"Publicly, Belgacom has played down the extent of the compromise, insisting that only its internal systems were breached and that customers’ data was never found to have been at risk. But secret GCHQ documents show the agency gained access far beyond Belgacom’s internal employee computers and was able to grab encrypted and unencrypted streams of private communications handled by the company.
The spy agency was able to obtain data that was being sent between Belgacom and other operators through encrypted tunnels known as “virtual private networks.” GCHQ boasted that its work to conduct “exploitation” against these private networks had been highly productive, noting “the huge extent of opportunity that this work has identified.” Another document, dated from late 2011, added: “Network Analysis on BELGACOM hugely successful enabling exploitation.”
GCHQ had accomplished its objective. The agency had severely compromised Belgacom’s systems and could intercept encrypted and unencrypted private data passing through its networks. The hack would remain undetected for two years, until the spring of 2013."
Good article - the control of the infrastructure of the internet is a large problem today. For historical context, I suggest looking into Paul Garrin's project Name.Space - it highlights the often-invisible control of TLDs and DNSs by companies close to their respective governments (often granted sole control over their market). Although Name.Space was more pertinent while Network Solutions still held a monopoly over domain registration, it seems like the same kind of problem continues today.
IIRC, Silk Road 1.0 (is this what we're calling it now?) had mirroring servers. As we know, somehow the IP of the main server was leaked, whether through the CAPTCHA or by other means.
Security by obscurity always fails - especially against the FBI. Given that Tor is essentially an obscuring mechanism for servers that have to function to some degree on the clearnet, if the FBI really wants to find a hidden service there are apparently many points of failure to exploit.
However, given that Ulbricht and now Benthall both had poor OpSec, criminals on the internet have as a last resort the ability to have no identifying information on their servers, even if their servers get owned.
They located Silk Road 2.0's server in an unspecified way, not directly related to their undercover agent on the support staff. Given that two other darknet markets (Black Market and Cloud9) have been shut down today, and they didn't specify how they located the SR2 server, it seems plausible that law enforcement have a vulnerability to locate servers over the Tor network.
From the complaint:
"In or about May 2014, the FBI identified a server located in a foreign country that was believed to be hosting the Silk Road 2.0 website at the time. On or about May 30, 2014, law enforcement personnel from that country imaged the Silk Road 2.0 Server and conducted a forensic analysis of it. Based on posts made to the SR2 Forum, complaining of service outages at the time the imaging was conducted, I know that once the Silk Road 2.0 server was taken offline for imaging, the Silk Road 2.0 websites went offline as well, thus confirming that the server was used to host the Silk Road 2.0 website."[1]
Then, as a result of extremely poor OpSec (Benthall accessed the server directly, used his real email for registering the server), they got his IP's and, well, you know where it goes from there.
"Publicly, Belgacom has played down the extent of the compromise, insisting that only its internal systems were breached and that customers’ data was never found to have been at risk. But secret GCHQ documents show the agency gained access far beyond Belgacom’s internal employee computers and was able to grab encrypted and unencrypted streams of private communications handled by the company.
The spy agency was able to obtain data that was being sent between Belgacom and other operators through encrypted tunnels known as “virtual private networks.” GCHQ boasted that its work to conduct “exploitation” against these private networks had been highly productive, noting “the huge extent of opportunity that this work has identified.” Another document, dated from late 2011, added: “Network Analysis on BELGACOM hugely successful enabling exploitation.”
GCHQ had accomplished its objective. The agency had severely compromised Belgacom’s systems and could intercept encrypted and unencrypted private data passing through its networks. The hack would remain undetected for two years, until the spring of 2013."