url: http://mithrakushhvfyto.onion
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Around when Evolution disappeared people complained that there were no good
alternatives to Agora, so I started making my own.
It's finally good to go. It's not pretty, but I have focused on keeping the
interface user friendly for both vendors and buyers.
If anyone cares to pen test it I may have a small reward if you find any
weaknesses, but don't expect too much unless my market becomes a success.
It's the first time I'm doing something like this, so I'm excited to see how
it goes. I believe I've taken adequate steps to protect myself and the
server, but whether it's enough remains to be seen.
I hope you like it.
**Policy**
* No weapons.
* No child porn.
* No stolen property (except pirated media/software).
* No scans, cards, counterfeits or forgeries (except physical fake IDs).
* Don't scam, fraud or impersonate anyone.
* Don't spam or advertise using the private message system.
* If you break my rules I will disable your account and confiscate your money.
* If buyer and vendor can't agree on who deserves the escrowed funds, they
will remain in escrow until one of them gets banned or I shut the site down.
If one gets banned, the other gets the funds. If you think someone should get
banned, you can contact me.
**Security**
* No javascript is used anywhere on the site so you can safely keep it disabled.
* Passwords are salted and hashed.
* Two-factor authentication using PGP is supported for logging in and changing
settings.
* Vendors must sign a message from their PGP key in order to display their PGP
key on the order form. That way users can verify that a vendor is who they
claim to be.
* Even though the address field is automatically encrypted if the vendor has
a pgp key, you should still encrypt it yourself before ordering. The website
will detect if your message is encrypted so it won't get encrypted twice.
* Even though uploaded images are automatically stripped of EXIF and XMP
metadata, you should still strip them yourself before uploading.
* Lost your password? If you can prove that it's really your account, I may be
able to help. Don't expect me to just take your word for it though.
* The primary address is mithrakushhvfyto. The secondary address is
calmgigglenwkdeq. If the primary address ever gets compromised I will switch
to the secondary address. If the secondary address is up, that means the
primary address has been compromised and should no longer be used.
**General information**
* I take a 4% cut of all finalized orders.
* Vendors must pay a 160 CHF activation fee before their ads will be listed in
the search results.
* Free accounts (buyers and unactivated vendor accounts) must pay a collateral
to message other users. The collateral will be refunded if the receiver
whitelists the sender or deletes the message. Reporting a user for spam or
blocking a user will cause the collateral to be forfeit. Ordering from a
vendor or accepting an order from a buyer will automatically whitelist the
user in question.
* The site makes payouts automatically when orders are finalized, subject to
small delays (less than an hour normally).
Regards, Zanzibar Admin
- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1
mQENBFVJnwYBCACinj8hdRXWBX6lDRUR1/NNx0l++WvjN5Mc5nKV0fK8LIcfvOaF
bKdqEpUqrEIhlJ/+f2Ato/Brco+0I8X9iFltP42x/rSCRl6Uf2XS5V1Ly6JpkgcI
TdmXAbCR1srUEEZHF8Ur+v8lSg0FmrcG9OQ3v20fWEfe6vB6eHz22xLjGo1fJOU6
B8D9/LDT0JFJCYMUpVp1X+6gInLzpYY0TJ3BXSAwH0h/KPHB9M0eoe9WxcHyb3N5
fFdbLM+hSPX6zJXkrtadUaUe/OjVlmngf/mid21qmkq/pv3EDX8nnfKmbn1iN7IJ
VMtxIRUw//XSvFgaCOnKIHaDzY1dQqKafowhABEBAAG0LVphbnppYmFyIEFkbWlu
IDxhZG1pbkBtaXRocmFrdXNoaHZmeXRvLm9uaW9uPokBOAQTAQIAIgUCVUmfBgIb
AwYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQFeGN+WQIbjg4Qgf+LwQLl7RX
kLFkHXTtaAX2zkfxlq88COVQVSq/caZqdj/JbzddcbgH9T2RauJNRXFqFQZlntOW
OEvVzhzCay+6dj06062zONRFda1tlk058sBWjJ+5T7lHPWxBUKVgUWPbxnUlVybM
HZaBmW9x3Xa1ofG2NfBAxFXd9wxxn0tSKZaNyMakvnTazyOkvM0xRm/ZouG3gvbd
cmwQQvUuToZnTfnf2s93xOnoG5/dBTaeyelPxPQuOCDPSAEJF79+EjymrBA4BAee
GNfXLkEnoLKYSpW94CDxHgGipMufsuaIv+Bg0FhW1AFqYF/afz9xQ8Y06X9W96Si
TK+4FWqGn3mKjbkBDQRVSZ8GAQgAyPXb3f4ZS8mjusmzsPU63g3w/X7nmsZB06qM
+q0Rk/GYEcSnFf695OKKlbvhQz7qLJychU01eLV/Sobb84TCVBFQZrPGIyMjqRNC
Z1dLdybZpbMhEjPvqtcFTINACRo5V5/rCREyYuxaIKt70pkrR/I9tzusXlkRwgF2
bdjiQ82ULiwLe742oibz0CirsE+EnKu1gR07cTL5KnQ/bLjiIPGsxYU6I0iw/IDZ
+r4ugoaj1tGHU9Km0TvOaTXtEuerO6dR0dTIEePXRuvmIMWk1lvm0ZXyWOzXRSXy
CItMyGs+ByZUTuZMkKLNfyEa5yJgDfxOoVmyZYVLD5obaYrp5QARAQABiQEfBBgB
AgAJBQJVSZ8GAhsMAAoJEBXhjflkCG44BvoH/3CVL9aVgpHJjJjpXWU+gJePiVGv
ex0RIO+WgltC3KIVMqaPBZt761bSWF1ltEO/bAZhEeCXBisyTwaF4AZkbrHUagp/
AFqE6zVuyTJcHE3zpXa5uUNecWh0wkeEAxcaFS28Sg9T5E6nu9c97gLtVuxi7G64
SPn/pTtP21pnIUJ51MSr8dqozbyNpjzFEpUJ6kbvbboBdrPW7NQEYsl2hi2sOl+A
OC3A4+BmRE3O0wtVW8HKX7fysPrsG1PkX99Dc4MWsNvW6OwDA3lny8cnsedd+aC9
Yjn1Q99X1+HbLszjuIrpXG0rP0ud0NJ+ageN4WRr3yOd0bofsQsgFVSKf8Y=
=HvQ1
- -----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBAgAGBQJVSv7SAAoJEBXhjflkCG44KqoH/1g9YCC4XtA7EIwG+/AcduHG
XEiklION2LN2lAno1kjFLKXZmMfx2mWJkWqPBBGqlFXPgoXBVxmAr4BjZRSeg8XD
LqeIAWq3+MI2D3P8YoMVjzdoYZnLjNcZ7j0Lh9lp8Vfo2Ij3Mx17TzjSFjKl0Hv2
fsE+497tJKRgBk0+dGmt6bkCGKYiLnOgzAduxvRbO4ueVkkmtuDrI1FeaTRNEMTP
leqriQzRUOJ1AA43prpiD1RPSNklz3472dp/ORp7hc874ZunxV7osWdRe5jNv0BY
k/gF4Ch9BP2yB6oWBaAWIyzlij50zHxalKpw70GUjT3wSf9cglks4puigA8hHRM=
=DW/a
-----END PGP SIGNATURE-----
This will end badly