/r/DarkNetMarkets
has received its first known LE subpoena: a request for 5 accounts'
data, including mine, related to Evolution and the supposed
doxing/leaks.
Recently (2015-03-25), I was alerted by Reddit that there had been a
subpoena for my Reddit account information and they would be responding
by 2015-03-30; this followed their privacy policy where they inform all accounts affected by subpoenas if there is no gag order (which is more than most websites will do for you):
16. We may disclose - or preserve for future disclosure - your
information if we believe, after due consideration, that doing so is
reasonably necessary to comply with a law, regulation, or valid legal
process. If we are going to release your information, we will do our
best to provide you with notice in advance via reddit's private
messaging system unless we are prohibited by court order from doing so
(e.g., an order under 18 U.S.C. § 2705(b)). We reserve the right to
delay notice to users in cases involving the exploitation of minors and
when we believe a delay is necessary to prevent imminent and serious
bodily harm to a person.
Such subpoenas are not unprecedented, especially for third-party data; see for example the 2014 Reddit transparency report. The subpoena (#BA13CR12BA0018) turned out to be a 2-page "21 U.S.C. § 967, Public Law 97-258, section 1, as amended" (Controlled Substances Act) administrative subpoena (very commonly used by USG) sent by a Baltimore DHS ICE agent, dated 2015-03-20, demanding information about 5 Reddit accounts:
- EVOSMITH (evosmith)
- NSWGREAT (NSWGreat)
- Z-L (z-l)
- GWERN
- DEEPTHROAT_ (DeepThroat_)
For those who mercifully missed the drama: NSWGreat is an Australian
vendor who sold on Evolution & also was an employee in a mostly PR
capacity who memorably confirmed the recent Evolution exit scam (ending
the doubt and uncertainty about the failing withdrawals); z-l,
DeepThroat_, and evosmith were just 3 of the legion of trolls and
scammers and fools who popped up in the immediate aftermath, claiming to
have secret information, offering to dox or attack the Evo admins in
exchange for Bitcoins (upfront, naturally), posting faked chats intended
to deliver malware (example).
z-l claimed to have been an Evo programmer and to be offering the
source code, user database etc; the normal way of verifying such a claim
is for the leaker to give someone with accounts the hash of their
password, which that someone can then hash their password and check it
matches, and since I had one or two Evo accounts for spidering, I
offered to verify using mine to either show z-l to be somewhat genuine
or a troll like all the others. z-l never gave me any hashes, databases,
or the source code, claiming that - oops! - his copies must be on some
other hard drive and he was still looking for it. Last I saw, he was now
claiming to have given up on releasing the info to anyone but the FBI
or to have been paid off by Kimble/Verto, I forget which.
Given the date and the affected accounts, it doesn't take Holmes to
deduce the reason for this subpoena: the ICE agent is interested in the
trolls z-l and Deepthroat, and also thinks that they may be able to get
IPs for NSWGreat (just one naked connection revealing his home IP would
be enough and if he's like past market employees, a raid will turn up
all the damning evidence one could hope for).
This is a bit hilarious because z-l and Deepthroat never produced
anything but drama: nothing but a lot of big talk, threats, and a chat
conversation of dubious authenticity, which nevertheless got eaten up by
this subreddit's readers and other subreddits and got some media
attention.
I'm sure that they were both thrilled to be told by Reddit about the
subpoena - they couldn't've hoped they would be able to draw such
attention and increase the drama even more.
I'm presumably included because I offered to verify z-l's Evolution
hashes using my own Evo accounts' passwords, which he was never able to
provide - instead I got excuses about how he couldn't find the user
database and it must be on another hard drive.
And this subpoena furnishes further proof that z-l was a troll, since he
claimed to have sent all his material to the FBI, and if he did, why on
earth is an ICE agent (located, incidentally, in the same city as the
Marco Polo FBI task force) subpoenaing his account?
The specific information required:
a. The subscriber's name; email address, registration IP address,
registration date, current IP address
b. The subscriber's address;
c. The subscriber's local and long distance telephone toll billing
records;
d. The subscriber's records of session times and durations;
e. The subscriber's length of service (including start date) and types
of services utilized;
f. The subscriber's telephone or instrument number or other subscriber
number or identity, including any temporarily assigned network address;
and
g. The subscriber's means and source of payment for such service
(including any credit card or bank number).
I assume the main goal here is the IPs. While Reddit may have phone
numbers for 2FA and billing information for Gold or advertising, it is
unlikely any of our accounts have that and those parts are more
boilerplate. (Reddit's lawyer declined to specify what information would
be provided, referring me to the privacy policy.)
Administrative subpoenas effectively cannot be fought because the
judicial standards are ultra-low and because they are going to a
third-party (Reddit); one has little legal standing or rights in data
held by third-parties, which is one reason subpoenas feature so
prominently in the past black-market cases I've written about (cases
often involve subpoenas to Amazon, ISPs, Gmail, PayPal, etc, and those
are just the ones mentioned - implying many more subpoenas were sent off
but didn't turn out immediately useful).
So there's nothing that can be done about this.
So the basic lesson here is:
Don't feed the trolls. If someone claims to be a hacker, or
staff, or whatever, don't swallow their stories and excuses; either they
are going to leak & provide proof, or they are not. If the latter,
then they are of interest, otherwise, simply ignore them like you would
any other spammer. It's not that hard.
If you people had kept your heads more level and hadn't overloaded
Reddit with doxing fervor, I wouldn't have been forced to waste a day
reading up on subpoenas & seeking legal advice, being stressed out,
and having LE violating my Reddit account to read my PMs and potentially
endanger my source - all in addition to the time I already wasted answering questions about z-l and reading through alerts related to him/me.
Gee thanks guys... (And this is despite all the effort the mod team put into putting a lid on the worst of the frenzy! And believe it or not, it's continuing, with /u/Bluehighsky and /u/z-l2.)
The subpoena does include some boilerplate language to the effect
that "You are requested not to disclose the existence of this subpoena
for an indefinite period of time. Any such disclosure will impede this
investigation and thereby interfere with the enforcement of federal
law.", however this threat is obviously hollow: Reddit has already
notified the accounts involved, 21 U.S.C. § 967 includes no gag order
like NSLs and financial subpoenas do, subpoenas are commonly discussed
publicly, administrative subpoenas are commonly used, discussing it fits
under no laws or cases of interference,
discussion of LE activity is protected by precedent & free speech,
and as a journalist & researcher I pretty much have to write about
this.
My personal vulnerability is relatively low: I am well-aware that as a
semi-public figure writing about the black-markets I am doxable,
especially by LE, and for that and many other reasons, I have never been
a seller, market operator, or market employee, and I have never
accepted payment from any of the above; in addition, I have not
purchased from any markets for quite some time now (because it would
interfere with my self-experiments, true, but nevertheless).
However, it is impossible to not violate laws in the USA and I cannot
really afford a good legal defense, so I am still worried.
This seems like a good time to note that my writing & research on
the blackmarkets - my mirroring of the markets such as Evolution, my research into arrests, analysis of market lifetimes, and background - are supported by donations: 1GWERNEDr2o3JYfD3n5GHkoPxSxPk3MbK3
(EDIT: thanks to everyone who donated. I am surprised and humbled to have received ฿3.5 so far!)
Nevertheless, how can I continue as a moderator knowing that all my
non-PGPed communications have been laid bare, there may be followup
subpoenas for my Gmail account, and I may be under further investigation
myself? I am still considering this, but I will probably step down as a
moderator soon; I'd been considering moving on to other areas for a
while now, but the subpoena may be the last straw and a message.
Finally: don't panic. The Eye of Sauron is upon us indeed, but we all
expected this would happen eventually or had been happening all along.
Double-check you are using Tor; archive copies of any important pages or
comments; remove any comments or posts which on reflection may reveal
too much to the entire world; switch accounts or switch to using
hidden-service forums like The Hub for any dangerous talk.
(Wired article; ars technica; Forbes; HN)
[NSWGreat was ultimately arrested by Australian police in February 2019. It is unclear if the various subpoenas had anything to do with his arrest. —Editor, 16 February 2019]
[–]NicholeRichey 138 points139 points140 points (8 children)
[+][deleted] (3 children)
[–]lividliver 4 points5 points6 points (0 children)
[+][deleted] comment score below threshold-10 points-9 points-8 points (1 child)
[+]Vendor_BBMC comment score below threshold-10 points-9 points-8 points (0 children)
[–]ParanoiaCat 53 points54 points55 points (7 children)
[+]Vendor_BBMC comment score below threshold-11 points-10 points-9 points (6 children)
[–]Theeconomist1 60 points61 points62 points (23 children)
[–]lamarrotems 47 points48 points49 points (5 children)
[–]Theeconomist1 14 points15 points16 points (4 children)
[+][deleted] (2 children)
[–]impost_r 0 points1 point2 points (0 children)
[–]_-________________-_ 11 points12 points13 points (4 children)
[–]Derrick4Real 7 points8 points9 points (1 child)
[–]-STIMUTAX- 1 point2 points3 points (0 children)
[–]Theeconomist1 2 points3 points4 points (0 children)
[–]Theeconomist1 -2 points-1 points0 points (0 children)
[–]brightBlinker 1 point2 points3 points (1 child)
[–]doubledoseopimpin 2 points3 points4 points (0 children)
[–]bvbvbvbvfhfhfhfh 6 points7 points8 points (8 children)
[–]samanthasecretagent 13 points14 points15 points (0 children)
[–][deleted] 7 points8 points9 points (2 children)
[–][deleted] 7 points8 points9 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[–]Deafcunt -2 points-1 points0 points (1 child)
[–]brfRottenPotato 0 points1 point2 points (0 children)
[–]someguitarplayer -1 points0 points1 point (0 children)
[–]gwernbatsignal 48 points49 points50 points (2 children)
[–]brightBlinker 4 points5 points6 points (0 children)
[+]Vendor_BBMC comment score below threshold-19 points-18 points-17 points (0 children)
[–]_Colorado_ 26 points27 points28 points (11 children)
[–]AgoraMarket 25 points26 points27 points (3 children)
[–]_Colorado_ 11 points12 points13 points (2 children)
[–]tripsmagee 0 points1 point2 points (1 child)
[–]_Colorado_ 0 points1 point2 points (0 children)
[–]warriorlord 3 points4 points5 points (0 children)
[–]brightBlinker 0 points1 point2 points (0 children)
[–]cannaoil 0 points1 point2 points (2 children)
[–]InfinitelyOutThere -3 points-2 points-1 points (0 children)
[+]Vendor_BBMC comment score below threshold-7 points-6 points-5 points (0 children)
[+]Vendor_BBMC comment score below threshold-9 points-8 points-7 points (1 child)
[–]lamarrotems 34 points35 points36 points (39 children)
[–]gwern[S] 15 points16 points17 points (0 children)
[–]666fun 13 points14 points15 points (12 children)
[–][deleted] (1 child)
[removed]
[–]AutoModerator[M] 0 points1 point2 points (0 children)
[–]lamarrotems 10 points11 points12 points (6 children)
[–]brightBlinker 2 points3 points4 points (4 children)
[–]lamarrotems 1 point2 points3 points (3 children)
[–]brightBlinker 1 point2 points3 points (2 children)
[–]lamarrotems 1 point2 points3 points (1 child)
[–]brightBlinker 1 point2 points3 points (0 children)
[+]Vendor_BBMC comment score below threshold-6 points-5 points-4 points (0 children)
[–]brightBlinker 0 points1 point2 points (0 children)
[–]Vendor_BBMC -4 points-3 points-2 points (1 child)
[–]sobulbous 1 point2 points3 points (0 children)
[–]throoorowowowooaaa 8 points9 points10 points (20 children)
[–]clairvoyance1 8 points9 points10 points (16 children)
[–]throoorowowowooaaa 6 points7 points8 points (15 children)
[+][deleted] (14 children)
[+]Vendor_BBMC comment score below threshold-5 points-4 points-3 points (2 children)
[+]Vendor_BBMC comment score below threshold-7 points-6 points-5 points (2 children)
[–][deleted] 16 points17 points18 points (3 children)
[–]brightBlinker 1 point2 points3 points (2 children)
[–][deleted] 0 points1 point2 points (1 child)
[–]brightBlinker 0 points1 point2 points (0 children)
[–]-moose- 22 points23 points24 points (10 children)
[–]impost_r 1 point2 points3 points (1 child)
[–]brightBlinker 0 points1 point2 points (0 children)
[+]Vendor_BBMC comment score below threshold-10 points-9 points-8 points (7 children)
[–]pxck 11 points12 points13 points (1 child)
[–]gwern[S] 12 points13 points14 points (0 children)
[–]mephestus 12 points13 points14 points (1 child)
[+]Vendor_BBMC comment score below threshold-9 points-8 points-7 points (0 children)
[+][deleted] (18 children)
[–]MLP_is_my_OPSEC 13 points14 points15 points (7 children)
[–]lamarrotems 5 points6 points7 points (3 children)
[–][deleted] -1 points0 points1 point (1 child)
[–]lamarrotems 1 point2 points3 points (0 children)
[+]Vendor_BBMC comment score below threshold-7 points-6 points-5 points (0 children)
[–]SWIMstains 6 points7 points8 points (1 child)
[+]Vendor_BBMC comment score below threshold-7 points-6 points-5 points (0 children)
[+]Vendor_BBMC comment score below threshold-6 points-5 points-4 points (0 children)
[–]tonyeverready 7 points8 points9 points (0 children)
[–]ShulginsCat 6 points7 points8 points (1 child)
[–]gwern[S] 5 points6 points7 points (0 children)
[–]DankNetMarkets 7 points8 points9 points (3 children)
[–]AgoraMarket 5 points6 points7 points (2 children)
[–]DankNetMarkets 0 points1 point2 points (0 children)
[–]KillMeAndYouDie -2 points-1 points0 points (0 children)
[–]mackenley95366646 2 points3 points4 points (4 children)
[–]gwern[S] 1 point2 points3 points (2 children)
[+][deleted] (1 child)
[–]itisike 0 points1 point2 points (0 children)
[–]dsfgsad 6 points7 points8 points (4 children)
[–]IGetDankShit 12 points13 points14 points (1 child)
[–]dsfgsad -4 points-3 points-2 points (0 children)
[–]InfinitelyOutThere 0 points1 point2 points (0 children)
[+]pinkprincess1 comment score below threshold-5 points-4 points-3 points (0 children)
[–]Oracle_DNM 4 points5 points6 points (4 children)
[–]gwern[S] 29 points30 points31 points (3 children)
[+][deleted] (1 child)
[–][deleted] 2 points3 points4 points (0 children)
[–]throwahooawayyfoe 6 points7 points8 points (1 child)
[–]gwern[S] 3 points4 points5 points (0 children)
[–][deleted] (3 children)
[removed]
[–]AutoModerator[M] 16 points17 points18 points (2 children)
[–][deleted] 8 points9 points10 points (1 child)
[–]throoorowowowooaaa 0 points1 point2 points (0 children)
[–]Toruser6669 1 point2 points3 points (1 child)
[–]gwern[S] 0 points1 point2 points (0 children)
[–]earthmoonsun 1 point2 points3 points (0 children)
[–]PsyHighBuyTieDie1 1 point2 points3 points (0 children)
[–]guyfromaplace2 1 point2 points3 points (0 children)
[–]Sloppy__Jalopy 3 points4 points5 points (0 children)
[–]ThrowawayTehGay 0 points1 point2 points (7 children)
[–]ClearlyRandomName -1 points0 points1 point (6 children)
[–]throoorowowowooaaa 4 points5 points6 points (3 children)
[–]sapiophile 1 point2 points3 points (2 children)
[–]ThrowawayTehGay 0 points1 point2 points (0 children)
[–]ThrowawayTehGay 0 points1 point2 points (0 children)
[–]MrCrappy57 2 points3 points4 points (0 children)
[+][deleted] (4 children)
[–]massiveweiner 3 points4 points5 points (1 child)
[–][deleted] 1 point2 points3 points (0 children)
[+][deleted] (2 children)
[–][deleted] 3 points4 points5 points (0 children)
[–]ttrravis 3 points4 points5 points (1 child)
[–]StuffyKnows2Much 1 point2 points3 points (0 children)
[–]CocaineNose 1 point2 points3 points (6 children)
[–]gwern[S] 7 points8 points9 points (5 children)
[–]lamarrotems 5 points6 points7 points (4 children)
[–]CocaineNose 5 points6 points7 points (1 child)
[–][deleted] 0 points1 point2 points (1 child)
[–][deleted] 1 point2 points3 points (0 children)
[–]grandpajoe_dnm 1 point2 points3 points (0 children)
[–][deleted] 1 point2 points3 points (0 children)
[–]trecht 1 point2 points3 points (0 children)
[–]PatchWork- 1 point2 points3 points (0 children)
[–][deleted] 1 point2 points3 points (0 children)
[–]presari0 1 point2 points3 points (0 children)
[–]mad87645 1 point2 points3 points (0 children)
[–][deleted] 1 point2 points3 points (3 children)
[+][deleted] (1 child)
[–][deleted] 1 point2 points3 points (0 children)
[–][deleted] 1 point2 points3 points (0 children)
[–][deleted] 1 point2 points3 points (0 children)
[–]DoctrZoidberg 1 point2 points3 points (0 children)
[–]Jay-__ 1 point2 points3 points (0 children)
[–]anti-omni -1 points0 points1 point (0 children)
[+][deleted] (1 child)
[+][deleted] (4 children)
[–]ThisIsCanadaMan 0 points1 point2 points (0 children)
[–]MF17 0 points1 point2 points (0 children)
[–]throwthrowitaway11 0 points1 point2 points (11 children)
[–]lucasjkr 8 points9 points10 points (7 children)
[–]-STIMUTAX- 1 point2 points3 points (1 child)
[–]InfinitelyOutThere 0 points1 point2 points (0 children)
[–]throwthrowitaway11 0 points1 point2 points (4 children)
[–]sobulbous 6 points7 points8 points (3 children)
[–][deleted] 2 points3 points4 points (0 children)
[–]arbitrarysquid 1 point2 points3 points (0 children)
[–]leave_a_lilypad 2 points3 points4 points (0 children)
[–]gwern[S] 6 points7 points8 points (2 children)
[–]alwayslookingformore 8 points9 points10 points (1 child)
[–]MrCrappy57 2 points3 points4 points (0 children)
[–]R4ID 0 points1 point2 points (0 children)
[–]Moridakkubokka 0 points1 point2 points (0 children)
[–]huntokartography 0 points1 point2 points (0 children)
[–]adam2222 0 points1 point2 points (0 children)
[–]deepdot 0 points1 point2 points (0 children)
[–]token_dave 0 points1 point2 points (0 children)
[–]Therealfed1 0 points1 point2 points (0 children)
[–]GIEV_RP_PLZ 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]RUMBLINGBUTTHOLE 0 points1 point2 points (0 children)
[–]KW-NZ 0 points1 point2 points (0 children)
[–]GriseldaBlancoke 0 points1 point2 points (3 children)
[–]lamarrotems 1 point2 points3 points (0 children)
[–]BurungHantu 0 points1 point2 points (1 child)
[–]GriseldaBlancoke 0 points1 point2 points (0 children)
[–]rickross47 -1 points0 points1 point (0 children)
[–]durgsrbad -1 points0 points1 point (0 children)
[–]throwthrowitaway11 -2 points-1 points0 points (6 children)
[–]SWIMstains 1 point2 points3 points (0 children)
[–]Axaq -4 points-3 points-2 points (4 children)
[–]lamarrotems 1 point2 points3 points (2 children)
[–]Axaq -2 points-1 points0 points (1 child)
[–]666fun -1 points0 points1 point (0 children)
[–]causejodysaysso 0 points1 point2 points (1 child)
[–]AutoModerator[M] -1 points0 points1 point (0 children)
[–]Glassjunkie -1 points0 points1 point (0 children)
[+]DoctrZoidberg comment score below threshold-5 points-4 points-3 points (4 children)
[–]SilentDager -4 points-3 points-2 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[+]Vendor_BBMC comment score below threshold-7 points-6 points-5 points (2 children)
[+]IntellectualEuphoria comment score below threshold-7 points-6 points-5 points (5 children)
[–]1percentof1 -2 points-1 points0 points (0 children)
[–]Biteitliketysen -2 points-1 points0 points (0 children)
[+][deleted] (2 children)
[–]thewilloftheuniverse -2 points-1 points0 points (0 children)
[–]mwthink -3 points-2 points-1 points (0 children)
[–][deleted] -3 points-2 points-1 points (0 children)
[+][deleted] (2 children)
[–]STEZN -3 points-2 points-1 points (0 children)
[–]STEZN -3 points-2 points-1 points (0 children)
[–]blamehofmann -3 points-2 points-1 points (0 children)
[+]Smokeyz comment score below threshold-6 points-5 points-4 points (3 children)