These are not standard parts to the image, based on previous seizures. (though I'll admit those all were clear-web seizures that just took over the DNS and resolved back to a gov controlled IP hosting a image - here the image is hosted on-site).
So there is a chance that this is DPR's "dead-man" script running after DPR was not able to communicate with the site for X hours.
It's hard to tell if the actual site (with it's data) has been taken over or compromised.
There is also the possibility it's only the onion domain-name that has been taken, though I'm not sure how TOR/ONION works (if that's possible without access to the server).
In any way, I hope that none of you used a plain-text (vs a PGP'ed one) home address for your recent orders, nor have any tracking #s lingering in messages from the vendors in your accounts. If I recall correctly, messages are deleted after 30 days. But who knows what type of backups where maintained.
It will be intresting to see if -
1. There are admins that have access to the data + site that can get it back up and operational.
2. The forums (which are still working) will produce another site.
3. BMR (BlackMarketReloaded) and another one I'm not familiar with called Sheeps Market will continue to operate and/or pick up the majority of SR's business.
...and also if the DEA and FBI will go after the users (and not just the vendors) that they can find enough "conspiracy to commit" evidence on to make a point.
Tor .onion addresses work by signing a message to a gateway with your RSA-1024 private key, while the actual address is the first half of SHA-1 of the public key. [0] So you have to brute force 80 bit to find a collision for a specific hidden service and you need to break RSA-1024 to actually impersonate a .onion hidden service. In the light of recent news, both seems to be borderline possible. But as far as I understand, brute forcing a SHA collision would lead to strange error messages or some people who can see the original and some who see the FBI version. Since no one reported anything like this, they would need to brute force the RSA key pair for SR in order to hijack the domain.
For the other two possibilities, why would DPR's dead man switch pretend to be a FBI note instead of a 'dead man warning,' especially since a hoax FBI message would immediately destroy SR? So I would assume that the FBI managed to get the actual hardware.
While that would let you 'impersonate' a hidden service, you would have to hope the actual hidden service goes down because otherwise the HSDir servers will point requests to the proper host and requests will be encrypted to their key
AFAIR there is nothing in TOR that prevents races between two servers trying to get a specific .onion address. So my understanding is, that a collision ( or a broken RSA private key) would put the HSDir into a inconsistent state. And in this case, some people would get the real server and some people would get the impersonated server. ( Additionally TOR hopefully warns if the public key of a hidden server suddenly changes.)
If I recall correctly, it's basically a case of last server to update the dir servers wins, so impersonating hidden services shouldn't be too hard unless the actual service goes down and is restarted.
In the document they released they made it clear that the server had been located and compromised. An image of the server from July 2013 was part of the evidence in the indictment.
While I hope a dead man switched was flipped it doesn't look good for the integrity of the site. Hopefully everyone involved was smart enough to encrypt.
I have not read it yet, but from what others have quoted, it looks like a disk image was made and handed over in July. Nothing else.
The disk image would of course contain the heavily encrypted data of SR (wallets, transactions, messages).
So unless the private key was on the server right next to the public key (AKA the Linode Incident), or the site did not encrypt that data (which goes against what we have seen so far), the disk image would not compromise that much.
Messages between buyers and sellers are generally encrypted end to end using PGP by the users so that information, which includes shipping addresses, is likely safe.
Notice:
1. The SilkRoad Camel image in the background.
2. "THIS HIDDEN SITE HAS BEEN SEIZED" text.
These are not standard parts to the image, based on previous seizures. (though I'll admit those all were clear-web seizures that just took over the DNS and resolved back to a gov controlled IP hosting a image - here the image is hosted on-site).
So there is a chance that this is DPR's "dead-man" script running after DPR was not able to communicate with the site for X hours.
It's hard to tell if the actual site (with it's data) has been taken over or compromised.
There is also the possibility it's only the onion domain-name that has been taken, though I'm not sure how TOR/ONION works (if that's possible without access to the server).
In any way, I hope that none of you used a plain-text (vs a PGP'ed one) home address for your recent orders, nor have any tracking #s lingering in messages from the vendors in your accounts. If I recall correctly, messages are deleted after 30 days. But who knows what type of backups where maintained.
It will be intresting to see if -
1. There are admins that have access to the data + site that can get it back up and operational.
2. The forums (which are still working) will produce another site.
3. BMR (BlackMarketReloaded) and another one I'm not familiar with called Sheeps Market will continue to operate and/or pick up the majority of SR's business.
...and also if the DEA and FBI will go after the users (and not just the vendors) that they can find enough "conspiracy to commit" evidence on to make a point.