मुख्य कंटेंट तक स्किप करें

जो लोग पहले से Monero की परवाह करते हैं उनके लिए P2P और OpenPGP literacy

· 9 मिनट में पढ़ें
Domestic Monero
Domestic Monero team

Monero का ledger पहले से amounts और counterparties default रूप से छुपाता है। यह ज़रूरी है। पर्याप्त नहीं। Careful stack को बर्बाद करने वाला leak अक्सर boring होता है: messenger के अंदर plain text में बैठा trade secret, share का screenshot, 「support」 DM जो वही paste करने को कहे जो सिर्फ आपके पास होना चाहिए।

यह post literacy है — P2P role और सीमाएँ, फिर क्यों अपनी ही public key पर sensitive delivery encrypt करना उसी skill set का हिस्सा है — thriller के रूप में सजा product pitch नहीं।

एक नज़र में

फ़ील्डमान
विषयP2P trade literacy; OpenPGP public-key delivery; messenger plaintext risk; Monero layer hygiene
प्रारूपGuide-first explainer privacy / security-minded readers के लिए
मुख्य स्रोतOpenPGP encryption overview · RFC 9580 · Telegram cloud vs secret chats · Domestic Monero public FAQ / Profile copy
उल्लिखित उत्पादDomestic Monero — encrypted notifications के लिए Profile पर optional OpenPGP
आधिकारिक प्रवेश@domestic_monero_bot
सहायताकेवल आधिकारिक bot पर /support (Trade #ref + trade state शामिल करें)
संपत्ति (P2P)XMR ↔ BTC, LTC, ETH, SOL, USDT (Ethereum mainnet पर ERC-20 केवल)
यह नहीं हैUser-to-user encrypted chat; seizure-proof guarantee; legal या tax advice; concealment manual
तीन horizontal layers — Monero chain, messenger delivery, और OpenPGP envelope — प्रत्येक पर short what-it-covers line।
तीन layers। उन्हें एक slogan में मिलाना leaks कैसे होते हैं।

P2P किस लिए है (role, effect, performance, security)

Role. Peer-to-peer trading दो लोगों को जोड़ता है जो पहले से asset, amount, और rails पर सहमत हैं — बिना central limit-order book के match decide किए। Platform फिर भी deal stage कर सकता है (offers, locks, proofs, settlement gates)। वह staging 「group chat में stranger आपके coins पकड़े」 के बराबर नहीं।

Effect. जब regulated venues privacy coins delist करते हैं या mid-KYC accounts freeze करते हैं, P2P conversion paths एक category के रूप में उपलब्ध रहते हैं: desktop Tor markets, instant swaps, structured Mini Apps, और — सबसे risky — informal chat deals। Archive पहले से उन अंतरों को map करता है: Instant swap vs P2P, Telegram is not an escrow

Performance. P2P आमतौर पर liquid CEX click से धीमा है। Stake, on-chain payment proof, confirmation waits, और human timing — उस trust model की लागत जो licensed broker assume नहीं करता। Trust trade नाम लिए बिना उसे 「bad UX」 कहना अधूरा है।

Security. P2P risk को इन तरफ shift करता है:

Riskक्यों मायने रखता है
Counterpartyकिसी को पहले move करना होता है या lock पर निर्भर रहना
Payment railsFake proofs, third-party deposits, tainted fiat (अगर कोई हो)
Channel hygieneFake support, off-platform pushes, paste-the-secret scams
Operational disciplineDeadlines, exact amounts, credentials offline रखना

Escrow या multisig-style staging कुछ theft shapes कम करता है। Bad payment sources, device compromise, या chat history में plaintext secrets मिटाता नहीं। Fiat-receipt P2P पर bank-freeze angles के लिए देखें P2P bank freezes

Monero लोगों के लिए यह literacy अनिवार्य क्यों है

Monero on-chain visibility address करता है। ज़्यादातर users अभी भी:

  1. Transparent asset (BTC, ETH, USDT…) से आते हैं
  2. Messenger या web UI से coordinate करते हैं
  3. Recovery material और trade credentials devices पर store करते हैं

अगर step 2 Authorization Credentials को readable chat history में छोड़ दे, chain की privacy fail नहीं हुई — delivery path fail हुई।

Privacy advocates पहले से layers में सोचते हैं (keys, freeze planes, legal obligations)। वही आदत Monero ops पर लगाएँ:

Layerक्या छुपा सकता हैक्या नहीं छुपा सकता
Monero chainउस ledger पर amounts / counterpartiesआपका Telegram identity, screenshots, exchange KYC
Messenger cloudTransit में casual ISP snoopingPlatform-accessible cloud content; process के तहत phone metadata
OpenPGP to your pubkeyउस channel में delivered secret का readable bodySeized device जो आपकी private key + passphrase भी रखे

Messenger architecture के लिए sibling framing: Why a Telegram Mini App

OpenPGP एक पेज में (उपयोगी आधा)

OpenPGP एक hybrid cryptosystem है (openpgp.dev, RFC 9580):

  1. Random session key message body encrypt करता है (symmetric)।
  2. वह session key recipient की public key पर encrypt होती है।
  3. केवल matching private key session key unlock करती है, फिर body।

कोई भी आपकी public key रख सकता है। Private key सिर्फ आपके पास होनी चाहिए। Cloud chat में ciphertext उन सबके लिए ciphertext रहता है जिनके पास वह private key नहीं — curious admin, stolen session screenshot farm, या chat backups का future dump सहित।

Hard limits (ज़ोर से कहें):

  • Endpoint compromise जीतता है। अगर private key और passphrase seized phone पर हैं, envelope खुला है।
  • Metadata रहता है। किसे message गया, कब, और कि PGP blob आया — अभी भी visible हो सकता है।
  • Default रूप से forward-secret नहीं। Long-term private key leak पुराना captured ciphertext decrypt कर सकता है।
  • Chat protocol नहीं। Inbound service delivery के लिए key register करना 「counterparties के साथ encrypted DMs」 नहीं है।
दो कॉलम: बाएँ chat bubble में plain trade-share string; दाएँ PGP ciphertext block — केवल आप decrypt कर सकते हैं।
वही channel। History बाद में copy हो तो अलग residue।

Domestic Monero वास्तव में क्या ship करता है (public UI)

Profile optional OpenPGP public key रख सकता है। Notifications configure होने पर, sensitive trade materials — trade share delivery सहित — PGP message के रूप में भेजे जा सकते हैं जिसे केवल आप decrypt कर सकते हैं। Public string: 「Sensitive trade details are sent as a PGP message only you can decrypt.」

Critical disambiguation:

Operator PGP packYour Profile OpenPGP key
PurposeOfficial bot / authenticity materials prove करनाआपको inbound sensitive notifications encrypt करना
Who decryptsPublished operator key से आप signatures verify करते हैंआप अपनी private key से decrypt करते हैं
Chat?नहींनहीं — अभी भी user-to-user messaging नहीं

Unshipped / Archive के लिए 「live」 scope से बाहर: counterparties के बीच peer-to-peer encrypted trade chat। Invent न करें।

Trade create होने पर भी आपको trade share मिलती है। Offline रखें। App चेतावनी देता है कि agree के बाद फिर नहीं दिखेगी। Lost share recovery paths जो Telegram से resend करते हैं — ठीक इसीलिए उस chat में ciphertext plaintext से बेहतर है।

Telegram Mini App Profile Notifications — toggles और PGP key card, key material blurred।
Profile पर optional PGP — notifications, social inbox नहीं।

Practical habits (छोटी, checkable)

  1. Mid-trade ज़रूरत से पहले OpenPGP key offline generate और back up करें।
  2. Profile में केवल public key register करें; private key या passphrase कभी Telegram में paste न करें।
  3. Key verify होने के बाद ही encrypted notifications enable करें।
  4. Trade shares offline storage में copy करें; chat history को long-term hostile storage समझें।
  5. ऊपर से पहले bot verify करें: Verify official channels
  6. Adrenaline के बिना decrypt → settle → Receive XMR / refund rehearse करने के लिए छोटे trade से शुरू करें।
दो कॉलम — operator authenticity PGP बनाम encrypted inbound delivery के लिए user Profile PGP।
दो अलग keys। उन्हें मिलाना common support ticket waiting to happen है।

इस लेख में शब्द

शब्दयहाँ अर्थ
P2P offerSupported payment assets के खिलाफ XMR buy/sell का peer listing
Trade shareसही state पर XMR receive या refund के लिए required authorization credential
OpenPGPData encrypt/sign करने का public-key cryptography standard
Cloud notificationTelegram के default (non–Secret Chat) path से delivered bot message
Multisig Trade WalletIn-app दिखाया गया platform-staged wallet address — आपके control वाला on-chain Monero multisig नहीं
Trade #ref/support के लिए short public trade identifier

अस्वीकरण

यह लेख editorial opinion और general security literacy है — legal advice नहीं, tax advice नहीं, और lawful process evade करने की guide नहीं। Notifications encrypt करना बदलता है कि chat transcript कौन पढ़ सकता है; यह आपको invisible, seize-proof, या local law से exempt नहीं बनाता। अगर private key रखने वाला device compromise हो, उस key का ciphertext readable मानें।

FAQ

क्या Domestic Monero पर OpenPGP ज़रूरी है?
नहीं। Optional है। Public FAQ recommend करता है अगर आप Authorization Credentials और notifications plain chat से बाहर रखना चाहते हैं।

क्या key register करने से मैं counterparty से privately chat कर सकता हूँ?
नहीं। No user-to-user chat है। PGP service → you sensitive materials delivery encrypt करता है।

अगर police मेरा phone seize करे, क्या मैं safe हूँ?
अगर private key / passphrase उस phone पर unlock होता है, नहीं। Telegram में ciphertext मदद करता है जब दूसरे आपके key के बिना cloud copy पढ़ें। यह device-seizure talisman नहीं।

Secret Chats क्यों नहीं?
Secret Chats one-to-one human E2EE हैं और rewrite नहीं करते कि bots cloud notifications कैसे deliver करते हैं। Product notifications cloud path पर चलते हैं; payload sensitive हो तो payload encrypt करें।

Domestic Monero क्या है?
BTC, LTC, ETH, SOL, और USDT (ERC-20) के खिलाफ peer-to-peer Monero trades का Telegram Mini App। Official entry: @domestic_monero_bot

Mini App खोलें: @domestic_monero_bot

संबंधित: Why a Telegram Mini App · Telegram support DM near-miss · Self-custody habits · Verify official channels