How do people get caught multi-accounting using Tor?
by - Thursday, January 1, 1970 at 12:00 AM
(July 20, 2022, 07:38 PM)FirstAccount Wrote: JavaScript tracking? HTTP logs? Poor OPSEC? Admission of guilt? I know stackz420 on Dread found someone's multiple accounts because they were making accounts in the same window (probably because the cookies from previous accounts were sent as HTTP headers). Do only people dumb enough to use the clear net site get tracked, or do the people who run the site collect information on us for tracking / LE snitching purposes?


Session tracking, some sites (darknet markets) do this to catch vendors padding feedback, other sites use it to catch out people that are trying to evade bans, etc. If you just log out a site and log back in the same TOR session, it's still using the same cookie which is how they do it, and this is in reference to the Empire Market thing right?
Reply
agree with screen size, seems possible
Reply
Pom will find you sooner or later, sometime they get caught even with the best tech but with stupid mistakes on reacting/comment/topics..here
TG https://t.me/Valhalla0X0

Reply
(August 20, 2022, 10:12 AM)Valhalla Wrote: Pom will find you sooner or later, sometime they get caught even with the best tech but with stupid mistakes on reacting/comment/topics..here


A lot of people can and will change personalities, behavior and style of writing. Even if that person messes up, there would be reasonable deniability.
Reply
(August 9, 2022, 04:41 AM)Stackz420 Wrote:
(July 20, 2022, 07:38 PM)FirstAccount Wrote: JavaScript tracking? HTTP logs? Poor OPSEC? Admission of guilt? I know stackz420 on Dread found someone's multiple accounts because they were making accounts in the same window (probably because the cookies from previous accounts were sent as HTTP headers). Do only people dumb enough to use the clear net site get tracked, or do the people who run the site collect information on us for tracking / LE snitching purposes?



Session tracking, some sites (darknet markets) do this to catch vendors padding feedback, other sites use it to catch out people that are trying to evade bans, etc. If you just log out a site and log back in the same TOR session, it's still using the same cookie which is how they do it, and this is in reference to the Empire Market thing right?


There's also tools like p0f that can insert flags into TCP or ICMP requests, where the response differs from various OSs. This might be enough to identify someone using a Linux distro, but if you are using Windows 10 you should be fine. Also are you the same stackz420 from Dread?
Reply
because of the internet
Reply


 Users viewing this thread: How do people get caught multi-accounting using Tor?: No users currently viewing.