TRUST THE KEY · NOT THE DOMAIN
What PGP Is and How to Verify a Torzon Signature in 2026
PGP is the check that separates a real Torzon signature from a page that only looks correct. It lets you confirm who signed a file and whether anyone altered it, without trusting the site that handed it to you. Every Torzon onion address on this reference traces back to the same signed key, and this page is the full walkthrough of how that Torzon signature check actually works, start to finish.
Written by Alex Ferran, security research · last checked 2026-08-25
PGP in one plain paragraph
PGP stands for Pretty Good Privacy. In practice it gives one person a private key they keep secret and a public key they hand out. When they sign a file with the private key, anyone holding the public key can confirm two things: the file came from that key, and not one byte changed on the way. That is the whole idea, and it is why a signature beats a screenshot.
A signature is a small proof attached to a file. It does not hide anything and it does not encrypt the address list. It only answers the question of who signed this, and was it touched after.
Why a reader trusts the key, not the address bar
A clone can copy a Torzon page down to the last pixel and buy a name one letter off. What it cannot do is sign a directory with the canon private key, because that key never leaves the owner. So the safe habit is simple: decide what to trust by the signature, then let the address follow from the signed list.
One secret key
Only the canon holder can produce a valid signature. A phishing site has the look but not the key.
Tamper-evident
Change a single character in the address list and the signature stops verifying. There is no quiet edit.
Checked offline
You run the check on your own machine. The result does not depend on the server being honest.
Portable proof
The same signature verifies anywhere. Move the file to another device and the answer is the same.
How a signature check runs, end to end
Three things meet on your machine: the signed file, the detached signature, and the public key you imported. gpg does the arithmetic and returns one of two answers. Here is that path drawn out.
Import the key, then run gpg --verify
- Save the published public key as canon-pub.asc.
- Run gpg --import canon-pub.asc to add it.
- Read the fingerprint and match it to the canon.
- Fetch the signed list and its .sig file.
- Run gpg --verify and require a Good line.
gpg --import canon-pub.asc
gpg --fingerprint # compare with the canon
gpg --verify mirrors.json.sig mirrors.jsonThe signed directory lives at mirrors.json, and the primary reference address on the canon reads http://torzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onion. Compare, never guess.
What a signature catches that your eyes miss
A signed release
Verifies against the canon key. The fingerprint matches on your own machine. The address list is exact, and gpg prints Good.
A convincing clone
Same colours, same wording, a badge that says verified. No valid signature, or a key whose fingerprint does not match. That gap is the tell.
If you can only do one check, do this one. A page that cannot produce a matching signature has failed, however polished it looks.
The Torzon PGP key: where it comes from and how to keep it
Every claim on this page depends on one thing: getting the Torzon PGP public key from a source you have independently reasoned about, not just the first result a search engine hands you. The key published on the Torzon canon is the one this whole reference is built around, and it is worth understanding where a key like that legitimately comes from before you trust it.
A key is generated once, then reused
A PGP keypair for a project like Torzon is typically generated once and reused for every signed release afterward — the address list, status updates, and any official announcement. That consistency is useful: if you have verified the Torzon fingerprint once against a source you trust, every future signature from the same key inherits that trust, without you needing to re-verify from scratch each time.
Keep your own copy, not just a bookmark
Bookmarking this Torzon reference page is not the same as keeping the key. Browsers get compromised, bookmarks get hijacked by malware that silently edits saved URLs, and a page can be cached in a state that predates a key rotation. Import the Torzon public key into your own keyring with gpg --import so the verification step works even if you cannot reach this page at all.
What a key rotation looks like, and why it matters
Occasionally a project rotates its signing key — after a suspected compromise, a long gap in operations, or simply good hygiene. A legitimate Torzon key rotation is itself announced and signed by the outgoing key where possible, creating a chain you can follow. A sudden, unexplained "new official key" posted only on a forum, with no link back to the previous Torzon key, is a strong clone signal rather than a routine update.
Common PGP verification mistakes on Torzon
Most Torzon phishing incidents that involve a PGP step at all do not happen because the math failed — they happen because a shortcut was taken somewhere in the process. The mistakes below account for the overwhelming majority of failed verifications reported around Torzon and similar markets.
Trusting a fingerprint pasted in chat
A fingerprint copied into a Telegram or Discord message from someone claiming to represent Torzon is not verification — it is a claim about verification. Get the fingerprint from the signed canon itself, not from a third party repeating it, however confident they sound.
Skipping the character-by-character compare
It is tempting to glance at a fingerprint, see that it "looks right," and move on. A single swapped character in a 40-character hex string is invisible at a glance and catastrophic if missed — it means you imported an attacker's key instead of the real Torzon key. Compare it in full, ideally by copying both strings into a text tool rather than eyeballing them.
Verifying the key but not the file
Importing the correct Torzon key is only half the job. You still need to run gpg --verify against the specific file or address list you intend to trust. A correctly imported key sitting unused in your keyring protects nothing on its own.
Assuming a matching layout means a matching key
A cloned Torzon page can reproduce the entire visual verification instructions, including screenshots of a correct-looking fingerprint. Never treat the instructions on a page as proof of anything about that same page — only an independent gpg --verify run on your own machine, against a key you sourced carefully, counts.
Quick verification checklist for the Torzon PGP key
Before opening any Torzon onion address, run through this short checklist. It takes under a minute and covers everything this page has walked through in detail.
- Import the Torzon public key from this canon, not from a forum or chat message.
- Compare the full Torzon fingerprint character by character — never a partial glance.
- Run
gpg --verifyagainst the signed Torzon address list, not just the key. - Confirm the result says Good, with no substituted or expired Torzon key warning.
- Only then copy the verified Torzon onion address and open it in Tor Browser.
Skipping any single step in this Torzon checklist reintroduces the exact risk PGP exists to remove. Treat it as all five steps or none.
What it means when a Torzon PGP key rotates
A signing key can be rotated for the same reasons an onion address is: suspected compromise, routine hygiene, or an operator simply moving to a stronger key. A rotation on its own is not a red flag, but it changes what "verify" means for a short window — the old key can no longer vouch for new material, and the new key has not yet built the track record the old one had. The signed transition itself is what matters: a legitimate rotation is announced and signed by the outgoing key before the incoming key takes over, creating an unbroken chain a reader can follow. A rotation that simply appears with no prior announcement, or where a new key claims authority without the old key's endorsement, is the pattern a phishing operation would produce if it were trying to insert its own key into the trust chain.
Frequently asked questions
What does a PGP signature actually prove?
It proves a file was signed by the holder of one private key and has not changed since. It says nothing about which website served it, which is exactly why the key is the thing you trust.
How do I import the Torzon key?
Save the published public key to a file and run gpg --import on it. Then read back the fingerprint and compare it, character by character, with the one shown on the canon home page.
What is a fingerprint, and why compare it?
A fingerprint is a short hash of the whole key. Two different keys will not share one, so matching it confirms you imported the intended key and not a swapped copy.
gpg says Good signature but also a warning. Is that fine?
The Good line means the math checked out. A trust warning only means you have not marked the key as trusted in your keyring. Confirm the fingerprint by hand and you are done.
The page looks identical to the real one. Is that enough?
No. Layout, wording, and a status badge are all easy to copy. A signature is not. Check the file with the URL validator and the key, then decide.
Do I still need PGP if the onion address matches?
Matching the address is a good first pass, but the signed list can hold several mirrors. PGP is what ties that whole list to one key you can check offline, which is why the access guide puts it first.
What if the Torzon key I find online doesn't match this page?
Treat any mismatch as a serious red flag rather than a minor discrepancy. Do not import the mismatched key, do not use the address list it claims to sign, and re-source the Torzon fingerprint from this canon before doing anything else.
Can Torzon's PGP key ever change without warning?
It can happen after a compromise, but a legitimate Torzon rotation is normally signed by the outgoing key, creating a traceable chain. An unexplained "new Torzon key" with no link back to the previous one, especially one posted only on a forum, should be treated as a clone attempt.
Is checking the Torzon PGP fingerprint enough on its own?
It is the single strongest check available, but pair it with the full onion address comparison on the validator page. A matching Torzon fingerprint on a correct address is the combination this whole reference is built around.