Mars Market Reference Plain descriptions of what each step involves, what you will experience, and where it can go wrong

Mars Market addresses

Three published addresses for the same market. Copy rather than retype, and check the signature once you are through.

Address 1 marsautkudspgk6j23cxdtrk36ae4fpis2eoe7izu5y2rsksvmfji2ad.onion
Address 2 marshjhtog245vzjzcicnmv2ci6yljibvdm4pngq5kmkfvcutppboxad.onion
Address 3 marsiujka6lrsaqpnxiwvknthhzsrlmq77mnl2fi62guc4lwxif65syd.onion

This list is published, not monitored. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.

Reference › Procedures

Verifying a link

The one step on this site that answers a question nothing else can. It takes under a minute once the preparation is done.

What this step is
Confirming that the party answering at an address holds the key the market is known by.
How to prepare
A pinned fingerprint, established from independent sources and stored where you control it. Without it this check proves nothing.
What you will see
A block of text between armour lines on the page, and a short result from your own software after checking it.
How it works
A signature establishes two things: that whoever produced it held a specific private key, and that the signed text is unchanged. Narrow, absolute, and enough.
How long it takes
Under a minute once set up. The setup is an hour, once.
What you will experience
Almost nothing. It is mechanical and boring, which is exactly why people stop doing it.
What can go wrong
Four possible results, two of which look like success. See the table below.
Benefits and limits
It answers whether you are where you think you are and nothing else. Not whether the site is honest, not whether your own machine is trustworthy.

The procedure

  1. Find the signed block. It begins and ends with the armour lines. If there is no signed block, you are finished and the answer is no.
  2. Copy all of it. Nothing trimmed, no whitespace altered, no quotation marks converted. A partial copy fails in a way that looks identical to tampering, which causes unnecessary alarm.
  3. Check against your pinned fingerprint. Not a key the page offers, and not one you fetched because the check complained.
  4. Read the output. Both which key signed and the date inside the signed text. This is the step people skip.

The four results

ResultMeaningWhat to do
Bad signatureText altered after signing, or the signature fabricatedLeave. Unambiguous, no judgement needed.
No public keySigned by a key you do not hold. A gap in your keyring, not a verdictImport the right key after checking its fingerprint. Never one the page hands you.
Good, unexpected keyThe maths works against a key that is not yoursLeave. The word good appears, which is why this one catches people.
Good, old dateVerifies perfectly, statement is months oldTreat as unconfirmed. Signatures never expire, so genuine old ones get replayed.
The habit inside the habitThe last two rows are what catch experienced readers, and one habit defeats both. Read which key signed and when, rather than stopping at the word good. Two seconds.

Why the date sits inside the signature

A signature has no expiry. A statement signed two years ago verifies exactly as cleanly today, which makes signatures excellent for archives and awkward for anything about the present. Putting the timestamp inside the signed text fixes that, because the date cannot then be changed without breaking the signature. Somebody replaying an old statement is stuck presenting an old date, and the only remaining question is whether you look at it.