Logging in

The login page is not the first thing you see. The first thing is a test, and the test is not the login. Keeping those two straight is most of the security model.

Mirror addresses · 3

same market · no ranking
ONIONtail dpsdad
blackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onion
ONIONtail r67hid
blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion
ONIONtail ak4dqd
blackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onion

Copy one address, paste it into the Tor Browser, and compare the last six characters against what landed in the address bar. If one will not connect, build a new circuit and take the next. Why an onion refuses to load.

What the first load looks like

Open one of the addresses above, wait out the circuit, and the market greets you with a captcha: a night city with circles and squares drawn over it and a thirty second timer. Click the shape that has a cut in it. This is the bot filter. It exists because the login page is the single most copied page on the internet's darker half, and a shape that has a cut in it is cheap for a human and annoying for a script.

If the timer expires, the image refreshes. If the circuit died, the page never comes and the fix is a new circuit, not a new password.

The login itself

After the captcha: username, password, and, because 2FA is required on every account, a six digit code from your authenticator app. From a device or network the market has not seen before (on Tor, that is every time), a PGP check can follow: a one time code the market signs with its key, which you sign back with yours. The whole exchange is there to prove the person typing the password holds the private key that registered the account.

When a password is due, and when it is not

A password is due in exactly one place: the market's own login form, on an address whose last six characters you checked, after the captcha, on a circuit you built yourself. Anything else that asks for it is asking too early.

A "re verification" message. A link in a direct message. A page that says your session is about to expire and offers a familiar looking form. In each case the form may be perfect, and the page may be perfect. The only thing a copy cannot reproduce is the address in the bar. The check is two steps: the characters and the signature.

Reverse proxy phishing

The advanced version does not copy the page at all. It sits between you and the real market, forwards your traffic, and reads it going past. Every element you see is the real element, including the footer. The address bar is the one place the proxy cannot reach, which is why it is the only check that matters.

Nothing on this page will ever ask for a password. Login happens on the market, after the captcha, at an address you verified. New here? The registration path is mapped out.