News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

why username and password? isn't pgp enough? : OpSec | Torhoo darknet markets

most markets have a weird combination of authentication methods, but isn't pgp enough? why do i have to put a username / password first? preventing fingerprinting on encrypted messages? i feel like most market operators are blindly following an outdated concept because "why not".
I guess it is a barrier for new buyers and many vendors. People don't understand the PGP and won't use the market = less profit.
/u/pgpfreak P
2 points
3 days ago
less profit

This exactly. Shame.
/u/Doraemon
2 points
3 days ago
majority of market force vendor to have 2FA pgp activated on there account.
/u/purple_floyd 📢 🍼
1 points
3 days ago
people who don't understand pgp shouldn't be allowed on such markets. they are dangerous, not only to their own opsec.
/u/quark P ⚛ Царь ⚛
2 points
3 days ago
I agree with you but some market has the pgp-login like drughub and darkmatter.
I will also implement it on omega.

Thank you,
Q
[removed]
/u/quark P ⚛ Царь ⚛
1 points
3 days ago
Why you always reply to my comments and remove it?
It's not abt comment it's abt flair , i thought if i remove comment flair will dissapear too but no that's the reason
beelzebub is abusing the whole sub
/u/ImpactMarket
1 points
3 days ago
We have it too! :P Actually, it was added earlier today right before this post showed up. What a coincidence!
/u/pgpfreak, you’ll want to check it out. Guest browsing is on the list and will be available by this weekend.
/u/kesselrun
1 points
3 days ago
Dark Matter still makes you login with a username and password and a captcha first before the 2fa PGP. At least for buyers.
/u/pgpfreak P
2 points
3 days ago
It's about time somebody mentions it. I wouldn't mind protecting my account exclusively through my private key. Your safety is only as strong as the weakest element in the chain. I know for sure it's not PGP.
/u/PotionsNPortals
1 points
2 days ago
Username checks out...
Old habits die hard
/u/I8urmastodon
1 points
3 days ago
DrugHub kind of does that. I don't mind that login process.
/u/PotionsNPortals
1 points
2 days ago
DrugHub is WAY too easy to get onto... Something sketch about them. I feel like they will be the next to exit scam (my personal prediction).
/u/PotionsNPortals
1 points
3 days ago
This why I love vending on Dark Matter. They have a private mirror for vendors that only utilizes your PGP to login. It is amazing. It skips all the captchas, login & everything (which could bring up OpSec issues due to not having that extra barrier to protect you, but even 2FA can be hijacked by spoofing, mostly the 6 digit pins and stuff on phones, not really your 4096 bit RSA Key Pair. Add auto-withdrawals upon finalization to that and you have a very happy vendor haha not to mention that they lower the fees as you gain experience as as a vendor... anyways why am I rambling about this in OpSec? lol... but yeah I agree on some level. PGP verification should suffice instead of needing to continuously input your login information redundantly. Totally get that. The harder a market is to get into, the less people will continuously try to overcome the learning curves.
/u/kesselrun
2 points
3 days ago
Torzon is really the one that needs to take a hint.
/u/fnaisodhfui 🍼
1 points
3 days ago
This should really be standard. Makes it easier for people who use pgp anyways, and also makes sure that everybody on the market has a pgp key.
However, considering there are still markets that accept bitcoin, I doubt we'll see it implemented any time soon.
/u/drjapi2
1 points
3 days ago
Extra protection always better
/u/kesselrun
1 points
3 days ago
Drug Hub lets you sign in with just PGP only, but of course you do still have to register a username.
/u/DoubleUp447
0 points
3 days ago
The PGP key is cool and easy to login and identify people, but User+Pass+PGP 2FA will always be better OpSec for Vendor's IMO