a weakness in tor. That is also your fault for not hiding your browser signature.
@OnajTamo
@OnajTamo 8 жыл бұрын
Eric Smith i guess...the last time I used it, it was turned on.
@topsecret4791
@topsecret4791 3 жыл бұрын
Someone screamed, and stretcher was brought in. Something bad happened in the background!!
@marconius101
@marconius101 8 жыл бұрын
i would like t use encryption but 90% of my friends can't use it. I set it up tor, veraCrypt tel them what to do and do not, they use it 2 days and stop. To slow, to hard, can't find my favorite porn site and what else. So what to do?
@Sawta
@Sawta 8 жыл бұрын
+marconius101 The idea of using stuff like Tor is that you don't use it constantly, every single day. You use it when you need to use it, for whatever reason that might be. In a sense, your friends should think of it as having two persona's, the one's that they use when they're looking at porn or youtube videos or whatever, and the other persona that they use when they're using an encrypted service. That is, they should be using Tor when they are trying to accomplish something specific, not when they're just trying to surf the net casually. Surfing casually using encrypted services is generally bad practice and can lead to lax security precautions and a false sense of security. If you want a basic encrypted service that they could use with you on day-to-day stuff, look into PGP. I believe firefox has a plugin that can enable/disable it quickly for gmail accounts. Simple as a 5 minute setup, and clicking a button to turn it on or off.
@jameelahjohnson9683
@jameelahjohnson9683 4 жыл бұрын
You must be one of those weirdo friends that secretly like cp ,I just want to be safe form pornhub viruses . Get a life bro .
@ronmeister9000
@ronmeister9000 11 ай бұрын
Smart dude i can listen to him forever😅😅😅😅
@ERROR204.
@ERROR204. 3 жыл бұрын
Great talk and despite the impediment comments I actually kinda like his voice
@allanpaiz3348
@allanpaiz3348 7 жыл бұрын
well that was entertaining.
@chovyfu
@chovyfu 8 жыл бұрын
wtf is a "lemon wipe"? I couldn't find anything in Google.
@jurio3117
@jurio3117 4 жыл бұрын
Basically you urinate on your device
@napalm3899
@napalm3899 3 жыл бұрын
A "lemon wipe" is kind of like a "lemon party". Google "lemon party" for more info.
@daa3417
@daa3417 9 жыл бұрын
CWC got cleared to do a Defcon talk?
@mer_meh
@mer_meh 4 жыл бұрын
How to never (no guarantees) get caught 1. Use tor 2. turn off java scripts 3. turn off images and media 4. switch accounts frequently Only reason to be _this_ anonymous is if you're doing highly illegal activities such as whistle blowing government documents or you run a site that generates a lot of untaxed profits. An extra step would be to live in a city where many people probably use tor. This makes it harder to narrow you down.
@trancetuberevived1131
@trancetuberevived1131 3 жыл бұрын
Or - if you think privacy should be a foundational human right, you can claim it.
@karthikmishra3188
@karthikmishra3188 3 жыл бұрын
@@trancetuberevived1131 But what if the government is involved for whatever reasons?
@trancetuberevived1131
@trancetuberevived1131 3 жыл бұрын
@@karthikmishra3188 Well, then the government should uninvolve itself.. or, I am not sure what you are getting at.
@karthikmishra3188
@karthikmishra3188 3 жыл бұрын
@@trancetuberevived1131 I mean, as u said to claim the privacy, but from whom? U don't have a chance if u r referring the hackers and u probably know y. Also if the govt it is, then no one could say for sure that they gonna stop track cuz they are authority. Either way we are doomed unless we care about our own privacy.
@trancetuberevived1131
@trancetuberevived1131 3 жыл бұрын
@@karthikmishra3188 Claim your privacy from anyone who is trying to snoop on our personal stuff. From an OPSEC perspective I dont think it matters much. In my eyes cybersecurity/privacy is a gradient and we each can set our own level. You say "we have no chance against hackers or the authorities"! Why is that so? Set up a Libre booted computer with say OpenBSD and use gpg for encrypting your messaging. Sounds pretty solid to me.
@cronicdee
@cronicdee 3 жыл бұрын
Never use google! Location, location, location! lol
@Jzombi301
@Jzombi301 3 жыл бұрын
KZfaq=Google
@Ryan-xq3kl
@Ryan-xq3kl 3 жыл бұрын
I only use google when i want accurate geo lol
@PaulChauvat
@PaulChauvat Жыл бұрын
Interesting
@theelastog1580
@theelastog1580 2 жыл бұрын
How does China block directory servers ?
@KenSherman
@KenSherman Жыл бұрын
I kid you not. I soon as I saw your comment, the speaker read it off. Talk about perfect timing @5:46! That actually happened twice today, tbh😄.
@casperghost1467
@casperghost1467 Жыл бұрын
Polyester road lmfao
@neteheste3277
@neteheste3277 3 жыл бұрын
I wish the caption was a bit better
@fuckyoutube5033
@fuckyoutube5033 7 жыл бұрын
Curiosity something bad
@xRIDExTHExSPIRALx
@xRIDExTHExSPIRALx 4 жыл бұрын
i love you
@thelemonking3288
@thelemonking3288 8 жыл бұрын
Dat hand tho 0:25
@edrutmayer6877
@edrutmayer6877 8 жыл бұрын
The Lemon King ?
@Steven-wv3qm
@Steven-wv3qm 8 жыл бұрын
+Ed Rutmayer He's talking about the audience member who briefly raised their hand at 0:28. Not sure why somebody took the time to type "dat hand tho" lol.
@Zorn101
@Zorn101 8 жыл бұрын
Dead man switches any one?
@maziku4749
@maziku4749 8 жыл бұрын
Zorn101 hey i played shadowrun returns too :)
@Zorn101
@Zorn101 8 жыл бұрын
maziku lol I never played shadow run. Just make a script that shuts your computer down if you do not type for 10 mins. dead man switch.
@kekistanimememan170
@kekistanimememan170 2 жыл бұрын
@@Zorn101 wouldn’t that be more of a dooms-day switch? If that what you would call it.
@mkmike4903
@mkmike4903 3 ай бұрын
Wtf is "The Lemon Wipe?" Does he mean "LemonParty?"
@DrewWalton
@DrewWalton 21 күн бұрын
The lemon wipe literally refers to pissing on your phone to "wipe" it.
@richymcbeath3238
@richymcbeath3238 9 жыл бұрын
You sound like Jimmy from South Park
@torbellinochacon9997
@torbellinochacon9997 9 жыл бұрын
Richy McBeath hahahahaha
@grilla6874
@grilla6874 9 жыл бұрын
Richy McBeath 100
@user-zm3wd6nj8l
@user-zm3wd6nj8l Жыл бұрын
They say there is no 100% inkognito. But there is.always the human fcck up sokething. Everytime somebody get caught its bcz of their fault. There is rules what you need to follow to be safe
@armymobilityofficer9099
@armymobilityofficer9099 8 жыл бұрын
Adrian has no speech impediment or accent. He is a huge recurring character of "Barry Kripke" in The Big Bang Theory.
@Ponder_the_Cross
@Ponder_the_Cross 4 ай бұрын
Need anyone wonder why THIS GUY is worried about getting caught sharing files on the darknet. Very few pictures are illegal, bro.
@memegazer
@memegazer 4 ай бұрын
My guy, he is giving a talk at defcon, a cybersecurity confrence.
@Ponder_the_Cross
@Ponder_the_Cross 4 ай бұрын
@@memegazer Did you know that the bible is so true that archeologists use it to find lost cities? Also I'd bet a months wages that this guy is a pedo
@drygordspellweaver8761
@drygordspellweaver8761 3 жыл бұрын
oWo i haw no secwecy whatsoewer
@lometatron357
@lometatron357 3 жыл бұрын
My question is,who are the people who spy on other people on the internet ? How the hell do you spy on someone on the internet if you are not physically with the person???🤷🏾‍♂️
@trancetuberevived1131
@trancetuberevived1131 3 жыл бұрын
Watch the documentary called "Citizenfour"
@lometatron357
@lometatron357 3 жыл бұрын
@@trancetuberevived1131 appreciate you
@N99622
@N99622 11 ай бұрын
I can't with the autism
@Ponder_the_Cross
@Ponder_the_Cross 4 ай бұрын
It wasn't the red pedo flags for you?
@KingsSlayerSportFishing
@KingsSlayerSportFishing 4 ай бұрын
The information belongs in defcon the voice belongs at comicon 😂 so you dont want a fish[th] sandwhich? Sorry i have downs.
@ssneg
@ssneg 2 жыл бұрын
If you are listening to this in 2014, go buy some Bitcoin.
@jay-ov6vh
@jay-ov6vh Жыл бұрын
if you are listening to this in 2022, go buy some eth
@casperghost1467
@casperghost1467 Жыл бұрын
@@jay-ov6vh u mean monero
@lisawood2340
@lisawood2340 8 жыл бұрын
21:05 FAIL. Uses PP on a Mac.....I lul
@root1657
@root1657 7 жыл бұрын
PP on a VM on a Mac... you missed the rest of what he was doing...
@SaureHefePegorino
@SaureHefePegorino 8 жыл бұрын
god hes nervous
@humbllbug
@humbllbug 3 жыл бұрын
Jesus was born to a virgin, turned water to wine, taught, healed the sick, raised the dead, casted out demons, walked on water, and calmed the storm, among many other things. He was killed, and three days later He rose from the dead. Forty days later He ascended into heaven where He sits at the right hand of the Father. He is returning very soon, but before He does, Satan, the devil, is coming to pretend to be Jesus. Satan is an angel, and he will have certain supernatural powers with which to try to fool everyone. He will, for example, be able to make fire come down from heaven in the sight of men. He will only be on earth a short time before the real King of Kings, Jesus Christ, God in the flesh, returns. When the real Jesus comes we will all be transformed into our spiritual bodies at the same moment. Jesus came to offer forgiveness of sins and eternal life to anyone who believes and calls on His precious name. For all have sinned, and come short of the glory of God; - Romans 3:23 For the wages of sin is death; but the gift of God is eternal life through Jesus Christ our Lord. - Romans 6:23 For God so loved the world, that he gave his only begotten Son, that whosoever believeth in him should not perish, but have everlasting life. For God sent not his Son into the world to condemn the world; but that the world through him might be saved. He that believeth on him is not condemned: but he that believeth not is condemned already, because he hath not believed in the name of the only begotten Son of God. - John 3:16-18 The blessing of the LORD, it maketh rich, and he addeth no sorrow with it. - Proverbs 10:22
@lazarus8237
@lazarus8237 3 жыл бұрын
Amen , but wrong audience . I became aware at 30 , beliver at 50 , born again ??? still praying for forgiveness .
@neilf335
@neilf335 2 жыл бұрын
Does he use TOR?
@pimplepickerton
@pimplepickerton Жыл бұрын
@@neilf335 he actually uses a newer version of tails. It's called Nails.
@Ataraxia_Atom
@Ataraxia_Atom 11 ай бұрын
​@@pimplepickerton brutal
@l0k048
@l0k048 9 ай бұрын
fun fact: you can read the bible on tor if you are in an country that makes bring christian illegal.
@spatterlight7846
@spatterlight7846 Жыл бұрын
frequently too off topic
@ChaceBonanno
@ChaceBonanno 10 ай бұрын
Something hilariously ironic about a genius with a speech impediment. It’s like hearing a 5 year old who somehow has vast knowledge.
@rogerwilco2
@rogerwilco2 8 жыл бұрын
This guy sounds like he's tripping over his own tongue all the time.
@royalcrown7180
@royalcrown7180 8 жыл бұрын
+robotic turdle Well said. I enjoyed his presentation!
@LTDanno360mods
@LTDanno360mods 8 жыл бұрын
he is prolly hard of hearing
@Ryan-xq3kl
@Ryan-xq3kl 3 жыл бұрын
Have you people never heard of speech impediment?
@Owyourhurtingme
@Owyourhurtingme 2 жыл бұрын
Idiot. He has a lisp. You’re prob perfect, right?
@smisheski
@smisheski 9 жыл бұрын
ppl with the speech impetiment drives me crazy, with the lazy R and L pronunciations. no offense to the speaker, but jeez this long of a speech with that? I'm sorry but just use R's normally
@montetown5741
@montetown5741 9 жыл бұрын
Steven Misheski Did you have any trouble understanding him? I didnt at all. I think its your problem. What about ESL speakers? "English as a Second Language"? Depending on what their native language is there are dozens of pronounciations they cant get their tongue/mind around. Really man people like you should think about that. I was so fascinated in what he was talking about it just didnt even occur to me until I read some of these comments here.
@Rightly_Divided
@Rightly_Divided 9 жыл бұрын
Steven Misheski Whatever you Justin Bieber wannabe.
@auscaliber1
@auscaliber1 8 жыл бұрын
+Steven Misheski Awfully ironic to criticize someone's use of language and misspell "impediment".
@forevershampoo
@forevershampoo 6 жыл бұрын
This dude is a G tho
@lazula
@lazula 6 жыл бұрын
You probably also tell disabled people to "just use their legs normally" too, don't you?
Black Hat 2013 - OPSEC Failures of Spies
25:11
HackersOnBoard
Рет қаралды 221 М.
Good People Restore Faith in Humanity: A Heartwarming Act of Kindness on a Bus #shorts
00:32
He FOUND MYSTERY inside the GUMMY BEAR 😱🧸😂 #shorts
00:26
BROTHERS VLOG
Рет қаралды 53 МЛН
Bill Swearingen - HAKC THE POLICE - DEF CON 27 Conference
41:18
DEFCONConference
Рет қаралды 599 М.
Defcon 21 - The Secret Life of SIM Cards
42:36
HackersOnBoard
Рет қаралды 693 М.
Tactics of Physical Pen Testers
44:17
freeCodeCamp Talks
Рет қаралды 877 М.
Robin Dreeke - Sizing People Up - DEF CON 27 Social Engineering Village
53:48
I'll Let Myself In: Tactics of Physical Pen Testers
44:56
Wild West Hackin' Fest
Рет қаралды 2,8 МЛН
Defcon 21 - Forensic Fails - Shift + Delete Won't Help You Here
47:10
HackersOnBoard
Рет қаралды 635 М.
DEF CON 30 - Kenneth Geers - Computer Hacks in the Russia-Ukraine War
20:54
Phone charger explosion
0:43
_vector_
Рет қаралды 6 МЛН
Компьютерная мышь за 50 рублей
0:28
🤯Самая КРУТАЯ Функция #shorts
0:58
YOLODROID
Рет қаралды 969 М.
Vortex Cannon vs Drone
20:44
Mark Rober
Рет қаралды 11 МЛН