Simple PGP Guide

xenxra

Member
OPAL SPONSOR
Joined
Dec 2, 2023
Messages
281
Preface
you MUST include the header and footer segments containing ----begin/end public key block---- when saving keys to file or else you will encounter an error with importing (file extension doesn't matter, you could just use none)


MAKE SURE YOUR PUBLIC KEY IS SENT SEPARATE OUTSIDE THE ENCRYPTED TEXT (SAME EMAIL), YOU WILL ONLY NEED TO INCLUDE THE KEY FOR YOUR FIRST EMAIL SO THE VENDOR IS ABLE TO ENCRYPT COMMS BACK TO YOU



iOS
1)
download PGPro - App Store
2) locate and save vendors pgp key to file

(i dont have an iPhone to test so these steps are assumed from app store screenshots)

3) navigate to "keychain" tab in pgpro, then tap the + button at top right and import your key file(s)
4) navigate to "encryption" tab → "select contacts" and pick vendor's key from keychain
5) type message and copy encrypted text to clipboard
6) send email to vendor with encrypted text AND your public key (i would assume you can get this in PGPro by selecting your key in keychain tab and then tapping the share button in the top right — i typically include the full text appended but you could just attach a file with your key)



Android
1)
download OpenKeychain - F-Droid / Google Play
2) locate and save vendors pgp key to file
3) navigate to "keys" tab on sidebar, then tap the + button at bottom right and import key file(s)
4) navigate to "encrypt/decrypt" tab on sidebar
5) select "encrypt text", select vendors key, type message, then tap the copy icon at the top right
6) send email to vendor with encrypted text AND your public key (to locate this in openkeychain, select your own key entry from the "keys" tab and then use the copy button located on the left side of the QR code)



Windows + MacOS/Linux
1) download Kleopatra
— a) For Windows - Gpg4win (contains Kleopatra as add-on)
b) MacOS/Linux - App Store (alternatively, you could run the command sudo apt install kleopatra from terminal

2) locate and save vendors pgp key to file
3) open kleopatra, then select the "import" button on the top ribbon bar and import key file(s)
4) open a text editor (any will work), type out the message you want to send and copy it to your clipboard in clear text
5) in your taskbar, right click the kleopatra icon, navigate to "clipboard" then select "encrypt..."
6) in the encrypt window, select "add recipient...", select your vendor's key and then toggle the "openpgp" option (if it isn't done automatically)
7) send email to vendor with encrypted text AND your public key (to locate this in kleopatra, right-click your own key entry from the main window, select "details", then select "export" at the bottom and copy all the text that appears in the new pop-up window (you can remove all the lines containing "Comment: ...")



Stay safe out there! :ninja:
 
Last edited:
Drugbuyersguide Shoutbox
  1. uncharted @ uncharted: @xenxra It's not the best advice but you could alway's bind a RAT to PDF file and pose as a lawyer from a different email saying someting about sueing or anything you can think that would make them scared/curious/greedy enough to open it and then drain their crypto or find out who it is and pinpoint their location and file charges. Just brainstorming.
  2. xenxra @ xenxra: I've opened a case with numerous exchanges at this point to monitor all the addresses I have on hand but after a lot of bakc and forth they all ultimately suggest I file a report with local PD but the people in my area are generally definitely not savvy enough to handle a case like this so I'd be left waiting around for them.to pass my case upto secret service or something
  3. xenxra @ xenxra: not a bad idea, I'm open to anything. problem is I don't really have a direct method of contact with the attacker. they used a VPN with a Google voice number to reach me.bc my number was leaked in a data breach (like 10 times at this point) and then the rest of the ordeal was carried out through a falsified coinbase front-end. atm I'm mostly just concerned with getting any phone numbers I have on hand suspended (done) and as many addresses as possible frozen (in progress)
  4. uncharted @ uncharted: @xenxra It's not the best advice but you could alway's bind a RAT to PDF file and send them an email from a differnt email posing as a lawyer/or some authority figure from a saying someting about sueing/fake affidavit or anything you can think that would make them scared/curious/greedy enough to open it and then drain their crypto or find out who it is and pinpoint their location and file charges. Just brainstorming.
  5. xenxra @ xenxra: appreciate the kind words everyone. I think I'll make it. if I can even just so much as manage to get one of these guys locked up with the trail.i have on them then I can sit well with that. based on a couple addresses I've come across they've taken at least $5mil total from other victims.
  6. T @ timyboy: BTC is soaring woohoo
  7. K @ knofflebon: @xenxra fuuuuuuuck I'm so sorry to hear that, goddamn. Crypto scammers are getting so sophisticated these days. Here's hoping this won't keep you down for too long, painful though it may be.
  8. PHXINC @ PHXINC: i dunno its not up my field. I understand you being over it. im sorry and people suck. shit i was pissed when the snow kids took 1200 from me. You have a good balance. kudos to you. There is another 100k out there.
  9. PHXINC @ PHXINC: i dunno its not up my field. I understand you being over it. im sorry and people suck. shit i was pissed when the snow kids took 1200 from me. Right before that i had a very large amount of things taken from me from a 'friend' through a combined deal to his drop of course. You have a good balance. kudos to you. There is another 100k out there.
  10. RiftChems @ RiftChems: My american heart shines bright tonight
  11. R @ rasetreydir: xenxra wow, 100k? So sorry to hear this but i I admire your patience, and optimism. I cant even pretend I would know what to do if i was in your shoes. Good luck
  12. xenxra @ xenxra: i mean i know how to do bc analytics and such so i figure the only thing a "hacker" on dread would be able to do is counter manipulate the dude but i have no method to contact him anyway besides maybe leaving a spooky note on chain with one of the eth addresses they funneled through
  13. xenxra @ xenxra: im honestly over it already, you live and learn.
  14. xenxra @ xenxra: meh not worth it. i know how to trade so i can bounce back in the end if im not able to recover it. i already spoke to binance and had three accounts frozen and im filing a police report tomorrow.
  15. PHXINC @ PHXINC: Go to the hacker forum on dread, i will say no more. People salivate for jobs like this. they gonna want 25-50% of your coin though if they get it.
  16. xenxra @ xenxra: looks like i lucked out and i might be able to trace this scumlord down
  17. xenxra @ xenxra: @PHXINC it was a pretty complex script they hit me with. I would not be surprised to find out they know how to wash it but I am planning to start tracking it myself tonight. I filed a report with ic3 but I'm not sure how long it'd even take them to look into it.
  18. PHXINC @ PHXINC: Wow. Bitcoin that is easily traceable. Depends how good they are at cleansing it but many are not as good as they think. Go hire up. Shoud not cost too much.
  19. xenxra @ xenxra: it took me like 5 years to save up that bitcoin too
  20. xenxra @ xenxra: @BraveLittleToaster it was yesterday, i'm trying to stay optimistic but that was a pretty big chunk of my savings. no recourse to get any of it back due to where it was taken from.
Back
Top