You never made a key, and now nothing can be checked
Mars market mirrors
marshjhtog245vzjzcicnmv2ci6yljibvdm4pngq5kmkfvcutppboxad.onion
marsiujka6lrsaqpnxiwvknthhzsrlmq77mnl2fi62guc4lwxif65syd.onion
marsmtbwtxkohhpu34m4jkwcntian7n257wsex5tbkmsjdjrsz6me3yd.onion
Printed as supplied, in no order. Nothing here is watched or timed, so an address that opens is not proof of anything. More about the set
A notice appears claiming an address changed. A message arrives claiming to be from support. Neither can be verified, because verification needs a key and there is no key on this side of the exchange.
The reader then complains that the market does not confirm anything properly. The mechanism for confirming it was there the whole time and was never set up.
- Responsible
- You. The tool that answers this class of question was available and was skipped.
- Usually blamed on
- The market, for not communicating clearly enough, or for support that will not confirm things.
- What follows
- Setting up a key once converts a permanent guessing problem into a check that takes seconds. Nothing else available to you does that.
What a signature settles
A valid signature over a message says one thing precisely. Whoever holds the private key matching the public key you already have produced this exact text, and the text has not changed since. That is the whole claim.
It does not say the signer is honest. It does not say the signer is who they claim to be in the world. It says the same hand wrote this as wrote the thing you trusted before. For the question of whether an announcement really comes from the same source as the last announcement, that is exactly the right tool.
What it cannot settle
- Whether the address inside a correctly signed message is safe to use. A signature covers text, not truth.
- Whether a key you fetched today belongs to who you think. That depends entirely on where the key came from.
- Whether the signer still controls the key. Keys get lost and stolen like anything else.
- Anything at all, if you obtained the public key from the same page that served you the message.
That last point is the one people get wrong. A message and its verifying key from the same source verify each other in a closed loop and prove nothing. The key has to be older than the doubt.
The reason it never gets done
It looks like a project. Software, a passphrase, a concept of two keys, an unfamiliar vocabulary. The reader postpones it, and the postponement is permanent, because the moment when a key would help is always a moment when there is no time to make one.
The actual work is about fifteen minutes once, and most of that is choosing a passphrase and writing it down somewhere that is not the same machine. The second time somebody does it, it takes four.
What follows from getting it right
The reader with a key can answer a question that the reader without one can only have opinions about. That is a change of category, not a small improvement. It also changes what a support message is worth, because an unsigned message from support and a signed one are no longer the same object.
One caution. A key does not make a bad address good. Verification tells you where a statement came from. Judging the statement is still yours to do.
The order the work goes in
- Install the software on the machine you actually use, not the one you mean to start using.
- Generate a pair. Accept the defaults, because the defaults are fine and choosing otherwise is how people stall for a year.
- Write the passphrase down on paper. A passphrase held only in memory is a key you will lose.
- Collect the public keys you care about now, while nothing is wrong, and note where each one came from.
- Verify one signed message you already believe, just to see the tool say yes. The first success is what makes the habit stick.
Step four is the one people skip and it is the one that does the work. A key collected calmly, from a source you chose while nothing was urgent, is worth something later. A key fetched in the middle of a panic, from whatever page was in front of you, is worth nothing at all.
