Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Privacy Security Technology

Alleged Dark Web Kingpin Doxed Himself With His Personal Hotmail Address (vice.com) 62

Joseph Cox, reporting for Motherboard: On Thursday, US authorities announced the seizure of the largest dark web marketplace AlphaBay. Europol and Dutch police also claimed seizure of Hansa, another popular market. In their dark web investigations, law enforcement have increasingly turned to hacking tools, including the deployment of browser exploits on a mass scale. But tracking down the alleged AlphaBay administrator was much more mundane, officials said. Alexandre Cazes, who US authorities say used the handle alpha02 as administrator of the site, allegedly left his personal email in a welcome message to new AlphaBay members, according to the forfeiture complaint published on Thursday. The news echoes the arrest of Ross Ulbricht, the convicted creator of the original Silk Road, who made a similar security mistake. "In December 2016, law enforcement learned that CAZES' personal email was included in the header of AlphaBay's 'welcome email' to new users in December 2014," the complaint reads. Users received this message once they signed up to AlphaBay's forum and entered an email address. Cazes' email address -- Pimp_Alex_91@hotmail.com -- was also included in the header of the AlphaBay forum password recovery process, the complaint adds. From there, investigators found the address was linked to an Alexandre Cazes, and discovered his alleged front company, EBX Technologies.
This discussion has been archived. No new comments can be posted.

Alleged Dark Web Kingpin Doxed Himself With His Personal Hotmail Address

Comments Filter:
  • He used the same email address in his LinkdIn profile.
    • by Anonymous Coward on Thursday July 20, 2017 @06:41PM (#54849779)

      He Dohxed himself.

    • by wbr1 ( 2538558 )
      But we need encryption backdoors!
      • by infolation ( 840436 ) on Friday July 21, 2017 @12:44AM (#54850961)
        Cazes provided his own encryption backdoor, because the police literally walked into his house through the back door and found his computer running unencrypted and connected to alphabay. [wired.com]

        Although the linked article doesn't mention the link between his email and his 'front' company, the Wired article says that police identified him because his Hotmail address was linked to a PayPal account which was linked to his company.

        My head reels at the inept OpSec of this clown. He runs the largest illegal marketplace in the world, yet posts links to his real PayPal account. With no visible source of income, he lives a high profile lifestyle in Bangkok with 3 houses and the most expensive Lamborghini they make, while running the marketplace with an unattended decrypted laptop. Another demonstration that intelligence and common sense rarely go hand-in-hand.
        • by tlhIngan ( 30335 )

          My head reels at the inept OpSec of this clown. He runs the largest illegal marketplace in the world, yet posts links to his real PayPal account. With no visible source of income, he lives a high profile lifestyle in Bangkok with 3 houses and the most expensive Lamborghini they make, while running the marketplace with an unattended decrypted laptop. Another demonstration that intelligence and common sense rarely go hand-in-hand.

          The problem is greed. I'm sure when he started out he was careful. But after tha

          • by Tom ( 822 )

            proper opsec requires you to not get greedy, so remove all thought of making lots of money - just make enough to pay for itself.

            Nonsense. What you need is plausible deniability. Invest in a wide portfolio of stocks, launch a startup company or two, invent three more that - on your CV - you sold for an undisclosed sum to an unnamed "big player". Become a regular at several casinos.

            None of that will stand up to close scrutiny. But it will help avoid close scrutiny, because someone wondering where you get your money from has a couple possible answers to choose from.

          • The guy was brought up in the boonies, repairing computers from home was his business. In a town of 2,775 people, with a population density of 8 acres per person (78 per square mile), there's not much except farmlands and forests, so not exactly a goldmine for a computer repair business. It's something that someone who doesn't have a clue what they want to do after high school will drift into. After all, how hard is it to reformat and re-install?

            And anything else more complicated - "you need a new computer

        • by AmiMoJo ( 196126 )

          It amazes me that someone has the knowledge and skill and desire to run a dark web illegal market, something which many others have already been caught and sent to prison for decades for, and yet they don't bother to learn the most basic elements of security.

          Somehow they read through all the documentation about setting up a dark web site, full of warnings about how seemingly minor mis-configuration can compromise the whole thing. They got systems in place to handle payments between users, with some sliced o

          • by rtb61 ( 674572 )

            There is an old saying "just know enough to be dangerous" and that is exactly what applies here. Learned enough to set up a dangerous, if fact very dangerous network but don't bother to learn more to secure it. This applies across all professions, which is why there are so many licensing boards, idiots learn enough to do the job badly and then go ahead and do it, just very badly. This often ties in with another saying, greed driven stupidity, where greed overcomes common sense and people don't bother to loo

    • by borcharc ( 56372 ) *

      It still took them several years and millions of dollars to figure it out.

      • Or they could have just done this [slashdot.org]. Given the linkedin profile (which used the same email addy that was sent out with every registration and password reset for his site), you get his business name, and from that a quick search of government records (follow the links) yields his name and other details. Literally 1 minute.
  • Dupes for those that don't RTFA? Or is to that slow a news day?

  • by Anonymous Coward

    Can you buy legal stuff on these sites? Or only illegal crap. I'd buy just to avoid Amazon tax.

    • by Anonymous Coward

      There is a wide variety of legal goods sold on such sites. Mostly things that would be of interest to the same clientele.

  • You'd think these people would have a clue that there are going to be powerful people with a great deal of resources doing everything possible to track them down. Perhaps some sort of impairment was involved?

    Oh, well, to quote Law Dog, "Are you listening? Quit guinea-pigging the product. Seriously."

  • Ok, this guy was exceptionally stupid, or maybe he got arrogant over time, whatever. But there's a lesson to be learned here: Anonymity is actually hard.

    Here, and on most sites, I use my real identity. On some sites, I post under a pseudonym with its own email address. For me, it's not critical, but I still try to keep the pseudonym separate. It's a lot harder than you suppose - it's easy to mix the two identities. If privacy were a serious concern, it would be essential to always use proxies for the pseudo

    • by green1 ( 322787 )

      I too have a second "private" identity I use in a very small handful of places. It's hard to maintain, and I have no illusion that it would protect me from a government entity, only from random person who wants to link it to me.

      A true private identity that could not be linked to me by a government agency? I think it would be possible, but it would be very difficult to both set up, and maintain long term. I do have an idea how to do it, but it's just too much effort to be practical.

    • by tlhIngan ( 30335 )

      Ok, this guy was exceptionally stupid, or maybe he got arrogant over time, whatever. But there's a lesson to be learned here: Anonymity is actually hard.

      Here, and on most sites, I use my real identity. On some sites, I post under a pseudonym with its own email address. For me, it's not critical, but I still try to keep the pseudonym separate. It's a lot harder than you suppose - it's easy to mix the two identities. If privacy were a serious concern, it would be essential to always use proxies for the pseudo

  • Is there anyone here (an anon please!) who received this supposed welcome email and can post the headers for us to see? Or are we supposed to take LEA's word for it? How would none of the thousands of Alphabay members not have noticed this email address and doxxed him earlier? Color me skeptical.
    • > How would none of the thousands of Alphabay members
      > not have noticed this email address and doxxed him earlier?

      Think about this carefully... do you ***REALLY*** want law enforcement to know that you're a member of Alphabay? Guess what happens when they seize the servers and find what transactions you did there. A police undercover agent is the only guy who could admit to being on Alphabay, assuming that he was investigating it. Anybody else ends up in the slammer.

As you will see, I told them, in no uncertain terms, to see Figure one. -- Dave "First Strike" Pare

Working...