Mars Market addresses
Three published addresses for the same market. Copy rather than retype, and check the signature once you are through.
marsautkudspgk6j23cxdtrk36ae4fpis2eoe7izu5y2rsksvmfji2ad.onion
marshjhtog245vzjzcicnmv2ci6yljibvdm4pngq5kmkfvcutppboxad.onion
marsiujka6lrsaqpnxiwvknthhzsrlmq77mnl2fi62guc4lwxif65syd.onion
This list is published, not monitored. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.
The client
Short, because the correct answer is one piece of software. Most of this page is about the things people use instead.
What to install
Tor Browser, downloaded from the Tor Project directly, with the installer signature checked against their published key. Then set the security level to Safest before going anywhere that matters.
| Level | What changes |
|---|---|
| Standard | Everything enabled. The largest attack surface, and the reason the other two exist. |
| Safer | Scripting off on non-secure sites, some media restricted. A compromise that mostly helps. |
| Safest | Scripting off everywhere, most media and fonts blocked. Pages look plain and behave predictably. |
Some pages break at Safest. That is the trade and it is a good one, because the scripting it disables is what most drive by compromise depends on. A page that stops working is a visible cost. What it prevents is invisible, which is why people talk themselves out of this setting.
What to avoid
- Clearnet gateways. A site that opens onion addresses for you makes the request itself, which means it reads everything you send including credentials. That is the mechanism rather than a flaw in it, so an honest operator does not fix it.
- Anything promising faster Tor. There is no such product. The category is made of malware and fingerprinting, and it is where address substitution usually comes from.
- Repackaged bundles. Software named similarly, distributed anywhere other than the project itself.
- A VPN as a substitute. Different tool, different problem. Stacking one in front of Tor adds a company that knows exactly who you are and that you are using Tor, which is information that did not previously exist in one place.
Mobile, honestly
Workable and worse. The specific problem is not that a phone is insecure in the abstract, it is that checking a signature is inconvenient enough there that people stop doing it. A tool that makes the load bearing habit annoying quietly removes the habit, which is a larger risk than anything technical about the platform.
Tails and similar
Genuine improvements, and wrongly presented as the first step. For a reader on their own machine, pinning a key properly buys more protection than changing operating system, and it takes an hour rather than a weekend. Where a separate system genuinely matters is a shared or managed computer, and on a device you do not control the honest answer is not to do this at all.