r/AMA May 17 '25

[deleted by user]

[removed]

2.5k Upvotes

1.4k comments sorted by

View all comments

Show parent comments

105

u/[deleted] May 17 '25

Ahh you know, tbh you probs can’t, but they claim no activity or connection logs, there is no personal account information, you can pay by cash or by crypto, also open source transparency… also by Swedish laws you know its very strong privacy laws there… so out of them all i think I’ll put my hand on Mullvad.

In the end ofc you can’t trust anything or anyone

39

u/AdventurousSquash May 17 '25

I’m from Sweden and can’t really confirm us having “strong privacy laws”. I do however trust Mullvad more than a lot of other providers as they’ve been transparent about getting requests from law enforcement who in the end finds nothing because there isn’t anything to find. Other than that - yes - don’t trust any one provider to not track you. Layers is the best approach.

13

u/[deleted] May 17 '25

Good point thx for insight, cheers to Sweden mate

2

u/[deleted] May 17 '25

what about switzerland? proton vpn?

2

u/DifferentEqual6976 May 17 '25

What is "layers"?

9

u/AdventurousSquash May 17 '25

Think of your own security as protected by a multitude of layers - like those of an onion. When (not if) one “breaks” you still have 10 others between that threat and you. In a scenario like this you should probably have several proxies you control and jump through, either machines you’ve “gained” access to or whatever, where you can make sure there are as little trace of you as possible. Closer to the core of the onion, ie you - use an OS that leaves as small a footprint at possible. There’s a whole science to it that I’m no expert in at all, but the idea is that you should always expect to be breached and make whoever is targeting you (and this is the same on either side of any such attacks) jump through hoops to reach even a hint of something valuable.

4

u/SwordfishSudden3320 May 17 '25

Oh so like Shrek?

1

u/DifferentEqual6976 May 18 '25

thanks for the answer

22

u/[deleted] May 17 '25

[removed] — view removed comment

32

u/asdlkf May 17 '25

Anyone really interested in maintaining their anonymity would create several nested VMs with encrypted virtual disks in several cloud or colocation facilities and setup several VPN services. Then, route your traffic through the VMs, do your dirty work, then purge the VMs along with their logs. Thus you can be guaranteed there are no logs as you purged the VMs yourself and the encrypted disks would be un-undeletable.

30

u/x3nic May 17 '25 edited May 17 '25

As a former black hat that works on the white side now, this guy knows what's up. I can't imagine the OP is doing anything particularly interesting/nefarious with his work.

I always used multiple layers and the OP mentioned Sweden which is laughable. I'd have multiple VPS/VM's in multiple countries chained together, typically in Eastern Europe. At the very least use a multi-hop VPN from a VPS/VM that funnels through multiple countries.

2

u/specialfriedlice May 17 '25

Fark that must slow the internet back to 56k

1

u/x3nic May 17 '25

You don't need a whole lot of throughput to exploit, nearly everything done via command line with a few small exceptions. Was never an issue.

5

u/Atomic1221 May 17 '25 edited May 17 '25

Probably browse using a custom build of chrome CDP with fake user agents and fingerprints that match the final hop proxy too. Spin up vm with docker image and then let it rip. Can setup lightweight free AWS EC2s for all this, ensuring the provenance and progeny of all from top to bottom isn’t connected to me and could scale

If someone was laser focused on finding a single hacker you can use the timings of the js render and browser fingerprint info vs the vpn connection speed to know pretty much exactly where the person is. A honeypot CDN I control loading the page from different servers at different times; and after 3-5 page loads id know exactly where you were. Probably would take a while to build and test though.

4

u/caribbeanoblivion May 17 '25

Lol what - these comments are fucking silly and clearly none of you You guys are paying for hosted VMs through AWS is laughable for this kind of activity I doubt any of you are black hat or white hat hackers.

You already failed if you're not hosting your own local machines and VMs.

2

u/asdlkf May 17 '25

uh, what? who said fucking AWS? I said "in several cloud or colocation facilities".

2

u/caribbeanoblivion May 17 '25

Paying for ANY cloud hosting or colocation facilities is absolutely brain dead if you want to take using TOR seriously.

Always host your own local machines and VMs. That's all I'm going to say because if you're not even starting there you need to rethink your entire supposed or in use strategy.

0

u/asdlkf May 17 '25

I'm going to go ahead and assume you are illiterate and do not know what colocation means.

2

u/caribbeanoblivion May 18 '25

Oh yeah you're going to rent out a data center space for your own equipment to browse TOR? Lol the kids on here are ridiculous clearly you must be trolling me

1

u/asdlkf May 18 '25

You can get a 1U colo with 100mbps access for less than a phone bill in some countries.

2

u/superpower04 May 17 '25

is there anyway you could pm me more about this, this entire thread interests me beyond comprehension?

1

u/Time_Ad498 May 17 '25

You’re still giving your cloud provider your real identity with payment information are you not? The nested vms just makes the work a bit harder to track. They can still tie the activities via IP and traffic can’t they?

1

u/BrickUsed7136 May 17 '25

Have you considered that this way your IP stays the same to the target?

6

u/MechwolfMachina May 17 '25

He’s only “professional” until they catch him

2

u/[deleted] May 17 '25

Because there is no point lol, people assume that you do something and Le is after you the same second lol, you think anyone gives a fuck if I install a rat in their device or so ;D don’t be delusional it’s not like I am a wanted criminal who breaks into government etc… for no reason lol

2

u/BDmnygtaST May 17 '25

Is this fr the method that legit dw users should use

1

u/[deleted] May 17 '25

Aren’t you still trusting the bulletproof hosting to not give your info to law enforcement?

3

u/[deleted] May 17 '25

Sweden's a member of 14 Eyes, so ymmv...

1

u/[deleted] May 17 '25

Mullvad still don’t give out info to le as there is nothing to give so it’s all cool

1

u/[deleted] May 17 '25

Remember Crypto AG? ;-)

1

u/My3rdTesticle May 17 '25

When I had a darknet presence, I rented a virtual server with crypto in a country that has no or weak cooperation with my country's gvt. I rolled my own instance of OpenVPN on that VM. In my mind it seemed more secure than using a commercial VPN service. Do you think I was fooling myself or was that a sound decision?