Two things that look the same

Pairs people confuse on Nexus Market, and the one test between them

Home Getting in A code that does not match against a clock that does not

Nexus market mirrors

nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
nexusma2iegzo7atzwbrwxhcdopyri3vare2twibldnlc3txqjdeb5yd.onion
nexusabcdpvtnivv6owtqjkvd22k5x3hlpofkgjqjmgzltlde6mwe2qd.onion

Published as supplied. Nothing here is monitored, so none of this is a claim that any address opens right now.

Getting in / Pair 12 of 41

A code that does not match against a clock that does not

Six digits go in and come back refused. The code was correct arithmetic either way, so the question is whether the arithmetic was done at the right moment.

A code that is wrongA

A one off slip in the entry

A digit went in twice, a digit went missing, or the code rolled over between reading it and sending it. The device is healthy and the shared secret is intact. What failed was a single entry, and the next one will very likely work.

A clock that is wrongB

The right secret at the wrong moment

The device that generates codes has drifted away from the time the market is keeping. It is still doing correct arithmetic with the correct secret, and every answer it produces is for a moment that has passed or has not arrived. Nothing about the account is broken.

Why a wrong code and a wrong clock refuse alike

A time based code is a number worked out from two things. A secret shared between your device and the market when you set the second factor up, and the current time chopped into thirty second steps. Feed the same secret and the same step into the same arithmetic on both sides and you get the same six digits.

The check at the other end compares the digits it expects against the digits you sent. It has no way of knowing why they differ. A code that was fat fingered and a code that was worked out for a step three minutes ago fail in the same place, with the same message, and there is nothing left over to inspect.

Where the comparison actually happens

Nothing about your code travels except the six digits. The market does not see your device, your secret or your clock. It works out what it thinks the answer should be for the step it is in, allows a step either side, and compares. That is the whole of it.

Which means the failure is always one of two shapes. Either the digits you sent were not the digits your device produced, or your device and the market are not standing in the same thirty second window. The first shape is a slip. The second is a measurement problem, and it will keep happening until the measurement is fixed.

What you noticePoints at the clockPoints at the entry
How many have failedEvery one, with no exceptionsOne or two, with successes in between
When it startedAfter a restart, a flat battery, a long flight or a manual time changeAfter a rushed entry or a code caught late
Other time based thingsTimestamps and alarms also look offBehaving exactly as normal
A fresh code taken slowlyRefused as wellAccepted

The thing that tells a drifted clock from a bad secret

Compare seconds, not minutes

Put the clock on the code generating device next to a clock you trust and compare the seconds, not the minutes. Anything past half a minute of difference is enough to refuse every code you will ever produce on that device.

  1. Find the seconds display on the device that makes the codes.
  2. Put it beside a clock you have reason to trust, on another device or elsewhere.
  3. Watch both roll over. A difference you can see is a difference that matters here.
  4. If they roll together, the clock is not your problem and the next careful entry is the answer.

Notice that this test never spends an attempt. That matters, since a run of refused codes lands you behind the same counter described in rate limiting against a wrong password, and once two refusals are stacked you cannot read either of them.

The expensive direction here

If you treat a drifted clock as a bad code
You keep entering fresh codes that cannot pass, spend your attempts, and eventually decide the second factor is broken. That is the point at which people go looking for a way to re-enrol it, in a hurry, and re-enrolling a second factor from a page you found while frustrated is about the worst evening available.
If you treat a bad code as a drifted clock
You go and look at a clock for two minutes and find nothing wrong with it. The cost is two minutes and mild embarrassment, then you take one careful code and get in.

It is hard to think of a pair in this section where the gap is wider. One direction costs you a couple of minutes of looking at a phone. The other ends with somebody dismantling a working second factor to solve a problem that a time setting would have fixed. When in doubt, check the clock first, since it is the cheap move.

What each one needs from you next

If it is the entry
Wait for a fresh code rather than chasing the last seconds of a dying one, type it in one go, and send it. Codes read at the end of their step are the most common slip of the lot.
If it is the clock
Correct the time on the device that generates the codes, by hand or by letting it sync, then take a single attempt. Do not touch the secret and do not remove the second factor.

Two smaller habits remove most of this pair from your life. Read codes at the start of a step rather than the end, and leave the code device set to sync its time automatically. Everything else in this section is about refusals decided by somebody else, which makes this one unusual. Here the refusal is decided by arithmetic, and arithmetic can be argued with.

Questions readers send about this pair

Why did my codes stop working all at once?

A clock that moves in one jump, usually after a restart or a battery going flat, will take every code with it. Nothing gradual happened to the secret. The device simply stopped agreeing with everybody else about what time it is.

Do I need an internet connection for the codes?

No. The arithmetic happens entirely on the device. The only thing a connection helps with is keeping the clock honest, which is exactly the part that breaks this pair.

Is a refused code a sign the account was interfered with?

It is very weak evidence at best. Refused codes are far more often a step boundary or a drifted clock, and the clock takes two minutes to rule out before you consider anything more dramatic.

Every page here

AddressesGetting inMoneyOrdersPeopleWordsDown for now, or finished for goodOld address, or one built to be misreadSame page at two addresses, and only one is theirsThe redirect and the string it stands in forYour path through Tor, or the far endDid the set move, or did your copy slipLoading proves a server answered, and nothing moreRate limiting against a password that no longer matchesWhen the puzzle is broken and when the reader isA door you shut yourself against a lock somebody changedLogged out by a clock against logged out by a decisionA code that does not match against a clock that does notAn absence against a single character out of placeA wait somebody planned against a wait nobody didA deposit that is slow, or a deposit that is goneThe address expired, or it was never issued to youA rule about release, or a decision about youWho took the difference, the operator or the networkA saving on quantity, or a saving on protectionMoney back, or the end of the argumentStill moving, or already refusedStill settling, or short by a fractionA date with something behind it, and a date withoutOne request moves a clock, the other moves the moneyAsking for a ruling, or handing over informationA word in a database, and an event in a recordNothing new to report is not the same as bad newsA rule that runs by itself, and a date somebody prefersSilence and being ignored look identicalQuiet is not the same as goneFeedback tells you a mood, evidence tells you a factWhat a signature actually provesThe market only speaks in one placeAn empty history and a claimed historyThe result is good. Whose key was it?The same clean result, months apartYou cannot check an image, however clear it isOne of these strings was chosen by somebodyPosted where, and written by whomWho granted it, and what were they promisingTwo lists of addresses, two different guaranteesHow to read a pairEvery pairThe testsThe costsMirrorsQuestions