13 ms·
Z-Library Returns on the Clearnet in Full Hydra-Mode
- politician 4y ago[flagged]
- Lacerda69 4y agoI wonder what they use to build this Hydra feature...
- heywhatupboys 4y ago[flagged]
- bhaney 4y agoZ-Library the book/article piracy project, not zlib the compression library
- heywhatupboys 4y agomy comment was a joke :(
- loeg 4y agoNo, Z-library is not related to zip or compression.
- userbinator 4y agoBut given how pervasive zlib is, it's probably used somewhere in its infrastructure.
- mikewarot 4y agoDomain names turned out to be a weak point susceptible to attack by the statists. To route around this weakness, an array of names is used. However, there is still the matter of having an account to get to these names. Which was the original reason the statists went after them in the first place. The users themselves will thus become the next target, just like in the days of Napster.
- fudgefactorfive 4y agoTo me that was the real strength in IPv6. (I know I know innefficient protocol with complex upgrade path lead to near negligible adoption) NAT "fixed" the problem of address exhaustion, but it killed the old internet. You cannot run your own network anymore. In the "old" times, I gave you a phone number or IP address and that's it, direct connection. All anyone could do was show up and take the computer to stop that. Sure there's a phone company or ISP involved, but they just powered the pump, you completely controlled what went through it. Now I can't do that. They ran out of addresses and I share an address with X unknown others. So I can't give you a home address, just to a bank of doors. I could give you an apartment number, but that's also shifting transparently, so num X to you is num Y to someone else. IPv6 would have solved the problem of exhaustion while preserving the right to an address. I could be some number permanently and you could reliably find a connection to my system using it. In that world I could set up a private DNS service in my house no one can alter without physically plugging in. Then have that store records to other addresses. Every part of that chain requires someone finding you and showing up at your door to disrupt. Instead now I have to pay digital ocean 5 bucks to keep an address for me so anything can find me via them. A bunch of servers in my home effectively an island without a coordinate until DO points me out on request. Like having all mail addresses be to the local town hall for them to forward to me. Sure maybe you trust your local town hall, but they are fundamentally beholden to someone else. With IPv6 support and adoption a whole network could be set up independent of any other authority besides BGP. Which requires nation-state levels of mobilization just to block an address, with fallout affecting literally thousands of others. They'd have to nuke a block to suppress any site, only for that site to find another address and be back to normal within minutes. Instead they do a WHOIS, send a scary email and boom, you're unknown, unfindable and disconnected. Hoping that word of mouth brings people to your new "address" exactly like losing your phone (and SIM) while abroad. I know it sucks as a protocol but v6 to me is a massive extremely important development that would change how the internet, and from that all communication, works.
- Steltek 4y agoThat title is straight out of a cyberpunk novel.
- user3939382 4y agoLet’s keep iterating on the takedown evasion strategies until they’re impenetrable. It’s the only hope the People have of actually being in control of anything important.
- unsupp0rted 4y ago> It’s the only hope the People have of actually being in control of anything important. Well I wouldn't go that far. There are more $5 wrenches than there are people. https://xkcd.com/538/ https://xkcd.com/538/
- user3939382 4y agoYep, aka rubber-hose cryptanalysis. The real test here was Assange who embarrassed the U.S. military by publishing drone footage of them killing civilians not to mention everything else. They got him on an individual level (IMHO by blatantly discarding any remaining vestigial pretense of abiding by the law) but-- the site is up.
- wkat4242 4y agoThe site is up but it's no longer what it once was. It's disappeared from news reports. Nor has another one taken its place. After the prosecution of Assange and Manning and with Snowden in exile, they've mandated to basically stop the whole whistleblower phenomenon in its tracks. Which was probably a bigger goal than one easily-replaced website. It feels a bit like the Arab spring, a lot of hope in the beginning and then it all fizzled out.
- JetSpiegel 4y ago> Nor has another one taken its place. Yes it has, the spook-friendly Bellingcat. It filled a Wikileaks-shaped hole.
- deleted 4y ago[deleted]
- 4y ago
- in_vestor 4y agoELI5 why the gov doesn’t just seize the servers.
- sudosysgen 4y agoThey're not in a country that wants that to happen.
- irrational 4y agoWhich government? Where are the servers located? Whose jurisdiction? Are all the servers in the same place?
- dragonwriter 4y ago> ELI5 why the gov doesn’t just seize the servers. Because “the government” is not a single unitary global institution.
- deleted 4y ago[deleted]
- Infernal 4y ago...yet
- kergonath 4y agoHow could it be? Why would countries like China, Russia, or Thailand align with the US on that subject when they clearly have no interest in doing so? Being overly cynical sounds good to some people, but it does not result in an accurate understanding of how the world works.
- martin1975 4y agoThe desire for control will unite even philosophically disparate governments. Pay attention.
- irrational 4y agoI tried it. The url I got looked like guid.domain.net. At first I was thinking that the guid part must be unique for every user, but then the domain.net part is still susceptible to being seized. So… without being able to compare the url I got with other people, I’m left wondering how this actually works.
- deleted 4y ago[deleted]
- BHSPitMonkey 4y agoFTA: "The domain names in question are subdomains of newly registered TLDs that rely on different domain name registries." There are multiple TLDs/SLDs involved (and the pool will likely grow over time)
- dkjaudyeqooe 4y ago> domain.net part is still susceptible to being seized Yes it is, but how do you discover the domains? There could be just a few hundred users per domain. Then you have to expend substantial effort to seize each domain. Meanwhile any affected user just moves to their second domain. Even if the authorities got much better at taking down domains the only issue would be increasing the number of extra domains per user. I can't see how the authorities can beat this.
- stevenhuang 4y agoI had to use https://singlelogin.me/ https://singlelogin.me/ for it to generate the special domain, so can't the central https://singlelogin.me/ https://singlelogin.me/ domain be seized at some point?
- esposm03 4y agoFrom the article: > If users can’t access the universal login page, Z-Library says they can log in through TOR or I2P and get their personal clearnet domains there.
- 4y ago
- oseityphelysiol 4y agoHow did they take it down the domain last time? Was it by picking on the registrar? In my country they so this by asking all the ISPs to block the domain from their DNS servers. This works for 90% of the population, but all you have to do is just change the DNS server to something other than what the ISP gives you and you’re good to go. Also, I just don’t get how current approach is any better. As far as I understand, there’s still a single point of failure, i.e. the site you get your “personal” domain from.
- jocaal 4y agoyou can get the personal domain from tor and then use the domain on the regular net.
- EarlKing 4y agoI'm honestly shocked no one has openly laughed themselves silly at the idea of "personalized domains" for a site openly engaging in piracy... because surely that wouldn't be a way to build a stronger case against individual users engaged in piracy, riiiiiight?
- braingenious 4y agoI have heard of people using throwaway emails and VPNs for this sort of stuff!
- hellotomyrars 4y agoDepends. If the database that contains those domains and the account they are linked to is obtained by whatever law enforcement agency gets them, than sure. But the network of torrent piracy detection doesn’t work for this situation so it requires that database to be seized. It is also possible the information is not stored after it is processed. Because copyright trolls can’t get the information like they do with torrents either, they can’t easily send bullshit threatening notices to end users, and it is extremely doubtful that the FBI is going to provide linking information for individual prosecution. I don’t believe there is any example of that, though I’d be interested to hear otherwise.
- super256 4y agoWhat's the difference between Library Genesis and Z-Library? Aren't they the same catalogue?
- IronWolve 4y agoz-library uses a freemium model, a for-profit model.
- droopyEyelids 4y agoDo you have evidence they make a profit or are you smearing the way they accept donations into “a for-profit model”
- kergonath 4y agoLast time I tried, they prevented me from downloading a 6th ebook unless I paid. That’s a bit more aggressive than “accepting donations”.
- crtasm 4y agoI don't defend them pushing for payment but did you not also have the options of A: waiting 24hrs then downloading it. B: registering an account to get 20 downloads per day ?
- kergonath 4y agoI saw that today (and created an account); I don’t remember it was like that when I used it last time but I could well be wrong, it was a couple of years ago. Sure, you could wait 24 hours or get a new IP address and clear cookies to bypass the limitation altogether. I cannot say how much money they did with this, but that’s the definition of freemium.
- IronWolve 4y agofreemium is a for profit model, the model has nothing to do if they make a profit.
- 0xDEF 4y agoWhy did they go so hard after Z-Library when all of the other Library Genesis mirrors are still up and running? Is it because Z-Library have ads and paid subscriptions while the others are non-profit volunteers?
- xdfgh1112 4y agoThey have limited resources, better to go after the one getting 99% of the traffic.
- hellotomyrars 4y agoZ-lib has more content than lingen and was more well known and had more traffic.
- gwbrooks 4y agoSo where does one go to log in and be redirected to their personal domain?
- dkjaudyeqooe 4y agoThey give you your domains when you log in on Tor.
- deedree 4y agoPer the Torrenfreak article: https://singlelogin.me/ https://singlelogin.me/ to login on Z-lib
- aborsy 4y agoI don’t know what’s the solution to this problem, but this library is extremely useful. Most of the time, you don’t want to read the books entirely, but mostly to check something, read a section or browse see if what you’re looking for is there. Eventually, you may buy a book that you know is worth it. Right now even the table of contents may not be available before buying.
- ChewFarceSkunk 4y ago[dead]
- jrochkind1 4y agoAre people making money off of z-library, or is it being run purely out of principle/generosity, or what?
- musicale 4y agoI'd expect enterprising bad actors to upload malicious PDFs and rent out compromised machines. Site operators could potentially re-render uploads and inject their own exploits.
- redtriumph 4y agoAnyone has any links or good intro videos about what is Hydra-mode? Reading through the article, it seems the domain name is not publicly exposed and a new domain (?) is created on-the-fly? I am not sure if I understand how it works. But every user who logs in with a inter-mediator would get his own domain and that's their strategy to keep shop open for now.
- danaos 4y ago> Anyone has any links or good intro videos about what is Hydra-mode? Probably just a reference of Greek mythology. You chop one head, two grow. An analogue of spawning multiple domains a site is taken down. https://en.wikipedia.org/wiki/Lernaean_Hydra https://en.wikipedia.org/wiki/Lernaean_Hydra
- userbinator 4y agoLater versions of the Hydra story add a regeneration feature to the monster: for every head chopped off, the Hydra would regrow two heads. The crucial line in that article; amusingly enough, it almost reads like a changelog entry.
- braingenious 4y agoI’m so happy to see this available to everybody! Z-lib is definitely in my top 5 favorite websites of all time.
- kristianp 4y agoWhere do these books come from in the first place? Have publishers systems been leaked/hacked?
- mardifoufs 4y ago> Where do these books come from in the first place? Have publishers systems been leaked/hacked? Most of zlib is libgen, and I think libgen relies on user uploads and sourcing from their forums
- labster 4y agoIn the first place, the books come authors who write words based on what a muse or ChatGPT tells them.
- kristianp 4y agoTouché
- archon1410 4y agoLibrary Genesis has an "Upload" button on the top bar, the common login and password for which can be found from simple a Google search. They might also run more organised scanning/sourcing operations on their forums.
- jephdo 4y agoAt least in torrenting communities a lot of these books come from book databases like OverDrive. Most public libraries give access to OverDrive and removing DRM is straightforward
- ilaksh 4y agoDumb question.. how do I find the URL?
- gustavorg 4y agodump answer: you ask a dump question. You can start somewhere around https://singlelogin.me/ https://singlelogin.me/
- mike_mg 4y agowait, aren't "they" going to gather evidence on user of "my account" and associate the downloads from this domain to "me" and come after me and ask hard questions?
- pradn 4y agoCurrent shadow libraries (zlib, libgen, scihub) suffer from centralized data hosting and opaque librarians/custodians (who modify metadata and gate inclusion/exclusion of content). We already have the tools to solve this. 1. Files are stored in a distributed fashion and referred to via their content hash. We already have IPFS for this. 2. Library metadata can be packaged up into a SQLite DB file. The DB would contain IPFS hashes, book names, authors, etc. 3. Teams of volunteers assemble and publish the library metadata DB files. There can be multiple teams, each with their own policies. The latest library files can be published via RSS. Each team can have their own upload portal. 4. A desktop app can pull multiple RSS feeds for multiple libraries. The libraries can be combined together and be searched easily on the client side. Users can search for content via the latest library metadata files, locally on their desktop. Content can be downloaded via IPFS. 5. The desktop app can also double as an IPFS host, allowing users to choose specific files to pin or simply allocate an amount of space for the purpose (100 GB, etc). There could also be servers that aggregate pinning info to make sure no gaps are there. 5. For ease of access, people can run websites that preclude the need to setup your own desktop app / download libraries. 6. Library teams can publish metadata DBs and content via torrents, too, for long-term/disaster-recovery/archival purposes. This would be a true hydra. No one centralized team, no reliance on DNS. If one team's library set up goes down, you can use another's.
- dark-star 4y ago1. yes, ipfs could solve that, but it relies on people hoting content. Previous examples of content-based addressing showed that little-accessed content tends to disappear as nodes go offline over the years. This would need to be solved, and I think the only way to solve it is to have a battery of centralized ipfs servers mirroring each other, which defeats the "fully distributed" setup 2. this would also need to be hosted and could be taken down. You'd need to mirror this too, but that's a simpler problem to solve (gigabytes instead of terabytes) 3. the upload portals and the RSS feeds would, again, be centralized or would have to change so regularly that they become impractical in the end you would end up with a dozen (a hundred? more?) different z-libraries, which would make it actually worse from a preservation standpoint, since only the most popular content would be shared, libraries that focused on rare/exotic/fringe material would be endangered of being lost since they have fewer volunteers/mirrors/seeds/... Also, freenet and other projects already showed that end-users allocating some storage and using that to spread data around is not an easy problem, the fluctuation in end-nodes is so big that it slows down the entire network to a crawl. I'm not sure this problem has been solved yet.
- grapesurgeon 4y agoi frankly dont see what on earth this actually does. when users sign up, their account gets hooked up with a randomly generated subdomain for some domain that 1lib.(some tld). what fundamentally makes it harder for domains to be revoked like the 200 or whatever that were revoked before? i dont think it would be that hard for lawyers to just generate a bunch of fake accounts, take note of the domains and report them. or even better just go after the singlelogin.me domain
- voldacar 4y agoHow are they able to afford so many domain names? And what stops the state from just asking the domain registrar for the details of who purchased the domains? Besides, there are only so many domain registrars in the world, eventually you will lose the ability to purchase new domains And if the actual web server is behind a service like cloudflare, the state can just ask cloudflare for the IP of the real server, then ask the datacenter who owns the server at IP x ...
- Run_DOS_Run 4y ago>what stops the state from just asking the domain registrar for the details of who purchased the domains Some domain registrars don't ask for your personal data and the registrars who ask for it won't verify them. >then ask the datacenter who owns the server at IP x ... Many datacenters in China and Russia doesn't care about some warez and if the zlib staff pays over Tor with cryptocurrencies the datacenter also don't know who rents the server
- x-desire 4y agoUsers don't actually get a personalized domain for each account, only a subdomain.
- mr-pink 4y agopeople think z-library is good because it gives access to everyone, but really it gives more access to those who have capital to use the content to train AI.... it's very foolish
- lofaszvanitt 4y agoHow does this affect book sales? Do average people know this site exists and depend on it, or mostly the tech savvy types frequent zlib? A site like this could be a godsend, but what about the authors? I can see the benefit of this if it would have a lead time of let's say T+1 years (assuming that the first year is most important for sales and not sales over time).
- kovac 4y agoI can't speak for all categories of books, but here's an actual author's opinion on the matter for text books: http://from-a-to-remzi.blogspot.com/2014/01/the-case-for-free-online-books-fobs.html?m=1 http://from-a-to-remzi.blogspot.com/2014/01/the-case-for-fre...
- __turbobrew__ 4y agoThis seems like a worse system than just using Tor. What is the point in making the system available on clearnet? I think it is more work to go to the single sign on, create an account, and save the custom domain names than just installing the tor browser and going to the zlib onion address?
- 2Gkashmiri 4y agoyou are using your existing login so you just have to use singlelogin as a gateway.
- account42 4y ago> Z-Library’s very existence was put to the test last November when U.S. law enforcement seized over 200 domain names connected to the site. From the list: > 1lib.ae > 1lib.in > 1lib.io > 1lib.mx > b-ok.as > b-ok.cc > booksc.eu > booksc.me How does U.S. law enforcement get to seize domains under other countries' ccTLDs? Were the respective countries involved or did they just bully the operators who probably have name servers in the US? And seizing domains is questionable in the first place - there isn't anything illegal about the domains itself and shouldn't the name -> IP association fall under free speech in the US?
- mattymf 4y agoThey also had a similar response to Telegram banning their bot: Each user gets their own personal Telegram bot.