Subscribe to our YouTube playlist Darknet.
Everyone is talking about "The DarkNet" these days. What exactly is it? To begin to understand the darknet and the dangers, you must first understand "what" it is.
Before you continue reading, you should fully understand that any actions that result from reading this are entirely YOUR responsibility. The darknet can be a dangerous place, and you should understand that before experimenting or exploring. Think of it as learning to do the tango while in a digital minefield, one wrong step and it's lights out.
The darknet is a collection of computers and technologies configured to provide as much anonymity as possible. How this works is very simple. You connect through a special browser (discussed below) and bounce through a series of relays. This keeps the user anonymous, as well as each relay node connected to it. As you pass through each node, encryption is added and removed. Also, on the regular internet, we have websites, such as www.arrakisconsulting.com, which are accessible via a service called DNS. Domain names (www.arrakisconsulting.com) are easier to remember than IP addresses (10.20.30.247). So, for the sake of making our lives easier, DNS translates domain names into IP addresses and connects to the website. Darknet follows the same process but uses a different extension or last name (i.e, .com or .net). The darknet extensions, or last names, are .onion, also called "onion links". Because DNS servers do not resolve onion links on the Internet, they are effectively hidden. Generally, the first name (Google in Google.com) is also a random set of letters and numbers, making it harder to remember. Additionally, how you connect to the darknet is through a special browser. The most common browser is the TOR browser, offered by the TOR Project. Anything not found on the Internet, also known as "The ClearNet", is considered to be on the darknet. Also, originally, the darknet was designed and used primarily in countries with restrictive laws on freedom of speech. The darknet removed those restrictions, allowing free speech advocates and reporters to anonymously and securely submit information without a restrictive country knowing. The deeper you go into the darknet, the more perverse, strange, and illegal it will also get.
What most people don't know is that the USG designed the DarkNet in the 90's to access blocked websites in countries where it wouldn't normally be allowed. In 2004, the USG had to open up the DarkNet to the rest of the world, or else any TOR traffic would be traced back to the USG. By opening it up to everyone, the USG is also anonymous.
Here is the easy part: once you download and install the TOR browser. You are now just a couple of mouse clicks away from being on the darknet. After opening the TOR browser, just treat it like any other web browser, and you can easily browse the darknet. While the browser is running, it will natively bounce through multiple TOR relays before putting you on the darknet. Generally, you get bounced 3-4 times, but it could be more. This way, you may be in Texas and bounce through the Netherlands, Germany, and Canada before accessing an onion link in California. As far as the onion server is concerned, you are in Canada. If there were a hostile or inquisitive entity, they would have to work backward through all the relays before getting to you... assuming they know how to do that.
So, you just saw how easy it was to get on the darknet. So, should you do it? Unless you have a good reason to do so, Arrakis recommends against it. The reasons are simple because the darknet can be a dangerous place. Should you attract the wrong attention, then you may become a target for hostile parties. Should you ask the wrong questions, you may attract the attention of law enforcement, which may also want to speak with you. To be clear, law enforcement is all over the darknet. Additionally, numerous private entities monitor the darknet and provide information to law enforcement. As an example, should you run across an illegal drug onion site and you attempt to purchase those illegal drugs, then you should very well expect to get a visit from law enforcement. The short story about the darknet is that if you play stupid games, then you will win stupid prizes. You will run across a variety of illegal and unethical onion sites, and before you become too curious and click that onion link, you should know that some things can't be unseen. If you would like to see an example without going on the darknet, do a Google search for "Silk Road," and you will find an illegal narcotics distribution site that was shut down.
So how can you protect yourself a little bit more? First and foremost, don't draw attention to yourself. Secondly, if you are unsure of something, do some research and learn about it rather than just doing it. However, you can also add a few layers of protection on top of the anonymity provided by the TOR browser. Increasing your security can be as simple as using Whonix in a virtual environment. Whonix offers a free workstation and proxy ISO that can be loaded into a virtual environment on your computer. Then, on the virtual Whonix workstation, you load the TOR browser and configure it to access the darknet via the Whonix proxy (also virtual). So what happens is the virtual Whonix workstations run the TOR browser (3-4 layers of anonymity), then connect to the virtual proxy (also anonymous). Because of how virtual technology works, your virtualized environment would bounce through several private, unrouteable networks (for greater anonymity). The result is that if someone does attempt to hack your machine, the workstation is virtual, so you simply shut down the virtual machine. If the machine is compromised, you can delete it and spin up a new virtual machine in just a few minutes. Instructions on how to set all this up can be found online; however, it's really not that hard. You can even add another layer of protection by subscribing to a commercial VPN service in a neutral country, such as Switzerland, that your Whonix proxy connects to before getting on the darknet.
Can the darknet be useful? It sure can... if you are a cybersecurity professional, that is. Quite often, cybersecurity personnel will browse the darknet looking for company or personal data that has been compromised. So, for example, if you work for a large company and are unsure whether a server has been compromised, theoretically, you could seek out various darknet onion sites that sell compromised servers. If you find your compromised server, you can purchase it from the hacker and then fix the issue. You may consider this a little difficult to swallow. Still, if your company can purchase its compromised server back from the hacker for $100 rather than suffer downtime that could cost several thousand dollars, it seems good business sense to pay that $100. Some companies even have $5K in Bitcoin available under the Incident Response Plan for immediate use to minimize downtime.
From a personal standpoint, as a cybersecurity professional, it never hurts to check whether your own information has been compromised or is for sale. The IRS, Target, Home Depot, Blizzard, and many other entities have been hacked. Given the USA's population and Americans' general personality, it is unlikely that you are affected by any of those breaches.
The darknet can also come in different flavors. Essentially, anything not on the Internet is the darknet, as previously discussed. We discussed using the TOR browser because it is the most popular; others are less popular and possibly more dangerous because they are more secretive. Specifically, there is Freenet, I2P, and some others that are much, much more private. All offer some of the same functionality as TOR, but differ slightly and include additional features to help ensure anonymity. In a few cases, interconnectivity is based on trust and uptime, so the longer you are on the darknet, the more trust you have. The more trust you have, the more darknet sites you get to browse.
Some advice if you do decide to get on the darknet:
1. Use Whonix as described earlier in a virtual environment,
2. Establish an onion email address; don't use your real Internet email address. Just understand that onion emails can only be reached on the darknet.
3. Never release your real name or any actual information about yourself. Hackers have been known to pull minor bits of data over time and then rebuild it to have a target profile.
4. Don't make friends with anyone on the darknet; they aren't your friends, they are there to either sell or purchase something that can't be found on the ClearNet, which generally means it will be illegal.
5. If you are accessing the darknet from your company computer, be sure you have permission first to avoid getting terminated or opening a hole in your corporate network.
Stay alert... stay safe... don't do something stupid.
If you would like to see a quick video on the DarkNet, then click this link to a YouTube video