Mars Market Reference Plain descriptions of what each step involves, what you will experience, and where it can go wrong

Mars Market addresses

Three published addresses for the same market. Copy rather than retype, and check the signature once you are through.

Address 1 marsautkudspgk6j23cxdtrk36ae4fpis2eoe7izu5y2rsksvmfji2ad.onion
Address 2 marshjhtog245vzjzcicnmv2ci6yljibvdm4pngq5kmkfvcutppboxad.onion
Address 3 marsiujka6lrsaqpnxiwvknthhzsrlmq77mnl2fi62guc4lwxif65syd.onion

This list is published, not monitored. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.

Reference › Before you start

The client

Short, because the correct answer is one piece of software. Most of this page is about the things people use instead.

What to install

Tor Browser, downloaded from the Tor Project directly, with the installer signature checked against their published key. Then set the security level to Safest before going anywhere that matters.

LevelWhat changes
StandardEverything enabled. The largest attack surface, and the reason the other two exist.
SaferScripting off on non-secure sites, some media restricted. A compromise that mostly helps.
SafestScripting off everywhere, most media and fonts blocked. Pages look plain and behave predictably.

Some pages break at Safest. That is the trade and it is a good one, because the scripting it disables is what most drive by compromise depends on. A page that stops working is a visible cost. What it prevents is invisible, which is why people talk themselves out of this setting.

Never do thisBeing asked to lower the security level so something will work is a warning sign in itself. It does not help speed and it removes the protection at the moment somebody wants it removed.

What to avoid

  • Clearnet gateways. A site that opens onion addresses for you makes the request itself, which means it reads everything you send including credentials. That is the mechanism rather than a flaw in it, so an honest operator does not fix it.
  • Anything promising faster Tor. There is no such product. The category is made of malware and fingerprinting, and it is where address substitution usually comes from.
  • Repackaged bundles. Software named similarly, distributed anywhere other than the project itself.
  • A VPN as a substitute. Different tool, different problem. Stacking one in front of Tor adds a company that knows exactly who you are and that you are using Tor, which is information that did not previously exist in one place.

Mobile, honestly

Workable and worse. The specific problem is not that a phone is insecure in the abstract, it is that checking a signature is inconvenient enough there that people stop doing it. A tool that makes the load bearing habit annoying quietly removes the habit, which is a larger risk than anything technical about the platform.

Tails and similar

Genuine improvements, and wrongly presented as the first step. For a reader on their own machine, pinning a key properly buys more protection than changing operating system, and it takes an hour rather than a weekend. Where a separate system genuinely matters is a shared or managed computer, and on a device you do not control the honest answer is not to do this at all.