Mars Market addresses
Three published addresses for the same market. Copy rather than retype, and check the signature once you are through.
marsautkudspgk6j23cxdtrk36ae4fpis2eoe7izu5y2rsksvmfji2ad.onion
marshjhtog245vzjzcicnmv2ci6yljibvdm4pngq5kmkfvcutppboxad.onion
marsiujka6lrsaqpnxiwvknthhzsrlmq77mnl2fi62guc4lwxif65syd.onion
This list is published, not monitored. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.
Credentials
Ten minutes of setup that completely answers one of the most common ways accounts are lost.
Uniqueness rather than strength
Strength protects against guessing, which is not the attack. The attack is a credential pair leaked from an unrelated service being tried everywhere by something automated. A long complicated password reused somewhere that leaked it is exactly as useless as a short one, and the confidence it produces makes the situation worse.
What a second factor covers
| Attack | Stopped? |
|---|---|
| A leaked password tried later | Yes, completely. This is exactly what it was designed against. |
| A live copy of the login page | No. It collects the password and the code together and replays both while the code is still valid. |
| Something running on your own machine | No. Nothing on the account side helps. |
So it is worth turning on immediately and it is the second line. The first is arriving at the genuine site, which is the check and nothing else.
The part people regret
- Save the recovery material at setup, before closing the page. Recovery without it is limited and frequently impossible.
- Keep it separate from the password. Both in one place is one factor wearing a costume.
- Do not keep the only copy on one device. Devices get lost and replaced, usually at the worst moment.
- Not in a screenshot. Photo libraries sync, back up, and get indexed by software that reads text in images.
- Test once that you can actually produce it from a second place.
Two failures that look like an attack
Codes suddenly rejected is usually clock drift, which is common on machines that have been off for a while or run in an isolated environment. A code accepted and then rejected is usually a slow circuit pushing you past the window. Both read as something sinister and are neither, and both are worth ruling out before concluding anything. They come up again in rejected login.