nexuscheckVerification checklists for Nexus Market, with pass criteria
18 checks across 5 moments
3 verified addresses
Overview Full checklist First time setup Every session Before funding On delivery Periodic review Addresses FAQ Scope

Checks > First time setup > C-01

C-01: Browser obtained from the Tor Project and verified

IdentifierC-01
Weightcritical
AppliedFirst time setup (M1), Once, before you ever sign in
StatementThe Tor Browser you are using came from the Tor Project website and its signature was checked on first install.
Grading criteria
PASSDownloaded from the official site and the signature was verified before first run.
PARTIALDownloaded from the official site but the signature was never checked.
FAILObtained from a forum, a file locker, a torrent, a friend or any mirror.
COSTA modified build can route everything you do through an operator of its choosing while looking identical to the real thing. Nothing else on this site protects you from that.

Why this is first

Every other check on this site assumes the software reporting your address bar is telling the truth. A modified browser can display one address while connecting to another, and it can do that without any visible symptom. If this check fails, the rest of the list is decoration.

How to satisfy it

  1. Download only from the Tor Project website, typed into the address bar rather than reached through a search result
  2. Verify the signature against the Tor Project public key before the first run, following the procedure documented on the same site
  3. Reinstall from the official source if you cannot account for where the current copy came from

Why signature verification matters more than it sounds

A download can be intercepted or a mirror can be hostile without the site itself being compromised. The signature is what ties the file in your hands to the people who built it. Checking it takes a few minutes once, and it is the only moment where the question can be settled rather than assumed.

Common ways this fails quietly

  • A copy carried across from an old machine years ago with no memory of its origin
  • A version installed from a package that was convenient at the time
  • A build recommended in a chat as faster or more private
  • A mobile application claiming Tor support that is not the real client

Re-checking

This check is run once per installation rather than per session. Run it again after moving to a new machine, after any reinstall, and if you ever find yourself unable to say where the copy came from.

Verified address set

Verified address set
[1]nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
[2]nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
[3]nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Run C-07 before you type anything. Open in Tor Browser only, then compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed.

Other checks in this group

C-02high
Applies: First time setup (M1)
Passes when: Shield control reads Safest and no exceptions have been added.
The Tor Browser security level is set to Safest and has not been lowered for any site.
C-03critical
Applies: First time setup (M1)
Passes when: Newly invented for this account and used nowhere else, ever.
The username on this account has never been used on any other site, market, forum or messaging service.
C-04high
Applies: First time setup (M1)
Passes when: Generated, unique, stored in a local manager.
The account password was generated by a password manager, is used nowhere else, and is stored in that manager rather than remembered or written in a note.
C-05critical
Applies: First time setup (M1)
Passes when: Phrase on paper, two factor on, key backed up in a second location.
The recovery phrase is written on paper and stored away from the machine, PGP two factor is enabled, and the signing key is backed up offline.