Silk Road forums

Market => Rumor mill => Topic started by: thetruebeachcomber on January 04, 2013, 11:44 pm

Title: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: thetruebeachcomber on January 04, 2013, 11:44 pm
verify that i am the true owner of beachcomber send a message to me encrypted with my pgp, i will reply with the info to verify.

do not buy anything or finalize anything a thief has highjacked my account!

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2.0.17 (MingW32)

mQENBFCl4w8BCADQ/5ivp6qlGze/WApsrhAAiNqZyLR5ZWketea5L00P3bpCRDW3
Kde8XPJyryMHCGj3pH04SZy08WPcIbVTpE+zTbtTmILiZbbHUle17aBeNjY365PN
di1NcL73SLAyZ5NCSL5pOtfqUODXsJFD8mMIUEGTXLuovN+GO8tNOFNCuYzSI87O
67jETt+3M5XnR+0JtS3KBR52vuBMOkL9ipOQ4rXBZKAeuhpfSHakvXu+cUE9ceAs
cWSLfIC6od+7Gj8kOlK4TM58vP11NLaxOGMF8T0rzFy8rDK98IBpgKpIoCVkxM0v
i9dQswuwSUZZjPm34FryAVOSQPrFeELA13/tABEBAAG0JGphY2sgcHJvdWRvbiAo
c2hvZXMpIDxqYWNrQGphY2suY29tPokBOAQTAQIAIgUCUKXjDwIbDwYLCQgHAwIG
FQgCCQoLBBYCAwECHgECF4AACgkQ413v00T7PSLAzAf/aH+tdNoLl0wnVNGuN9st
lpTEKj2kdafykoiGS1wWbYOqcF0b8MfTDftjbuY1ytKn+pqT5hkKk3fBHhAbIWmc
6xuJXUhUKhHT0aNeO6MDuKv9/n2DhI0tvIajs0wtR/HRvHu4aqhTSy+FU2SDpP+j
7quEUC5AgRcHNbvdbOruSvR4ECofhnDqp0RXhMMxxO8gkjeTHXhw42ivtJk58bxN
uSX2fI4QuuevMZWo1QwolkfgeLUDl5lMNI6VnR3t0XMS6UXESPfT39ObK9fokmWT
t1/9VZdzWQwLNahtc6ojrjXSK7eYhlJ7+TxHvThxhCKNR5qlPQlA7b1KMEulXsgy
4A==
=22+u
-----END PGP PUBLIC KEY BLOCK-----
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: midlandsmafia on January 04, 2013, 11:51 pm
Remove your pgp from here. Your customers should have it in their keyring.

 You're just confusing people by posting it up, whether you're serious or not.

If their is a previous customer of yours reading, they can encrypt a message to the PGP they have used to deal with you before.
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: thetruebeachcomber on January 04, 2013, 11:59 pm
its the same key in any case.

how can i get a hold of someone from the site??
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: thetruebeachcomber on January 05, 2013, 12:16 am
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Any of my customers please verify i am the true beachcomber! signed with my pgp key now removed by the highjacker
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (MingW32)

iQEcBAEBAgAGBQJQ53DcAAoJEONd79NE+z0icmQH/1tgOtUNbhWFUV7mxZdDYeFY
xPWM/bl0MReqQ7heY8e1zI9/2hq7jdfPjf/wv+s4/oy1Mjmn0Q05XXr2fFMJqD1z
eBd8PWj2cGGrf00xF9cHAF8hrdes6vvlcgMWr94AgBmylCrkcEzA7B7tRDspl0Ej
ZaX/M7X0tlF/HAW2zV/X9OK1mjeEvJ/sELAeqZIlYDZ6ME9J2al7y3hQ337CyLuS
6EJe9nVf7IcVmOMd2aHEXlE+Vo/MljZ8xOygd/KFNBAgAihTTff8p+bafQ1HSGpx
n4XilSmYTMtGz2il5Lhnqnn5gbAajW16KEClvDAvXKQPGWp7p6REy2nyO3hi7o4=
=dnhc
-----END PGP SIGNATURE-----
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: talawtam on January 05, 2013, 12:28 am
when was it hijacked? i just placed an order and was asked to finalize early... which i didnt... obviously. also there was no pgp key to encrypt with and i only got in contact with beachcomber today so i cannot verify.
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: anak94 on January 05, 2013, 01:00 am
ive ordered and he asked me to FE which i wont to!
 what was the reason he gave you to FE?
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: Nightcrawler on January 05, 2013, 01:16 am
Remove your pgp from here. Your customers should have it in their keyring.

 You're just confusing people by posting it up, whether you're serious or not.

When someone claims an account has been hijacked, my first inclination is to distrust BOTH parties.

If their is a previous customer of yours reading, they can encrypt a message to the PGP they have used to deal with you before.

Exactly.  If a vendor's PGP key is _only_ posted here on the Forums, and on the main site, then if a hijacker manages to gain control of both, it is very difficult for the vendor whose account has been hijacked to prove their identity as the true account holder.  That is why I strongly recommend that vendors post their PGP keys to venues that cannot be hijacked, such as the various PGP keyservers, e.g. the IndyMedia keyserver: http://qtt2yl5jocgrk7nu.onion/

I would also recommend that SR managment implement an anti-hijacking strategy; this would be easy to implement, consisting of one or more challenge strings shared by both vendor and SR management as shared secrets.
Think of it as another password of sorts, long, complex. and not stored with the account, thus not available to a hijacker. . The vendor should store this information separately, so it can be verified by management in the event of an accusation of account hijacking.

NC
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: talawtam on January 05, 2013, 04:18 pm
so... any idea whats going on here? i think i just want my money back and buy from another vendor. this all seems a bit weird.
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: Nightcrawler on January 06, 2013, 01:23 am
so... any idea whats going on here? i think i just want my money back and buy from another vendor. this all seems a bit weird.

No one has any real idea what is going on here.  If your purchase has been made in escrow, then after 4 days, when it has not been indicated as shipped, you may cancel the transaction and have the coins returned to your wallet. If, on the other hand, you have finalized early (FE) then you're screwed, and out of luck.

NC
Title: Re: beachcomber highjacked verify with pgp - any of my customers contact me!!
Post by: thetruebeachcomber on January 10, 2013, 11:02 pm
all orders not filled have now been cancelled, back to business as usual.

bc