Logging in
The login page is not the first thing you see. The first thing is a test, and the test is not the login. Keeping those two straight is most of the security model.
Mirror addresses · 3
same market · no rankingblackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onionblackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onionblackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onionCopy one address, paste it into the Tor Browser, and compare the last six characters against what landed in the address bar. If one will not connect, build a new circuit and take the next. Why an onion refuses to load.
What the first load looks like
Open one of the addresses above, wait out the circuit, and the market greets you with a captcha: a night city with circles and squares drawn over it and a thirty second timer. Click the shape that has a cut in it. This is the bot filter. It exists because the login page is the single most copied page on the internet's darker half, and a shape that has a cut in it is cheap for a human and annoying for a script.
If the timer expires, the image refreshes. If the circuit died, the page never comes and the fix is a new circuit, not a new password.
The login itself
After the captcha: username, password, and, because 2FA is required on every account, a six digit code from your authenticator app. From a device or network the market has not seen before (on Tor, that is every time), a PGP check can follow: a one time code the market signs with its key, which you sign back with yours. The whole exchange is there to prove the person typing the password holds the private key that registered the account.
- Use a long password, one you have not used anywhere else. If Black Ops were the only account you ever held, a short memorable one would be fine. It is not the only one.
- Keep the authenticator app seed. Losing the private PGP key and the 2FA seed together is how accounts stop being recoverable.
- The market mails through PGP only. Your password reset, your login confirmation, your support thread, all of it is encrypted to the key you registered.
When a password is due, and when it is not
A password is due in exactly one place: the market's own login form, on an address whose last six characters you checked, after the captcha, on a circuit you built yourself. Anything else that asks for it is asking too early.
A "re verification" message. A link in a direct message. A page that says your session is about to expire and offers a familiar looking form. In each case the form may be perfect, and the page may be perfect. The only thing a copy cannot reproduce is the address in the bar. The check is two steps: the characters and the signature.
The advanced version does not copy the page at all. It sits between you and the real market, forwards your traffic, and reads it going past. Every element you see is the real element, including the footer. The address bar is the one place the proxy cannot reach, which is why it is the only check that matters.
Nothing on this page will ever ask for a password. Login happens on the market, after the captcha, at an address you verified. New here? The registration path is mapped out.