Login Register






The issue regarding searched threads returning 404s has been fixed. My apologies. - NekoElf
Thread Rating:
  • 0 Vote(s) - 0 Average


Dark.Fail warrant canary hasn't been updated filter_list
Author
Message
Dark.Fail warrant canary hasn't been updated #1
What is a warrant canary?
A canary is a posting that operators of a site can use to keep users of the site - whether that is a forum, a darknet market, an image board, anything - aware of any DMCA (Digital Millennium Copyright Act) notices, federal searches or seizures and other nefarious activities. The way this takes place, is that the owners simply do not update the canary. In case of seizures, where, typically, the government and LE will not take the site down directly, they will wait a while for other users to use the site (which is then under their control until it eventually gets taken offline).

If you're smart, like 4% of DNM users, you're aware that - on most serious onions - there are both a /mirrors.txt file and a /canary.txt file. Both of which, on Dark.Fail, in conjunction with the valid PGP signature of the owner, haven't been updated recently. The admin did recently have his site taken over or hijacked by "spammers". This was a very huge thing and you can google it when you have 5 minutes. It was a large blow to the security of Dark.Fail and it was mitigated by simply warning users directly on the .onion (which is not privy to such hijackings due to their not being a way to spoof or steal the domain) that there was a breach. The links from the Dark.Fail clear-net site were changed to other real websites that all looked the same to users but had been replaced by phishing links.

This attack went on for a while until the owner had gotten control again but the damage was so severe, many people probably lost money and completely lost their trust in the services hosted by the admin. Now, it has been a while since that attack, but the admin hasn't updated the canary file in quite some time, leading many to believe that the domain is, once again, not under control of a friendly entity.

A screenshot of the file is available here and has not been updated since the 5th:
[Image: Screenshot-2021-06-02-134538.png]
(This post was last modified: 06-02-2021, 06:48 PM by ConcernedCitizen.)
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply

RE: Dark.Fail warrant canary hasn't been updated #2
Interesting!
Although if the links didn't/don't change from official ones there's not much risk.
He's only 2 weeks late, let's see what happens next!

Reply

RE: Dark.Fail warrant canary hasn't been updated #3
I hope all is well and this isn't a bad situation for the owner of the domain. He isn't even doing anything wrong but we all know how unfortunate that turned out to be for Aaron Shwartz, Barrett Brown, etc. Linking to anything shouldn't be so criminally defined as it is today.
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

[+] 1 user Likes ConcernedCitizen's post
Reply

RE: Dark.Fail warrant canary hasn't been updated #4
The problem with these sorts of canaries is that they are open to lapses of error/forgetfulness. If there isn't a seizure page, that's generally a good sign.
[Image: fSEZXPs.png]

Reply

RE: Dark.Fail warrant canary hasn't been updated #5
(06-03-2021, 04:15 AM)Dismas Wrote: The problem with these sorts of canaries is that they are open to lapses of error/forgetfulness. If there isn't a seizure page, that's generally a good sign.
The admin of the site has not missed a check-in and has outstanding OPSEC, as far as the last few years I've known him to be running the domain.
It struck a lot of people as odd when he didn't update as usual, but I'll wait and see what happens. Could be they forgot, as you said.
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

[+] 1 user Likes ConcernedCitizen's post
Reply

RE: Dark.Fail warrant canary hasn't been updated #6
(06-03-2021, 08:36 AM)vittring Wrote:
(06-03-2021, 04:15 AM)Dismas Wrote: The problem with these sorts of canaries is that they are open to lapses of error/forgetfulness. If there isn't a seizure page, that's generally a good sign.
The admin of the site has not missed a check-in and has outstanding OPSEC, as far as the last few years I've known him to be running the domain.
It struck a lot of people as odd when he didn't update as usual, but I'll wait and see what happens. Could be they forgot, as you said.

He's been on Twitter recently, at the very least:
https://twitter.com/DarkDotFail
[Image: fSEZXPs.png]

Reply

RE: Dark.Fail warrant canary hasn't been updated #7
If no mislinking has occured, and no seizure has been announced, maybe remind him on Twitter to update it and see where that goes. If it still isn't updated, be hesitant about using the site. In the past, DNMs have done this when exit scamming.

More than likely though, since there isn't much to gain or exit scam at all, its just forgetfulness.
You can find me on Keybase
"Reach the state of ubiquity, and you will be in control"
Student, Technician, Designer, and more.
[Image: YUpAMpx.png]

Reply

RE: Dark.Fail warrant canary hasn't been updated #8
Any update? It is a lovely service and I would be very pissed to see them go down. It's not like deepdot who was taking funds from the markets....

Reply

RE: Dark.Fail warrant canary hasn't been updated #9
(06-11-2021, 07:16 AM)404errorist Wrote: Any update? It is a lovely service and I would be very pissed to see them go down. It's not like deepdot who was taking funds from the markets....

(06-04-2021, 06:18 AM)zorrophreak Wrote: If no mislinking has occured, and no seizure has been announced, maybe remind him on Twitter to update it and see where that goes. If it still isn't updated, be hesitant about using the site. In the past, DNMs have done this when exit scamming.

More than likely though, since there isn't much to gain or exit scam at all, its just forgetfulness.

Update: The canary has been updated but that doesn't really mean a whole lot - it took some extra time and the admin could have still been compromised. But the good news is that there isn't a potential exit scam, it's just some hosting index and none of the links are owned by the owner of the site. You should be PGP verifying every link anyways so it's not exactly a threat to most smart users of the darknet markets, blogs, such as Dread and Dark0de etc. Always verify links and vendors.
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply

RE: Dark.Fail warrant canary hasn't been updated #10
(06-11-2021, 07:20 AM)vittring Wrote:
(06-11-2021, 07:16 AM)404errorist Wrote: Any update? It is a lovely service and I would be very pissed to see them go down. It's not like deepdot who was taking funds from the markets....

(06-04-2021, 06:18 AM)zorrophreak Wrote: If no mislinking has occured, and no seizure has been announced, maybe remind him on Twitter to update it and see where that goes. If it still isn't updated, be hesitant about using the site. In the past, DNMs have done this when exit scamming.

More than likely though, since there isn't much to gain or exit scam at all, its just forgetfulness.

Update: The canary has been updated but that doesn't really mean a whole lot - it took some extra time and the admin could have still been compromised. But the good news is that there isn't a potential exit scam, it's just some hosting index and none of the links are owned by the owner of the site. You should be PGP verifying every link anyways so it's not exactly a threat to most smart users of the darknet markets, blogs, such as Dread and Dark0de etc. Always verify links and vendors.

Good to hear.

I was more worried about the owner than the links or whatever.

Reply







Users browsing this thread: 2 Guest(s)