A password typed into a copy of the site
Minutes to undo
You typed a login into a page that was not the market. The gap between that and somebody using it is short, and you are probably still inside it. The next few minutes decide whether this is a scare or a loss.
Osiris market addresses
osiriseultmx3so5ef6ayasy4kdyekbywr7pyggpmjazeogxoyaodsyd.onion
osirislivpetlbabbl3zzqhupurfkxxbzbheu3bkrshkaiwg2hcxbyqd.onion
osirisydmlx47esm6ylhzhtnjrucgnymi7beqoyzze5jn3opbr3zy4id.onion
Printed as supplied, in no order. Nothing here is watched or timed, so an address that loads is not proof of anything. More about the set
1.What you handed over, exactly
A copy of a market front page is cheap to build. It renders, it takes what you type, and then it either shows an error or passes you through to the real address so the visit ends looking ordinary. Either way the string now sits on a machine you do not control.
It is useful to a stranger only for as long as it still opens something. That is why this belongs in the minutes section and not among the things that are gone at once.
- Window opens
- The moment the form is submitted.
- Window closes
- When somebody signs in with what you typed.
- What closes it
- A person or a script using the login, not the clock.
- Still possible after
- Cutting that password off everything else it opens.
2.What you do first, before anyone uses it
- Change the password on the real address, reached the way you normally reach it and never from a link on the page that took it.
- Change it anywhere else the same string was used, starting with mail.
- Sign out every session the account will show you.
- Only then read the page that fooled you, and note what made it convincing.
The order is the point. Most people read first and act second, and the reading is the half that can wait an hour.
3.What the gap actually depends on
Not on you. It depends on when a person or a script gets round to the string, which is somebody else's schedule. Some logins are used in seconds because the copy feeds them straight into an automated sign-in. Some sit for days because nobody has looked. You cannot tell which from the outside, so treat it as the fast kind.
So the honest answer is never to change it at the weekend. There is no version of this where waiting improves your position.
4.The beliefs that do the damage
- That nothing happened because the page showed an error. The error is output. It says nothing about what the page kept.
- That changing the password later in the week is soon enough. Soon enough is measured against a stranger's convenience, not your calendar.
A third is quieter. People decide the account held nothing valuable, so the login is not worth chasing. The value is rarely the account. It is that the same password opens three other things, and one of them is mail. More of these sit on the page about things people are sure they can undo.
5.If it has already been used
Then this becomes a cleanup. Assume anything readable inside the account has been read. Change whatever else that password opens. Look hard at old messages, because a stored delivery address is the part with a real cost, and that one sits in the section on things already sent. The window index lists what else moves when an account changes hands.
A page built to take a password does not need to accept it. Rejecting it buys a second attempt, and the second attempt is what makes the visit feel routine.
Questions people send in
Does changing the password fix it on its own?
It shuts one door. It does not shut doors that share the same string, and on many systems it does not end sessions opened before the change.
Should I use the link from the page that took the login?
No. Reach the site the way you normally do, from an address you already held. The list is on the addresses page.
How would I have known it was a copy?
Often you would not, at the time. Afterwards the giveaway is usually how you arrived: a link from a message rather than an address you kept.