HN user

dobbsbob

1,976 karma
Posts0
Comments721
View on HN
No posts found.

http://www.psmag.com/science/vancouvers-free-heroin-injectio...

They gave 322 homeless street addicts free opiates, which allowed them to sort their lives out since their day to day activities weren't entirely consumed with scoring heroin. Property theft and street violence also plummeted, saving ambulance costs for overdoses, and the police and courts millions which was all in the full SALOME study as most of the addicts used property crime to fund their addictions.

I imagine BI would do the same. Instead of being on an automatic pilot mode of desperately finding money for drugs and booze everyday there would be time to reflect and maybe seek out detox.

Bank xfers they will transfer to a cashing service, somebody willing to use fake identity to open business accounts to receive stolen funds and show up in person to a bank to withdraw it, then pay back a percentage to whoever sent the funds via bitcoins or other method. A good fraudster will ddos the bank after the transfer(s) to prevent the mark from logging into online banking and discovering the fraud.

Credit cards they make their own fake stores by the hundreds and pay themselves small amounts, or they do instore fraud which is extremely risky. In the UK they simply card Tesco and then sell the groceries half price. Can also fraud bitcoins now as services exist to buy small amounts. None of this is easy, profits aren't huge it's all very small time unless you're the guy getting and selling the data to the legions of petty hustlers worldwide.

German police and intel agencies sent 440,000 sms type0/stealth attacks to trace phones last year, FBI sent an OTA to a suspects internet stick to broadcast his location, and something shady is going on at airports according to Cryptophone GSMK who's radio 'firewall' goes off whenever you get near an airport. Besides that Samsung backdoor found by Replicant Mod that has access to /data and /sdcard haven't heard of other directed attacks yet.

Of course google can install whatever they want on your device if given a NSL including a modified WhatsApp that sends in plaintext straight to the police everything you type but haven't heard of that yet either.

Since Facebook makes money harvesting data wonder if WhatsApp grabs advertising keywords first then sends via textsecure layer.

Indeed, it works like freenet IRC where you have to make an account first then log in to it with Tor. This is solved by making a throwaway VPS or virtual desktop you ssh into with Tor, make your account, shred the VPS and then change the password when you log in directly to Fb with Tor.

You can also edit Torrc to temporarily only use your own Tor exit nodes if worried about malicious exits while setting up accounts.

You can exchange bitcoins on IRC for prepaid virtual visas and mastercards, paypal, any 3rd party payment you want. There's a few web services for exchanging coins to visa too, which I can't remember right now but are posted to bitcointalk forums.

Of course if you were setting up an illegal hidden service payment would be the least of your worries. Moving it around every few weeks inside Russia like the inter-dimensional dark fortress in Krull to prevent long term traffic analysis, maintaining your site from a moving location everyday, and making sure you don't blow opsec giving away your identity is probably more difficult than finding creative methods to pay for hosting.

Vendors there sold phony identification for the sole puposes of renting drops to import narcotics or start a false front company. SR wasn't involved in trading databases of stolen info, though the other major sites that weren't busted are. Agora is like the walmart of e-crime

SR#1 they created the Armory, a seperate market. It was full of scams and extortion attempts so shut it down. Best listing was some guy in Russia trying to peddle uranium for GPS coord drop.

He sold cookie cutter stores that vendors bought and wouldn't take long to que up puppet and deploy a .onion for the hundreds of vendors on SR2. I wouldn't give Tor a green light either though, esp with people considering peddling narcotics using that p2p alpha market software Open Market where you run your own server. Seems incredibly risky for timing analysis plus nobody knows how they discovered SR #1.

The SR2 guy 'defcon' was also selling his services as a .onion developer/ops so likely all these other sites he set up for vendors and they were seized when he was caught and cooperated. From the FBI complaint he was completely careless like all other recently busted darknet admins and mods so wouldn't be surprised if they were all hosted at the same host too.

They catch Russian carding marketplace admins all the time so living in Brazil or Russia is no guarantee you won't end up in jail either. Just takes one mistake and you are on a plane in handcuffs to a federal court. They could bribe local police to pick you up for them too especially if you aren't politically connected in those countries.

Textsecure for Android uses wifi/reg data and SMS if you want. Signal, the version for iOS with combined Redphone + TextSecure will be data too. Soon they will also allow email identity instead of only phone numbers. WhatsApp requires just as much registration as TS, and you have to allow WhatsApp full permissions to mine your entire device from reading SMS to /sdcard.

A friend of mine in Washington DC can go down to a public park where they have movie night in the summer, and with a bunch of random people they can openly drink wine and enjoy a movie outside without incident.

Every time they have temporarily relaxed drinking laws to try something similar here like DC movie night it resulted in brawling, stabbings, street hobos showing up to scream gibberish and aggressively pan handle, and the audience got so wrecked ambulances had to be called. It's like the heavy regulations that the West Coast cities screws into society creates a community that turns to bedlam the moment those chains are temporarily removed.

There is plenty of extortion attempts, not for narcotics but for weapons sales many of those listings are criminals who will threaten you once they get an address according to their market forums. Buying a gun online isn't really necessary, here gangsters pop down to Arizona and buy any gun they want on craigslist or local classifieds for cash in a parking lot, then mail the gun(s) in pieces camoflauged with spare bicycle parts back to themselves.

Most buyers on these sites are using some kind of drop, like a virtual office that accepts the package then forwards it or they go pick it up.

Encryption and password locks are pointless against a cartel, presumably they will employ rubber hose cryptanalysis to get any information they want.

Seems like one solution would be to have a web browser that keeps no history, and use that to log into Twitter and report about cartels instead of an app that automatically logs you in or keeps history, or gives away the fact you have a twitter account they will demand to know about.

There's also schemes like this which could be helpful to at risk journalists https://www.ccsl.carleton.ca/~askillen/mobiflage/ unless you are kidnapped while in PDE mode.

If it's any small comfort, whoever was seen involved in this kidnapping is now a liability, as this case has brought a lot of heat so they were almost certainly finished off in the desert by their own cartel compadres to avoid potential snitching. The blog borderlandbeat has countless posts of mass executions the cartels do on their own guys as everybody except the capos are disposable.

edit: Likely cartels have employees at telecoms in Mexico to look up logs for them, there's prob no easy solution. It wouldn't be expensive for them to hire anybody to exploit journalists with old carrier builds that are never updated either http://nakedsecurity.sophos.com/2014/09/16/shocking-android-...

The UK if I recall already has very strict libel laws, where you can accuse somebody of libel and they have the burden of proof to prove they didn't libel you, which is why authors leave England for the US like Christopher Hitchens did. David Irving wasted everybody's time abusing this law http://en.wikipedia.org/wiki/Irving_v_Penguin_Books_and_Lips...

Are these new laws even needed? Between the harsh libel and existing criminal laws on threatening what difference does this new law make except the slightly broad definition of "verbally abusive". I can think of a few The Exploited or Sex Pistols songs that will likely now be deemed verbally abusive towards the Queen.

It does go away, nobody remembers Boxxy/Katie of youtube/4chan fame? The horde went after her worse than threats and calls yet she's still there making vids. She didn't write a big victim blog or appear on Oprah (Jessi Slaughter) and the lynch mob quickly lost interest when denied their reaction prize.

Threats of course should be handled by police and not ignored, but the moment you seek media attention or acknowledge how the horde has "ruined your life" you are throwing gasoline on the fire.

Media has distorted the meaning of trolling. You would never outright threaten or ad hominem attack somebody while trolling them because that would be too obvious. This is what trolling actually is (well, was) http://youtu.be/AHqGV5WjS4w

Doxing, also now totally misused. Hackers would drop dox on each other to expose them to all the secret service agents and FBI agents watching. If somebody is not wanted by the feds and using their real name on social media there's no point in telling the world their information, considering there are eleventy billion personal data mining services to find out anybody's complete personal info for under $10. We're all already doxxed.

The worst thing you can possibly do when a horde of e-cretins is trying to bait you into losing face in public is to acknowledge them by writing "I'm a victim" posts and articles. That's exactly what they want. If you get death threats sue their asses or call the police. Otherwise that horde is just a bunch of meaningless text on a screen you can safely ignore that will quickly move on to a more responsive target.

https://mobile.twitter.com/kpoulsen/status/52246310994522931...

All they did was smear away the logo in photochop, though their OEM might have provided this image. Anybody can make their own Anonbox with a Cubieboard or similar Allwinner A1x/A20 box for under $60. Or use thegrugqs PORTAL on a chipped TP-Link router you can find plenty on amazon/ebay for $40 https://github.com/grugq/portal/blob/master/README.md