Skip to main content

Why PGP Matters on Tor

When you open your bank's website, a lot of people you've never met are quietly vouching for it. On an .onion address, almost none of them are around. This page is about what replaces them, and why the answer keeps coming back to a PGP signature.

How You Trust a Normal Website

Type a bank's name into a browser and you rely on a stack of things you probably never think about. The domain name is registered to a company, and that registration is public record. A certificate authority checked that whoever set up the site actually controls the domain. Your browser refuses to load the page if any of that looks off. And on top of it all sits plain reputation: everyone knows the brand, so a fake stands out.

None of it is perfect, and fake sites still get through. But there's a lot of outside machinery working in your favor, and you never lift a finger.

What's Missing on an Onion Address

An .onion address looks like a random string, something like abc…xyz.onion. There's no company name attached to it, no public registration record, and nobody handing out certificates that say "this address belongs to this specific service." The address is not a name someone picked. It's derived from the service's own cryptographic key.

That design has a real upside. If you reach an address, you're talking to whoever holds the matching key, and nobody can quietly swap in someone else. You can read how that works in the Tor Project's own onion services overview.

But notice what it does not say. The address tells you "this is the same service you reached last time." It says nothing about whether that service is the one you actually meant to visit.

The Gap Phishers Live In

Because the addresses are long and unreadable, people don't really read them. They glance at the first few characters, maybe the last few, and move on. Scammers know this. They keep generating keys until they land on an address that starts with the same characters as a real one, then build a copy of the site on it.

Every address in that situation is technically "authentic." It really is the clone's own address. It just isn't the one you wanted. So the address can't defend you by itself, and something outside it has to tie an address to a real identity. The mechanics of how those clones are built are covered in the phishing analysis.

What a Signature Actually Adds

PGP fills the gap in a fairly simple way. A service owns a PGP key. To say "this address is really mine," it writes the address into a message and signs it with that key. Anyone with the matching public key can check the signature. A clone can copy the text of the message, but it can't produce a valid signature without the private key.

The important part is where you got the public key. If you picked it up earlier, from more than one unrelated place, then a valid signature tells you something an address never could: this address was vouched for by the same party who held that key before. That's the whole trick. Trust doesn't come from the address, and it doesn't come from a site telling you it's legit. It comes from a key you already checked independently.

How this looks in practice, with fingerprints and signed notices, is laid out in the PGP key and canary archive.

Where It Stops Working

A signature is not a guarantee of anything beyond one narrow thing, so it's worth being clear about the limits.

It proves a key, not a character

A valid signature means the signer controls the key. It doesn't mean the person behind it is honest, competent, or going to stick around. A perfectly signed message can come from someone who's about to disappear with everyone's money.

The first key is the hard part

Everything depends on getting the right public key in the first place. If the key you start with is a fake, every later "valid" signature just confirms the fake. Checking the same key from several unrelated sources cuts this risk down a lot, but it never goes to zero. In security circles this is known as trust on first use.

Keys change and keys leak

Operators rotate keys on purpose, and sometimes they lose control of one by accident or by force. A rotation announced with no proof it came from the old key should make you nervous. A key that suddenly stops signing anything is a warning sign too.

Why Signed "Still Here" Notices Exist

Because a key is only useful while its owner is still in control, the community came up with a habit: sign a short dated statement on a regular schedule, basically "we're still free and in control as of today." If the notices stop, or the signature looks off, people take that as a reason to be careful. It's a small workaround for the fact that there's no outside authority to announce a problem on anyone's behalf.

The Short Version

On the regular web, other people vouch for a site so you don't have to. On Tor, that help mostly isn't there, so the checking falls to you. A PGP signature won't tell you whether someone deserves trust. What it can tell you is that you're dealing with the same party as before, and not a copy. If you want to see how that plays out in practice, the PGP key archive is the place to start.