Bitcoin Forum
May 26, 2024, 05:02:54 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Threats and countermeasures in buying real world things through the mail  (Read 1035 times)
njw (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
August 25, 2012, 11:05:39 AM
 #1

Hi there,

I've been following bitcoin for a while, and finally decided it was about time to get started with it. I do have a question about anonymity and threat models though, which I'm struggling to figure out myself.

Let's say I want to buy a banned book using bitcoins. I'm new to bitcoin, so I do the following:

1) Buy bitcoins using wire transfer from an exchange.
2) Transfer bitcoins from exchange to my wallet.
3) Buy the book from somewhere online place.
4) Get the book shipped to my house.

The threats that I see here all revolve around the seller getting busted. In this case, the attackers have:
- My postal address (from shipping it, presuming the seller kept logs)
- The address my bitcoins came from.

Am I correct in thinking that the attacker can also see the history of the transactions that passed through my wallet (as they now have the wallet address)? If so, presumably they could see that the bitcoins originated from an exchange, and subpoena the exchange.

The subpoena an exchange issue could be dealt with largely by depositing in cash, rather than wire transfer. That way the exchange need have little knowledge of my identity.

The postal address issue seems pretty intractable, to me. A PO Box would provide another layer of indirection, but is also a subpoena (or less in many countries) away from revealing my identity.

Anything I haven't thought of, or have thought of wrongly, or better ways of doing things?

Thanks
Bitcoin Oz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Wat


View Profile WWW
August 25, 2012, 11:11:42 AM
 #2

Hi there,

I've been following bitcoin for a while, and finally decided it was about time to get started with it. I do have a question about anonymity and threat models though, which I'm struggling to figure out myself.

Let's say I want to buy a banned book using bitcoins. I'm new to bitcoin, so I do the following:

1) Buy bitcoins using wire transfer from an exchange.
2) Transfer bitcoins from exchange to my wallet.
3) Buy the book from somewhere online place.
4) Get the book shipped to my house.

The threats that I see here all revolve around the seller getting busted. In this case, the attackers have:
- My postal address (from shipping it, presuming the seller kept logs)
- The address my bitcoins came from.

Am I correct in thinking that the attacker can also see the history of the transactions that passed through my wallet (as they now have the wallet address)? If so, presumably they could see that the bitcoins originated from an exchange, and subpoena the exchange.

The subpoena an exchange issue could be dealt with largely by depositing in cash, rather than wire transfer. That way the exchange need have little knowledge of my identity.

The postal address issue seems pretty intractable, to me. A PO Box would provide another layer of indirection, but is also a subpoena (or less in many countries) away from revealing my identity.

Anything I haven't thought of, or have thought of wrongly, or better ways of doing things?

Thanks


http://en.wikipedia.org/wiki/Dead_drop

Strider Hiryu
Newbie
*
Offline Offline

Activity: 29
Merit: 0



View Profile
August 25, 2012, 11:54:32 AM
 #3

Hi there,

I've been following bitcoin for a while, and finally decided it was about time to get started with it. I do have a question about anonymity and threat models though, which I'm struggling to figure out myself.

Let's say I want to buy a banned book using bitcoins. I'm new to bitcoin, so I do the following:

1) Buy bitcoins using wire transfer from an exchange.
2) Transfer bitcoins from exchange to my wallet.
3) Buy the book from somewhere online place.
4) Get the book shipped to my house.

The threats that I see here all revolve around the seller getting busted. In this case, the attackers have:
- My postal address (from shipping it, presuming the seller kept logs)
- The address my bitcoins came from.

Am I correct in thinking that the attacker can also see the history of the transactions that passed through my wallet (as they now have the wallet address)? If so, presumably they could see that the bitcoins originated from an exchange, and subpoena the exchange.

The subpoena an exchange issue could be dealt with largely by depositing in cash, rather than wire transfer. That way the exchange need have little knowledge of my identity.

The postal address issue seems pretty intractable, to me. A PO Box would provide another layer of indirection, but is also a subpoena (or less in many countries) away from revealing my identity.

Anything I haven't thought of, or have thought of wrongly, or better ways of doing things?

Thanks

The wallet tracking issue is solved by mixing your bitcoin with some large collection of bitcoin (or many of these to lessen the potential problem of records being kept), then withdrawing it to a new wallet.

I guess you could have things sent to a vacant house with an accessible mailbox.
SaintFlow
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


The first is by definition not flawed.


View Profile
August 25, 2012, 12:04:14 PM
 #4

One can always send things to a friend and tell them you cannot order it to your place because it is a gift for your wife or girlfriend and you do not want her to find out beforehand. My friends do not open my post.

don't let me make you question your assumptions
njw (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
August 25, 2012, 01:55:36 PM
 #5

Thanks for the replies folks! Responding to things in no particular order:

Quote
I guess you could have things sent to a vacant house with an accessible mailbox.
I'd vaguely considered that. Depending on area, such buildings aren't always easy to find, though.

Quote
Dead drop
Fun article, thanks. Rather too hardcore spy-ish for me, but still, good to know more about.

Quote
One can always send things to a friend and tell them you cannot order it to your place because it is a gift for your wife or girlfriend and you do not want her to find out beforehand. My friends do not open my post.
That has the disadvantage of potentially getting your friends in trouble. Not ideal.

Quote
The wallet tracking issue is solved by mixing your bitcoin with some large collection of bitcoin (or many of these to lessen the potential problem of records being kept), then withdrawing it to a new wallet.
Ah, thanks for that. I hadn't quite grokked that before, but it makes sense.
njw (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
August 29, 2012, 09:48:35 PM
 #6

Browsing around the bitcoin world more broadly I found some good relevant advice on the Silk Road website - http://silkroadvb5piz3r.onion/index.php/silkroad/buyers_guide

Quote
Use a different address, such as a friend's house or P.O. box, that is unrelated to the one where your item will be kept. Once the item arrives, transport it discreetly to its final destination. Avoid abandoned buildings or any place where it would be suspicious to have mail delivered.

Do not sign for your package. If you are expecting a package from us, do not answer the door for the postman, let him leave it there and then transport it as described above.

Do not use your real name. This tactic doesn't work in some places because deliveries won't be made to names not registered with the address. If you think this is a problem, send yourself a test letter with the fake name and see if it arrives.

If you follow these guidelines, your chances of being detected are minimal. In the event that you are detected, deny requesting the package. Anyone can send anyone else anything in the mail.
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
August 29, 2012, 09:59:36 PM
 #7

njw the mods are serious about the "Linking to illegal sites is forbidden. If you bypass this censorship, you will be banned" warning.  It is one of the very few things which will get you banned.  Even scamming (normally) won't get you banned.   That entire domain and similar sites are off limits.

An expensive but comprehensive solution would be to operate a remailer service (possibly funded by bitcoins) from a country which still protects privacy.  The postal mail equivalent of a VPN proxy.
DannyHamilton
Legendary
*
Offline Offline

Activity: 3402
Merit: 4656



View Profile
August 29, 2012, 11:04:14 PM
 #8

The postal address issue seems pretty intractable, to me. A PO Box would provide another layer of indirection, but is also a subpoena (or less in many countries) away from revealing my identity. . .
This came up in a recent discussion I was involved in.  By the end of the discussion, we decided that for the right price (or the right persuasion technique) you might be able to convince a complete stranger to acquire a P.O. Box and turn the key over to you.  Then, in case of the small chance that authorities might stake out the box and wait for you to collect the contents, you might be able to convince (pay) a new stranger to run in, collect the contents, and bring them out to you while you wait at a safe distance where you can keep an eye on the exit.

finkleshnorts
Sr. Member
****
Offline Offline

Activity: 336
Merit: 250



View Profile
August 29, 2012, 11:10:04 PM
 #9

Since the "book" has to eventually arrive in your hands, there is no way to completely eliminate risk.

The best way I can imagine is to set the name on the package to be the name of the previous resident. When the package arrives, walk straight from the mailbox to your outside trashcan and throw it away. Wait a few days and then take it back out at night. Plausible deniability all the way around, I believe.

I hope I will never need to do something like this.
stevegee58
Legendary
*
Offline Offline

Activity: 916
Merit: 1003



View Profile
August 29, 2012, 11:14:26 PM
 #10

What's an illegal web site?  I didn't know they existed.

You are in a maze of twisty little passages, all alike.
StrictlyBusiness
Member
**
Offline Offline

Activity: 78
Merit: 10


View Profile
August 29, 2012, 11:42:25 PM
 #11

If you are in the USA USPS needs a warrant to open mail........ Just thought I would share my two cents!
DannyHamilton
Legendary
*
Offline Offline

Activity: 3402
Merit: 4656



View Profile
August 30, 2012, 12:10:40 AM
 #12

If you are in the USA USPS needs a warrant to open mail........ Just thought I would share my two cents!
Yep, but if the seller has just been arrested in the U.S. and has records indicating where his recent shipments were sent, then getting that warrant won't be very difficult, will it?
njw (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 0


View Profile
August 30, 2012, 08:47:56 AM
 #13

Quote
njw the mods are serious about the "Linking to illegal sites is forbidden. If you bypass this censorship, you will be banned" warning.  It is one of the very few things which will get you banned.  Even scamming (normally) won't get you banned.   That entire domain and similar sites are off limits

My apologies. I'm new here, and hadn't read the rules closely enough. I did include the relevant section from that site in my posting so that visiting the site wasn't required, but didn't consider that linking would be frowned upon. Won't happen again.

Quote
An expensive but comprehensive solution would be to operate a remailer service (possibly funded by bitcoins) from a country which still protects privacy.  The postal mail equivalent of a VPN proxy.

I had to reread that about 3 times before realising that you weren't making a confusing reference to remailer software... I spent too much time playing with anonymity stuff! Anyway, interesting idea.

Quote
If you are in the USA USPS needs a warrant to open mail

That's interesting (and great), I didn't know that. I imagine they must be in the minority, though.
StrictlyBusiness
Member
**
Offline Offline

Activity: 78
Merit: 10


View Profile
August 30, 2012, 04:42:08 PM
 #14

If you are in the USA USPS needs a warrant to open mail........ Just thought I would share my two cents!
Yep, but if the seller has just been arrested in the U.S. and has records indicating where his recent shipments were sent, then getting that warrant won't be very difficult, will it?


They can't get a warrant just because you have active shipments now depending on what you were arrested for I'm pretty sure that they could open your mail if say this is a case dedicated to mail fraud or something of the sort, but I'm pretty sure that if you just get arrested that they cannot open your mail I believe it's like against the law or something. I maybe wrong if I am please somebody  fix my wrongs. And if its that hard to get it into the US why wouldn't you just e copy and print it off that way?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!