Live data from Hacker News

Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

radar.cloudflare.com

241–250 of 351 posts

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#241
post #208

Earlier quoted context omitted.

what is the vector here? dns traffic is practically anonymous, there would have to be some very specific and purposeful trickery going on to link dns traffic to an identity. It sounds like something more hypothetical than a tangible threat model

I did some experimenting recently and I'm quite convinced that when I use Comcasts DNS they are selling it to advertisers. I've switched to 1.1.1.1 simply because it annoys me that Comcast is doing this.

How could that experiment work?

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#242
I, for one, completely trust Cloudflare on this one. The guys running a MiTM attack on a substantial chunk of all global internet traffic, and working tirelessly to ensure billions of people behind CGNAT in the global south can't access the free and open web are the premiere experts on malicious, predatory, harmful internet-scale network behavior, after all.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#243
post #70

A bit context if you are confused why Public DNS server blocking websites. 1.1.1.2 is Malware blocking DNS server similar to AdBlock DNS server. It is not 1.1.1.1 and 1.0.0.1 Here is the DDoS context https://gyrovague.com

And for parents: 1.1.1.3 blocks adult content :)

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#245
post #238
post #235

Earlier quoted context omitted.

Does the Great Cannon of China coordinate the attacks? Does archive.today? Hijacking a software like the browser is something completely different to a simple JS on a website.

> Does the Great Cannon of China coordinate the attacks? Yes. > Does archive.today? Yes.

How does archive.today coordinate the attack?

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#247

Earlier quoted context omitted.

It isn't anonymous. DNS server resolve, IP addresses by hostnames. It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit. Since ISP know your identity, and all it takes is to (request and get) the DNS logs and ISP servitude for all sort of questionable information, you as an identity are giving away all sites domains you visit.

[flagged]

I didn't mean to offense. It did seem OP didn't get the IP can be logged, either that or how an IP can reveal identity.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#248
post #79

Earlier quoted context omitted.

Should providing a public service absolve all sins?

So far, the only sin archive.today has been accused of is retaliating against a guy attempting to dox them. That's a pretty small sin in my book. To be written off as wildly unsuccessful but entirely justified self defense. DDoSing gyrovague.com is silly, not evil. The content on gyrovague.com which targets archive.today is evil, plain and simple.

By this logic, the Code Green worm is ethical; forcing a security patch upon users who didn’t install one is obviously Not Evil. And that’s why operating systems aren’t wrong to force security updates on their users using invisible phone-home systems that the users aren’t aware of: it’s a small sin that is entirely justified self defense for the users and the device maker. Clearly we should all be updated to iOS 26 without our consent.

The ‘small sin’ of wielding your userbase as a botnet is only palatable for HN’s readers because the site provides a desirable use to HN’s readers. If it were, say, a women’s apparel site that archived copies of Vogue etc. (which would see a ton of page views and much more effective takedown efforts!) and pointed its own DDoS of this manner at Hacker News, HN would be clamoring for their total destruction for unethical behavior with no such ‘it’s just a evil for so much good’ arguments.

Maintaining ethical standards in the face of desire for the profits of unethical behavior is something tech workers are especially untrained to do. Whether with Palantir or Meta or Archive.today, the conflict is the same: Is the benefit one derives worth compromising one’s ethics? For the unfamiliar, three common means of avoiding admitting that one’s ethics are compromised: “it’s not that bad”, “ethics don’t apply to that”, and “that’s my employer’s problem”. None of those are valid excuses to tolerate a website launching DDoS attacks from our browsers.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#249
post #175

Earlier quoted context omitted.

It isn't anonymous. DNS server resolve, IP addresses by hostnames. It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit. Since ISP know your identity, and all it takes is to (request and get) the DNS logs and ISP servitude for all sort of questionable information, you as an identity are giving away all sites domains you visit.

> It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit. Correction: they can log host names/IPs, not URLs. The path of any given URL is part of the HTTP header, invisible to onlookers (assuming HTTP and assuming HTTPS is uncracked).

I can't edit. That is correct. URLs can't be known to a DNS server. Just the hostname and IP.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#250
post #205
post #132

Earlier quoted context omitted.

> why do you use Cloudflare on your pi-hole? Because "if it ain't broke, don't fix it." i'm not one of those users who want to endlessly tweak their ad blocker. i want to set it up, clicking as few checkboxes as necessary to get it going, and then leave it. However, (now) knowing that Cloudflare filters different only each of their servers, i'm incentivized to go tweak a number in the config (as opposed to researchin…

If you mean you had 1.1.1.2 as a secondary, and don't want it to have a different configuration, you can use 1.0.0.1 along with 1.1.1.1 instead.

> If you mean you had 1.1.1.2 as a secondary, and don't want it to have a different configuration, you can use 1.0.0.1 along with 1.1.1.1 instead.

i had no clue which one was active. It was, for me, just a checkbox at the time. This thread prompted me to go check and tweak appropriately.

Post reply on HN