Connect with us

Cars

The dark web is nothing fancy: It’s just a different set of protocols – like Tor

Published

on

Dark web criminals are selling tools to help target your firm’s data
Dark web listings of malware aimed at companies are on the rise.

Commonly when surfing the web, Transport Layer Security (TLS) is the cryptographic protocol that provides confidentiality for your communication with the server. The green lock on your URL bar is an assurance, but not a guarantee, that you’re communicating confidentially with the entity you think you are. While TLS is designed to provide confidentiality and identity, dark web protocols are designed to provide confidentiality and anonymity. There are many of these dark net protocols, but Tor is by far the most common, likely because of its use of exit nodes to allow a user to obtain anonymity on the public internet by routing traffic across the Tor network. 

On Anonymous Networks, Reputation Is Everything 

The quality of your collection strategy dictates how confident you can be in your analysis. Garbage in, garbage out. This is an often-ignored part of dark web marketing. Anonymous networks help segment your actual identity from the persona (or avatar) you develop on these dark nets. Because of this, the reputation of your developed persona is the only currency you truly have. Also remember that there’s no guarantee the person behind the persona you are interacting with isn’t a criminal, a threat intel company, or possibly even law enforcement! The story of the Besa Mafia is a great example of criminals scamming criminals, getting hacked themselves, and then law enforcement arresting people who were trying to hire these fake hitmen. It’s also not uncommon when law enforcement takes control of a hidden site only for them to continue hosting it in hopes of deanonymizing the users of the site. Basically, trust nothing. 

I Registered For Access, And All I Got Was This Low-Confidence Assessment 

Developing personas to obtain and, more importantly, maintain access is time-consuming and most of the work involved with good tradecraft on the dark web. Be wary that some “dark web intelligence” offerings skip the hard part and are just using technical collection to scrape information from essentially public markets and forums. To say this is a commodity capability would be a major understatement, as the ability to automate the scraping of websites is as old as the internet, and as we’ve established, dark networks really just reflect a difference in protocol selection. The use of the iceberg metaphor is a clever bit of psychological warfare . . . ahem, marketing . . . to remind you that they have access to all this stuff under the surface that you don’t. As someone who evaluates these vendors, many of them don’t either. 

Any Company Selling You On “Dark Web Intelligence” Is Only Talking About Its Collection Strategy . . . And There’s Big Problems With That 

After collection, the next challenge would be processing and exploitation. Processing is frequently discussed as stripping out things like HTML tags from the raw data that’s been collected. If you think that is a big deal, I have a regular expression (regex) to sell you. Where things get interesting is trying to exploit this data to get something useful on an analyst’s desk. Here’s a few examples: 

  • Very few, if any, public sector vendors have swaths of analysts translating everything on the dark web on a daily basis from languages such as Arabic, Farsi, Spanish, Russian, and Mandarin. How is this being done at the same scale as collection? 

  • How does your translation software handle slang? Without specific knowledge of a particular group, you would have no idea they are using the code name “Iowa” when describing a target in Iran. Keep this in mind if someone mentions they are going to Iowa next month; it might be a lot more exciting than it sounds. 

  • Then there’s something I call “the Target problem.” Target is a retail chain with stores in the United States, Canada, and India — many of you may be familiar with the brand. Now, imagine the data problem created in attempting to parse out relevant chatter about the Target brand from the rest of the noise on the internet. Incidentally, the string “target” appears five times in this blog post and only three times in the context of the retailer. 

A vendor cannot have an appreciation of these problems and not talk about their solution to them. If they are just trying to sell you on their ability to collect data from the dark web and then show you their platform, you don’t need to see the platform. 

Finally, There’s Some Really Bad Stuff On Dark Nets, But They Also Are A Critical Resource For The Oppressed 

I’m going to wrap this blog with a bit of a personal appeal. Anonymous networks are critical to journalists, whistleblowers, survivors of domestic abuse, people with sensitive medical conditions, the politically oppressed, and more. Please consider supporting projects such as the Tor Project or Tails — and if you’re in a decision-making position at an organization where people might assemble or seek to obtain information, please ensure that your site is usable when coming from a Tor exit node with JavaScript turned off. Unlike so much that we do in the cyberdomain, this can actually save lives. 

Must read: Revolutionize your security strategy by applying Zero Trust to your business.        

This blog was written by Senior Analyst Josh Zelonis and originally appeared here. 

Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published.

Cars

Today’s Wordle Answer #472 – October 4, 2022 Solution And Hints

Published

on

The answer to today’s Wordle puzzle (#472 – October 4, 2022) is bough, which is what you call a branch, especially the main branch, of a tree. The word bough has roots (no pun intended) in the Old English word “bōg,” which means shoulder, similar to Old High German’s “buog,” which means the same thing (via Etymonline). There’s a popular Roman myth about the Golden Bough, which is a tree branch with golden leaves that enabled the trojan hero Aeneas to travel safely through the land of the dead. 

We solved the puzzle in three tries today, kicking things off with an expert-endorsed starter word, slate. We tried the word brush next, which turned out to be a really lucky guess with three green tiles. The answer was apparent by the third guess, and since we also solved the puzzle in three guesses yesterday, that begins a three-try streak that we hope we can continue tomorrow!

Continue Reading

Cars

How To Display iPhone 14 Pro’s Dynamic Island On Any Android Device

Published

on

You can also choose whether to display the cutout at the center of the display (for hole-punch cameras on the center of the display) or on the left for cameras placed in the corner. Remember that as you increase or decrease the cutout size, the icons shown in it will also scale to match. Thankfully, the app gives you a preview of the cutout when you are changing the settings.

You can also modify gestures such as single tap or long press. Dynamic Spot also allows you to change the default time, after which the pop-up automatically disappears. Additionally, you can fiddle with a lot of appearance-related settings, such as the animation when the Dynamic Island clone pops up or unfolds.

Just as on the iPhone 14 Pro, the Dynamic Spot on your Android app will show the app icon when a new notification arrives. You may selectively choose which apps display the notifications or allow all apps of them. You can also tap on the app’s icon to open the notification or long-press the icon to preview the notification.

Continue Reading

Cars

The 10 Wildest Features Of The Mercedes Maybach Off-Roader

Published

on

Sustainability is a word on every car manufacturer’s radar right now, with more focus being given to the idea of eco-friendly vehicles than ever before. The Off-Roader plays into that theme by featuring a prominent set of solar panels mounted on its hood, which could be used to generate power to extend the range of the car. It’s worth pointing out that this is all hypothetical, as the show car is non-functional, and has no drivetrain. Mercedes is keen to stress, though, that if the car did have a drivetrain, it would be all-electric, although no detail is given on the power or range that would be available to drivers.

The solar panels are interwoven with yet more Maybach logos, and their tinted finish makes them blend in almost seamlessly with the rest of the hood. It’s been pointed out by industry analysts that adding solar panels to cars is not always as environmentally friendly as it might seem, as the panels are only able to generate a very small amount of power. That power can easily be consumed by the added A/C strain caused by parking a car out in the sun all day to charge it. Car-mounted solar panels might be a flawed idea in practice, but even so, it’s interesting to see how Abloh was able to inconspicuously add them in without compromising the overall look of the car.

Continue Reading

Trending