Live data from Hacker News

Our investigation into the suspicious pressure on Archive.today

adguard-dns.io

381–390 of 473 posts

Re: Our investigation into the suspicious pressure on Archive.today

#381

I speculate, and the conspiracy theorist in me believes, something of a compromising nature has been archived and they want that data inaccessible, but at the same time, pointing out what they want hidden would shine a light on it. It is even more interesting the US government is coming after archive.today at the same time, or maybe that is just a coincidence, and this is just a tech-savvy philanderer trying to hide…

Like a genocide? Or maybe various statements of politicians and events around and related to Ukraine, elections, Epstein, and any number of hot button topics, especially as the writing is on the wall that populations all around the West are starting to get extremely fed up?

I know for a fact that political classes of several European countries have started openly talking about destroying evidence if they lose power and America just declared Antifa a terrorist organization; that all seems to be a plausible motivation.

Re: Our investigation into the suspicious pressure on Archive.today

#383
post #206

Earlier quoted context omitted.

Someone asked the archive.is owner why he does this in the past. It's because of similar situations to this one where someone who wants to get archive.is taken down uploads illegal content, requests archive.is to save it, and immediately reports archive.is to their country's legal authorities. His solution to this is using the EDNS information to serve requests from the closest IP abroad, so any takedown procedure re…

> Even if you're worried about other people sniffing network traffic, the hostname you're visiting still gets revealed in plaintext during the SNI handshake Many sites now support Encypted Client Hello. This makes it possible to send the hostname after the connection has been encrypted. This is enabled by default on cloudflare hosted domains (when cloudflare also manages DNS).

There was a report some years ago that found the IP address being connected to is often enough to identify the website being visited, even when using a CDN. I think you have to go to VPNs at a minimum, or Tor preferably. Tor doesn't help with correlation attacks from global passive/active adversaries though, or even folks with access to a lot of netflow data.

Re: Our investigation into the suspicious pressure on Archive.today

#384
post #379

Earlier quoted context omitted.

You misunderstand the situation and what I was suggesting. GP was saying that AdGuard should have checked the contents of some random URL supposedly containing CSAM on archive.today. This is not AdGuard’s job. Knowingly downloading CSAM is very likely illegal. And it also potentially opens them up for additional liability if they do determine that CSAM is present. AdGuard seems like they did exactly the right thing,…

> Knowingly downloading CSAM is very likely illegal. Put CSAM in a banner ad, and arrest everyone who was served that ad? Post a CSAM photo behind plexiglass on a wall in a public space, and arrest everyone who walks by and glanced at it? Just how stupid do you think lawmakers, judges, prosecutors, and police are? People get arrested for paying for, or sharing CSAM, not just stumbling on a website that might have som…

https://www.merriam-webster.com/thesaurus/knowingly

You even quoted the word...

Re: Our investigation into the suspicious pressure on Archive.today

#385
post #379

Earlier quoted context omitted.

You misunderstand the situation and what I was suggesting. GP was saying that AdGuard should have checked the contents of some random URL supposedly containing CSAM on archive.today. This is not AdGuard’s job. Knowingly downloading CSAM is very likely illegal. And it also potentially opens them up for additional liability if they do determine that CSAM is present. AdGuard seems like they did exactly the right thing,…

> Knowingly downloading CSAM is very likely illegal. Put CSAM in a banner ad, and arrest everyone who was served that ad? Post a CSAM photo behind plexiglass on a wall in a public space, and arrest everyone who walks by and glanced at it? Just how stupid do you think lawmakers, judges, prosecutors, and police are? People get arrested for paying for, or sharing CSAM, not just stumbling on a website that might have som…

Arrests aren't the only way a company can be harmed. Being flagged or investigated is enough of a legal burden and reputational hit that it could be catastrophic. "Stumbling" is not a part of any network protocol. Over a network, viewing a link is indistinguishable from downloading its contents.

Re: Our investigation into the suspicious pressure on Archive.today

#386
If an opaque actor can fabricate legal-ish complaints and pressure DNS providers into blocking a site, the system is wide open for abuse. Smaller services without legal teams would just fold.

Curious if others are seeing this kind of “shadow regulation” pop up more frequently elsewhere — especially in email filtering, CDN layers, and AI content moderation.

Re: Our investigation into the suspicious pressure on Archive.today

#387

How can you even sue without any legal identity? This website and an organisation does not happen to have any. Might as well be some shell company in the Carribeans with no legal standing in France. It's not even good enough for public prosecution, as the tip would then go through French services. This law is completely backwards, and worse than a SLAPP. If you cannot respond to a report in any way, it should be null…

In the U.S., “John Doe” is typically used when cannot (yet) identify the person to name as a defendant. Once the case is filed then the plaintiff can execute the necessary subpoenas to identify the defendant specifically.

See here: https://en.wikipedia.org/wiki/Doe_subpoena

Re: Our investigation into the suspicious pressure on Archive.today

#388
1. I am confused, did copyright holders not amused by archive.today etc, intentionally serve CSAM material when they detected a visitor was in fact archive.today scraping one of their pages? It seems they are on the hook for more than just "inaccurate reporting of CSAM materials".

2. Is it a legally allowed tactic for copyright-luvva's to intentionally seek out CSAM content online, and then submit those URL's to sites like archive.today? Which entity is at greater legal peril, the one that aids the distribution of CSAM materials by intentionally having a site like archive.today archive CSAM content, or archive.today unintentionally being tricked into archiving CSAM content?

3. Everyone has traumas, of one kind of another. Each deals or tries to deal with them in their own way. Suppose a victim of crimes (still unpunished) finds or is informed of the presence of evidence online, and suppose this victim (regardless of how representative) finds the preservation of this evidence more important than the humiliation associated with it, how (in)just are laws that blanket suppress CSAM material? To give a more vigorous example: imagine you were raped by some no-yet-fallen UK nobility, and you are made aware of the presence of this evidence on some royal FTP server (or whatever), and you succeed in having archive.today "notarize" this evidence (independently from legal channels, since theres a suspiciously low amount of nobility being convicted, in contrast to your personal experience). These rules for supressing CSAM can be wielded as a sword precisely against those who fell prey to perpetrators...

Re: Our investigation into the suspicious pressure on Archive.today

#389
post #299

Earlier quoted context omitted.

Out of curiosity, does ArchiveBox integrate some way of verifying the contents of the archived page(s) are legitimate and unmodified?

ArchiveBox open source does not, but I have set it up for paying clients in the past using TLSNotary. This is actually a very hard problem and is not as simple as saving traffic hashes + original SSL certs (because HTTPS connections use a symmetric key after the initial handshake, the archivist can forge server responses and claim the server sent things that it did not). There is only 1 reasonable approach that I kno…

If web pages were signed the way emails were, it would authenticate if an archived copy of a web page is indeed authentic, but good luck getting such a major change all the way across the entire web. Why would anyone who would gladly retract / redact information on a whim even subscribe to this technology? Would be nice if they all did though.
Post reply on HN