News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Mirror : pgppractice | Torhoo darknet markets

[removed by moderators]
/u/pgpfreak P Moderator
1 points
4 days ago
Hi :) This sub is for PGP practice only. Please do the exact same post on /d/pgp. I'll be glad to help. Thanks!
So first you need the public key of the site. You want to get this from a trusted source, or else you are verifying bad information with bad information, and will get bad information.

I don't see a /mirror.txt on dark fail though. I'll walk you through DrugHub 's.
So /d/DrugHub/wiki?id=9f54f84b is their market key. Import market key.
/d/DrugHub/wiki/?id=a36f94a6 has their market links in a PGP signature message. Copy message. Paste into (I'm assuming you use Kleopatra) Click Decrypt/Verify.

You would see Notepad → Notepad:
Valid signature by drug_hub_master_key
Signature created on Saturday, 15 March 2025 17:40:01 UTC
With certificate:
drug_hub_master_key (0DF7 7920 9883 8DF5)
The signature is valid and the certificate's validity is fully trusted.

Meaning that PGP key signed that message and we should believe it's legitimate, make sense?

Now if I make a change to the PGP signed message
I get Notepad → Notepad: Invalid signature.
With certificate:
drug_hub_master_key (0DF7 7920 9883 8DF5)
The signature is invalid: Bad signature

Make sense?
/u/pgpfreak P Moderator
1 points
4 days ago
Damn man you're too fast :) OP, this is the answer.
I'll repost if he makes a new thread.
/u/pgpfreak P Moderator
1 points
4 days ago
Thanks :) I'm trying to progressively route all non-practice to /d/pgp, so we can centralize all questions in a single sub and keep this one strictly practice. Maybe I'm overthinking it though. It just feels like a waste to let a topic like this one lose itself between generic PGP discussions.
/u/ByTheHour 📢 🍼
1 points
4 days ago
Yea I added his public key in there. However, whenever the decrypt option under Tools>clipboard>decrypt/verify is not highlighted/ disabled.

I have the drug_hub_master_key certificate on there. I am running kleo.
/u/ByTheHour 📢 🍼
1 points
4 days ago
oh LOL so I had to copy and past the whole PGP message from top the bottom. I thought only the signature. it reads this now " Signature created on Saturday, March 15, 2025 12:40:01 PM
With certificate:
drug_hub_master_key (0DF7 7920 9883 8DF5)
The used key is not certified by you or any trusted person.

So the mirror there is basically saying its legit? As it why does he say this is the perm Mirror.... Is the mirror a .onion link thats basically backed up dark.fail?
Did you trust the public key you imported? Sounds like you did not.