Vendors reporting not being able to read when using auto-encrypt on Dream

I use auto-encrypt for simple chit-chat and manual encrypt for anything important. I have had a few vendors report that they were unable to read or unecrypt my message. Something is obviously going on. I've seen a few other reddit posts mentioning similar things. Beware.


Comments


[2 Points] Gimmethatcandy:

I have a buyer acct. that I can test this with, but I'd rather not mess with auto PGP even on a throwaway. Just stop using it and encrypt it yourself please!


[1 Points] ItzNotLuck:

-Most likely- That means one of these is a possibility:

This is my opinion take it for what it's worth this is what I personally think could be causing it.

  1. Vendor has been compromised and le doesn't have access to the private key of that vendor but unlikely since they could of just changed it like done many times.

  2. A similar backdoor to the one used on hansa has been implemented possibly faulty, could be encrypting it with Le's key which explains why they would be unable to read it.

  3. Dream could of disabled auto encrypt somehow because of what happened with hansa maybe encrypting using their public key maybe to cap it off to prevent le from getting the msgs? Not sure about that one.

Regardless take what happened to hansa as an example on why not to use auto pgp. As of now treat any market as if it is comprised and make sure your opsec is sound.


[1 Points] Gimmethatcandy:

I'm a vendor. I've been able to decrypt messages just fine, except for one. It was formatted a little weird...margins were off. I looked into it further and when I view it on my computer (paste it to clipboard or whatever to decrypt with my key) it looks fine except one line is almost double in length. Had to scroll the bar to the right to see it all.

However, when viewed on Dream, the key looks totally normal except for one part of the code that says -scrubbed- I know Dream does this a lot to links and whatnot, but I've never seen it scrub anything from a PGP key. Anyway, if I remember I'll pop a screenshot on here when I get to my computer. Just seemed odd.