XMR $317.16
FIRO $0.73

Please login

Region:

Current view: Classic | Threads
Sort by: New | Tips

Questions About the Purpose of PGP and Ideas for Marketplaces and Users

BoggleBoatt Donor - Supporter
5 (1)
Posts: 6
Earned: 0 XMR
Tipped: 0.02 XMR
This marketplace is needed in the current climate of surveillance and control. That is why I must share some thoughts of what I seen here as a new user and observer.

After checking it seems many users on AnonBazaar are not in the frequent habit of signing with PGP. I have a suspicion the market is not getting a fair use or understanding of PGP encryption. They could use it to validate their linked accounts, other user keys, or trade agreements across platforms and hardware. Sometimes they do attempt to verify but do not understand they must sign both messages they want linked with that exact key derived from that key pair. Getting vouched for by other members is good but no substitute for proof of key custody. In spirit, after you are sure of an identity you should sign someones key with yours and share to further the Web of Trust model. I feel some users also believe the in house javascript encryption to be a silver bullet. Verification requires that you own and can use the keys.

What is the exact purpose of a PGP key on your profile if most users are not going to use it to sign or verify important data such as account bio, messages, other user keys, or contracts of trades? The only thing I wish to see is the site let users put their own PGP key in place or easier to find in the settings. Dating the key submission to the site would also be great. The thing I wish more users would do is to publish both their PGP signature with the message and PGP public key block to all accounts on any sites they wish linked to be linked with that particular key pair. That they should not only upload new keys to PGP keyservers but also cross sign both keys in the event they wish to revoke an old key pair. They should keep evidence of these key developments public, shared, and archived.

After the attacks on Haveno and RetoSwap, I do not think we can afford to be silent or confused about the security of the current P2P and DEX economy. I think we should steer away from the CEX model when possible, at least in some aspects that are important like identity and keys. I also acknowledge that PGP and WOT is no panacea either, as it is user unfriendly and bloated. The encryption is inherently undeniable and has no forward secrecy once compromised. That is also not mentioning the potential privacy and metadata risks by using such WOT model which may require extreme account and identity segregation. I think particl and its BasicSwap has the 1/2 multisig collateral method I've been curious about too but I'm curious as to anyone and their opinion of using the service.

As an update to this thread, I did finally find the NoJS messenger and it did add some clarity even though I can't get it to detect and decrypt the format. I guess the other stuff still stands regarding the nature of CEXs, WOT, and users getting into the habit of not wanting to sign or verify.

The things I think we should make easier and accessible to most users:
http://opbible7nans45sg33cbyeiwqmlp5fu7lklu6jd6f3mivrjeqadco5yd.onion/opsec/multisig-wallets/
https://en.wikipedia.org/wiki/Web_of_trust
Edited: Jun 3 11:46
Tip Monero to BoggleBoatt
QR Code 853E3ezsKKbjUUcZ247R6P2ri4cDv2eiSGKuUydydTSx8PKkggZToZxenwuEiZ7MDJGhj4f1hTBhBXVciuHc4G4H8DmvYfa
Tip Firo to BoggleBoatt

BoggleBoatt has not setup a Firo tip address yet.

Publish Tip to BoggleBoatt

Please login to publish your tip

Page:
1
You must login in order to publish a post