There will always be new markets springing up to fill the void created when one gets busted
If you're only buying small personal amounts of weed, I wouldn't imagine you'd be at much risk. But I'm not a lawyer so
DarkNetMarkets subreddit maintains a list of marketplaces and their statuses, and you'll be able to find news and shyt on there and warnings about which markets to avoid, etc.
DarkNetMarketsNoobs probably has some info that you'll find useful
I can't recommend any particular vendors since I'm in the UK and I rarely use overseas vendors (I'm assuming you're from elsewhere). You'll probably want to stick to vendors who have a good track record, so look for high number of transactions and good rep. Also make sure you read some of the rep comments in case there's some fukkery going on, if it looks like the same person repped them a zillion times, that should set off alarm bells. FWIW I've done around ~25 separate transactions and never been scammed. One time the goods didn't arrive, and the vendor gave me a full refund. Other than that, everything's been sweet. Scamming is widespread going by the forums, but if you're smart about it you'll give yourself the best chance of avoiding it.
For bitcoins, I just go on localbitcoins.com and buy from someone with a good price + high number of transactions + good rating. They have noob guides and FAQs and shyt on there too under the "Info" heading
For encryption, I use
http://gpg4win.org/
it's very easy to use, you just create a text file containing the pgp public key of whoever you're going to communicate with (copy and paste from their profile), import it as a key, open the clipboard, type whatever message you're encrypting, then hit Encrypt and select the key you imported. It'll output a bunch of mumbo jumbo that you then paste in the message box when you're sending the vendor your info. Never give your name, address etc unencrypted obviously.