Live data from Hacker News

Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

radar.cloudflare.com

141–150 of 351 posts

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#141
post #126

Earlier quoted context omitted.

So far, the only sin archive.today has been accused of is retaliating against a guy attempting to dox them. That's a pretty small sin in my book. To be written off as wildly unsuccessful but entirely justified self defense. DDoSing gyrovague.com is silly, not evil. The content on gyrovague.com which targets archive.today is evil, plain and simple.

archive.today has a documented history of altering the archived content, as such they immediately lose the veil of protection of a service of "public good" in my books. Just my 2 ¢, not that it really matters anymore in this current information-warfare climate and polarization. :/

> archive.today has a documented history of altering the archived content

Wow, I had no idea. Thanks.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#142

Earlier quoted context omitted.

I use cloudflare DNS because it’s faster. But should I worry, having read your comment? What is the downside to using it? What would you recommend instead?

Quad9. Many years ago I used Cloudflare, and more than once I had issues with them blocking websites I wanted to access. I absolutely despise that. I want my DNS to resolve domain names, nothing else. For blocking things I have Pi-Hole, which is under my control for that reason. I can blacklist or whitelist addresses to my needs, not to the whims of a corporation that wants to play gatekeeper to what I can browse.

So… why not use 1.1.1.1, cloudflare’s resolver that does not block resolution?

1.1.1.2 and .3 are explicitly offered with filtered responses.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#143

Earlier quoted context omitted.

Jani Patokallio who runs gyrovague.com published a blog post attempting to dox the owner of archive.today. Jani justifies his doxing as follows "I found it curious that we know so little about this widely-used service, so I dug into it" [1] Archive.today on the other hand is a charitable archival project offered to the public for free. The operator of Archive.today risks significant legal liability, but still offers…

Jani here. What you describe as "doxxing" consisted of a) a whois lookup for archive.is and b) linking to a StackExchange post from 2020 called "Who owns archive.today" [1]. There is literally no new information about the site's owner in the post, all names have been dug up before and are clearly aliases, and the post states as much. [1] https://webapps.stackexchange.com/questions/145817/who-owns-...

I don't see how this description changes the fundamental nature of your actions.

Even a half-assed attempt at doxing is still an attempt at doxing.

It'd be much easier to accept that you're acting in good faith had you deleted the post when it became obvious that the target doesn't appreciate it.

You could still do that, and it would very simply be the right thing to do.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#145

I think there are two angles to look at this. Yes, there’s the attack on the weblog. But there’s also pressure on archive.today, e.g. an FBI investigation [1] and some entity using fictitious CSAM allegations [2]. [1]: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tri... [2]: https://adguard-dns.io/en/blog/archive-today-adguard-dns-blo...

Jani Patokallio who runs gyrovague.com published a blog post attempting to dox the owner of archive.today. Jani justifies his doxing as follows "I found it curious that we know so little about this widely-used service, so I dug into it" [1] Archive.today on the other hand is a charitable archival project offered to the public for free. The operator of Archive.today risks significant legal liability, but still offers…

> It's weird to see people getting fixated on the DDoS, which is obviously far less nasty than actually attempting to dox someone.

Why even do that, then? Why not just make a public post of theirs like: "Hey, here's someone trying to doxx me, and here's the unfair and fictitious bullshit the lying government is trying to pin on me. Here's all the facts, decide for yourselves."

Why do something as childish as DDoSing someone which takes away any basic good will and decency/respect you might have had in the eyes of many?

That way, it'd also be way more clear whether attempts at censorship are motivated by them acting as a bad actor, or some sort of repression and censorship thing.

I don't really have a horse in this race, but it sounds like lashing out to one own's detriment.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#146
post #92

Cloudflare dns has gone back and forth on whether it wants to resolve them since 2019. It’s taken that away and restored it again (intentionally? mistake?) at least four times. The c&c/botnet designation would seem to be new though.

> Cloudflare dns has gone back and forth. Just tells me they are an unreliable resolver. Instead of being a neutral web infra, they actively participate in political agendas and censor things they "think" is wrong.

[flagged]

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#147
post #126

Earlier quoted context omitted.

archive.today has a documented history of altering the archived content, as such they immediately lose the veil of protection of a service of "public good" in my books. Just my 2 ¢, not that it really matters anymore in this current information-warfare climate and polarization. :/

> archive.today has a documented history of altering the archived content Wow, I had no idea. Thanks.

Archive.org has an even worse history of this, FWIW.

It allows website owners and third parties to tamper with archived content.

Look here, for example: https://web.archive.org/web/20140701040026/http://echo.msk.r...

Archive.today is by far the best option available.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#148

Earlier quoted context omitted.

1.1.1.2 is their malware-blocking DNS, and 1.1.1.3 is their parental-controls DNS. If you want an unfiltered DNS, use 1.1.1.1 - which resolves archive.today just fine, although archive.today itself refuses to work on Cloudlfare DNS.

I have no idea why anyone would use Cloudflare DNS, much less trust their more filtered versions.

Same thoughts. Cloudflare DNS is noticeably slow to resolve on some of my devices.

Switching to literally any other DNS and the same domains resolve instantly.

Could be a issue specific to my location or devices, but its been consistent enough that I stopped bothering.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#149

Earlier quoted context omitted.

I'm just curious, given all the other options that respect your privacy and don't put data collection at the center of their business model, why do you use Cloudflare on your pi-hole?

what is the vector here? dns traffic is practically anonymous, there would have to be some very specific and purposeful trickery going on to link dns traffic to an identity. It sounds like something more hypothetical than a tangible threat model

It isn't anonymous. DNS server resolve, IP addresses by hostnames. It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit.

Since ISP know your identity, and all it takes is to (request and get) the DNS logs and ISP servitude for all sort of questionable information, you as an identity are giving away all sites domains you visit.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#150
post #142

Earlier quoted context omitted.

Quad9. Many years ago I used Cloudflare, and more than once I had issues with them blocking websites I wanted to access. I absolutely despise that. I want my DNS to resolve domain names, nothing else. For blocking things I have Pi-Hole, which is under my control for that reason. I can blacklist or whitelist addresses to my needs, not to the whims of a corporation that wants to play gatekeeper to what I can browse.

So… why not use 1.1.1.1, cloudflare’s resolver that does not block resolution? 1.1.1.2 and .3 are explicitly offered with filtered responses.

Because that would be subject to the whim of the provider, who subject to court orders would have to oblige to continue operating as US entity.
Post reply on HN