Traps / Dossier 08 of 57

A QR code that encodes a different string than its nexus market link label

The label and the payload split

Nexus market mirrors, as published on this site

nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Published as supplied. This site does not probe an onion, so nothing here is a claim that a given address opens for you right now.

This is the dossier for the nexus market links trap where a printed QR code is labelled as a nexus market address but scans to a different string than the label spells out under it.

What it is

A QR code is a payload. The payload is the string the code encodes. The label under a QR is a human aid, printed for the reader who cannot scan or wants a second check. The trap is that the payload and the label can differ. A reader who trusts the label above the code and scans without reading may end up opening a string that does not match the label at all.

The label above the code is a nexus market link the reader believes they are about to open. The payload can be a nexus market link too, or it can be an address for a different market, or it can be a link to a phishing page on the clearweb. The QR itself gives no way to tell which one it is until it has been scanned, and by then the address is loading.

Where the mismatch comes from

A printed handout where the label and the QR were made at different times is one origin. The label was set once, the QR was regenerated later, and only the QR was replaced on the layout. A sticker where the label and the QR came from two different templates is a second. The templates were both branded, but the underlying payloads were not the same.

A generated QR on a chat message is the third. A friend meant to send the QR for the address in the label above it, and by accident dragged the wrong image from a folder that also held QRs for other markets or other pages. The message reads clean. The QR does not point where the message promised.

Lifeline

  1. A label and a QR drawn from different sources
  2. A scan whose result does not match the label
  3. A scanner that shows the payload before opening

How to catch it

The catch is a scanner that shows the payload as text before opening it in a browser. Every major mobile scanner has this option. The reader scans, the scanner prints the string, and the reader compares the string with the label under the code. If the two do not match, the code is not the code the label promised.

On a mobile scan
Set the scanner to show the payload as text first. Compare the head and tail of the payload with the head and tail of the label.
On a paper QR
The QR itself cannot be read by the eye. The label is the only place the reader can read what the print claims.
On a screen QR
A QR image on a screen can be replaced without the label changing. The label is not a proof that the QR is current.

What this card does not claim

  • It does not print a QR of any nexus market link on this page. The trap is the mismatch between a QR and its label, and the card describes only that.
  • It does not say QRs are a bad way to carry an address. Many surfaces carry them well.
  • It does not say every scanner will show the payload as text. Some open the payload directly, which is where the trap wins.

A code the reader has scanned twice

A QR that the reader has scanned twice and read out twice is a QR the reader can trust for the length of the paper it sits on. The next reprint is a new QR. On this site the addresses on the panel above are not printed as QRs at all. The strings themselves ride at the top of every page, and the copy button copies the string not an image of it.

A payload the reader can hold in the head

The payload of a QR for a nexus market link is a string of characters the reader could in principle write down. The head and the tail of the payload are what a reader can hold in the head, five characters at either end. A scan that shows the payload as text gives the reader the chance to check the head and the tail against the label, without reading the middle. That check is not proof, but it fails on most mismatches.

A payload longer than a v3 onion is a payload that carries more than an address. It may hold a URL scheme, a path, a query string. Any of those is a reason to look harder at the payload before opening. A nexus market link is just an onion. It has no scheme, no path, no query in the version this site publishes.

A label that describes what it is

A label that names the market, the mirror number and the format of the string tells the reader more than a label that says only the market name. A reader who reads that kind of label knows what the payload should look like before they scan. A payload that does not match the description is a payload to discard, even if it opens on the tor network.

A reader who prints their own

A reader who prints their own QR from a copy on this site holds a code they made and can verify. The label the reader writes under it is the label the reader chose. The payload the reader encoded is the payload they can read again. That kind of code carries the same address as its label because the same reader made both. The trap on this rubric does not fire on a code the reader owns end to end.

Engagement

1label the reader can read with the eye
1payload the reader can read only after a scan
0QR codes for nexus market on this site
3related dossiers on this trap

Discover more

Every dossier on nexusmirrors.store