News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Unpopular Opinion: PGP is Overrated and Misused by 90% of People Here : CafeDread | Torhoo darknet markets

So my buddy — we’ll call him “Captain Darknet” — thought he was the king of Opsec. He’d encrypt every message with PGP like he was smuggling CIA secrets.
He even signed his feedback like anyone cared:

-----BEGIN SIGNED MESSAGE-----
“10/10 stealth, will buy again”
-----END PGP SIGNATURE-----

Bro was encrypting his thank yous. But here’s the plot twist:
He was doing it all from his Android phone...
On public Wi-Fi at Starbucks...
Using some random free PGP app from the Play Store… with ads.

No VPN. No Tor. Just vibes.

Vendor got busted. Now he’s wondering if GCHQ is going to decrypt his order history or just laugh themselves into retirement.
Listen, I’m not saying PGP is useless. It’s not.
But if your idea of OpSec is “encrypting dumb shit” while using Telegram and Google Drive, you’re not safe —
You’re just decorating your coffin with base64.


---

✅ Want real OpSec?
Head to https://torhoo.cc/go.php?u=TDJRdmIzQnpaV009# and actually learn how to protect yourself before you end up as the subject of one of these posts.

PGP is great.
Your hygiene? Probably trash.

Change my mind.
/u/DrugHub P
3 points
1 week ago
End to end encryption becomes useless if one end is compromised and messages are intercepted before encryption or after decryption. Also PGP has a major drawback but that's by design: the lack of PFS, if a private key is compromised all messages encrypted for that key can be decrypted.
/u/Yugong P
4 points
1 week ago
To add to your comment.

It's interesting feature Kleopatra by default would encrypt for yourself the messages you write to the other party. I would say that shouldn't be the default state at all. While it's great for being able to follow up on conversations a feature like that would render any future implementation of PFS useless.

Come to think of it I don't know any other PGP software that does this by default and I haven't actually seen this discussed anywhere on Dread. Definitely something people should be mindful of.
/u/DaVenom
4 points
1 week ago
Right, as /u/Yugong writes, be mindful.

In some conversations signing and encrypting to your self and others has the benefit that you can decrypt, and also show receivers that you are the sender.

When sending sensitive information like names and addresses it's not wise to sign and encrypt to your self, plausible deniability flies out of the window, you have stamped it with your "fingerprint".
Plausible deniability is definitively the main issue here.
It's kind of obvious when it comes to signing. As for encrypting to yourself, there's a couple of strategies to mitigate the risk. One is to create a short-lived, separate encryption key that you don't expose anywhere online. Encrypt your own messages with it so you can read them later without exposing yourself as a recipient (and probable author). Another way is to hide recipient fingerprints with the "--throw-keyids" option, so they can't be harvested for metadata analysis. Both these methods won't cover a seizure-level threat model. But it could be enough for buyers.
/u/DrugHub P
1 points
1 week ago
Yes, sometimes encrypt for yourself is not ideal. While nice for the regular user Kleopatra also lacks a needed feature imo: searching by key fingerprint. But again Kleopatra is not PGP, it's just a frontend. I for one like the console better, it's more fine grained and gives you access to some useful features like session keys.
/u/mistermista
2 points
1 week ago*
I wonder if optional FS or PFS could be implemented in a PGP update - and then a market can generate one random session key for the buyer/seller to additionally encrypt each PGP message with. The session key would be generated and visible to buyer/seller when a trade is opened and be destroyed when trade is finalised either through finalising or dispute resolution

of course a newly generated random session key would be needed for every new trade
/u/DrugHub P
2 points
1 week ago
I don't think so, it would need core changes client side. PGP was designed for email so if you got an encrypted message today you (or whoever intercepted it in transit) can decrypt it 10 years from now just by having access to the private key. PFS basically uses ephemeral keys that are discarded so even if you have the private key you can't decrypt previous messages, they are usually stored on device. PFS is something PGP was not designed for.
[removed]
/u/pgpfreak P Biker Babe 🏍️
2 points
1 week ago*
Stumbled across a post earlier suggesting this exact solution as part of an emailing protocol.
This would be difficult for darknet though. Part of why PGP is popular here is because we can do the encryption ourselves, from open-source software. We can't trust the market to automatize things for us. That being said it could make sense for a concerned buyer to use throwaway accounts and keys for each buy. A private key is definitively an identifying feature. It doesn't sound that useful to stick with it only for reviewing orders.
Change my mind.

Don't count on me. As you said. PGP is great for what it does. Which is only that much and nothing more.
/u/mistermista
2 points
1 week ago
alternative post title: 90% of people misuse PGP, weakening their OPSEC

once again the user is the cause of most problems
/u/Fyodor-MD 0pac
2 points
1 week ago
nice ai bro
/u/irvingwashington
1 points
1 week ago
surprised nobody else is pointing this out. I'm so tired of people using AI to write shit like it'll help with opsec
/u/Geckothemech
2 points
1 week ago
I'd say this has less to do with PGP and more so your friend being a dumb ass. PGP did its part. He maxed encryption and not enough OpSec.
/u/snowbunni P
1 points
1 week ago
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -----BEGIN PGP MESSAGE-----

hQEMA4aKI0efL/vZAQgA2Z/Z9PKgb/7t7bh74TrHC23BqjMdR8+wVg439RDOVHgb
9oP19lAtPnTs+bRHuZlsIknqUzibrgllJAJGg5PkbkO4aMH1HLpJ+Q07+lzVyQWT
sGW+WKeIqXCPi7jUaZQTjiJ8BvfjHVmmt8BSy86DAmLHkWy6fHI2/eXkju3QmM5o
m2+G6m3e+a/uPU73u26W25H+RgtuWqkkqifrXlhyXWQ4/TYCflcGoJKQ/jzhTiAL
Y/p/JijKyLeH+a+9cyLarmQOhcyqxXteSmSy/mNjqvsBGsZZugQRiguXbYFx0Z+a
rdXtRzEaPOAD9OhyW8nHDK2UdafadG5X/ssuxWqnDdJPAQirlE+s4bMVPN2ZbJoA
N7x5RlPao21SJKx/45wRuveocbhsE3hROKvFrQdGgjC59QqdgQEAFrrMXOEmayhI
BnjkujWnNpXb4j9+4RKv2w==
=egYZ
- -----END PGP MESSAGE-----
-----BEGIN PGP SIGNATURE-----

iQGTBAEBCgB9FiEEx9b5ilYoCVl7Y6FnfjwbP6b1EhoFAmhm8p5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEM3
RDZGOThBNTYyODA5NTk3QjYzQTE2NzdFM0MxQjNGQTZGNTEyMUEACgkQfjwbP6b1
EhpZJAgAyoVq6f3I1K6FnwPc5WEUqy+5fWQqZVBdXH9nJnTaIMYdyZYLEcy6bW5E
CP5DN3ME1eHWnYjWP5jZyjN9EPKJ+7eLoyvPKfxGcbVFFAxHsEm0jaSGfwVcd2vc
TZxmQ8dMkxQ/09MdmMnAuU4xapJSSXe7iG7yNNVRcgMDaJ+kun3pw3j+4UbCjk6b
zIYoqAi+8nkCR58BpRi7A5ZTkydY6Gl8vxOKuvXtISyPxQwqP+H3lKCuegD/I6pp
6nPM7osX9t5po5oFewZeBCWZ9VG6hIPtVub/ftYR7rNjKY0g8IqKUyByP32lAz1r
k1YvGeNiDbKd9pastZzdZKGo8viHqQ==
=eLwc
-----END PGP SIGNATURE-----
/u/mistermista
1 points
1 week ago
-----BEGIN PGP MESSAGE-----

hQEMA4aKI0efL/vZAQgAswVkK1v1qQ/yti5ro0m4XDnDltDNifTSPVVp3e8bm6qi
hJlePxGOt3MFU3I2uhCL0zBch1czR0FHghIbA01rL3+CdPWmnNpfHTqUTW8vhn5Y
kVULC4TZInlSSeyaJeOAECFxktf9wmcpcZCaNUBHljIiiahVDD+EjJu5XqRvgQoz
1Gt4zNuwc1xY9lweLV7QjlySs4/OyJIWwvwoy9q4QMb2bubhENP1t/JfYP17xpuF
3VfGebJSclRfBZkC8DetTRnVnNahnM1qNRr5VjQC/1fH4hgLPWXll/t9zsrxaimE
h/l4KOdypGJC3aY32/96vVdM+c5LNhiUN5MVU3cpl4ReA1Impmk6PZtYEgEHQArW
PjIgVr9bTrpO/kI2qEs3DYp7kSr7rvM4Dnbea6QEMOxS/8IOtqhmsRltpqgq3qYi
r2Nea4kjJf19G2XaLGh7asBGp7NKopJrUFXuvzBHS4ReA+HnDZZJ/sczEgEHQB71
fQK1jEDY7Ow3KLzYl7/bld5mG9BahvPOnCk2i2gKMPWzAtX+sQKOHO9tASlTDqir
0VCpLVXCJgUwAxK06dTu0NCjFGOyH5oYpDP3a4taRtJjAbwf898wJBCPIBHd1alq
ySEg2xRCC1B0wvcpyqyfc9sopnUeFR90tS0jJOSYu87UNiW9iFBkQwlZcVxn8Srv
BT/DSGLDii1rETB3S9abmUTuoNhjO1YIg2Aj01ncPaOFOv9m
=EmxZ
-----END PGP MESSAGE-----
/u/snowbunni P
1 points
1 week ago
-----BEGIN PGP MESSAGE-----

hQEMA4aKI0efL/vZAQf/UM6vmFoJD75sWSqIpbMP40ef/rBwzOQ6Gtqijama5D55
v9e5ua9gL/+FueTG9c5p7dZfPJw3ARNY1rqJS86dYPqFG6fGk4vvXUCaFQmiG3r0
7u6kOHKyU9q7hyF6qMqn/mI1+jN24YXBAhYGhKPqRLAvUWJ/Sk+1vkWmAOOktalp
eDxer2ByKq4X/f00Qrqmsd2sC5WYDyPrx/WxRVl7jSZayyiiMPgb3+7yNCFnsU9H
BTEIiWGI/4W5RA8eEFoKmX+fw6eQHQPojwf+e3Lvy0Nm4tTp6h8Y/8Z8NAE+5JFH
AnlEZ8iQhojl2owsfo2kb0F7jPl7OOq59iBGY0zsudJoATRzA8vluUUkJOmzlMrK
W4ONns6tNnvRsp9OTHyeCbcxH5H8xB/YJEWVp7pYCb9Qh8lgSHrcYdjxiiHPstNF
UC6aWIY6wZp6H2Sw/nOz/YklHs7tb1wy7CXQeNr5blhHuzeKKdORGqU=
=gWQr
-----END PGP MESSAGE-----
/u/mistermista
1 points
1 week ago
-----BEGIN PGP MESSAGE-----

hQEMA4aKI0efL/vZAQgAqCv1rFVGpKUkhbJhB49DqpucgNFCgqtZSLXrCE9J1shh
kdZWIXtAwnc4mGMPdSatD7rWC5KC3WkberGPiPY7hmSeY3cy78AspJSpjjOq3Dr/
hWJz8rYnUFvLT8R/MhLfWlLXgPHnFhK2BcoU/cetB2P5PHH4fj7t9GqxHSUBULK0
OPScEbEIddp/I4flsii36aXhZqBMDSNa4bphPR3zVHk4LwvHVVYB7LrGKhp9W8W0
08ROgkn2Ihd0WErh/ABbfT15ozUqBek7189N6JybZPS//V6lA0d8v9XKLte9GYjC
7L8QE0YFt3WLCT90p/NbBel2TKgtFjhv5VErqpgpbtKHAehvFVQRk47YiJC9cf7Z
SJz0ZMeUPj4h8+prMkrae40Exb+JKkTqqJ8B8HKGswq1QZp09KxpRr9He93bSBhe
Rymk4TCmBBiVG+mPXwr7QVl5RzWAG9w2CJ6dRTFQeVOKcRk9rs4a8crGcU68Vjni
k5GNSO4qiC4FRTI1zhA4NQ9jHXjI26Mv
=7jhg
-----END PGP MESSAGE-----
/u/snowbunni P
2 points
1 week ago
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Muahaha!
-----BEGIN PGP SIGNATURE-----

iQGTBAEBCgB9FiEEx9b5ilYoCVl7Y6FnfjwbP6b1EhoFAmhoCfxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEM3
RDZGOThBNTYyODA5NTk3QjYzQTE2NzdFM0MxQjNGQTZGNTEyMUEACgkQfjwbP6b1
EhpT6wf8DaQTLVbccO07IfNaGKkBbtXg3203k9hJEkz+QApFeLb/xlS6hZcjscKn
OQc6DA5ylma8Ag85/GFWc7iQvj6flxVWIXf03N+OF4Fd63nGVlqAZp8htFp3y6lv
S+mgj91nzy4IPqlnqiuhPjGy+MOIGMYfWcoNlnd6W91rhLewm1ZX2ly4AtovmEMZ
wZQl71b1mauTxS9LtaWJt4oZD2fQIOfWebd95x1pD4TJrpb+RCmAxgzna3gUpZtw
/3opvxOuHUGPaUS+cudV4+kCe2bEVL/kEauK0JVz/fFpKqWMUUiCU1z8QQKWFpWe
7Pj7a8At7TjG2j2mkdfKaZJ3jZKwEQ==
=1thq
-----END PGP SIGNATURE-----
/u/tortilla_eyez
1 points
1 week ago
"with ads" lmaoooo, if youre doing anything from your phone youre fucked
/u/darkripper
1 points
1 week ago
✅ Want real OpSec?

Use a system comprised of well maintained 100% free and open source software. Beware forums, they are full of social engineers and shitty mistakes to copy. Learn the concepts from books, not your homies.
/u/miner21 P
1 points
1 week ago
That does seem a bit excessive. I encrypt sensitive stuff. Not just saying hi to someone
/u/CTI
1 points
1 week ago
did you write this with Deepseek? lol
/u/Daptronix
1 points
7 hours ago
Popular opinion: the post title is dumb, the problem is nothing to do with PGP