PGP bench // verify yourself // 2026
Torzon Signature Bench 2026: Verify the PGP Key Yourself
A signature check is not a vibe. It is one command that returns a clean pass or a hard fail, and the fail ends the session. This bench walks the whole thing: load the key once, verify the signed record, and read the output like a switch, not a suggestion. The onion string itself stays on the card.
logged by Alex Ferran // checked 2026-08-25
torzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onionOpen the cardHow one command settles the Torzon signature question
Verifying a Torzon onion sounds heavy, but it collapses into three beats. You load a key, you run a check against a signed file, and you read a verdict. Everything else on this page is detail hung off that spine.
This bench exists because a Torzon address is easy to copy and hard to authenticate by eye. A phishing clone can reproduce the layout, the copy, and even a plausible-looking key block on its own page; what it cannot reproduce is a signature that verifies against the specific key you imported from a source you trust. That single cryptographic fact is worth more than any amount of visual polish a fake page can manage.
Five moves to prove a signed Torzon record
- Pull the Torzon signing key into your keyring. This happens once and sets the yardstick for everything that follows.
- Grab the signed record and its detached signature in the same breath. You need both files side by side.
- Run the verify command on the pair. The tool does the maths so your eyes do not have to.
- Read the line it prints. A good signature from the canon key is the only pass; silence on the key is a fail.
- Set the printed fingerprint beside the one you already held. Equal, and you proceed. Off by anything, and you walk.
Nothing here runs on our servers. The command runs on your machine, against files you fetched, and we never see the result.
The two Torzon verification lines you actually type
Here are the commands with nothing hidden. The first plants the key. The second weighs the signed record against it and reports back in plain words.
gpg --import torzon-signing.asc # once, up front
gpg --verify torzon-mirrors.sig torzon-mirrors.jsonWatch the second line. A phrase such as "Good signature" tied to the canon key is your pass. A "BAD signature", an unknown key, or no signing line at all means you got nothing, and nothing is a fail.
Good signature
The record is authentic and every address inside it was signed by the canon key. Copy your onion from the card and open it in Tor.
Anything else
Bad signature, wrong key, or no result. The record cannot be trusted and neither can the addresses in it. Close the tab and begin again from the card.
Reading gpg output when a Torzon check is not a clean pass
Common gpg error messages explained
gpg: Can't check signature: No public key means you have not imported the signing key yet, or imported the wrong one — go back to the import step before anything else. gpg: BAD signature is the serious one: the file was altered after signing, or you are checking it against the wrong record entirely; treat the addresses inside as compromised. gpg: WARNING: This key is not certified with a trusted signature is expected and not itself a failure — it means you have not built a web of trust around the key, which is normal for a first import; what matters is the line above it reporting a Good signature.
Verifying on Tails vs. a regular OS
On Tails, GnuPG is preinstalled and already routes nothing outside the Tor state you are running in, so the two commands above work identically to any other GNU/Linux system without extra setup. On a regular OS, make sure your GPG installation is current and, more importantly, make sure the terminal or file manager you are using is not itself compromised — the verification is only as trustworthy as the machine running it. Neither environment changes the commands themselves; it changes how much you can trust the result.
Where to learn GnuPG itself, not just this one check
This page shows the two commands needed to verify a Torzon signature specifically, not a general PGP tutorial. For the underlying tool, the official GnuPG documentation covers key generation, the web of trust, and every flag in more depth than a market-verification page should. For the broader question of why signature verification matters at all before trusting any downloaded key or address, Privacy Guides' overview of email and key security covers the same trust model in a non-market context.
What changed recently on the Torzon signature bench
The two-command Torzon verification flow documented above has not changed and is not expected to change once it goes live: import the key, run gpg --verify, read the result. What has moved is the troubleshooting detail around it, expanded below after repeated questions about running the Torzon bench on unfamiliar systems.
Running the Torzon bench from a live USB session
Tails ships GnuPG preinstalled, so the Torzon signature commands above run identically whether the session started five minutes ago from a fresh USB boot or has been open for hours — Tails does not cache or alter a prior Torzon verification between reboots, because nothing on Tails persists across a reboot by design unless a persistent volume was explicitly set up. This makes a fresh Tails session one of the cleanest places to run the Torzon bench, precisely because there is nothing left over from a previous check to second-guess.
Why the Torzon bench avoids listing the key here directly
This page deliberately does not paste a full Torzon signing key inline as plain text for you to copy, even once the key ships out of Phase 0 — a page that shows you a key and asks you to trust it on the page's own say-so recreates exactly the failure mode this bench exists to prevent. The Torzon key belongs on a channel with its own independent trust path, imported directly by you, not relayed a second time through this reference.
The bench versus a Torzon browser extension or app
No browser extension, mobile app, or one-click "Torzon verify" tool should be trusted as a substitute for running gpg --verify yourself on your own machine. An extension can be swapped or compromised independently of the record it claims to check, and an app store listing offers no cryptographic guarantee at all — the whole point of this Torzon bench is that the verification runs somewhere nothing else can quietly interfere with it.
Bench questions people ask
What if gpg prints BADSIG?
Stop. A BADSIG means the record was altered after signing, or the signature does not belong to the key you hold. Either way the addresses inside are not trustworthy. Close the tab and start over from the card.
Do I need the key before the record?
Yes, in that order. Hold the Torzon signing key first so the record has something to be measured against. Pull the Torzon record first and you are tempted to trust it before you can test it.
The signing key is pending, so what do I check now?
Until the key ships in Phase 0, the bench is a dry run. For now, read the full 56-character string against the card by eye and watch the canary. The command flow above is exactly what you will run once the key is live.
What does "No public key" mean specifically?
It means gpg cannot find the signing key in your local keyring to check the signature against. Re-run the import command with the correct key file before attempting verify again.
Is the "not certified with a trusted signature" warning a problem?
No, it is expected on a fresh import and refers to your personal web of trust, not the validity of the signature itself. Focus on whether the line above it reports a Good signature.
Can I run this check on a phone?
GnuPG is available for Android through some terminal apps, but the setup is more fragile than a desktop environment when checking a Torzon record. A dedicated computer running Tails or a hardened OS remains the more reliable choice for this kind of verification.
Why does this Torzon signature bench use gpg instead of a simpler online checker?
An online checker means uploading the record to a third party's server, which is exactly the kind of leak this bench is built to avoid. GnuPG runs entirely on your own machine, offline once the key is imported, so nothing about which record you are checking, or when, ever leaves your device.
Does a Good signature on the Torzon record mean the market itself is safe?
No. A Good signature confirms the record has not been tampered with since it was signed by the key you trust — it says nothing about the market's own operational safety, escrow reliability, or vendor quality, which are separate questions this bench does not answer.
Can two different Torzon records both pass the signature check?
Only if both were genuinely signed by the same trusted key, in which case both are authentic — for example an older archived record and a current one. A record that fails the check was either altered after signing or never signed by the key at all; there is no partial pass.
Do I need to run this Torzon signature check every single time I visit?
Once a specific record has verified against the trusted key, that verification does not expire on its own — but a new mirror list, a new onion address, or any record you have not personally checked before needs its own fresh gpg run. Do not extend trust from one verified record to a different, unverified one just because they came from the same page.
Can I verify a Torzon signature without installing GnuPG?
Not meaningfully. Some online "PGP verify" tools exist, but pasting a private-adjacent workflow like signature verification into a third-party web form defeats the purpose — you would be trusting that tool as much as the record you are trying to check. GnuPG is preinstalled on Tails and available as a standard package on essentially every Linux distribution, so the barrier to running it locally is low.
Know what a clone looks like
A signature is the proof. Knowing how a fake is built tells you why the proof matters and where the eye gets fooled. This signature bench and the clone teardown linked below cover the same Torzon threat from two angles: the cryptographic check that proves an address, and the visual tells that a clone gets wrong along the way.