News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

What is the PGP used for in my Dread account? : PGP | Torhoo darknet markets

Sorry for the noob question, but I'm new to the dark net and have been lurking this site quite often and happy with this project so far.

I have basic understanding of OpenPGP and how/why it's used, and is the reason why I use ProtonMail to begin with. What I can't find out for the life of me (not only the clearnet doesn't have straight answers, but the public community is refusing to answer my questions, subreddit mods even removed my post...), is not only I'm seeing a few commenters posting their "signed messages", but I'm also seeing an option to upload my own PGP key in my account settings on Dread.

So... why?
/u/[deleted]
1 points
5 years ago
When you post your PublicKey someone can use it to encrypt a message to you.

You could also send your PublicKey to someone with a PM but then i would need to first contact you in cleartext.
If you uploaded it to your dread profile i can just grad it and immediately start an encrypted conversation with you.

And 2FA with dread only works when dread has your PublicKey.
/u/[deleted] 📢
1 points
5 years ago
So basically, if someone wants to send me a super secret message, they simply won't necessarily need to ask me for the public key because it's already available in my profile?

And another question. Why is it so important to sometimes "sign" your messages, as I'm still seeing comments in some places where they have a plain-text comment and then a signed message?
/u/[deleted]
1 points
5 years ago
So basically, if someone wants to send me a super secret message, they simply won't necessarily need to ask me for the public key because it's already available in my profile?

If you dont use 2FA for dread then this would be the only use case i have in mind.

And another question. Why is it so important to sometimes "sign" your messages, as I'm still seeing comments in some places where they have a plain-text comment and then a signed message?

With signing a message you can prove someone that it was really you writing that message (or at least the person in possession of your keys).

For example if you dont trust the dread mods but want to send me a message with PM and for some reason dont want to encrypt that message you could sign it so that i can be sure it really was you sending that message and not some of the dread admins impersonating you and just using your account for sending me messages.

Or if you post something and want that everyone can read it but you still want to make sure that the other ones could check if that message was really sent by you then you could sign it instead of encrypting it.

Signing is then useful when encrypting it is not needed but you still want to show that you were in possession of your keys.
/u/[deleted]
1 points
5 years ago
Another reason why to sign messages:

When you encrypt a message to a vendor you use his PublicKey and he use yours.
But a malicious market could just change your PublicKey to his one without telling you and the vendor would grab "your" PublicKey and encrypts it for "you" but the market will be able to read it and your communication is not encrypted anymore.
Thats what LEA did with Hansa Market.

If you sign every message you encrypted with the vendors PublicKey then the other one can be sure to really talk with you.

I had a vendor once who refused to talk with me because i only encrypted the messages but did not signed them.
/u/OnionUrl OnionUrl.org Owner
1 points
5 years ago
You can add your PGP to your dread account which gives people peace of mind that it is you they are talking with, to add a key to your account it has to be validated by decrypting a signed message containing a code. This validates you are the person behind that key. You may also use this to further secure your account by enabling 2 factor authentication which will encrypt a message with your key each time and you will have to decrypt that message and paste they code into dread.