The verify approach for a friends message
A friend sent me an address in a chat. I trust the friend. The chat is a different question, and this article is about the chat.
The three addresses
Nexus Market publishes these three onion addresses. Present as supplied, in no order, with no ranking. This site does not probe them and shows no uptime figure.
nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion
What the chat app is between us
The chat app is not neutral. It is a service, run by a company, on a network, with staff, with software, with logs. A message that appears from my friend has passed through that whole stack. That stack is where a substitution could happen, if anybody wanted to substitute the address the friend sent.
That is not an accusation of any particular app. It is a description of what happens with every app.
The verify approach for a friend's message is really a verify approach for the medium that carried the message.
The check I do without contacting the friend again
I take the address from the chat and I compare it against this site. If the address in the chat matches one of the three at the top of this article, character by character, I treat it as verified enough to look, and I proceed.
If it does not match any of the three, I treat it as unverified. That does not mean the friend sent me a wrong address. It could mean the market publishes more addresses than this site currently tracks. But it means I am not going to use it without a second confirmation.
That confirmation could be another list I trust, not derived from this site, that also has the address. If I do not have such a list handy, I ask the friend to send the address again on a different channel and I compare the two.
Asking the friend on a different channel
If I have to ask, I ask on a channel that is not the one the first message came through. If the first was a chat app, I ask by voice. If the first was voice, I ask by a paper note. The point is not that any one channel is safe. The point is that a substitution across two channels is harder than across one.
When the friend responds on the second channel, I compare the two responses. If they match, I have moved from one source to two, which is where the verify approach gets its confidence.
If they disagree, I do not use either address today. I ask what happened. Sometimes the answer is a typo in one of the messages. Sometimes it is not.
What I do if I have no second channel
If the only way I can reach the friend is the chat app that sent the first message, I do not verify the address by asking again on the same app. I use this site as the second source and compare there.
If the address matches this site's addresses, I proceed with the look but not the sign in. If it does not, I do not use it.
That is the honest fallback when there is no independent second channel. It is not perfect. It is what the verify approach can do without pretending.
What the friend is not responsible for
The friend is not responsible for verifying the chat app. The friend sent an address they believed was right. If a substitution happened in the app or the network, that is not the friend's failure.
The verify approach does not treat the friend as suspicious. It treats the channel as a separate thing that can carry errors independent of the friend. That framing keeps the friendship out of the technical question.
What I do after the verify
I use the verified address the way I would any address on this site. I copy, I paste into Tor Browser, I let the front page load, I let the captcha finish. I do not sign in on the verify visit, because verify visits and account visits are separate on my setup.
I thank the friend, on whichever channel is easiest, and I say the address checked out. That is polite and it also closes the loop for the friend, who otherwise does not know I received the message correctly.
When a friends message is a signal in itself
- When the friend has not sent anything in a while, and a market address is the first message. That is a stronger signal to verify carefully than a message from somebody I chat with daily.
- When the address is embedded in a longer message that also asks for something urgent. Urgency plus a link is a shape worth pausing on.
- When the address is on its own, in a message that only says here it is. That is not a red flag; it is neutral. The verify still happens.
- When the address is offered as a fresh one that nobody else has yet. That is a claim I want to double check before I act on it.
The tone of a verified friend-message visit
A verified friend-message visit is unremarkable. It is a normal visit that happened to start with an address from a chat. The verify approach ran quietly in the background, added two minutes, and produced a small confidence.
The rare cases where the verify fails are the ones the whole approach is here for. Those days the two minutes were the cheapest defence in a long time.
The helper approach that only points at this site, giving somebody an address rather than receiving one
What this article is not. This is not a claim that a friend is trustworthy or not. It is a claim that a chat app is not the same as the friend at the other end of it.