deep dark web - how to get inside?
TRANSCRIPT
1
Deep Dark Web
How to get inside?
- Anshu Prateek
2
About me?
● http://about.me/anshuprateek● Manager, Devops at Reliance Jio Public Cloud● Ex – Aerospike, Yahoo! Search● @anshprat / hackalyst.info
3
Agenda
● Disclaimer● What is deep web?● What is dark web?● What is Tor?● Why to use tor on surface web?● How to enter the dark web?● How to stay secure on dark web?
4
Disclaimer
● This presentation is provided for informational and technical training purposes only.
● It is intended to familiarize you with some of the methods, tools and services used to provide Internet anonymity.
● It may at times “pull back the veil” and offer a look at the darker side of the Internet. If your senses are easily offended, this session may not be for you.
● Neither I, Reliance Jio Infocomm, or anyone who employs me, in any way encourage or support using the information presented in this session for illegal, or unethical purposes.
● Individuals should have the authorization of the system and network owners before using any of the tools or techniques demonstrated or described here on any systems, networks, or applications
● http://www.slideshare.net/jlmaynard/acpe-2014-internet-anonymity-using-tor?qid=d3f2eb23-85d6-4010-b902-3e352da3c9b5&v=qf1&b=&from_search=3.
5
What is deep web?
● The part of the World Wide Web not indexed by traditional search engines.
● The Deep Web, Deep Net,Invisible Web, or Hidden Web are search terms referring to the content on the World Wide Web that is not indexed by standard search engines.
● Computer scientist Mike Bergman is credited with coining the term in 2000.
6
Deep != Dark
A website requiring login is part of deep web.Example – gmail, private twitter accounts, private fb accounts.
7
How big is the universe?
●Ok, how big is the surface web?
●And then the deep web??●And the dark web???
8
How big is the surface web?
As of 2014 Google has indexed 200 Terabytes (TB) of data. However, Google's 200 TB is just an estimated 0.004 percent of the total Internet. Jul 22, 2014
9
The Surface Web (aka the internet)
Google knows 0.004% ONLY!
10
And its not just quantity… … but quality as well!
11
12
What is dark web?
Part of deep web that cannot be accessed via normal browsers or methods.
Example – The hidden wiki
kpvz7ki2v5agwt35.onion
13
Is it all illegal???!!!
Not really.
The guns used by terrorists and security forces are same.
Facebook is on tor.
https://www.facebookcorewwwi.onion/
Emails / IM
Wikileaks
Tor was invented as a U.S. Navy research project in 2002
But yes – Some (a lot?) of dark web is on the other side of the gray line.
14
So can I let my kid on the dark web?
Probably not.
Most of it is 'hidden' for a reason.
15
Silk Road
16
Silk Road 3.0
17
How do I enter the dark web?
Khul ja sim sim!● Tor – https://www.torproject.org/● I2p - https://geti2p.net● Freenet - https://freenetproject.org/
18
Show me the good stuff!
19
TOR
● Tor prevents people from learning your location or browsing habits.
● Tor is for web browsers, instant messaging clients, and more.
● Tor is free and open source for Windows, Mac, Linux/Unix, and Android
● Anonymity Online● Protect your privacy. Defend yourself against network surveillance and traffic analysis.
20
How TOR works?
https://www.torproject.org/about/overview.html.en
21
22
23
24
Tor makes me Invisible?
Tor can't solve all anonymity problems. It focuses only on protecting the transport of data. You need to use protocol-specific support software if you don't want the sites you visit to see your identifying information. For example, you can use Tor Browser while browsing the web to withhold some information about your computer's configuration.
Also, to protect your anonymity, be smart. Don't provide your name or other revealing information in web forms. Be aware that, like all anonymizing networks that are fast enough for web browsing, Tor does not provide protection against end-to-end timing attacks: If your attacker can watch the traffic coming out of your computer, and also the traffic arriving at your chosen destination, he can use statistical analysis to discover that they are part of the same circuit.
25
Tor on mobile?
Android – Torfox / Orbot
Windows – Nothing really – VPN+TOR service is your best bet.
IOS – Official TOR app is in progress after ios 8.0, some paid apps w/ tor support
26
Tor + Torrent?
So – can I use Tor along with Bittorrent to download my perfectly “legal” copy of that piece and then no one would know who I am? :)
27
Tor + Torrent?
No!
https://blog.torproject.org/blog/bittorrent-over-tor-isnt-good-ideahttp://tor.stackexchange.com/questions/64/how-can-bittorrent-traffic-be-anonymized-with-torTribler – Work in Progress.
28
Can we get inside now please?
https://www.torproject.org/download/download-easy.html.en
https://www.facebookcorewwwi.onion
http://bit.ly/hiddenwiki
https://en.wikipedia.org/wiki/List_of_Tor_hidden_services
29
30
How to stay secure on the dark web?
● No JS / No plugins.● Update! Daily! Yes – even the Fedoras and the Ubuntus!
● Use a VPN if you can. (But definitely not your company VPN for browsing the dark net!)
● DO NOT USE YOUR REGULAR USERNAME/PASSWORDS!
● Use Password manager – example KeePass!● Do not buy the latest iPhone off the dark web even if its dirt cheap. (Unless you have lots of black money you dont mind losing).
31
How to stay secure on the dark web?
● And even if you end up “buying” anything, remember – bitcoins are the only currency to be used.
● Tumble your bitcoin before using.● Most of the darknet runs on http.
32
Its not all bad :)