[Marketplace Announcement] Zanzibar Spice Market is now open for business!

url: http://mithrakushhvfyto.onion

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Around when Evolution disappeared people complained that there were no good
alternatives to Agora, so I started making my own.

It's finally good to go. It's not pretty, but I have focused on keeping the
interface user friendly for both vendors and buyers.

If anyone cares to pen test it I may have a small reward if you find any
weaknesses, but don't expect too much unless my market becomes a success.

It's the first time I'm doing something like this, so I'm excited to see how
it goes. I believe I've taken adequate steps to protect myself and the
server, but whether it's enough remains to be seen.

I hope you like it.

**Policy**

* No weapons.
* No child porn.
* No stolen property (except pirated media/software).
* No scans, cards, counterfeits or forgeries (except physical fake IDs).
* Don't scam, fraud or impersonate anyone.
* Don't spam or advertise using the private message system.
* If you break my rules I will disable your account and confiscate your money.
* If buyer and vendor can't agree on who deserves the escrowed funds, they
  will remain in escrow until one of them gets banned or I shut the site down.
  If one gets banned, the other gets the funds. If you think someone should get
  banned, you can contact me.

**Security**

* No javascript is used anywhere on the site so you can safely keep it disabled.
* Passwords are salted and hashed.
* Two-factor authentication using PGP is supported for logging in and changing
  settings.
* Vendors must sign a message from their PGP key in order to display their PGP
  key on the order form. That way users can verify that a vendor is who they
  claim to be.
* Even though the address field is automatically encrypted if the vendor has
  a pgp key, you should still encrypt it yourself before ordering. The website
  will detect if your message is encrypted so it won't get encrypted twice.
* Even though uploaded images are automatically stripped of EXIF and XMP
  metadata, you should still strip them yourself before uploading.
* Lost your password? If you can prove that it's really your account, I may be
  able to help. Don't expect me to just take your word for it though.
* The primary address is mithrakushhvfyto. The secondary address is
  calmgigglenwkdeq. If the primary address ever gets compromised I will switch
  to the secondary address. If the secondary address is up, that means the
  primary address has been compromised and should no longer be used.

**General information**

* I take a 4% cut of all finalized orders.
* Vendors must pay a 160 CHF activation fee before their ads will be listed in
  the search results.
* Free accounts (buyers and unactivated vendor accounts) must pay a collateral
  to message other users. The collateral will be refunded if the receiver
  whitelists the sender or deletes the message. Reporting a user for spam or
  blocking a user will cause the collateral to be forfeit. Ordering from a
  vendor or accepting an order from a buyer will automatically whitelist the
  user in question.
* The site makes payouts automatically when orders are finalized, subject to
  small delays (less than an hour normally).


Regards, Zanzibar Admin


- -----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1

mQENBFVJnwYBCACinj8hdRXWBX6lDRUR1/NNx0l++WvjN5Mc5nKV0fK8LIcfvOaF
bKdqEpUqrEIhlJ/+f2Ato/Brco+0I8X9iFltP42x/rSCRl6Uf2XS5V1Ly6JpkgcI
TdmXAbCR1srUEEZHF8Ur+v8lSg0FmrcG9OQ3v20fWEfe6vB6eHz22xLjGo1fJOU6
B8D9/LDT0JFJCYMUpVp1X+6gInLzpYY0TJ3BXSAwH0h/KPHB9M0eoe9WxcHyb3N5
fFdbLM+hSPX6zJXkrtadUaUe/OjVlmngf/mid21qmkq/pv3EDX8nnfKmbn1iN7IJ
VMtxIRUw//XSvFgaCOnKIHaDzY1dQqKafowhABEBAAG0LVphbnppYmFyIEFkbWlu
IDxhZG1pbkBtaXRocmFrdXNoaHZmeXRvLm9uaW9uPokBOAQTAQIAIgUCVUmfBgIb
AwYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQFeGN+WQIbjg4Qgf+LwQLl7RX
kLFkHXTtaAX2zkfxlq88COVQVSq/caZqdj/JbzddcbgH9T2RauJNRXFqFQZlntOW
OEvVzhzCay+6dj06062zONRFda1tlk058sBWjJ+5T7lHPWxBUKVgUWPbxnUlVybM
HZaBmW9x3Xa1ofG2NfBAxFXd9wxxn0tSKZaNyMakvnTazyOkvM0xRm/ZouG3gvbd
cmwQQvUuToZnTfnf2s93xOnoG5/dBTaeyelPxPQuOCDPSAEJF79+EjymrBA4BAee
GNfXLkEnoLKYSpW94CDxHgGipMufsuaIv+Bg0FhW1AFqYF/afz9xQ8Y06X9W96Si
TK+4FWqGn3mKjbkBDQRVSZ8GAQgAyPXb3f4ZS8mjusmzsPU63g3w/X7nmsZB06qM
+q0Rk/GYEcSnFf695OKKlbvhQz7qLJychU01eLV/Sobb84TCVBFQZrPGIyMjqRNC
Z1dLdybZpbMhEjPvqtcFTINACRo5V5/rCREyYuxaIKt70pkrR/I9tzusXlkRwgF2
bdjiQ82ULiwLe742oibz0CirsE+EnKu1gR07cTL5KnQ/bLjiIPGsxYU6I0iw/IDZ
+r4ugoaj1tGHU9Km0TvOaTXtEuerO6dR0dTIEePXRuvmIMWk1lvm0ZXyWOzXRSXy
CItMyGs+ByZUTuZMkKLNfyEa5yJgDfxOoVmyZYVLD5obaYrp5QARAQABiQEfBBgB
AgAJBQJVSZ8GAhsMAAoJEBXhjflkCG44BvoH/3CVL9aVgpHJjJjpXWU+gJePiVGv
ex0RIO+WgltC3KIVMqaPBZt761bSWF1ltEO/bAZhEeCXBisyTwaF4AZkbrHUagp/
AFqE6zVuyTJcHE3zpXa5uUNecWh0wkeEAxcaFS28Sg9T5E6nu9c97gLtVuxi7G64
SPn/pTtP21pnIUJ51MSr8dqozbyNpjzFEpUJ6kbvbboBdrPW7NQEYsl2hi2sOl+A
OC3A4+BmRE3O0wtVW8HKX7fysPrsG1PkX99Dc4MWsNvW6OwDA3lny8cnsedd+aC9
Yjn1Q99X1+HbLszjuIrpXG0rP0ud0NJ+ageN4WRr3yOd0bofsQsgFVSKf8Y=
=HvQ1
- -----END PGP PUBLIC KEY BLOCK-----

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBAgAGBQJVSv7SAAoJEBXhjflkCG44KqoH/1g9YCC4XtA7EIwG+/AcduHG
XEiklION2LN2lAno1kjFLKXZmMfx2mWJkWqPBBGqlFXPgoXBVxmAr4BjZRSeg8XD
LqeIAWq3+MI2D3P8YoMVjzdoYZnLjNcZ7j0Lh9lp8Vfo2Ij3Mx17TzjSFjKl0Hv2
fsE+497tJKRgBk0+dGmt6bkCGKYiLnOgzAduxvRbO4ueVkkmtuDrI1FeaTRNEMTP
leqriQzRUOJ1AA43prpiD1RPSNklz3472dp/ORp7hc874ZunxV7osWdRe5jNv0BY
k/gF4Ch9BP2yB6oWBaAWIyzlij50zHxalKpw70GUjT3wSf9cglks4puigA8hHRM=
=DW/a
-----END PGP SIGNATURE-----


Comments


[3 Points] RosyPalm:

This will end badly


[1 Points] mithrakush:

I forgot to mention: Established vendors with good reputation on other markets can message admin to get activated for free.

To clarify, the normal activation fee is 160 CHF, but converted to bits that's 737332 bits.


[1 Points] holecloud:

  • If you break my rules I will disable your account and confiscate your money.
  • If buyer and vendor can't agree on who deserves the escrowed funds, they will remain in escrow until one of them gets banned or I shut the site down. If one gets banned, the other gets the funds. If you think someone should get banned, you can contact me.

LOL HITLER MARKET,NAZI MARKET, I DO WHAT I WANT MARKET, no fucking thank you lol

you got some fucking big balls and a tiny brain stem you unslick fucker


[1 Points] None:

[deleted]


[1 Points] hacks4what:

At least you didn't make it easy for me to tell you were using nginx. You took the time to replace the headers and clean up the error pages.

I will keep poking at it and let you know if I find anything interesting.


[1 Points] None:

[removed]


[1 Points] gwern:

Are you sure you want to run a market? You don't sound very enthusiastic about it.


[0 Points] holecloud:

  • Even though the address field is automatically encrypted if the vendor has a pgp key, you should still encrypt it yourself before ordering. The website will detect if your message is encrypted so it won't get encrypted twice.
  • Even though uploaded images are automatically stripped of EXIF and XMP metadata, you should still strip them yourself before uploading.

"SO, do all the shit you normally do, because my site is a piece of shit, I don't even trust it. So, just pretend my site is agora or blacbank witout the drugs". LOL

Fucking seriously guy?