Identifying Darknet Suspects: When Law Enforcement Hacks

No ratings

Presented at TechnoSecurity&DigitalForensics 2019 by

Increasingly, drug dealers and child abusers are using darknet anonymising technologies to peddle their wares and collaborate with like minded individuals. In many cases, this entirely thwarts law enforcement's ability to identify them giving them free reign to act with impunity. However, in recent years we have seen a select few agencies using computer vulnerabilities in common software (e.g. Firefox) to gain remote code execution (RCE) on the suspect's computer and force it to identify itself. These techniques, often called Network Investigative Techniques (NITs), have been deployed in a small set of darknet investigations allowing the identification and arrest of thousands of high value suspects who would have previously remained hidden. In essence, except for their end goal, NITs are no different from tools deployed by cyber criminals. In this session, the presenter will give an overview through a series of case studies of the use hacking capabilities to remotely compromise computers operated by criminals and collect evidence. Attendees will learn; An overview of a series of international darknet investigations; How Network Investigative Techniques work at a technical level; and Legal complications around the use of NITs.