PGP Encryption for WTN
PGP is the boring infrastructure that keeps marketplace accounts from getting popped with a leaked password database. On We The North it shows up in three places: login 2FA, encrypted buyer-vendor messages, and signed URL announcements that tell you which onion address is real.
Never touched GnuPG before? Start here — generate a keypair, upload your public key to WTN, turn on login 2FA, and encrypt your first vendor message.
Why Bother With PGP
Password-only login means anyone who guesses or buys your credentials owns the account. PGP 2FA adds a second step: after your password, WTN shows an encrypted challenge. You decrypt it locally with your private key. An attacker with your password but without your key file gets stuck.
Vendors publish a public key on their profile. Buyers encrypt shipping details to that key so only the vendor can read them — even if someone later gains access to message storage. The reverse applies when a vendor sends you sensitive info.
Finally, WTN signs its official onion URLs with the market’s PGP key. Phishing clones can copy the
login page pixel-perfect; they cannot sign a message with a key they do not hold. Run
gpg --verify on the signed URL announcement before you trust any onion address.
Install GnuPG
PGP today means OpenPGP, and OpenPGP means GnuPG in practice. Download from gnupg.org.
- Windows: Gpg4win bundles GnuPG with Kleopatra, a GUI that makes key management less painful. Get it from the official GnuPG download page.
- macOS: GPG Suite or
brew install gnupgif you live in the terminal. - Linux: Already there on most distros —
sudo apt install gnupgor equivalent.
The EFF’s deep dive on using PGP walks through the same install paths with screenshots. Worth keeping open in another tab while you work through this.
Generate a Keypair
Open a terminal and run:
gpg --full-generate-key
Choose RSA and RSA, 4096 bits, no expiry (or set a calendar reminder if you prefer expiry dates). Use a name field that does not tie to your real identity — a pseudonym is fine. Pick a passphrase you will remember; losing it means losing access to the private key.
When finished, list keys:
gpg --list-secret-keys --keyid-format long
The line starting with sec is your private key. The uid line shows the
name and email you entered. The fingerprint is what you compare when verifying someone else’s key —
the GnuPG wiki’s
FAQ on key validity
explains fingerprints in more detail.
Export your public key — this is the part you share:
gpg --armor --export YOUR_KEY_ID > wtn-public.asc
Back up the private key to encrypted offline storage (USB in a safe place, not cloud sync):
gpg --armor --export-secret-keys YOUR_KEY_ID > wtn-private-backup.asc
Treat that backup like cash. Anyone with the file and your passphrase owns every message encrypted to you and can sign as you.
Upload Your Public Key to WTN
Log into WTN through Tor Browser (see the
Tor Browser guide if you have not set that up). Open account
settings → PGP or Security. Paste the entire contents of wtn-public.asc — including
the -----BEGIN PGP PUBLIC KEY BLOCK----- lines.
Save. The market should show a fingerprint or short key ID. Compare it to
gpg --fingerprint YOUR_KEY_ID on your machine. One typo in the pasted block and 2FA
will fail mysteriously later.
Some vendors also publish keys on third-party keyservers. WTN profiles are the source of truth for who you are ordering from — cross-check fingerprint, do not trust a key ID alone in a PM.
Turn On PGP 2FA
In security settings, enable PGP two-factor authentication. On the next login, after username and password, WTN displays a PGP message block. Copy it, decrypt locally:
gpg --decrypt challenge.asc
Paste the decrypted token back into the login form. Kleopatra users can decrypt through the GUI — right-click, decrypt, copy result.
If decryption fails, you pasted the wrong key, enabled 2FA before uploading the matching public key, or corrupted the challenge text. Fix the key upload first; do not disable 2FA out of frustration and leave a funded account on password-only login.
Encrypting Messages to Vendors
Import the vendor’s public key from their profile:
gpg --import vendor-public.asc
gpg --edit-key VENDOR_KEY_ID
# type: trust, then quit
Write your shipping details in a plain text file, then encrypt to their key ID:
gpg --armor --encrypt --recipient VENDOR_KEY_ID order-details.txt
Paste the armored ciphertext into the market message field. The vendor decrypts on their end. If a seller asks for your address in plaintext private messages, that is a red flag — encrypt anyway.
Encrypting to multiple recipients (you + vendor) is possible with
--recipient flags for each key. Most buyers only need vendor-only encryption for
shipping data.
Verify Signed URL Announcements
WTN publishes onion URL lists as PGP-signed cleartext. Download the message and signature from the login page, then:
gpg --verify urls.sig urls.txt
A good signature from the known market key means the URLs inside are official. Import the market public key once from a source you already trust — PGP-verified WTN links or a previous successful visit — and compare fingerprints before you rely on it.
Phishing sites display fake URLs. They cannot produce a valid signature from the market’s private key. That single check beats visually comparing onion strings character by character.
Reporting a phishing clone? Send details through our contact page — include the fake onion and, if you have it, the signed announcement you used for comparison.
What to Do Next
PGP 2FA plus encrypted shipping messages cover most buyer risk on the messaging side. Funding your wallet is the next gap — see the Monero privacy guide for the exchange → wallet → market flow.
Related: Tor Browser setup · all guides · WTN forum · market security