So I'm familiar with checking the pgp of markets. I import their key from their subtforum or on the site itself. And use it to verify anything that needs it on the site. My question is do phishing sites have almost the exact same URL except they're off by a letter or digit? Also how do they get the exact URL they want?
An
Phishers generate onion links that look similar to official links in order to trick noobs. The only way to prevent phishing is to PGP verify before logging in or deposit funds.
Once you have imported a markets PGP key you can then verify any signature generated by that market. Each market signs official mirrors with the market PGP key and it can be found within the Wiki of the markets sub.
Using DrugHub as an example, here is the PGP signed link: /d/DrugHub/wiki/?id=a36f94a6
Paste that message into PGP software and click Verify, it will come back as a good signature if its genuine.
Once you have a genuine link, BOOKMARK it for later use.
Lets not discuss how phishers generate onion links, we do not want to promote it.
Once you have imported a markets PGP key you can then verify any signature generated by that market. Each market signs official mirrors with the market PGP key and it can be found within the Wiki of the markets sub.
Using DrugHub as an example, here is the PGP signed link: /d/DrugHub/wiki/?id=a36f94a6
Paste that message into PGP software and click Verify, it will come back as a good signature if its genuine.
Once you have a genuine link, BOOKMARK it for later use.
Lets not discuss how phishers generate onion links, we do not want to promote it.
Not the exact same URL, the first characters sometimes. They generate vanity onions with mkp224o.
Just make sure you're on the official tforum mirror so the pgp keys and market links aren't fake themselves.
Then like desnelweg said, use PGP to verfiy.
Just make sure you're on the official tforum mirror so the pgp keys and market links aren't fake themselves.
Then like desnelweg said, use PGP to verfiy.
What I've also seen before, is that in addition to using similar looking onion links, phishers also register lookalike clearnet domains using alternative TLDs (e.g., .online, etc.) and may also append "onion" to the domain name.