Silk Road forums

Discussion => Newbie discussion => Topic started by: crossreference on March 03, 2013, 01:42 am

Title: [HELP] Security Concern
Post by: crossreference on March 03, 2013, 01:42 am
WHAT'S HAPPENED:

1. I was already logged in to my SR account reading a message from a vendor who provided me with a custom listing link.

2. I opened this link in a new tab (a http://silkroad********.onion.to/silkroad/item/********** link)

3. This new link took me to what looked like the actual SR login page. (Remember I was already logged in reading my messages on the first tab)

4. I logged in again at this link provided from this vendor on the new tab.

5. It took me to the generic SR homepage and not to a custom listing.

6. I panicked! Thought I had been phished so immediately logged out of this new tab.

7. I changed my passphrase and pin on the original tab where I initially logged into SR.

8. I then reopened the custom listing link provided again in a new tab, and it worked! It took me to the custom listing the vendor said he had created for me.

QUESTIONS:

1. Have I been phished? Or am I worrying about nothing?

2. Should I created a new account?

I'm a rank novice. Fortunately I have no btc in my account here yet so even if I have been phished there is nothing to steal. I do plan on transferring a significant amount of btc into my SR account tomorrow though so need to know if my account has been compromised. Thank you.
Title: Re: [HELP] Security Concern
Post by: scout on March 03, 2013, 01:46 am
I don't think you've been phished - especially if you weren't asked for your PIN.

Also, you should NOT be accessing SR at the .to address - that is for accessing it over the clearnet which you should never, never, never do!  So dangerous.
Title: Re: [HELP] Security Concern
Post by: crossreference on March 03, 2013, 01:57 am
Thanks for responding quickly, scout.

I'm a complete newb to SR, and thus far I've only always logged into SR at the standard http://silkroad*******.onion url. But the link this vendor provided for my custom listing was the one described above: http://silkroad********.onion.to/silkroad/item/**********

Has this made me vulnerable? I'm connecting through a VPN and TOR, but has accessing this link somehow revealed my real IP to other parties???

What should I tell this vendor? Can he create the custom listing with a normal .onion link?

Thanks again, scout. I'm worried as hell right now.
Title: Re: [HELP] Security Concern
Post by: crossreference on March 03, 2013, 02:08 am
Also, what is the clearnet?
Title: Re: [HELP] Security Concern
Post by: scout on March 03, 2013, 02:27 am
clearnet = internet accessed normally without the use of Tor.

the VENDOR sent you .to links?  wow.  that is not smart at all ... if you're on Tor, you should be fine, but, still, it's best never to use .to links .... if someone gives you a link like that, copy and paste it into the URL bar but before navigating there, remove the ".to" part.
Title: Re: [HELP] Security Concern
Post by: crossreference on March 03, 2013, 02:57 am
Okay. I get it. I wasn't even aware you could access SR or .onion locations without TOR. I never have and never will. I always go through the VPN and TOR before coming to SR or this forum (the only .onion sites I know of), and have every other internet accessing program deactivated on my computer when doing so.

Yes, the vendor sent me that link. He has proven to be a really helpful vendor giving me advice pertaining to BTC purchases and transfers and has perfect feedback with hundreds of transactions. I really look forward to my first SR transaction being with this vendor. He has since replied that he inadvertently forgot to remove the .to part of the link so I guess it was an honest error.

If you don't mind could you confirm this for me though: Is it perfectly safe to purchase my BTC from spendbitcoins and have them placed directly into my SR account? Or should I have them placed into a BlockChain wallet before transferring them to my SR account?

Thanks again, scout.
Title: Re: [HELP] Security Concern
Post by: scout on March 03, 2013, 05:16 am
That is totally up to you.  SR does have its own built-in coin tumbler and for many people, that is enough.  Others prefer sending to another wallet first.  It really is just a matter of what makes you feel the safest.
Title: Re: [HELP] Security Concern
Post by: crossreference on March 03, 2013, 05:49 am
Thanks, scout. You've been very helpful. If I were cashed up I'd donate to your fund.