nexuscheckVerification checklists for Nexus Market, with pass criteria
18 checks across 5 moments
3 verified addresses
Overview Full checklist First time setup Every session Before funding On delivery Periodic review Addresses FAQ Scope

Checks > First time setup > C-04

C-04: Password generated, unique and stored locally

IdentifierC-04
Weighthigh
AppliedFirst time setup (M1), Once, before you ever sign in
StatementThe account password was generated by a password manager, is used nowhere else, and is stored in that manager rather than remembered or written in a note.
Grading criteria
PASSGenerated, unique, stored in a local manager.
PARTIALUnique but composed by hand rather than generated.
FAILReused from another account, or short enough to remember comfortably.
COSTA reused password turns any unrelated breach into a breach here. A composed one is shorter and more predictable than it feels.

Generated rather than invented

People compose passwords from a small personal vocabulary, and the substitutions they apply are the same substitutions everyone applies. The result is shorter and more guessable than its length suggests. A generated string has none of that structure, which is the entire point.

Unique rather than strong

Uniqueness matters more than complexity here. A very strong password reused across accounts is still a single point of failure, because a breach anywhere it was used exposes it everywhere. A merely adequate password used in exactly one place cannot be leaked by somebody else mistake.

Stored locally

A password manager on your own machine, rather than a browser sync feature tied to an account with your name on it. The manager holds the string so you do not have to choose between memorable and strong, which is the trade that produces weak passwords in the first place.

What this does not replace

Two factor. A password alone, however good, is one leak away from being enough. The item on recovery material and two factor covers that, and the two together are what make a credential leak survivable rather than fatal.

Verified address set

Verified address set
[1]nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
[2]nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
[3]nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Run C-07 before you type anything. Open in Tor Browser only, then compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed.

Other checks in this group

C-01critical
Applies: First time setup (M1)
Passes when: Downloaded from the official site and the signature was verified before first run.
The Tor Browser you are using came from the Tor Project website and its signature was checked on first install.
C-02high
Applies: First time setup (M1)
Passes when: Shield control reads Safest and no exceptions have been added.
The Tor Browser security level is set to Safest and has not been lowered for any site.
C-03critical
Applies: First time setup (M1)
Passes when: Newly invented for this account and used nowhere else, ever.
The username on this account has never been used on any other site, market, forum or messaging service.
C-05critical
Applies: First time setup (M1)
Passes when: Phrase on paper, two factor on, key backed up in a second location.
The recovery phrase is written on paper and stored away from the machine, PGP two factor is enabled, and the signing key is backed up offline.