Who Sees What
Awazon market onion addresses
awazonloedcyl2otgftfg7qm6e2klbgg2dhouyli3hdno6gdkueh6byd.onion
awazonozc4jwyrveu4473igv5ldt2hnccl2s7lerm2z27cvrc22e4uyd.onion
awazonth6ocz5cyos63czmhtsglqr7ydkdcc4lopux7nxbauoo2qmvyd.onion

Printed exactly as supplied, in the order supplied, with no labels and no ranking between them. This site runs no checks against any of them. It publishes no uptime figure, no status light and no date of last checking, because it never looks. An address that opens is not by itself evidence of anything.

The market inbox: unreadable messages still have a shape

A message inside a market does not travel from you to the vendor. It travels from you to the platform, and then from the platform to the vendor.

Who sees it

The market server · Whoever runs the platform · Anyone who later obtains the server

The inbox looks like a private channel between two people. Structurally it is a relay with a middle. Your message is submitted to the server, stored somewhere until the other person signs in, and served to them when they open the thread. The middle is not incidental to the design, it is the design, and there is no arrangement in which the platform is absent from a conversation it is hosting.

Contents versus the fact of sending

Two different things exist in every message and they behave differently. The contents are what you wrote. The fact of sending is everything true about the message regardless of what it says: that it exists, which account sent it, which account received it, when it was submitted, and roughly how long it is.

Encryption applied before submission makes the contents unreadable to the middle. It does nothing to the second category, because the platform has to know where to deliver the message in order to deliver it. This is the sense in which metadata survives encryption: it is not a leak, it is the addressing information the delivery mechanism runs on.

Always visible to the platform
That a message exists, its two ends, its time, its approximate size, and its position in a thread.
Visible only if unencrypted
The words themselves.
Never visible
Anything you thought and did not send. A conversation held elsewhere. What the recipient did after reading.

What the shape of a correspondence supports

A single message says almost nothing. A correspondence says considerably more, and none of it requires reading a word.

It shows which two accounts talk to each other, which is the raw material of a graph of who deals with whom. It shows the direction and rhythm: a long message from one side followed by a short one back, repeated, looks unlike two accounts trading short messages quickly. It shows timing relative to other events, such as a message immediately before an order or a burst of them after a delay. It shows whether the relationship is one-off or recurring, which is the same recognition problem as ordering from the same vendor again.

Message length is a coarse signal that people forget about. A block of encrypted text sent to a vendor at the point of ordering is a different length from a one-line question, and the difference is legible without decryption. That is not a hidden channel, it is just an observable property of the object.

Absence is legible too, in a limited way. A thread that runs steadily and then stops is a fact about the thread, and so is a thread that opens with a single message and never receives a reply. Neither tells anyone why, but both are visible without reading anything, and both are the sort of thing people assume is invisible because nothing was written.

What it does not support

The shape of a correspondence is not its subject. Two accounts messaging regularly may be arranging something, arguing about something that never happened, or exchanging pleasantries. Nothing in the pattern distinguishes those.

It is not proof of a transaction. Messages precede orders that are never placed, and orders happen with no messages at all.

It is not an identity for either end. Both ends are account labels, and turning a label into a person requires one of the exposures the rest of the catalogue covers: a name reused, an address typed in plain, a device holding a copy, or a person told. The people section deals with the last of those, and it is often the shortest path.

It is also not a record of a conversation held somewhere else. A discussion that happened outside the platform produced no rows on the platform. It produced records wherever it did happen, which is not an improvement so much as a relocation, and often a relocation to a place with worse properties.

A worked comparison

Consider the same message under three arrangements, from the platform's point of view.

How the message was sentWhat the platform receives
Typed in plain into the inboxWords, sender, recipient, time, length
Encrypted elsewhere, pasted inSender, recipient, time, length
Not sent at all, arranged in advanceNothing, though the arrangement exists wherever it was made

The gap between the first two rows is large and worth having. The gap between the second and third is smaller than people expect, and the third row carries costs of its own. This is why the inbox is not obviously the worst option available, only a known one.

What changes the answer

4 things change how much this action gives away. None of them takes it to zero, and none of them is a promise.

  1. Encrypt before pasting, not afterText encrypted on your own machine arrives unreadable. This removes the contents from every party in the middle, now and later. It leaves the sender, the recipient, the time and the length exactly as they were. See sending an encrypted note.
  2. Fewer messages, not shorter onesThe count and the timing are what build a pattern. Consolidating three questions into one message reduces the number of events. Abbreviating a message reduces its length, which is the least informative part of the shape.
  3. Nothing in the inbox that also exists in a formRepeating an address or an order detail in a message creates a second copy under the same account, sometimes in plain when the first was not. Keeping details in the field designed for them avoids the duplicate. See typing a delivery address.
  4. Treating the thread as durableA thread that can be displayed to you later exists somewhere in the meantime. Whether a delete action removes it is not visible from the interface, so the safe assumption is that what was sent remains sendable to someone. This is an assumption, not a mechanism.

What this card is not

This is not a statement about what Awazon Market keeps in its message store. It describes what any platform that delivers a message between two accounts necessarily handles in order to deliver it.