Important PSA to all Reddit users: by Gwern (Original thread):

/r/DarkNetMarkets has received its first known LE subpoena: a request for 5 accounts’ data, including mine, related to Evolution and the supposed doxing/leaks.

Recently (2015-03-25), I was alerted by Reddit that there had been a subpoena for my Reddit account information and they would be responding by 2015-03-30; this followed their privacy policy where they inform all accounts affected by subpoenas if there is no gag order (which is more than most websites will do for you):

16. We may disclose – or preserve for future disclosure – your information if we believe, after due consideration, that doing so is reasonably necessary to comply with a law, regulation, or valid legal process. If we are going to release your information, we will do our best to provide you with notice in advance via reddit’s private messaging system unless we are prohibited by court order from doing so (e.g., an order under 18 U.S.C. § 2705(b)). We reserve the right to delay notice to users in cases involving the exploitation of minors and when we believe a delay is necessary to prevent imminent and serious bodily harm to a person.

The subpoena (#BA13CR12BA0018) turned out to be a 2-page “21 U.S.C. § 967, Public Law 97-258, section 1, as amended” (Controlled Substances Act) administrative subpoena (very commonly used by USG) sent by a Baltimore DHS ICE agent, dated 2015-03-20, demanding information about 5 Reddit accounts:

  1. EVOSMITH (evosmith)
  2. NSWGREAT (NSWGreat)
  3. Z-L (z-l)
  4. GWERN
  5. DEEPTHROAT_ (DeepThroat_)

For those who mercifully missed the drama: NSWGreat is an Australian vendor who sold on Evolution & also was an employee in a mostly PR capacity who memorably confirmed the recent Evolution exit scam (ending the doubt and uncertainty about the failing withdrawals); z-l, DeepThroat_, and evosmith were just 3 of the legion of trolls and scammers and fools who popped up in the immediate aftermath, claiming to have secret information, offering to dox or attack the Evo admins in exchange for Bitcoins (upfront, naturally), posting faked chats intended to deliver malware (example). z-l claimed to have been an Evo programmer and to be offering the source code, user database etc; the normal way of verifying such a claim is for the leaker to give someone with accounts the hash of their password, which that someone can then hash their password and check it matches, and since I had one or two Evo accounts for spidering, I offered to verify using mine to either show z-l to be somewhat genuine or a troll like all the others. z-l never gave me any hashes, databases, or the source code, claiming that – oops! – his copies must be on some other hard drive and he was still looking for it. Last I saw, he was now claiming to have given up on releasing the info to anyone but the FBI or to have been paid off by Kimble/Verto, I forget which.

Given the date and the affected accounts, it doesn’t take Holmes to deduce the reason for this subpoena: the ICE agent is interested in the trolls z-l and Deepthroat, and also thinks that they may be able to get IPs for NSWGreat (just one naked connection revealing his home IP would be enough and if he’s like past market employees, a raid will turn up all the damning evidence one could hope for). This is a bit hilarious because z-l and Deepthroat never produced anything but drama: nothing but a lot of big talk, threats, and a chat conversation of dubious authenticity, which nevertheless got eaten up by this subreddit’s readers and other subreddits and got some media attention. I’m sure that they were both thrilled to be told by Reddit about the subpoena – they couldn’t’ve hoped they would be able to draw such attention and increase the drama even more.

I’m presumably included because I offered to verify z-l’s Evolution hashes using my own Evo accounts’ passwords, which he was never able to provide – instead I got excuses about how he couldn’t find the user database and it must be on another hard drive. And this subpoena furnishes further proof that z-l was a troll, since he claimed to have sent all his material to the FBI, and if he did, why on earth is an ICE agent (located, incidentally, in the same city as the Marco Polo FBI task force) subpoenaing his account?

The specific information required:

a. The subscriber’s name; email address, registration IP address, registration date, current IP address b. The subscriber’s address; c. The subscriber’s local and long distance telephone toll billing records; d. The subscriber’s records of session times and durations; e. The subscriber’s length of service (including start date) and types of services utilized; f. The subscriber’s telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and g. The subscriber’s means and source of payment for such service (including any credit card or bank number).

I assume the main goal here is the IPs. While Reddit may have phone numbers for 2FA and billing information for Gold or advertising, it is unlikely any of our accounts have that and those parts are more boilerplate. (Reddit’s lawyer declined to specify what information would be provided, referring me to the privacy policy.)

Administrative subpoenas effectively cannot be fought because the judicial standards are ultra-low and because they are going to a third-party (Reddit); one has little legal standing or rights in data held by third-parties, which is one reason subpoenas feature so prominently in the past black-market cases I’ve written about (cases often involve subpoenas to Amazon, ISPs, Gmail, PayPal, etc, and those are just the ones mentioned – implying many more subpoenas were sent off but didn’t turn out immediately useful). So there’s nothing that can be done about this.

So the basic lesson here is:

Don’t feed the trolls. If someone claims to be a hacker, or staff, or whatever, don’t swallow their stories and excuses; either they are going to leak & provide proof, or they are not. If the latter, then they are of interest, otherwise, simply ignore them like you would any other spammer. It’s not that hard.

If you people had kept your heads more level and hadn’t overloaded Reddit with doxing fervor, I wouldn’t have been forced to waste a day reading up on subpoenas & seeking legal advice, being stressed out, and having LE violating my Reddit account to read my PMs and potentially endanger my source – all in addition to the time I already wasted answering questions about z-l and reading through alerts related to him/me. Gee thanks guys… (And this is despite all the effort the mod team put into putting a lid on the worst of the frenzy! And believe it or not, it’s continuing, with /u/Bluehighsky and /u/z-l2.)

The subpoena does include some boilerplate language to the effect that “You are requested not to disclose the existence of this subpoena for an indefinite period of time. Any such disclosure will impede this investigation and thereby interfere with the enforcement of federal law.”, however this threat is obviously hollow: Reddit has already notified the accounts involved, 21 U.S.C. § 967 includes no gag order like NSLs and financial subpoenas do, subpoenas are commonly discussed publicly, administrative subpoenas are commonly used, discussing it fits under no laws or cases of interference, discussion of LE activity is protected by precedent & free speech, and as a journalist & researcher I pretty much have to write about this.

My personal vulnerability is relatively low: I am well-aware that as a semi-public figure writing about the black-markets I am doxable, especially by LE, and for that and many other reasons, I have never been a seller, market operator, or market employee, and I have never accepted payment from any of the above; in addition, I have not purchased from any markets for quite some time now (because it would interfere with my self-experiments, true, but nevertheless). However, it is impossible to not violate laws in the USA and I cannot really afford a good legal defense, so I am still worried. This seems like a good time to note that my writing & research on the blackmarkets – my mirroring of the markets such as Evolution, my research into arrests, analysis of market lifetimes, and background – are supported by donations: 1GWERNEDr2o3JYfD3n5GHkoPxSxPk3MbK3

Nevertheless, how can I continue as a moderator knowing that all my non-PGPed communications have been laid bare, there may be followup subpoenas for my Gmail account, and I may be under further investigation myself? I am still considering this, but I will probably step down as a moderator soon; I’d been considering moving on to other areas for a while now, but the subpoena may be the last straw and a message.

Finally: don’t panic. The Eye of Sauron is upon us indeed, but we all expected this would happen eventually or had been happening all along. Double-check you are using Tor; archive copies of any important pages or comments; remove any comments or posts which on reflection may reveal too much to the entire world; switch accounts or switch to using hidden-service forums like The Hub for any dangerous talk.


  This is exactly why a social news site about the darknet should be a hidden service…

      OK, we get it you spamming cunt. GTFO of this comment thread if you want to retain any credibility. Fucking ambulance chaser.

    Couple of comments –

    gwern, coming from a supporter I must agree with your inclination to bail as Mod of DNM. You could very well be jeopardizing members that are unaware that your shits been subpoenaed and those unaware folks could incriminate the fuck out of themselves to you before you have a chance to warn them off. I suppose you could go completely silent – no comments, messages etc, but that’s just silly.

    More importantly, the years you have spent as crawler, historian, confidant, and source have tremendous value. What I am saying is that if you back out NOW with your entire body of work intact, that body of work gets to move on to bigger things. I don’t know if your work would be valuable to Hollywood, a Publisher, or it could open the door for a fucking amazing, REAL journo job for you. Think Grsiwald walking with the files before it all just became public fodder and corporate property. Your credibility and value will only diminish rapidly remaining as mod – or involved in any way as gwern. jmho

    Last, to all the 16-20 year old redditors that are the majority of the subscribers in that sub – so many of you were sure that the Feds had better things to do than monitor a board populated by mostly “Harmless High School and College users that would get a little something – something for themselves AND their buddies – and especially to those that thought it was the coolest thing in the world to post YouTube videos and Instagrams of you getting your sheets and HP’s in the mail – you better clean house. You stupid cocksuckers would not listen the older crowd telling you to grow the fuck up.

    Do you see now? DO YOU, you little faggots? THIS IS NOT A FUCKING GAME. Being a cunt does not only have real world repercussions for your own future, but acting like the faggots you are draws attention. How about you get the fuck off that sub if you can’y act like a fucking adult from this day forward. That’s those that are not already fucked that I am talking to.

    gwern, why is the link to /u/z-l2 leading to bluehighsky overview and the link to /u/Bluehighsky leading to a dead page?

  4. The poster is a researcher, not a criminal, but without a print or large online entity behind him he will not be treated as a journalist. This subpoena should be quashed with as much energy as he can muster, a fishing expedition left unchallenged will only embolden them further.

    Obligatory technobabble: You should not be online unless you are using TAILS(beginner), Whonix(intermediate), Qubes(advanced), or something you built yourself which works along the lines of Whonix, and you built it that way because you’ve read enough to know how a “network investigative technique” likely works.

      I was in the process of breaking this up to quote and reply to your points, but then I realized that every word – no, every syllable of your post is mired in stupidity and stuffed into a bundt pan of horse shit. If you want to try again, fine. If not then just end it all today my Asperger buddy because being you is certainly worse than the 20 seconds of pain you might get from doing the world a favor and self immolate. Do it in your mother’s bed because she deserves it too for taking a mongoloid full term

    take a big DUMP in the subpoena, drop it into a PostPak and mail it back to the bastards! :)

  6. I’m sorry to hear about the subpoena for your information Gwern. Not to be a reactionist, but it seems possible that they could seize additional resources in your possession as part of their fishing trip, and disallow you from telling anyone, in an American version of Gestapo. Not that you are guilty of anything except exercising free speech. I’m sure you have plenty of friends out here that would help if they can, just let us know.

    What ever it is you do, delete or encrypt your notes offsite.
    clean house of anything. Go plain vanilla.

    Switch away from Gmail! or any other free host that logs or can read your emails. Use bitmessage or protonmail.ch etc.

    Mirror your site in the DarkNet and do not host it at home.

    And all the ebooks you bought off the darknet should not cause you a problem unless you keep them.

  8. deepdot really needs to put a discaimer at the top of this story to point out that it was an elaborate (but obvious) April Fools joke.

