You expect PGP to be optional paperwork
WeTheNorth addresses
hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onionhn2paw7zfvndw3dovycegeqmvvnf4pl67b3g2p7pohjlzavloosh73id.onionhn2paw7zrgujyhnt6mgxlt2q6uhgbke4itpqitxhyfbumq3wtnckbuyd.onionPrinted as supplied, in no order. Nothing here is checked or timed, so an address that opens is not proof of anything. more about the set
Keys and signatures are for people who enjoy that sort of thing. Being careful covers the same ground.
Being careful means looking at things, and every visible thing can be copied. A signature is the only check that does not depend on appearance, and it takes an afternoon to learn once.
The gap: you are treating the only working check as an accessory.
What a signature answers
Not who is honest. Not who is nice. One narrow question with a yes or no answer. Was this exact text produced by somebody holding this exact private key. Every character is covered, including the middle of an onion address where your eye stops working.
That narrowness is the strength. A page can be copied, a captcha imitated, a design cloned pixel for pixel, and none of it changes the answer. The copy either has the key or it does not.
Where the trust actually sits
A signature moves the question rather than removing it. Now you have to care about where the key came from, which is a smaller and more stable problem than judging a new page every time. A key you fetched a year ago, from a source you can still name, that has signed consistent statements since, is worth far more than any amount of careful looking at a fresh page today.
Verifying a signature against a key you took from the same page you are trying to check is theatre. The attacker supplied both halves. This is the single most common way the check gets performed uselessly.
The two uses that matter here
- Address announcements
- A signed list of addresses tells you the list came from whoever held the key last time. This is the answer to the whole links and addresses section.
- Vendor messages
- A signed message from a vendor is attached to a key rather than to an account, so an account takeover does not inherit it.
Why people skip it
- It looks like an engineering task and the tooling is unfriendly.
- The payoff is invisible. A check that passes feels like wasted effort every single time.
- It cannot be done in a hurry, and the moment people need it most is the moment they have the least patience.
- Nothing bad has happened yet, which feels like evidence and is not.
The honest counter is that the cost is front loaded. Installing a tool and importing a key is an afternoon, once. Verification after that is seconds, and it is the only step in this entire board that turns a judgement call into a definite answer.
If you never do it, be clear with yourself about what you are relying on instead. You are relying on recognising pages, which is the check that copies defeat by construction.
Questions people send about this
Do I need PGP just to browse?
No. It matters when you are deciding whether a set of addresses is genuine, and when a message needs to be attached to a key rather than an account.
Is a key from the site itself good enough?
Only if you took it earlier, from a source you can name, and kept it. A key handed to you by the page you are checking proves nothing.