News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Rate my opsec or advise (mobile user) : OpSec | Torhoo darknet markets

Ok because of various factors in my life I usually dont have acess to tails and even when I do I am using mobile hotspot for network connection.

Generally I am using a mobile device.

The device was purchased with cash and have made no outgoing calls or texts.

I am using the tor browser downloaded directly as an apk file from the tor site.

I have deactivated play services and all other google applications. I have no applications except foss software and the preinstalled bloatware that has been disabled.

I purchased monero using cash by mail and a fake return adress.I store this monero in the mobile monerujo wallet.

I use pgp but have not yet learned multisig (not sure if this make me more secure from an LE standpoint).

I browse markets using this mobile device and I have made various accounts on those markets.

I plan to log into those accounts from tails and then make my purchases.

Should i scrap all the accounts and do everything from tails? Does it matter?

Any other advice?

So far I have made no purchases due to my apprehension.
/u/MrPe
1 points
1 year ago
I think ur chillin , dont have to worry abt LE comming for you if ur just buying and reselling irl , just dont tell anyone from ur life where ur getting ur stuff from and LE cant do anything abt it
/u/Thedarkgod1000 📢
1 points
1 year ago
Thanks definitely not planning to tell anyone. But ive been in prison many years ago. It makes me hyper cautious.
/u/MrPe
1 points
1 year ago
yeah id be hyper cautious too , if u wanna be extra safe use public wifi from coffie shop and u will be fine
/u/aswcdtrl
1 points
1 year ago
i agree with MrPe... my only advice would be: 1. Fully encrypt the moble device/micro sd (if able). 2. Enable 2FA and do not reuse passwords across markets.
/u/Thedarkgod1000 📢
1 points
1 year ago
I try not to reuse passwords though they are somewhat similar with only three characters difference.

Ive been avoiding 2FA so that i dont connect any of these accounts to this phone. Is it better to have the 2FA?
/u/aswcdtrl
1 points
1 year ago
Boils down to preference and your threat model. 2FA on markets (commonly) uses some form of PGP message decryption.
You shouldn't have to store any one-time codes on your device. If using PGP to encrypt messages already it's just an extra layer.

Strong, "unlinkable", passwords is the big thing: for instance...
Market: username:password
Market1: darkgod1000:zeldafangirl123
Market2: dg1006:z3ldafang1rl!23
Market3: theevilone:Zeldafangirl123

Despite having different usernames, we can assume that the user in market's 1,2, and 3 is the same person.
Just something to think about... it's probably not too big a deal unless the markets u browse store user logins in cleartext.
/u/Thedarkgod1000 📢
1 points
1 year ago
Thank you for the explanation I understand. Appreciate the advice too. I think Ill make some changes to passwords add 2fa then take the leap and purchase.