Traps / Dossier 10 of 57

A hidden newline inside a pasted nexus market url

One character no one meant to keep

Nexus market mirrors, as published on this site

nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Published as supplied. This site does not probe an onion, so nothing here is a claim that a given address opens for you right now.

This is the dossier for the nexus market url trap where a paste carries a hidden newline or a space in the middle of the string, and the address bar reads the string as two.

What it is

A nexus market url is a single run of characters. Any whitespace inside the run breaks it. A newline in the middle of the paste turns the paste into two lines, of which only the first is read as an address. A space in the middle of the paste turns it into two words, of which only the first is read. A tab does the same. All three are invisible on many surfaces, and the reader who cannot see the character cannot remove it.

The break is not the trap on its own. The trap is that the browser tries to make sense of the first fragment, and often either fails silently or resolves it as something else. The reader looks at the address bar, sees the first half of the string in it, and has to decide whether the half is the whole url. On a fast day the reader corrects the address by hand. On a slow day the reader does not notice.

Where the hidden character comes from

A copy from a message that wrapped the address across two lines is the first origin. The wrap looked like a display wrap. It was a real newline. The copy carries the newline into the paste.

A copy from a document that used justified text is the second. The extra spacing between words that the layout added to justify the line is a real space in the copy. A copy that spans the space carries the space into the paste. A word processor with automatic hyphenation is the third. The soft hyphen it inserted at a display break is a character the paste picks up.

Lifeline

  1. A wrapped display of the address
  2. A paste that splits at the wrap
  3. A paste from a single line source

How to catch it

The catch is a paste target that shows whitespace. A plain text editor with a show invisibles setting reveals the character. Pasting into a search engine or a browser bar that treats a space as a separator produces two words the reader can see side by side. The address bar of tor browser drops trailing whitespace but keeps whitespace in the middle. A paste with a middle space in the tor browser bar is a paste that reads as broken there.

On a plain text editor
Enable show invisibles. Any dot, arrow or return glyph in the middle of the paste is a whitespace character to strip.
On a browser bar
A paste that shows only the head of the string in the bar has been split at a hidden character.
On a copy from prose
Copy the address by triple clicking a display line, not by dragging across a wrap. A triple click selects the display line, not the underlying paragraph.

What this card does not claim

  • It does not print a nexus market url with a hidden character in it. The trap is the invisible character, and the card describes only where it comes from.
  • It does not say every editor supports show invisibles. Most modern ones do, but the setting is off by default in many.
  • It does not say the trailing dot trap and this one are the same. Both are stray characters, but they sit at different positions in the paste.

A single line source

A single line source is the best defence against this class of trap. Every address on the panel above rides on one line, in one monospace field, and the copy button copies the line without a break. A reader who copies from the panel above carries the whole url in one piece and cannot split it on the paste.

A show invisibles habit

A show invisibles setting turned on by default in a text editor is a habit worth keeping. The setting prints a dot for each space, a return glyph for each newline and an arrow for each tab. A reader with that setting on can drop any paste of a nexus market url into the editor and see whether the paste is a single run or a run with a break in it. The check takes one paste and one look.

Not every editor calls the feature the same thing. Some call it show whitespace, some call it view invisibles, some call it display control characters. The words differ, the effect is the same. A reader who has turned it on once does not need to turn it on again, and every paste on that machine benefits from it.

A word about the tor browser bar

The tor browser bar is a single line field. A paste of a multi line string collapses in surprising ways depending on the version. A paste that shows only the head of the url in the bar has already lost the tail on the way in. Reading the bar before pressing return is the second chance to catch this trap after the paste target itself.

A paste that appears as a single line in the bar but is shorter than fifty six characters before the .onion label has lost a chunk. A paste that is longer has gained one. Neither is what the reader wanted. Counting the string in the bar, or comparing its length to any of the three nexus market urls on the panel above, is a small check that runs in under ten seconds.

Engagement

1hidden character breaks the paste in two
0whitespace characters in a valid v3 onion
56chars the paste should hold before .onion
3related dossiers on this trap

Discover more

Every dossier on nexusmirrors.store