USENIX Security2021Top-tier venue
Risky Business? Investigating the Security Practices of Vendors on an Online Anonymous Market using Ground-Truth Data
Jochem van de Laarschot, Rolf van Wegberg
Abstract
Cybercriminal entrepreneurs on online anonymous markets rely on security mechanisms to thwart investigators in attributing their illicit activities. Earlier work indicates thatdespite the high-risk criminal context -cybercriminals may turn to poor security practices due to competing business incentives. This claim has not yet been supported through empirical, quantitative analysis on ground-truth data. In this paper, we investigate the security practices on Hansa Market (2015Market ( -2017) ) and measure the prevalence of poor security practices across the vendor population (n = 1, 733).
We create 'vendor types' based on latent profile analysis, clustering vendors that are similar regarding their experience, activity on other markets, and the amount of physical and digital items sold. We then analyze how these types of vendors differ in their security practices. To that end, we capture their password strength and password uniqueness, 2FA usage, PGP adoption and key strength, PGP-key reuse and the traceability of their cash-out. We find that insecure practices are prevalent across all types of vendors. Yet, between them large differences exist. Rather counter-intuitively, Hansa Market vendors that sell digital items -like stolen credit cards or malwareresort to insecure practices more often than vendors selling drugs. We discuss possible explanations, including that vendors of illicit digital items may perceive their risk to be lower than vendors of illicit physical items.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b034a208-d38f-44a3-9974-4270e59f250bCited by top-tier papers8
- Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and CoverageGibran Gómez, Kevin van Liebergen, Juan CaballeroCCS 2023 · 10 citations
- Identifying Risky Vendors in Cryptocurrency P2P MarketplacesTaro Tsuchiya, Alejandro Cuevas Villalba, Nicolas ChristinWWW 2024 · 9 citations
- Does Online Anonymous Market Vendor Reputation Matter?Alejandro Cuevas Villalba, Nicolas ChristinUSENIX Security 2024 · 1 citation
- Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing ServiceFieke Miedema, Kelvin Lubbertsen, Verena Schrama, Rolf van WegbergUSENIX Security 2023
- Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at ScaleMichele Campobasso, Luca AllodiUSENIX Security 2023
Builds on5
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 243 citations
- Plug and Prey? Measuring the Commoditization of Cybercrime via Online Anonymous MarketsRolf van Wegberg, Samaneh Tajalizadehkhoob, Kyle Soska, Ugur Akyazi et al.USENIX Security 2018 · 97 citations
- "What was that site doing with my Facebook password?": Designing Password-Reuse NotificationsMaximilian Golla, Miranda Wei, Juliette Hainline, Lydia Filipe et al.CCS 2018 · 68 citations
- Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof HostingArman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Hernandez Gañán et al.USENIX Security 2019 · 40 citations
- Go See a Specialist? Predicting Cybercrime Sales on Online Anonymous Markets from Vendor and Product CharacteristicsRolf van Wegberg, Fieke Miedema, Ugur Akyazi, Arman Noroozian et al.WWW 2020 · 14 citations
Related papers
- Economic Factors of Vulnerability Trade and ExploitationLuca AllodiCCS 2017 · 82 citations
- Bits Under the Mattress: Understanding Different Risk Perceptions and Security Behaviors of Crypto-Asset UsersSvetlana Abramova, Artemij Voskobojnikov, Konstantin Beznosov, Rainer BöhmeCHI 2021 · 49 citations
- Ghost Clusters: Evaluating Attribution of Illicit Services through Cryptocurrency TracingKelvin Lubbertsen, Michel van Eeten, Rolf van WegbergUSENIX Security 2025
- Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared HostingSamaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian et al.CCS 2017 · 48 citations
- Measurement by Proxy: On the Accuracy of Online Marketplace MeasurementsAlejandro Cuevas Villalba, Fieke Miedema, Kyle Soska, Nicolas Christin et al.USENIX Security 2022
