Live data from Hacker News

Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

radar.cloudflare.com

231–240 of 351 posts

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#231
post #184
post #182

Earlier quoted context omitted.

The browsers of their site visitors.

If you need to be on the site it’s not a botnet and there is no C&C server coordinating the attack. It‘s just the JS on the site that makes the attack.

> If you need to be on the site it’s not a botnet

Why? I did not visit the site to participate in a DoS attack; yet my machine was coaxed into participating against my will. Whether this is happening in JS or a drive-by download or a browser 0-day is irrelevant.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#232
post #9

Earlier quoted context omitted.

Why? It’s accurate and if the owner has chosen to do this for months now, why should we ever trust they won’t again? Nobody should ever use that site and every optional filter should block them.

There's probably a worthwhile discussion to be had about what it takes for a site in this situation to be removed from blocklists. An apology? Surrender to authorities? Halting the malicious activity for a certain period of time? Regardless, another user reports the attack is still ongoing[1], so this isn't a discussion that's going to happen about archive.today anytime soon. [1] https://news.ycombinator.com/item?id=…

If there was an apology it could be considered, depending on the apology (i.e. is it earnest?). But so far that does not seem to happen.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#233

I think there are two angles to look at this. Yes, there’s the attack on the weblog. But there’s also pressure on archive.today, e.g. an FBI investigation [1] and some entity using fictitious CSAM allegations [2]. [1]: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tri... [2]: https://adguard-dns.io/en/blog/archive-today-adguard-dns-blo...

Jani Patokallio who runs gyrovague.com published a blog post attempting to dox the owner of archive.today. Jani justifies his doxing as follows "I found it curious that we know so little about this widely-used service, so I dug into it" [1] Archive.today on the other hand is a charitable archival project offered to the public for free. The operator of Archive.today risks significant legal liability, but still offers…

Don't use my computer to DDoS others please. That's nastier than the shallow post of that article.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#234

I think there are two angles to look at this. Yes, there’s the attack on the weblog. But there’s also pressure on archive.today, e.g. an FBI investigation [1] and some entity using fictitious CSAM allegations [2]. [1]: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tri... [2]: https://adguard-dns.io/en/blog/archive-today-adguard-dns-blo...

I suppose an argument can be made that archive infringes copyright. Hell I use it to circumvent paywalls.

So, if that's the case we can get all frontier provider sites marked as such as well?

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#235
post #211
post #184

Earlier quoted context omitted.

If you need to be on the site it’s not a botnet and there is no C&C server coordinating the attack. It‘s just the JS on the site that makes the attack.

Does this mean that the Great Cannon of China is not a botnet because it stops working when you close your browser?

Does the Great Cannon of China coordinate the attacks?

Does archive.today?

Hijacking a software like the browser is something completely different to a simple JS on a website.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#236

Earlier quoted context omitted.

As far as I am aware, all previous issues with archive.today and Cloudflare were on account of archive.today taking measures to stop Cloudflare's DNS from correctly resolving their domains, not the other way around. The current situation is due to Cloudflare flagging archive.today's domains for malicious activity, Cloudflare actually still resolves the domains on their normal 1.1.1.1 DNS, but 1.1.1.2 ("No Malware") n…

For context, archive.today is angry that Cloudflare won't pass through EDNS - which includes things like your IP address, which archive.today explicitly wants for DNS-based geographical routing. The obvious problem with this is that it would deanonymize all 1.1.1.1 users, at least down to their ISP and probably down to the individual subscriber.

[deleted]

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#237
post #184

Earlier quoted context omitted.

If you need to be on the site it’s not a botnet and there is no C&C server coordinating the attack. It‘s just the JS on the site that makes the attack.

> If you need to be on the site it’s not a botnet Why? I did not visit the site to participate in a DoS attack; yet my machine was coaxed into participating against my will. Whether this is happening in JS or a drive-by download or a browser 0-day is irrelevant.

You did participate in archive.today’s DDoS without visiting the site?

How if it‘s JS code in the site?

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#238
post #235
post #211

Earlier quoted context omitted.

Does this mean that the Great Cannon of China is not a botnet because it stops working when you close your browser?

Does the Great Cannon of China coordinate the attacks? Does archive.today? Hijacking a software like the browser is something completely different to a simple JS on a website.

>Does the Great Cannon of China coordinate the attacks?

Yes.

>Does archive.today?

Yes.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#239

Earlier quoted context omitted.

No, I do not keep any logs from domain name resolution from the DNS service I used from 7+ years ago. If you do, I commend you. I used the term "blocking" in a loose sense. I have no idea if Cloudflare was failing to resolve certain domains because it is a shitty service, or if it was ordered to block those domain names by its government, or if it was actively not resolving domain names because it thought a good idea…

> I have no idea if Cloudflare was failing to resolve certain domains because it is a shitty service, or if it was ordered to block those domain names by its government, or if it was actively not resolving domain names because it thought a good idea to be a sort of arbiter and gatekeeper. I'm going to go with option D) whatever shitty site you were browsing to had a broken DNS or more likely DNSSEC configuration and…

> I'm going to go with option D) whatever shitty site you were browsing to had a broken DNS or more likely DNSSEC configuration and Cloudflare was correct to not serve a corrupt response.

And once I switched DNS I could browse it normally.

This does not align quite well with the scenario you propose.

> "they're blocking my site! you guys are nazis!"

I said no such thing. I said it was a shitty DNS because it failed at the thing I was trying to use it for.

Post reply on HN