Live data from Hacker News

Someone is trying to steal archive.is's domain

twitter.com

21–30 of 48 posts

Re: Someone is trying to steal archive.is's domain

#21
post #9

Earlier quoted context omitted.

This looks like a job for: Blockchain! Seriously, though, imagine a public, distributed, append-only log, containing the hashes of the content stored by archive.is, with the data effectively signed by a (e.g. wallet) private key of the archive maintainers. People could volunteer to locally store copies of all the data that was archived, but only serve the data that goes "missing" from archive.is. With such a dead man…

This misses the point of censorship. A party determined to sow misinformation can hijack a domain to do so. All the blockchain in the world won't solve that problem.

That why we will solve censorship by mining my blockchain node hash with a sharding fork! /s

Re: Someone is trying to steal archive.is's domain

#22

Earlier quoted context omitted.

Serious question, in that thread some guy is attempting to have an old blog with his face pic deleted... id suport that. But then if some other news or political or corporate arm was seeking to get something deleted to prevent them from looking bad, then im against it... So what is the middle ground here, or how should one view this dilema?

You can't un-ring a bell.

That's not an excuse for other people to sit there re-broadcasting it.

There's a strong case to be made that we're actually substantially better off with certain kinds of information having a generally ephemeral and hard-to-collect nature.

Re: Someone is trying to steal archive.is's domain

#23

Earlier quoted context omitted.

Serious question, in that thread some guy is attempting to have an old blog with his face pic deleted... id suport that. But then if some other news or political or corporate arm was seeking to get something deleted to prevent them from looking bad, then im against it... So what is the middle ground here, or how should one view this dilema?

You can't un-ring a bell.

That doesn't really justify the decision to continue publishing private information. Just because someone somewhere may have access to it doesn't mean you need to make it easier for everyone to have access to it.

Re: Someone is trying to steal archive.is's domain

#24
post #10
post #8

Earlier quoted context omitted.

Not to worry. They have other domains too, as stated in the Twitter thread: .TODAY .FO .LI .VN .MD .PH

I'm not sure the existence of alternatives, advertised through Twitter, is much of a comfort here. The integrity of the domain name system shouldn't depend on someone having a well-known twitter account that can advertise alternatives in the event of a hostile takeover.

I agree, but that’s not what the GP and GGP we’re discussing.

Re: Someone is trying to steal archive.is's domain

#25
post #9

Earlier quoted context omitted.

This looks like a job for: Blockchain! Seriously, though, imagine a public, distributed, append-only log, containing the hashes of the content stored by archive.is, with the data effectively signed by a (e.g. wallet) private key of the archive maintainers. People could volunteer to locally store copies of all the data that was archived, but only serve the data that goes "missing" from archive.is. With such a dead man…

This misses the point of censorship. A party determined to sow misinformation can hijack a domain to do so. All the blockchain in the world won't solve that problem.

it's hilarious, to underscore the fragility of the conventional domain name system under pressure of politics and money, and portray it as an argument against blockchains,... this is literally what Namecoin (probably the second significant blockchain proposal) was designed for! of course lots of time has past now, and better mechanisms have been formalized (especially Algorand)...

Re: Someone is trying to steal archive.is's domain

#26

I don't see the value in a high profile stolen domain for a trader. Anyone have any ideas on why this would be financially worthwhile? I am assuming financial motives.

Sounds like someone really wants to push the narrative that, say, Zoe Quinn is a genius game designer and an innocent victim of targeted harassment, not a horrid person who herself organized harassment mobs against people she disagreed with -- and is running into the problem of all that pesky evidence to the contrary getting in the way.

Re: Someone is trying to steal archive.is's domain

#27
Could someone please explain this? What is going on? Either you hack a domain or you don’t—but once the owner finds out, shouldn’t they be able to verify that it’s locked down. How can someone steal a domain, permanently, and trade with it. Can this happen at any TLD or is .is just negligent/apathetic? Why would I ever buy a .is domain if the TLD lets people steal it? I don’t understand...

Re: Someone is trying to steal archive.is's domain

#28
post #26

I don't see the value in a high profile stolen domain for a trader. Anyone have any ideas on why this would be financially worthwhile? I am assuming financial motives.

Sounds like someone really wants to push the narrative that, say, Zoe Quinn is a genius game designer and an innocent victim of targeted harassment, not a horrid person who herself organized harassment mobs against people she disagreed with -- and is running into the problem of all that pesky evidence to the contrary getting in the way.

There are many more obvious reasons why someone might want to seize an archive domain without needing to delve into ridiculous gamer gate conspiracy theories.

Besides, stealing the domain doesn't delete any content on the servers.

Re: Someone is trying to steal archive.is's domain

#29
DNS Monitoring is a mandatory security requirement for anyone serious about DNS Security today. https://dnsspy.io is a good example of this.

Also, although I don’t think there is 100% agreement on this in the community, use LONG ttl’s. No reason to make yourself vulnerable by constantly reaching out to DNS every 5 minutes. Also makes you more likely to pick up a spoofing / hijacking attempt.

NOTE: also quick shout out to GCP here. I make all my money within AWS so if anything should not be saying this but there DNS security is amazing. They have DNSSEC + the crazy obscure records like IPSECKEY and TLSA and SSHFP. Wow.

Re: Someone is trying to steal archive.is's domain

#30

DNS Monitoring is a mandatory security requirement for anyone serious about DNS Security today. https://dnsspy.io is a good example of this. Also, although I don’t think there is 100% agreement on this in the community, use LONG ttl’s. No reason to make yourself vulnerable by constantly reaching out to DNS every 5 minutes. Also makes you more likely to pick up a spoofing / hijacking attempt. NOTE: also quick shout ou…

> use LONG ttl’s

It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.

Post reply on HN