wethenorth-links.store

what people expect from We The North, and what actually happens

You expect PGP to be optional paperwork

WeTheNorth addresses

hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onion
hn2paw7zfvndw3dovycegeqmvvnf4pl67b3g2p7pohjlzavloosh73id.onion
hn2paw7zrgujyhnt6mgxlt2q6uhgbke4itpqitxhyfbumq3wtnckbuyd.onion

Printed as supplied, in no order. Nothing here is checked or timed, so an address that opens is not proof of anything. more about the set

#14account and identity

Keys and signatures are for people who enjoy that sort of thing. Being careful covers the same ground.

what actually happens

Being careful means looking at things, and every visible thing can be copied. A signature is the only check that does not depend on appearance, and it takes an afternoon to learn once.

The gap: you are treating the only working check as an accessory.

What a signature answers

Not who is honest. Not who is nice. One narrow question with a yes or no answer. Was this exact text produced by somebody holding this exact private key. Every character is covered, including the middle of an onion address where your eye stops working.

That narrowness is the strength. A page can be copied, a captcha imitated, a design cloned pixel for pixel, and none of it changes the answer. The copy either has the key or it does not.

Where the trust actually sits

A signature moves the question rather than removing it. Now you have to care about where the key came from, which is a smaller and more stable problem than judging a new page every time. A key you fetched a year ago, from a source you can still name, that has signed consistent statements since, is worth far more than any amount of careful looking at a fresh page today.

Verifying a signature against a key you took from the same page you are trying to check is theatre. The attacker supplied both halves. This is the single most common way the check gets performed uselessly.

The two uses that matter here

Address announcements
A signed list of addresses tells you the list came from whoever held the key last time. This is the answer to the whole links and addresses section.
Vendor messages
A signed message from a vendor is attached to a key rather than to an account, so an account takeover does not inherit it.

Why people skip it

The honest counter is that the cost is front loaded. Installing a tool and importing a key is an afternoon, once. Verification after that is seconds, and it is the only step in this entire board that turns a judgement call into a definite answer.

If you never do it, be clear with yourself about what you are relying on instead. You are relying on recognising pages, which is the check that copies defeat by construction.

Questions people send about this

Do I need PGP just to browse?

No. It matters when you are deciding whether a set of addresses is genuine, and when a message needs to be attached to a key rather than an account.

Is a key from the site itself good enough?

Only if you took it earlier, from a source you can name, and kept it. A key handed to you by the page you are checking proves nothing.