Live data from Hacker News

Let us serve you, but don't bring us down

blog.archive.org

181–190 of 255 posts

Re: Let us serve you, but don't bring us down

#181

There's no reason for Archive.org to allow any traffic from AWS, Azure or Google Cloud. Archive.org should just block the CIDRs for all those networks. Most traffic that comes from them is scraping traffic and usually malicious.

Some users have virtual desktops in the cloud. Or use browser security sandboxes that run in the cloud.

"Sorry we cannot support your network" The needs of the many outweigh the needs of the very few...

Re: Let us serve you, but don't bring us down

#182
post #156

Earlier quoted context omitted.

Would it be possible to use bitcoin pow as a replacement for captcha? It both blocks ddos and create an income through mining (client side) for the host.

No. In fact, using such a well-known proof of work function would defeat the purpose of using PoW. Instead of having something that's cheap for occasional users but expensive for spammers, you'd have something that's cheap for people who own mining ASICs and expensive for occasional users. Hardware specialization breaks the economics behind a CAPTCHA. To fight that you need to use a PoW that hasn't been ASIC'd yet, a…

> cheap for people who own mining ASICs and expensive for occasional users.

Seems like it should be the same cost (barring the friction of having a wallet, etc.) for both sets of people since Bitcoin is just a commodity and the value is the same to everyone, miner or not.

For example, a miner should value some fraction of a BTC the same way anyone else does, since they can sell or buy it at the same price a normal user can. The fact that they can profitably mine BTC just means they have a profitable business on the side, it doesn’t mean they should prefer to pay for services (or emails) in BTC.

Re: Let us serve you, but don't bring us down

#183
post #126

Earlier quoted context omitted.

hCaptcha's accessibility model seems quite good to me: https://www.hcaptcha.com/accessibility

I disagree. To "solve" their CAPTCHAs I had to register by providing a working email address. I don't encounter HCAPTCHA problems that often, so when I need to solve a new one usually my cookie has expired and I have to reopen the link to get a new one before being able to continue. I just store such links in my password manager, but imagine you have to find an email with the link they sent you over a year ago before…

Good points

Re: Let us serve you, but don't bring us down

#184
post #67

I just wonder, is archive.org getting any government grant money? If they aren't they should. And I'm not even talking about just the US. All sorts of countries (US, UK, Germany - to name the few) and international organisations like EU pour hundreds of millions into "cultural projects" of very questionable value. How about they actually fund something really worthy of preservation? Of course it is archive.org role t…

There are various underfunded digital archives in the EU and elsewhere that have legal duties to preserve online content relating to their specific countries. They may be "of very questionable value" to you but your solution to remove funding from them to channel it to a much wealthier organisation in a wealthier country is neither ethical, legal or practical.

I think he or she rather meant some other cultural projects than digital archives.

There are indeed lots of cultural projects that get funding, that I consider not that important in comparison, but of course those people involved would think different. (Opera for example is heavily subsidized)

Re: Let us serve you, but don't bring us down

#185

https://support.aws.amazon.com/#/contacts/report-abuse It should teach them a lesson to have their AWS account banned.

For actual spammers this won't do much. You can create a new account with a new email and presumably use one of those gift cards for payments (or use Apple wallet to regenerate card numbers).

Re: Let us serve you, but don't bring us down

#186
post #107

Earlier quoted context omitted.

Proof-of-work was originally introduced by Adam Back's hashcash, to fight email spam. Bitcoin is an evolution of that idea applied to digital cash. https://en.wikipedia.org//wiki/Hashcash

no, this is incorrect. Proof of Work was invented by Moni Naor and Cynthia Dwork in 1992 as a proposal to fight email spam. https://www.wisdom.weizmann.ac.il/~naor/PAPERS/pvp.ps

Pretty sure my second-grade teacher invented it. Writing "I will not talk while the teacher is talking" 100 times on the chalkboard is proof of work, and it definitely cut down on unwanted chatter.

Re: Let us serve you, but don't bring us down

#187
post #159

Earlier quoted context omitted.

Be careful with that. A friend once did something similar to an active scraper who then went off and set his site up for a full blown DDoS. He knew that was the reason for the intentional DDoS due to messages (along the lines of “think it is funny to poison my information do you?”) in the query string of the bulk requests. Like unpleasant fools making a big noise in shops because they aren't served immediately after…

That's fair. Perhaps a middle-ground of poisoned answers that look like overload related errors. Though I did have success once stopping hot-linked images by serving up images that didn't fit well with the sensibilities of the internet forum that was hotlinking them. It had the advantage of looking like the people in the forum posting had deliberately chosen to post the image. Serving different images depending on cl…

> Serving different images depending on client ip made for fun too, as they argued with each other about why they posted "that".

Evil. I like it.

Re: Let us serve you, but don't bring us down

#188
post #67

I just wonder, is archive.org getting any government grant money? If they aren't they should. And I'm not even talking about just the US. All sorts of countries (US, UK, Germany - to name the few) and international organisations like EU pour hundreds of millions into "cultural projects" of very questionable value. How about they actually fund something really worthy of preservation? Of course it is archive.org role t…

There are various underfunded digital archives in the EU and elsewhere that have legal duties to preserve online content relating to their specific countries. They may be "of very questionable value" to you but your solution to remove funding from them to channel it to a much wealthier organisation in a wealthier country is neither ethical, legal or practical.

This is almost completely unresponsive to what parent actually wrote.

Re: Let us serve you, but don't bring us down

#189

Earlier quoted context omitted.

There are various underfunded digital archives in the EU and elsewhere that have legal duties to preserve online content relating to their specific countries. They may be "of very questionable value" to you but your solution to remove funding from them to channel it to a much wealthier organisation in a wealthier country is neither ethical, legal or practical.

I think he or she rather meant some other cultural projects than digital archives. There are indeed lots of cultural projects that get funding, that I consider not that important in comparison, but of course those people involved would think different. (Opera for example is heavily subsidized)

Opera the theater or Opera the web browser?

Re: Let us serve you, but don't bring us down

#190
post #67

I just wonder, is archive.org getting any government grant money? If they aren't they should. And I'm not even talking about just the US. All sorts of countries (US, UK, Germany - to name the few) and international organisations like EU pour hundreds of millions into "cultural projects" of very questionable value. How about they actually fund something really worthy of preservation? Of course it is archive.org role t…

Government money would risk making them dependent on it, which would reduce their ability to be self sustainable and independent, which risks becoming political. Best avoided if possible.
Post reply on HN