×
all 11 comments

[–]gwern 3 points4 points  (8 children)

Your site is leaking its IP and is not anonymous. Your security skills are bad and you should feel bad.

[–]26a2ueoc3xxrrgs4Tor Social Network / Marketplace 0 points1 point  (7 children)

Why should I or our admin feel bad? We only wish we had bitcoins to give to you. As for the leak, as you know 100% of our site is built using free open-sourced software. We're still kinda in beta as you can tell. We have been having problems with the way the ad pages were displaying, in particular the css. It was driving us crazy and some members even complained about it. As a test we linked directly to the css file and everything worked and looked fine. but we see that it displays the full path to the file! Thanks for pointing that out. In any event our site is assigned a new random IP address every few hours or so. we've since linked to the original css and will just fix the display problem from there. Since we have your attention, we're also wondering if you can become an active member of our site, like head of internal security or something. We realize you're probably swamped but our community really needs someone like you. Hope to see you there. BTW. In no way are we brushing off this incident! We take security and privacy very serious. But be aware that our site may have both clear web access and .onion access. The reason we chose this route is for users who don't mind browsing our site through the clearweb, it's faster and the name is easier to remember. We haven't implemented that part as we are waiting for more members before we put it up for a vote. Again for those who would like to browse our site through the clearweb that option may be available. Feel free to bring to our attention any other issues.

[–]gwern 1 point2 points  (6 children)

In any event our site is assigned a new random IP address every few hours or so.

AWS likely keeps records indefinitely, like most any other host. This is the same point I made as in Black Goblin's case: anyone who noted down the IP address (it's in dozens of people's IRC logs now, incidentally, and several others have been watching to see how long it would take you to notice until I got impatient) can turn it over to LE, and they can look up the connecting IPs, accounts, and payment methods, and image the VM.

We take security and privacy very serious. But be aware that our site may have both clear web access and .onion access. The reason we chose this route is for users who don't mind browsing our site through the clearweb, it's faster and the name is easier to remember.

Let me remind you of your plans to directly facilitate sales:

Ads & Multi-Sig

We offer a FREE place for Vendors to advertise. As well as Multi Signature Transaction support

How do you plan to survive on the clearweb?

[–]26a2ueoc3xxrrgs4Tor Social Network / Marketplace -1 points0 points  (5 children)

Darknet Nation is bigger than a .onion site or a VM on AWS. Maybe our definition of darknet is different. Darknet Nation is a movement. We are not a marketplace. We do not handle bitcoins, cash or any type of curency. Have you guys seen the price of bitcoins lately? Anyways, we use open sourced software to achieve our goals. Technology, software, and ways of gathering and disseminating information changes extremely fast and we at Darknet Nation keeps abreast of the current and relevant trends. We use Reddit (clearnet btw), Pidgin with OTR, Google+, AWS, PGP, multi signature transaction, several CMS's, LAMP stacks, android, SIP, http, https, ssl, etc. Whatever the open sourced community may offer if we can benefit from it we use it. A tip for system admins AWS accepts Vanilla Visa. Our offer still stands about helping us out with your skills. Come join the movement, we like your ideas and meticulous nature. To anyone else that may want to help the nation grow be sure to check the .onion site out. Like we stated earlier our full contact info will be coming soon, including Pidgin username, clearnet website url, irc channel, xxmp server, pgp public key, secure emails, and any other way we can be reached.

[–]gwern 2 points3 points  (4 children)

We are not a marketplace. We do not handle bitcoins, cash or any type of curency...We use Reddit (clearnet btw), Pidgin with OTR, Google+, AWS, PGP, multi signature transaction, several CMS's, LAMP stacks, android, SIP, http, https, ssl, etc.

What do you plan to do with multi-sig transactions if you are not in any way a marketplace and do not have the slightest trace of legal culpability or involvement in conspiracy to distribute drugs?

[–]26a2ueoc3xxrrgs4Tor Social Network / Marketplace -1 points0 points  (3 children)

This is our last comment on this topic, your statements are starting to assume way too much. Either you're very young, the site admin of a marketplace site that has centralized escrow, or somebody in the business of assuming we are any way part of some conspiracy. Thanks for saying that btw. Our Multi Sig Transaction app is A FREE OPEN SOURCED project that ANYBODY can download and use! We did not create it. it is availabe here https://coinb.in/multisig/. We don't plan on doing anything with the app that it wasn't designed to do. Create a Multi Signature Transaction! Like I said in the beginning, you're assuming way to much into the negative about our movement. Darknet Nation believes in free speech and the right to disseminate information. For everybody else, come join the movement, we could use you.

[–]gwern 1 point2 points  (2 children)

Either you're very young, the site admin of a marketplace site that has centralized escrow, or somebody in the business of assuming we are any way part of some conspiracy.

If you really are familiar with my work, you understand why I expect marketplace operators to lie to me about security and try to minimize and evade any real questioning about it.

[–]26a2ueoc3xxrrgs4Tor Social Network / Marketplace -2 points-1 points  (1 child)

Marketplace operators? Sir, we are not a marketplace. As for questioning site security, thank you for your input and we look forward to more. Has the ip leak been "fixed"? I'm not sure as I have no access to the Site administration, besides blog access, which is down at the moment until we find a suitable workaround. (side note, I personally don't give a shit whether the ip is broadcasted, hell we do have a bunch of clearnet contacts anyway. But the admins insist on doing it similar to what you suggested? Which is...?) Our security is handled by the community if you can help we'd love to have you on board (no pun intended)

[–]talkb1nary 2 points3 points  (0 children)

I like the design and everything, but what makes this service unique or even useful? What differs it from torbook? (except from js atleast beeing optional)

[–]aalewis____ 0 points1 point  (0 children)

some parts look kinda funky but still pretty good

[–]NekroTor -1 points0 points  (0 children)

Haven't said this in a very long time about an .onion service... I'm impressed