Addresses / Pair 02 of 41
Old address, or one built to be misread
Somebody hands you a string that is not in the published set. It might be an address the market really did use and drop. It might be one that was ground out specifically to sit beside the real one in a hurried eye.
Two dead strings, two different reasons
Real once, published once
A string the market actually controlled and published at some point, and no longer does. It came from a key the operator held. It is dead in the sense of no longer being the way in, not in the sense of having ever been a trick.
Built to be mistaken
A string produced by somebody else and deliberately shaped so that its opening characters or its closing characters match a real one. It was never the market. It exists so that a fast reader will accept it.
Both strings fail in the same instant and in the same way. You hold either one against the current set, it is not there, and you are left holding a string with no story attached. What people do next is fill that gap with the friendlier story, and retired is much friendlier than manufactured. History sounds like an explanation. Forgery sounds like an accusation, and accusing a string feels dramatic.
The friendlier story arrives with a follow-on thought that does the real damage. If this is only an old address, then perhaps it still works, or perhaps it redirects to the current one, or perhaps it is a mirror somebody forgot to list. None of that follows from age, and every part of it is exactly what a manufactured string was made to trigger.
The comparison that settles it
An onion address is fifty-six characters of base32 followed by .onion, and those fifty-six characters are not chosen by anybody. They fall out of a public key. The operator does not pick them and cannot order a specific one.
What somebody can do is grind through keys until one happens to start with a few characters they wanted, or end with them. The work required climbs steeply with every extra character demanded, and the full string is far out of reach for anyone. So manufactured resemblance lives at the edges. It agrees with a real address for a handful of characters and then falls apart, and it falls apart in the part of the string nobody reads.
Read from the middle outwards
Line the string up against a published one and read the middle rather than the ends. A retired address is unrelated all the way through. A manufactured one agrees at an edge and diverges in the middle.
- Put the string directly under a current one so the characters sit in columns.
- Ignore the first eight characters and the last eight. That is the region somebody may have paid for.
- Read the block in between. If it diverges immediately and completely, you are holding something that was never imitating anything.
- If the edges agree and the middle does not, the resemblance was bought on purpose.
Where the mismatch sits
| What you are looking at | Retired | Lookalike |
|---|---|---|
| Opening characters | Unrelated to the current set | Often an exact match |
| Middle of the string | Unrelated | Unrelated, and that is the tell |
| Closing characters | Unrelated | Sometimes matched instead of the opening |
| Where you got it | An old post, an old note, your own file | Sent to you, or sitting high in a search |
| What it wants from you | Nothing at all. It is just old paper | A login, a deposit, a click |
What each one costs you
- If you treat a retired address as a lookalike
- You bin an old note and feel briefly suspicious of whoever gave it to you. That is the whole bill, and you can pay it every day of the week.
- If you treat a lookalike as retired
- You have handed a hostile string a harmless explanation. The thought that follows is almost always to try it anyway, and being tried is the entire purpose of the string.
Only one direction here has a price worth naming, which makes the sensible bias obvious. Treat every unlisted string as manufactured until the middle of it says otherwise, and the times you are wrong will cost you a deleted line of text.
There is a related pair worth reading alongside this one, since the two get tangled constantly: a mirror against a copy of the site. A lookalike address usually exists to serve a copy, and the copy is where the money actually goes. The rest of the addresses section works through the other ways a string can be wrong.
Handling either one
- If it is retired
- Delete it wherever you keep addresses, including the note you copied it into two years ago. Replace your record with the current set as a whole rather than editing the old one in place.
- If it is a lookalike
- Delete it, then work out how it reached you. The string is disposable and the channel that delivered it is not, since that channel will send you another one.
That second half matters more than it reads. A manufactured string does not appear by itself. It arrived through a place, a person or a search result, and whatever route brought it will keep working long after you have thrown the string away. If the mismatch you are looking at is a single character rather than half the string, you are probably in a different pair entirely.
Questions readers send about this pair
Can somebody make an onion address identical to a real one?
No. The characters come from a public key, so an identical address would mean holding the same private key. What is achievable is matching a few characters at the start or the end, and the difficulty rises sharply with each extra one.
If an address is not in the current set, is it automatically hostile?
Not automatically. Old addresses are genuinely dropped over time. The point of reading the middle is that it separates old from manufactured without you needing to decide anything about the person who sent it.
Why do lookalikes match the beginning so often?
People read left to right and stop early. The first few characters are what gets checked in practice, so that is where the effort goes. Matching the end is the same trick aimed at people who check the other end instead.