Week 3 - The Dark Web Flashcards

1
Q

What are ‘don’ts’ when using TOR?

A
  • Don’t have a clear web browser open
  • Don’t use screen capturing software / add-ons unless you are aware of the implications
  • Don’t use a VM (leaks that you are using one & you want to appear like a regular user)
  • Don’t right click and save images
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are ‘do’s’ when using TOR?

A
  • use ‘ctrl prt sc’ / snipping tool
  • disable JavaScript on Tor in the settings
  • use refresh function to refresh your IP regularly when visiting different sites.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is TOR?

A
  • The Onion Router
  • open-source
  • enabling anonymous communication
  • directs Internet traffic via a free, worldwide volunteer overlay network that consists of more than seven thousand relays
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Usefull Links on DarkNet?

A
  • Hidden Wiki - list of popular Onion sites
  • Dark.fail - Also a list of popular onion sites, but in the clear web
  • Torch - Search Engine for Onion sites
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are positive aspects of the DarkNet?

A
  • Privacy - escaping regimes blocking communication (e.g. China)
  • Whistleblowers - leak information without disclosing their real identity (e.g. Wikileaks)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Payment Methods used in the DarkNet?

A
  • ESCROW
  • DIRECT DEAL / FINALISE EARLY
  • MULTISIG
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is ESCROW?

A
  • payments between a seller and a buyer are managed by a third party.
  • funds are held ‘in escrow’ & released to the seller once the buyer has received their items.
  • funds are managed by the marketplace - there has been a history of stealing customer funds (exit scams).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Direct Deal / Finalise Early payment Method?

A
  • no marketplace involvement in the financial transaction
  • payment up front before delivery
  • only trusted vendors
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Multisig darknet payment?

A
  • more complex & more advanced than escrow
  • Uses public key system between 3 parties - the buyer, the vendor & marketplace
  • need 2 of these 3 public keys to ‘unlock’ the payment
  • Only secure if the vendor & the market place are not the same eprson.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is PGP used for in the DarkNet?

A
  • verify communication between buyer and vendor (check authenticity of messages)
  • verify if site is active and operated - canary message signed every x days
  • verify funds - message encrypted using private Key of wallet
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does PGP stand for?

A

Pretty Good Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Investigation Techniques for Dark Web Marketplace Vendors

A
  • OSINT to research: username or profile image
  • Search the clear web on their key phrases / slang and descriptions. * Look for unique / wrong spelling and grammar
  • Exploit postal tracking services. E.G Can you get tracking numbers for TOR IP addresses?
  • UC tactics. Controlled purchases / infiltration
How well did you know this?
1
Not at all
2
3
4
5
Perfectly