First time buying off the Darknet today.

I wouldn't recommend buying anything with everything going on right now. Give it some time until the damage is properly assessed and we have a good idea of what to do from here on out. But if you're deadset on doing this, here's what you need to do.

I'm going to assume you're using Tails for this. If not, just adapt the directions:

  1. In general, but especially with everything going on, you need to cross-reference the vendors PGP key to the Grams Info Desk. Copy the vendor key and paste it into the search field here: http://grams7enufi7jmdl.onion/infodesk Make sure it leads you to the right vendor and make sure the info is correct.

  2. Assuming it's correct, copy the key from the vendors info page on Grams just to be safe. Click the clipboard, click "Manage Keys", then click "GnuPG Keys". Hit Ctrl+V, then click "Import". Wait a bit and then you should see it with the rest of the keys.

  3. I'm going to assume you've already made a personal PGP key. If not, just refer to the DNM Bible, it's not difficult. Before sending a message, do a quick test to make sure it's properly encrypted. For the test, we're going to do two things. First, encrypt it with your personal key, make sure you can read it, then with the vendors key, and make sure you can't read it.

Click the clipboard and click "Open Text Editor". Type random bullshit in it, then copy it. Click the clipboard, then click "Sign/Encrypt Clipboard with Public Keys". Check your personal key from the list and press OK. Click the clipboard and click "Decrypt/Verify Clipboard". Type in your password and the results should show whatever you typed on the text editor.

Next, repeat the above paragraph, only this time check the vendors key and click yes when it asks if you trust it. Also, make sure to click the "Sign message as:" drop down menu and click your personal key. This ensures the vendor knows 100% the message is from your key. When you decrypt it, you should get an error saying it's not readable. This is what you want. To make absolutely sure, paste it into the text editor. You should see BEGIN PGP MESSAGE, a bunch of random letters and symbols, then END PGP MESSAGE. This is what everyone, including you, will see. The only person able to read the proper message has to have access to the private key which the vendor has. If both of these tests worked as I described, your PGP works and you used it correctly.

So to summarize, type whatever message you want to send into the text editor. Copy it, encrypt it with the key of the person you're sending it to, and sign it with your personal key. As a quick test every time, paste it into the text editor as you did before and make sure you see BEGIN PGP MESSAGE followed by gibberish. Go to the market website and paste into whatever text field it tells you sends it to the vendor,

/r/DarkNetMarketsNoobs Thread