PGP keys are now quoted inside the Nexus listing header
The full PGP block, or at least the fingerprint line, has moved out of the vendor profile and onto the top of the listing itself on a growing share of Nexus shops.
The change looks cosmetic. It is not. Where the key sits changes when the reader is expected to check it, and when they are expected to check it changes whether they check it at all.
How it read before
The PGP key lived on a separate tab. You clicked "profile", scrolled, then clicked "PGP" or "keys" or "encryption", and the block appeared on a page of its own. The reader who wanted to verify a signed message on this vendor had to leave the listing, load a second page, load the key, and then come back. Most readers did the trip once, if that, and did not repeat it per order.
How it reads now
On the newer listings, the header carries either the full block or the fingerprint and a link to the block on the same page. The reader can copy it without switching tabs, and a signed message from the vendor can be checked without leaving the listing. Some vendors show a small "signed by" line under the block that the market renders automatically.
The fingerprint line is the load-bearing part. The whole ASCII armoured block reads as noise to a reader who is not planning to import; the fingerprint is a single line that a reader can compare against a cached fingerprint by eye. Putting it at the top of the listing means the comparison is done before the order button rather than after.
Why this probably shifted
A key on a separate tab is a key that is not verified. Vendors know this, and buyers pretend not to. Bringing the key to the listing header makes the key part of the visible transaction rather than an optional stop, and it lets the vendor point to a specific place when a reader claims the key does not match what they had cached.
The move fits with other quieter pressures on the same page. The market is nudging readers to notice signatures more; the invoice screen now displays a PGP signature block, and the way new readers handle PGP the first time has changed shape, which means the reader who arrives without a habit is more likely to try to verify than they used to be. Putting the key where they will look for it saves them a lookup.
The shift also matches an uglier trend. When address typos are landing readers on lookalike sites, the reader may be looking at a listing that is not on the market at all. The key in the header helps them notice this earlier, because a lookalike vendor page tends to copy the design but botch the key. A cached fingerprint that fails to match a header block is one of the earliest tells that the whole page is wrong.
What to change on your side
A key inside the header is not automatically the real key. Two vendors can print the same-shaped block. Store the fingerprint you first trusted, and compare, do not re-import blind. If the block in the header differs from the one on the profile tab, treat the mismatch as a reason to slow down, not as a proof of anything by itself.
- Cache the fingerprint you first trusted, not the whole block
- Compare the header key against the profile key, and against any earlier signed message you kept
- Do not accept a signed message that verifies against the header key if the profile key differs
- If a fresh onion is showing an unfamiliar key, read the fresh-onion panic entry first and slow the reflex
- Never copy the key from a message that came in a plain reader-to-reader chat off the market; use only what the market page prints
Verifying a key is a small habit, not a security ritual. The cost is one file lookup and one string comparison. The reward is that a lookalike page or a compromised header will fail loudly rather than quietly, and the loud failure is the point.
What this entry is not claiming
Putting the key in the header does not make the vendor honest and does not make the reader safer on its own. The shift is a matter of where the trust step happens, not whether it happens. It also does not claim the profile-tab copy has disappeared. Most vendors still have both, and the two should agree. The absence of a key from a listing header is not a claim of dishonesty; some careful vendors still keep it on the profile tab only, and that is a choice, not an oversight.