Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/10/2019
03:00 PM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
100%
0%

Demystifying the Dark Web: What You Need to Know

The Dark Web and Deep Web are not the same, neither is fully criminal, and more await in this guide to the Internet's mysterious corners.
Previous
1 of 8
Next

If you ask the average consumer about the Dark Web, chances are good they won't have a positive response. Most people assume the Dark Web is malicious – if they know about it at all.

Over the years, and especially of late with breaches and hackers making headlines, the Dark Web's reputation has been crafted by high-profile arrests and sensational news stories. Films and television shows have also shaped public perception. Even four to five years ago, people within the technology and security industries had a skewed opinion of what the Dark Web is.

"Anyone who was familiar with it typically had an outlandish view of what was happening there," says Emily Wilson, vice president of research at Terbium Labs. In recent years, the industry has begun to have more developed conversations, discussing how the Dark Web is changing, how it's responding to different events, and how it fits into their cyber-risk strategies. Employees in the finance and tech spaces, where security is paramount, are especially aware.

Still, she adds, most modern consumers are a few years behind. More have heard of the Dark Web, but those who have are afraid of it. "Their feeling about the Deep and Dark Web is it's just this bad place," adds Flashpoint chief strategy officer Chris Camacho.

So what exactly is the Dark Web, and how is it different from the Deep Web? How do they both work, and what goes on there? Here, we hope to fill in the gaps. We spoke with Dark Web experts, who answer your FAQs about the unknown Internet.

 

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
matty37
50%
50%
matty37,
User Rank: Apprentice
10/29/2019 | 9:08:32 AM
the dark web
But isn't it right? I do think that most people don't have their fears out of nowhere, and this perception about the dark web was created based on something. It might be not as bad as it's portrayed, but it's definitely not a safe place as well. I would like to try it out and see how it looks like, but I'm currently still debating if it's worth it. I heard that you have to use Tor to access it, although I also have SurfsharkVPN; hopefully, that will increase my safety if I decide to take a glimpse
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Why Cybersecurity's Silence Matters to Black Lives
Tiffany Ricks, CEO, HacWare,  7/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...