You expect the login screen to look the same every time
WeTheNorth addresses
hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onionhn2paw7zfvndw3dovycegeqmvvnf4pl67b3g2p7pohjlzavloosh73id.onionhn2paw7zrgujyhnt6mgxlt2q6uhgbke4itpqitxhyfbumq3wtnckbuyd.onionPrinted as supplied, in no order. Nothing here is checked or timed, so an address that opens is not proof of anything. more about the set
I know what the login page looks like. If it looked different I would notice and stop.
The front changes often, because the front is the part being attacked and patched. Familiarity is not a check, and it is the check most people are quietly relying on.
The gap: you are using memory of a picture to answer a question about a key.
Why familiarity feels like security
Recognition is fast and effortless, which is exactly what makes it feel reliable. You have seen this page thirty times. Your brain reports a match and you move on. The report is genuine. It is just answering a different question from the one you needed answered, and it answers with total confidence either way.
What actually changes at the front
- Challenge style, for the reasons in the captcha entry.
- Wording. Notices get added when something is going on and removed when it stops.
- Layout. The door gets rebuilt more often than anything behind it, because it takes the most damage.
- Language. A bilingual Canadian market carries English and French, and which one you land on can differ between visits.
So a person who trusts recognition gets trained twice over. Real change teaches them that difference is normal, which erodes the alarm. Then the one difference that mattered arrives and lands on an alarm that has already been worn down by honest updates.
The copy problem
A front page is public and static. Anyone can fetch it and serve their own version at their own address, character for character. There is no visual property of a page that cannot be reproduced by the person copying it, including a warning about phishing, including a French toggle, including a notice telling you to check the address carefully.
That is worth sitting with. The most reassuring thing on the page is available to whoever wants to reuse it. Appearance is the one dimension where the attacker has a free and perfect copy.
What to check instead
- The address you arrived on, compared against a set you stored yourself. Not the one printed in the page, the one in the bar.
- Where the click came from. An address pasted from your own note is a different situation from one clicked out of a message.
- Whether anything is asking for information the platform never needs, such as an email address or a recovery contact.
- Whether you are in a hurry. Hurry is the condition every convincing copy is built for.
And when a front page genuinely looks wrong, the useful response is not to conclude you are being attacked. It is to stop, go back to your stored set, and arrive again from a source you control. Most of the time you will find nothing was wrong at all, which is fine. The point of the habit is that it costs a minute and does not depend on your memory of a picture.
Questions people send about this
The page is in French this time. Is that a problem?
No. The market operates in English and French, and which you see first is not a signal about anything.
Should I screenshot the login page to compare later?
It will not help. A copy can match your screenshot exactly. Compare the address against your own stored set instead.