BlackOps Adversary Register Who takes money off buyers, and what actually stops them No ads, no affiliates
Register › What stops them

BlackOps addresses

Three published addresses for the same market. Copy rather than retype, and verify the signature once you are through.

Mirror 1 blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion
Mirror 2 blackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onion
Mirror 3 blackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onion

This site publishes the list and does not monitor it. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.

Unique credentials

A complete answer to one adversary and a partial answer to two more, for about ten minutes of setup.

Uniqueness, not strength

Password strength protects against guessing, which is not the attack. The attack is a credential pair leaked from an unrelated service being tried everywhere by something automated. A long complicated password reused somewhere that leaked it is exactly as useless as a short simple one, and the confidence it produces makes it worse.

Why it persistsThe cost of reuse is invisible at the moment you pay it. Nothing bad happens that day, that month, or often that year, which is a shape people reason about badly.

What two factor adds

AttackStopped?
A leaked password tried laterYes, completely. Exactly what it was designed against.
A live clone pageNo. It collects password and code together and replays both while the code is valid.
A compromised machineNo. Nothing on the account side helps.

So two factor is worth turning on immediately and it is the second line. The first is arriving at the genuine site, which is the check and nothing else.

The part people regret

  1. Save the recovery material at setup, before closing the page. Recovery without it is limited and often impossible.
  2. Keep it separate from the password. Both in one place is one factor wearing a costume.
  3. Do not keep the only copy on one device. Devices get lost and replaced, usually at the worst moment.
  4. Not in a screenshot. Photo libraries sync, back up, and get indexed by software that reads text in images.
  5. Test once that you can actually produce it from a second place.

Two failures that look like an attack

Codes suddenly rejected is usually clock drift, common on machines that have been off a while or run isolated. A code accepted and then rejected is usually a slow circuit pushing you past the window. Both read as something sinister, both are neither, and both are worth ruling out before concluding anything.