News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Tales from decrypt 🐷 Can I see your badge, officer? : CafeDread | Torhoo darknet markets

A short story about PGP signing ladies and gents! For the entertainment of veterans and the erudition of newcomers...
A couple of days ago somebody hit my DMs with this incredibly well-crafted piece of social engineering. PGP encrypted for some reason. No signature.

So, don't hate me here but i work for Federal Criminal Police Office in Wiesbaden. We took Arch down and Offered Elysium the same offer. However he bailed. Arch however took the deal and as you say threw everyone under the bus. I'm not here for buyers, just sellers of Fentanyl and the larger vendors. I know you will think fuck shit, but don't buyers are not on our radar.

I offered Elysium the route of trader for 1/2 years exit and pay a fee. They paid once then exit. However huge mistake we know them and will be very soon we knock.

Next Markets to go guess

Yeah. Take a load of this guy, right? Now the thing is, I'm not a smart individual. I was pretty high. And I have to admit, for a brief moment I had a creeping doubt there could be some truth in such a retarded claim. After all, LE belongs in a pigsty. Not on my key ring. Hopefully, PGP makes this kind of bullshit really, REALLY easy to answer to 👇

Send a verifiable PGP signature or get lost.

Needless to say, I didn't get the signature I asked for. They could have done it quite easily. But they didn't. I wonder why.
Now for the less experienced readers (including the scammer themselves...), what I was expecting was proof of affiliation to LE. Something like a PGP signature from a key I could check on the clearnet. Instead, what I received was... A brand new public key for a user "ddd <ddd@ddd[DOT]com>".
Are you stupid? I asked. And for the first time I received a firmly relevant answer:

You actually though ddd@ddd[DOT]com was an actual email?
🤡 This DM has been published and is still online! Get your ticket for the show before it runs out /post/1a2ffc13e9dce873e770/#c-7145708f21d56f297d

Sent back a "You're a joke <gofuckyourself@youfuckingmoron[DOT]de>" public key. Conversation was deleted soon after. Hopefully I keep a copy of it for your enjoyment.



✨ Moral of the story
/u/altforsuperstarreview
2 points
1 month ago
I thought this one was gonna be about me for a second haha. But fr. PGP signature verification or gtfo
Don't worry. I don't make fun of people having trouble with PGP. It's not convenient to use. I had my fair share of issues with it. I totally understand other people do too. Actually the discussion with mister law enforcement right there was initially about a vendor PGP key. I didn't mention them. That's not the point :)
/u/Dreadnautilus
2 points
3 weeks ago
To me, one's word is directly tied with the reputation of the PGP signature.

If you don't sign an important message, you may as well not bother typing it. Not to mention, where the public key is hosted, is it trusted, or any other number of "red flags" that can pop up.

PGP is such a powerful tool. USE IT!!!

And NEVER rely on "auto encryption." You can, and will get screwed if you do.

If you don't know how, learn. /d/pgppractice is a good resource. Read the pgp section on the DNM Bible. Hell, read the damn wikipedia article.

And if you do know how to use PGP, and actively choose not to out of laziness or any other reason, WHY?