Silk Road forums

Discussion => Security => Topic started by: max1259 on July 13, 2011, 01:44 am

Title: PGP?? I have small brain,please explain
Post by: max1259 on July 13, 2011, 01:44 am
Until recently all i used my computer for was games,games,ebay,games and emails..Oh and Youtube but in the last few days i've found Tor and this place but still don't know what im really doing,like i said,small brain-FACT...
 I just contacted somebody and they got back to me saying get in touch using PGP or via my PGP,i don't know anything this and before anyone say's it yeah im a dumbass.Obviously i'll Google it but could someone give me a heads up on where to start please?? And explain it as though you were talking to your 5 year old kids  ???
 Also,this will be wrong thread but if there's anyone in the UK can point me in the direction of easy.quick ways to get Bitcoins then that would really appreciated.
 Thanks in advance (or thanks for nothing seeing on how it goes lol)
 Max
Title: Re: PGP?? I have small brain,please explain
Post by: anarcho47 on July 13, 2011, 02:21 am
You need a PGP program.  There are a few out there - I personally use Portable PGP.

You need to download it, install it, and then you have to generate a new keypair.  Type in an email (if you are going to receive encrypted email to an addy use that), then in the comment you can put in a username or whatever.  Select how many characters (default it 1024 which is max on PortPGP - it's safe, even though some people will not go less than 2048). Next type in your passphrase (I recommend actually typing in a full sentence that you will be able to remember, as adding multiple words and spaces to a password make it exponentially more difficult to crack).

It will generate a keypair and you can click on the "keyring" icon to show which keys you have.  You should only have your newly created keys and the keys of the developers of the program (they come with it on installation - you can delete them if you like).

The top section is the Private PGP Key section.  Do not use this, do not give this to people.  In the bottom section is the Public PGP Keys section.  Your email/username will be there also.  if you click that you can then click the icon right above it with the floppy disk icon.  This will open up a "save as" window.  Just save this to your desktop, and then minimze the program and right-click the newly created file.  Click "open with" and choose Notepad.  Inside you will have your newly created public key.  Copy and paste it (be sure start at the "---" at the top left and end at the "---" bottom right after "end of PGP key".

This is your public key.  You can open this file any time and paste this into a message to give users your public key so they can send encrypted messages to you, which can only be opened with the pass-phrase you entered when creating it.

You can import other people's public keys into the program as well.  Go to the message where their public key is located.  Select the public key from top-left --- to bottom-right ---.  Copy it, open up notepad and paste it in.  I usually save it under that person's username until I have imported it. Save this to your desktop.  Go to PortPGP and click the icon with the arrow on it right above the public key section.  This will open an "open" window.  Select the file you just saved with the person's username and it will automatically import into the program and show up in your public key section.

The next part is easy.  Click the "encrypt" tab on the side.  You will have two options - you can either encrypt a file or ASCII text.  it should default to text but if not click that little bubble.  Type your message in there.  If the person doesn't already have your public key, paste it into the message after your text as well, so they can encrypt back to you.

At the bottom of the text window there are two dropdown bars.  One says "target".  Make sure you click that and select the person you want to actually send it to, or else you will encrypt it to the wrong person and your intended recipient won't be able to open the message.  Under that it gives you the option to sign it.  You don't have to if you don't want to, just leave it as "encrypt only".

Once you click encrypt, you will see an encrypted message that looks like this:

--- Start PGP Message ----

;klafds78fnafs78fs08fyhgahgdsygs7692hjnadnhgd;a7 74afhu18y (and so on)

--- End PGP Message ---

Click "copy to clipboard".  Go to the message you are sending in SR or on the forums or your email or whatever, and paste the message there.  Then click send.  Your recipient will be able to enter their keypass to decrypt the message and read what you wrote, and then use your public key to send back to you.

You will get a message back that looks similar to the above message (usually many lines longer of random characters).

Select it from starting "---" to ending "---", then copy it.  Go to PortPGP and click the "Decrypt" tab.  Again you have the option of a file or ASCII text.  Make sure the text bubble is selected.  Paste the encrypted message into the text window, and click "decrypt" on the bottom right.  A password request window will pop up and here you enter your pass-phrase you first put in to create your public and private keypair.  If you get the pass-phrase right, it will open a window with the text in it.

Voila!  You have encrypted and sent a message, and received and decrypted a message back to you.

I do this to be helpful, but also so that if you are ever in the market for fantastic organics, you will go here first:

http://ianxz6zefk72ulzz.onion/index.php/silkroad/user/7181

Cheers!  P.S. my pgp key for PM is in that link as well.
Title: Re: PGP?? I have small brain,please explain
Post by: anarcho47 on July 13, 2011, 02:25 am
Sorry, forgot to mention one other thing.  Unless you have your normal windows user set up as admin (hopefully not), right click the program to open it and click "run as administrator" then enter this password.  This applies in Win7 and I think Vista.
Title: Re: PGP?? I have small brain,please explain
Post by: max1259 on July 16, 2011, 03:47 am
Thanks a lot Bro,you've been a big help.Cheers  :)
Title: Re: PGP?? I have small brain,please explain
Post by: anarcho47 on July 16, 2011, 03:54 am
No worries.  Send this forum topic to anyone else you talk to who is having trouble with PGP - it's a real lifesaver.
Title: Re: PGP?? I have small brain,please explain
Post by: RedRocket on July 16, 2011, 04:15 am
i wouldnt touch that java applet with a ten foot pole...
Title: Re: PGP?? I have small brain,please explain
Post by: wicked420 on July 16, 2011, 06:19 pm
If you need any additional info:

http://p3lr4cdm3pv4plyj.onion/

Thats a PGP tutorial/test site, enjoy!
Title: Re: PGP?? I have small brain,please explain
Post by: Brazen on July 20, 2011, 02:17 pm
Until recently all i used my computer for was games,games,ebay,games and emails..Oh and Youtube but in the last few days i've found Tor and this place but still don't know what im really doing,like i said,small brain-FACT...
 I just contacted somebody and they got back to me saying get in touch using PGP or via my PGP,i don't know anything this and before anyone say's it yeah im a dumbass.Obviously i'll Google it but could someone give me a heads up on where to start please?? And explain it as though you were talking to your 5 year old kids  ???
 Also,this will be wrong thread but if there's anyone in the UK can point me in the direction of easy.quick ways to get Bitcoins then that would really appreciated.
 Thanks in advance (or thanks for nothing seeing on how it goes lol)
 Max
Don't be so hard on yourself Max, there's plenty of us here that need to ask questions.
Title: Re: PGP?? I have small brain,please explain
Post by: Grimlock on July 21, 2011, 01:56 am
Good looks bro.
Title: Re: PGP?? I have small brain,please explain
Post by: montypython999 on July 31, 2011, 02:36 am
Can someone please help me? I would like to test my PGP, but when I try the link for the PGP test/tutorial site all I see is this:

504 Connect to p3lr4cdm3pv4plyj.onion:80 failed: SOCKS error: host unreachable

The following error occurred while trying to access http://p3lr4cdm3pv4plyj.onion/:

504 Connect to p3lr4cdm3pv4plyj.onion:80 failed: SOCKS error: host unreachable

I can send messages to myself via PGP but would really like to see if it works in the big bad world. Here is my public key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2.0.17 (MingW32)

mQENBE4zpJYBCADc1XWThNPcxIceQiy1NilMyOE2pAeqpfkZX8O/0lPfiri41v8Q
+yhp9gnHpJ1OAEI7snzm+p0UF0id1wAycoT6eJaI6EestrS2kVQag1DTkFkdV8Aw
8ueljVXaa3lXbvMDcfuJ6ayYeuEp3yI7aYxzUrQKdpWHo8OkkN4t4xZ+1qVvXi83
+6mnEcOaxfcyRuBTaG9EEAHs4L+6vgkOsqyR5aLNGxFpVD3G8YA4tqUNWaH6qx0E
7zRdKRA01RQHfUIrIH+wdtF6h9eNY1V/jC4UklmOg3A5b+9btkQspNPHmmQdqnfk
rHx73aFfCORUBE5ZUU5gYE3IHbU6ODarU7SzABEBAAG0Km1vbnR5IHB5dGhvbiA8
aWxpa2VhZmluZXJ2YWdpbmFAZ21haWwuY29tPokBOAQTAQIAIgUCTjOklgIbAwYL
CQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQDAUCgQHGkWv+YQgAigahwk/lhcah
2liRl+vRpslyNS4w70mGi45f0FizOWeO7KSvowAJrW+JrMYxM7iy7p8urTZZISj2
CqHRVhfVe51laklPNhRS6OYnwIVSxl7wNbw9iLsZy7g5nMLNtdLxCSzoEhsy16iz
7mOkVVverFcDZJYVT5DtkCMbhy7TMfEN+6Nt/gCN01nL+M9hEbfBReSYD5gwhUko
RhVP9KitFEZImRUKYkB5+cuJqORy1hXwbx6lYLhk3i1IFMQrZJPLff9Ov+vlYmLR
EJD4FrwdxUa9ziGpkmF6UHOaABYNLkDSpGxHxmRvZektSs56Hz1IIeCIyIW2Ag70
nASMr70M+bkBDQROM6SWAQgAt8rGXSces/MRHsaw/jjX7sqa/+rqYkTubxD1Ni31
OA2BJZnAg0ZT8gaq4W/xgM/lAuqOgQ11a7HL3fnwrmLUs9LWtvaq+9ucOYkrLwpI
2Tbd2BuaCAgpfSpmzj7tCQAXjgoFeP3brL+hVVG517C2t1As/55wpwPa1omXa6/+
do82aKUX9AsXi5gPl3lWwPySw/PXmjf8gXjmQjybIDd3WFjf9xVAnNxN2zMVCe5X
2oNL4NwIRYfYPgSFJ7lVX07lYFn0EGQ0phoJ6y5uVXBfn5ZXNleJ1SAxagVafc7I
jELKO9tK+Zn2N8BkEsGktqMbULO+M8IFrk2CG4sVJGRlkQARAQABiQEfBBgBAgAJ
BQJOM6SWAhsMAAoJEAwFAoEBxpFrB3wH/3X50txw8ef8ksuKtgzFvONpbzdBO9Bm
zOMX4yMGRbJwJRgacjx+2lu0ysvEOqwzGJ1qdnJ1BFbQs6zfzSu5PmqTgIR7PKiO
9XW0zsdSqYFpRecjzOqC2e1mcSU3YuNW/vgUSL+6DQ8AKYA0wWwiWrhySlLuD+n3
boj1R6/G7uBaqnPkQHhT2KNP28Rw3Gjbwo+92QswV6dEoGHV0dbzk8Nv6X8Bl9iK
yWUUB0s/eBJ7hhABHaX+ZZTNdKHMNJDSuS782l8duL76+LIzk5Z8PD8ndsllMzdk
4tOkx1xJb3s3EMa1cOn0VzKMtYFICb4rKmEpEAAynpqWJugYz3eDNjo=
=yaZQ
-----END PGP PUBLIC KEY BLOCK-----

Title: Re: PGP?? I have small brain,please explain
Post by: anarcho47 on July 31, 2011, 06:09 am
You can send me one via SR - just click on my profile link and my PGP key is there.

I'll send you something back to make sure it works (be sure to include your key in the message text before you encrypt it).
Title: Re: PGP?? I have small brain,please explain
Post by: montypython999 on August 01, 2011, 02:00 am
Thanks Anarcho47, I have sent you a message, hopefully it works!
Title: Re: PGP?? I have small brain,please explain
Post by: anarcho47 on February 14, 2012, 07:14 am
Wanted to re-bump this to the top because I have been seeing a lot of people with questions about PGP over the past week.
Title: Re: PGP?? I have small brain,please explain
Post by: floryflory on February 14, 2012, 04:18 pm
For anyone who has a hard time understanding PGP, as did I, here is a short explanation:

You write a message, and then encrypt it with the receivers public pgp. What this means is that the only people who can read the message, are the people who have the private key and password for the publig pgp in which you encrypted the message for (a public pgp is a pair, and the person with the other part, the private key, and the appropriate password for the private key, can unlock the message).

You include your public pgp in the message, so the receiver can do the exact same thing back to you - encrypt it so that you and you only, can read the message (by unlocking it with the private key part of your pair and appropriate password).

This sounds stupidly obvious I know, but I had a hard time understanding this until recently :)

Here is a postal analogy from wikipedia: https://en.wikipedia.org/wiki/Public-key_cryptography#A_postal_analogy