Technical Access Guide

Standard Operating Procedure for secure market interaction.

OpSec Warning

Operational Security (OpSec) is user responsibility. Never access markets on a compromised machine. Always disable JavaScript in Tor (Security Level: Safest) when possible.

PGP Fingerprint:
8A4F 2B9C 1D3E 5F7A 9B0C
01

Tor Browser Configuration

Accessing the DrugHub darknet infrastructure requires the Tor Browser (The Onion Router). Standard browsers (Chrome, Firefox, Safari) cannot resolve .onion top-level domains and leak critical metadata.

Download: Obtain the Tor Browser bundle ONLY from the official Tor Project website. Verify the PGP signature of the installer if you are on a high-risk network.

Configuration: Once installed, set the security slider to "Safer" or "Safest". This disables JIT compilers and other potential attack vectors. DrugHub is built to function fully without JavaScript for maximum security.

NOTE: Do not modify window size manually. Leave it at default to prevent browser fingerprinting.

02

Mirror Verification

The primary vector for account compromise is the use of phishing links. You must only use a verified drughub link. We digitally sign all valid mirrors.

03

Network Connection

Paste the drughub onion address into your Tor Browser address bar. Connection times may vary depending on network congestion and Tor circuit pathing.

DDoS Mitigation Protocols

You will likely encounter the DrugHub Guardian queue or captcha. This system protects the market from Denial of Service attacks.

  • Clock Puzzle: Select the correct time displayed on the analog clock.
  • PoW Calculation: Your browser may need to perform a Proof of Work calculation (automatic).
  • Session Token: Once passed, you receive a session token valid for 6 hours.
04

Identity Creation

The drughub-market registration process is designed for anonymity. No email, phone number, or external identifiers are collected.

Required Credentials
  • • Username (Unique, non-identifying)
  • • Password (Alphanumeric, >12 chars)
  • • PIN (6-digit, for withdrawals)
Critical Recovery

You will be issued a Mnemonic Phrase. Save this offline immediately. It is the only cryptographic proof of ownership for account recovery.

05

PGP 2FA Implementation

We strongly enforce PGP (Pretty Good Privacy) usage. To secure your wallet and orders, you must configure 2FA immediately after login. This prevents unauthorized access even if your password is intercepted.

  1. Generate a 4096-bit RSA key pair using GPG Suite, Kleopatra, or command line GPG.
  2. Navigate to /settings/security in your DrugHub dashboard.
  3. Paste your Public Key block into the designated field.
  4. The server will encrypt a unique challenge code with your public key.
  5. Decrypt this message with your private key and enter the code to verify ownership.
  6. Toggle "Enable 2FA on Login" to active.