Nightmare OpSec is UNACCEPTABLE : DarkNetMarkets | Torhoo darknet markets
I've been using the market for some time now, and there are some glaring OPSEC related issues I wanted to bring up.
1: Vendors can't delete the PGP encrypted address after an order is completed. If LE seizes nightmare or a vendor, they have full access to either the auto-encrypted addresses or EVERY ADDRESS that has ever purchased from the vendor. A vendor has told me that this could be a huge problem if it gets seized.
Unacceptable.
2: It's impossible to delete previous orders from your order history. Again, could become an OPSEC issue.
3: Site uses Java Script for the icons.
https://torhoo.cc/go.php?u=TDNVdmJtbG5hSFJ0WVhKbGJXRnlhMlYw# PLEASE fix these crucial issues, ASAP.
If you have other opsec issues with Nightmare, please comment below, so that they can get fixed.
1. The fee. 4% to vendors for normal escrow, 8% for multsig. An ADDITIONAL 3% markup of prices that the customer pays, both escrow and multisig. So on a multisig transaction Nightmare is taking ELEVEN FUCKING PERCENT.
2. Autofinalization timer. A FUCKING MONTH.
3. Support sucks ass.
4. Multisig is currently broken.
5. Jabber notifications only if you use their server.
6. Ignoring vendor Terms of Service and Refund/Reship policy.
See: http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/00c2ca72e73f3d507af7/
7. Forcing XMR deposits to use a Payment ID even when Monero says that Payment ID's are obsolete
8. Cancelling orders despite vendor and customer wishes.
9. SLOW AS FUCK, NO VENDOR MIRRORS!
10. Why slow? Idiotic front end design. http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/187c25782d17c9852bbe
Vendor mirrors are a very bad idea. You just have to look at SR2 and several arrests made due to the site being compromised and vendor mirrors. As only a small amount of users access a market using a vendor only mirror correlation attacks are easy and the Feds know they are getting vendors so worthwhile.
1. A customer tried to place a MS order and I got an error stating **I** needed to deposit like 97 BTC to cover escrow or something.
2. When messaging Support THEY told me multisig was broken.
Just like you don't need to know how a car works to say its broken when it won't run.
This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.