PGP on Awazon Market: Keys and Two Factor Login
PGP is the encryption layer that sits underneath most of the trust on a Tor market. On Awazon it does three things: it backs the two factor login, it lets you encrypt shipping details to a vendor, and it is how the operator signs the announcements you actually trust. Here is how each part works and what you need to set it up.
The operator key
The operator publishes a PGP key and pins it in the footer of the storefront. Every state change that matters, a new mirror, a key rotation, an escrow change, is announced as a post signed with that key. Verifying the signature once and saving the fingerprint locally lets you read future announcements with confidence. A lookalike onion cannot serve a post signed with the operator's key unless it also holds the operator's private half, which it does not. That is the check that separates a real rotation from a phisher rushing a copy into a chat group.
Two factor login
Turning on PGP two factor adds a challenge to the login that only your key can answer. It sits alongside a standard authenticator code as a backup. The point is that a stolen password is not enough to get in if the second factor is a key you control offline. Enable it at registration, before you fund the account, because a fresh device login fires the second prompt and an unexpected sign in surfaces immediately rather than after the fact.
Encrypting order messages
Every vendor publishes a PGP key on their profile. If you want to keep shipping details out of the clear, import that key, encrypt the order message field with it, and paste the ciphertext. The vendor decrypts it with their private key. The storefront does not add an automatic PGP layer, because that would put a server side process in the path of your plaintext. The encryption stays on your machine, which is the way the threat model was written. It takes a few minutes to set up and a few seconds per order after that.