10 ms·
Archive.today is directing a DDoS attack against my blog
- NedF 8mo ago[flagged]
- JasonADrury 8mo ago[flagged]
- Bender 8mo agoTheir admin is a member of HN but I've never seen them reply to these threads. [edit] Perhaps they could share their perspective on what has been done thus far to mitigate the problem.
- JasonADrury 8mo agoWhat would they possibly say? I don't think one should explicitly have to ask to not be doxed for performing a public service. What gyrovague is doing here is obviously despicable.
- Bender 8mo agoI would imagine their technical perspective of what is happening and what attempts were made to mitigate it thus far. That is where the HN audience could chime in. If they have the resources I suspect they do then just about every option is on the table though assisting them may get people on some lists for assisting the Russian Federation. It's also not clear to me who is attacking who here.
- JasonADrury 8mo ago"Gyrovague", the author of the post we're commenting under has for reasons unknown engaged in targeted harassment of the owner of "archive.today". Now the owner of archive.today is attempting a rather lazy DoS attack against gyrovague.com. A rather mild response to gyrovague attempting to bring the archive.today owner physical harm by spreading potentially identifying information about them. There's really very little to be said about this whole thing besides that Gyrovague should try to be a less awful person in the future.
- Bender 8mo agoLike I said, I can't tell who is attacking who. Archive.is has more money, resources and ASN's than Akamai so surely they can mitigate anything anyone can throw at them. A little forum trying to respond in kind can't really be much of a threat. Archive could just tell their controlling nodes to ignore any requests to mirror the forum which means there is a lot more to this than any of us are seeing. That is why I would like to see the admin of Archive respond for both sides of the story.
- JasonADrury 8mo agoI don't think there's any dispute on what the story is. The blog post here contains the facts, and a rather clumsy attempt by Gyrovague to justify his bid to dox the operator of archive.today. > Archive.is has more money, resources and ASN's than Akamai I assume this is a joke, but Archive.is is a shoestring operation funded through donations.
- Bender 8mo agoI assume this is a joke, but Archive.is is a shoestring operation funded through donations. I am certain they would like people to think that. They have more IPv4 addresses under more ASN's than Akamai control which anyone who has tried to block them would know. Their controlling ASN's are in the Russian Federation which they make no attempt to hide at least for now and why I must assume they are fine with people discussing it. The GDP of the Russian Federation is somewhere north of 2 trillion dollars. Their nodes both in Russia and spread all around the world would not be permitted by Russia to mirror random sites without authorization to do so. One in or from Russia would not defy Russian leadership for very long.
- JasonADrury 8mo agoYes, it's apparently hosted behind some fastflux setup. That's neither new nor special, nor is it particularly expensive. Such setups are offered on various forums starting from a few hundred dollars a month. > Their nodes both in Russia and spread all around the world would not be permitted by Russia to mirror random sites without authorization to do so. This is simply not true. You can absolutely run a website like this in Russia without any authorization. Who would you even ask? The whole idea is bizarre.
- chrisjj 8mo ago> Their admin is a member of HN Citation needed.
- justsomehnguy 8mo ago[flagged]
- ZenDroid 8mo agoOTOH, after trying to conquer Finland in 1939-1940 Russians definitely have no moral right to judge Finns.
- gyrovague-com 8mo agoOP here. I obviously registered to post my own blog entry. You might also want to read your own link: https://en.wikipedia.org/wiki/Siege_of_Leningrad#Finnish_participation https://en.wikipedia.org/wiki/Siege_of_Leningrad#Finnish_par...
- JasonADrury 8mo agoFinland did send hundreds of people to be murdered in Nazi concentration camps.
- gyrovague-com 8mo agoNo, it did not. Unless you count the Soviet POWs who were murdered in Stalin's gulags. https://en.wikipedia.org/wiki/History_of_the_Jews_in_Finland#World_War_II https://en.wikipedia.org/wiki/History_of_the_Jews_in_Finland...
- JasonADrury 8mo agoNo, Finland handed both jewish and non-jewish Soviet POWs to Germany. Hundreds of people sent from Finland to Germany died in the camps. Finland also deported multiple jewish refugees to Germany, these people were neither Soviets nor POWs. https://journal.fi/haik/article/view/139103/86888 https://journal.fi/haik/article/view/139103/86888 Yes, sure, Finland had it's own complicated reasons for behaving the way it did. There's however no serious dispute about whether or not Finnish collaboration in the holocaust happened.
- 8mo ago
- its-summertime 8mo agopreviously https://news.ycombinator.com/item?id=46624740 https://news.ycombinator.com/item?id=46624740
- dang 8mo agoMacroexpanded: Ask HN: Weird archive.today behavior? - https://news.ycombinator.com/item?id=46624740 https://news.ycombinator.com/item?id=46624740 - Jan 2026 (69 comments) I cannot make head or tail of this but it's more fascinating than the usual internecine bloodbath.
- neonate 8mo agoSee also https://archive-is.tumblr.com/post/806832066465497088/ladies-and-gentlemen-in-the-autumn-of-2025-i https://archive-is.tumblr.com/post/806832066465497088/ladies... also Archive.today: on the trail of mysterious guerrilla archivists of the Internet - https://news.ycombinator.com/item?id=37009598 https://news.ycombinator.com/item?id=37009598 August 2023
- parable 8mo agoThere are several other posts made recently on the archive.is blog as well, some of which appear to be quite nonsensical or are otherwise irrelevant to the discourse at hand. They all appear to be LLM-generated. It's all very confusing.
- deleted 8mo ago[deleted]
- deleted 8mo ago[deleted]
- snailmailman 8mo agoInterestingly, theres an account in that thread claiming to be from Gyrovague, but its not the same one thats in this thread, which has been confirmed to be legit as it is mentioned by name in this latest Gyrovague article. I wonder, is the newer gyrovague-com account because they lost the login for the old one? or was the old one a different person? Hopefully they can clarify, because if there's an account pretending to be them that makes this story even more confusingly weird.
- deleted 8mo ago[deleted]
- archagon 8mo agoWhy is this flagged? Given the content, I find this suspicious.
- dang 8mo agoI looked at the flags and they seem to be legit flags from legit users. My guess is that they thought this was below-the-radar drama that wasn't on topic for HN. (I could make a "people who flagged X also flagged" list a la https://news.ycombinator.com/item?id=46771900 https://news.ycombinator.com/item?id=46771900 to support the point, but it's a time-consuming pain so I'd rather not!) Edit: after looking at this more closely, I have a counterintuitive (to me at least) take: I think this is interesting enough to transcend the usual categories. That is, we'd normally downweight this kind of post off the frontpage - but in this case there are so many unusual variables that the usual rules don't apply. I say this despite having zero clue what's going on here. We do have a nose for what the HN community might find interesting (we'd bloody well better after doing this job for so long), so let's override the flags and see what happens. But without relitigating WWII please.
- golfer 8mo agoThis is definitely interesting and HN-worthy. If nothing else, archive.today links are posted on tons of HN submissions, so it's topical.
- dang 8mo agoI agree - it's clear that archive.is / archive.ph / archive.today / who-knows-what-else has been a lubricant in many HN threads, letting people read things they otherwise couldn't, and that increases the interest of the topic. I suppose I should add that we prefer archive.org links when they're available, but often they aren't. Edit: I suppose I should also re-add that we have no knowledge of or opinion about what's going on in the dispute at hand.
- chrisjj 8mo ago> we prefer archive.org links when they're available Interesting. May we know why?
- Shank 8mo agoIt is academically very interesting to think about this in light of their long-standing dispute with Cloudflare (https://community.cloudflare.com/t/archive-is-error-1001/18227 https://community.cloudflare.com/t/archive-is-error-1001/182...) over EDNS, which could have privacy implications attached. I think no matter how you slice it though, it's unethical and reprehensible to coordinate (even a shoddy) DDoS leveraging your visitors as middlemen. This is effectively coordinating a botnet, and we shouldn't condone this behavior as a community.
- qmarchi 8mo agoIt's definitely interesting to see this roll around since the only individuals that see the CAPCHA page mentioned, are users of Cloudflare's DNS services (knowingly or not). P.S. Shout-out to dang for dropping the flags. I have a small suspicion that their may be some foul play, given the contents...
- greyface- 8mo ago> the only individuals that see the CAPCHA page mentioned, are users of Cloudflare's DNS services I don't think this is true. I run my own recursive DNS resolver, and get a CAPTCHA when visiting archive.today.
- k33l0r 8mo agoI use my ISP's default DNS servers and have consistently gotten the CAPTCHA page for weeks now. The CAPTCHA seems to be broken too, rendering archive.today entirely inaccessible.
- Hamuko 8mo agoSomeone has suggested that CAPTCHA is broken for everyone in Finland.
- cluckindan 8mo ago
- deleted 8mo ago[deleted]
- deathanatos 8mo ago… seems like we the HN community should find a new site to mirror with.
- mr_mitm 8mo agoThere isn't one. As far as I know, no one really knows for sure how they bypass all these paywalls. (Most credible theory I heard: They actually just pay for the subscriptions.)
- chrisjj 8mo agoWhat's your problem with that theory?
- blenderob 8mo agoHas people's ability to read messages and formulate sensible replies been going down of late? I see this kind of meaningless replies more and more often these days.
- direwolf20 8mo agoYes, there's a global intelligence crisis, due to tiktok instagram et al
- chrisjj 8mo agoMeaningless? Its a clear question.
- PKop 8mo agoYou're accusing him of having a problem with it, which his comment does not imply.
- mr_mitm 8mo agoNone
- 8mo ago
- deaux 8mo ago> Well, I wish I had one, but at this stage I really don’t. The most charitable interpretation would be that the investigative heat is starting to get to the webmaster and they’re lashing out in misguided self-defense. I don't think they're lashing out in self-defense. This is a harmless way for them to get attention, which is what they're desparate for because the FBI is after them at the behest of Bezos and other billionaires who control the paywalled media and don't like archive.today's role in making them accessible. The only thing that could possibly save them (though it almost certainly won't), is gathering as many eyeballs as possible from the people who like the service. HN having a super high concentration of those. Almost every paywalled post here has an archive.today link in the comments. That's also why they posted about it on HN, explicitly under that name. To get HN eyeballs. It's intentionally harmless because, as you confirmed, it's not costing you any money or resources.
- opengrass 8mo agogyrovague-com: posted this thread, claims to own the blog gyrovague: claimed to own the blog in the last thread rabinovich: posted last thread linking to gyrovague.com, identifying the owner as... well... "Masha Rabinovich" I believe these accounts are all connected.
- gyrovague-com 8mo agoOP here. As the blog publicly states, this account is Gyrovague, and so is HN "gyrovague". I have nothing to do with "rabinovich" but I also have no way of proving a negative.
- Bengalilol 8mo agoYou could specify that you wrote it on the last line of the post, so it clears up any basic speculation. <https://gyrovague.com/2026/02/01/archive-today-is-directing-a-ddos-attack-against-my-blog/ https://gyrovague.com/2026/02/01/archive-today-is-directing-...>
- opengrass 8mo agoFrom now on you rabies will sign off here and the blog with PGP or you're bullshitting.
- Bengalilol 8mo agoI do believe the opposite, although I feel that rabinovich is somehow tied to other personas. This thing is blurry, shady and I hope it will draw some more OSINT eyes on it. I am now curious.
- deleted 8mo ago[deleted]
- EdiX 8mo agoWhy does this say it's been posted 8 hours ago but on hn.algolia.com is archived 2 days ago, also I'm sure I already saw it yesterday.
- JasonADrury 8mo agoThis is a regular HN feature where admins resurrect old posts that did not get the attention they maybe deserved.
- techpulse_x 8mo ago[flagged]
- xvokcarts 8mo agoWhy were you trying to dox the archive owner?
- jdiff 8mo agoThis is misrepresentative of the situation, and an unloaded version of the question being asked here is answered within the article itself.
- JasonADrury 8mo agoHow is it misrepresentative of the situation?
- protimewaster 8mo agoBecause none of the names are real and they were all already posted publicly previously. This is covered in the article.
- JasonADrury 8mo agoWe don't know that none of the names are real. And even if they aren't, the article is still showcasing his failed attempt at doxing the owner of archive.today and providing a starting point for anyone else wanting to try. > they were all already posted publicly previously Doxing very often consists of nothing more than collecting data from a bunch of public sources
- protimewaster 8mo ago> Doxing very often consists of nothing more than collecting data from a bunch of public sources I simply don't agree that this looks like doxing. No addresses or even any private information were reported. It's just a Google using WhoIs data and, in one case, the person said, in a public forum, that archive.is is "my website." Why would they have said that if they were worried about people finding out who it belongs to? If they'd have stumbled upon an address to a private residence and reported that, sure, that would look like doxing. I just don't see it here.
- rsaarelm 8mo agoArchive.today does not seem to have worked for people connecting from Finland since mid-January, it just gives an endless captcha loop. Is this related to whatever this drama is?
- parable 8mo agoIt seems that the website has been blocked in Finland since at least August of 2023, see https://news.ycombinator.com/item?id=37011955 https://news.ycombinator.com/item?id=37011955.
- Hamuko 8mo agoI definitely used it from Finland last year. It was blocked some time in th past since the owner was mad at Finnish authorities, but at some point that was revoked. Even the post you linked acknowledges this: >he blocked the entire site in Finland, although later he lifted the block
- parable 8mo agoMy apologies, I clearly missed that. If I could edit my post, I'd change it to "It seems that the website has been blocked in Finland in the past, though the block was later lifted."
- Hamuko 8mo agoI’d give it a high probability, especially when the CAPTCHA loop is the bit of the site that causes the DDoS and the fact that the admin seems to consider all Finns nazis.
- Stagnant 8mo agoI would assume so. I can see from my browser history that i succesfully submitted captures to archive.today on 7th of January, but failed to do so starting from 12th of January. IIRC they contacted gyrovague around the 10th so seems unlikely to be a coincidence. Applies to VPNs as well. Tried first with a VPN located in Finland and it gets endless captcha loop, then with a Swedish VPN which let me through to the front page after solving one captcha.
- parable 8mo agoThis likely means nothing, but the .is webmaster seems to have some sort of existing issue with Finland (where gyrovague is from), see https://news.ycombinator.com/item?id=37011955 https://news.ycombinator.com/item?id=37011955. I thought I would point it out. Also, as someone interested in OPSEC and OSINT as a hobby, I find the measures taken by the .is webmaster, especially the dedication to setting up countless fake accounts for each persona, to be very intriguing. I spent about an hour looking into the Nora Puchreiner persona and all the accounts registered to it that I could find. It appears that "Tomas Poder" is another alter-ego used by the .is administrator. Nora also seems to have a sister: "Sara Puchreiner". Again, all very interesting and I can't seem to make a clear picture of the situation.
- cluckindan 8mo agoThere are multiple reports of these archive.something sites redirecting users to Russian sites. Personally, I stopped using them after I saw one connection attempt to yandex dot ru
- ada0000 8mo agoIn UK, was redirected to russia today. Cannot recall which domain(s).
- buzer 8mo ago> Finland (where gyrovague is from) They should probably review existing case around how Finnish courts treat the journalistic exception in the context of citizen's journalism (as he relied on that at least as one of the reasons): https://tuomioistuimet.fi/hovioikeudet/ita-suomenhovioikeus/fi/index/hovioikeudenratkaisuja/i-sho20245.html https://tuomioistuimet.fi/hovioikeudet/ita-suomenhovioikeus/... Of course facts are different, but at least two Finnish court seem to require a lot more reasoning from the controller in the context of citizen journalism compared to traditional media when they want to invoke the journalistic exception. No clue which side this would fall into.
- soultrap 8mo ago> I find the measures taken by the .is webmaster, especially the dedication to setting up countless fake accounts for each persona, to be very intriguing. This seems like a smart thing to do if you had exposed your real name somewhere and wanted to cover it up.
- m132 8mo agoIt's a puzzling situation: - The DDoS was certainly unethical and unneeded - Although the blog post only shows an extremely one-sided version of the story by skipping straight to the threats, there are reasons to think that diplomacy has also failed terribly - The website owner has all eyes of the "thought police" on them, and given the current political situation in Russia, it's more than likely they reside somewhere where it has real power; realistically speaking, who wouldn't be losing it? - The blog post is preserving information that could aid further investigations even if purged from the original sources, and reveals non-OSINT information in the follow ups - At the same time, it's, to say the least, hypocritical of the archive.today owner to attempt forcefully taking the original post down, when archive.today itself is an OSINT tool I don't think there's a way to fairly untangle this mess anymore. Hence, I'd focus on the possible outcomes: do we want archive.today taken down over this? Who would lose and who would benefit the most from this takedown?
- gyrovague-com 8mo agoGyrovague here. As linked in the blog entry, you can view both sides of the email correspondence here: https://pastes.io/correspond https://pastes.io/correspond As for outcomes, I'm very much a bit player/spectator in this drama, nobody's going to be "taking them down" over DDOSing an obscure nerd blog. If they do go down, it'll be the FBI or equivalent, and it will be publicly justified as some combination of "protecting the children" (cf. WAAD) and/or copyright violations.
- m132 8mo ago> As linked in the blog entry, you can view both sides of the email correspondence here: https://pastes.io/correspond https://pastes.io/correspond Thanks, I must have missed this. > [...] nobody's going to be "taking them down" over DDOSing an obscure nerd blog. > If they do go down, it'll be the FBI or equivalent, and it will be publicly justified as some combination of "protecting the children" (cf. WAAD) and/or copyright violations. Yes, this is exactly what I fear. That we might be playing into the hands of the greater evil by escalating a small, personal conflict.
- gettingoverit 8mo agoWhatever is going on here, is so magnificently complicated: sockpuppeting, doxxing, ddosing, psyops, pirating, FBI, cyberpunk capitalists, Russian hackers and Finnish activists. Somehow it does feel like in the middle of information war.
- wolvoleo 8mo agoWhen I read the original article it doesn't really feel like the Finnish guy is even an activist. He seems to be just a curious nerd who wrote one article about this topic (who's behind this big site that everyone uses) and about a whole load of completely unrelated and non-activist topics like why did Japan stop building subway lines. Then his blog gained some traction because of the reporting around the FBI threats. The article is also really appreciative of archive.today. It doesn't feel like a hit piece at all.
- JasonADrury 8mo ago>The article is also really appreciative of archive.today. It doesn't feel like a hit piece at all. That's why it's all so bizarre. The OP claims to be supportive of archive.today, but simultaneously publishes an article detailing his attempt at doxing the owner. It's hard to see how OP could be acting in good faith here, if they truly meant no harm and were as appreciative of archive.today as they claim to be, they'd just have taken down the article.
- navigate8310 8mo agoInterestingly, this website exists in badmojr-1Hosts-master-Pro-adblock list
- karel-3d 8mo agoThat's explained in the article itself
- Ms-J 8mo agoArchive sites are very important for freedom due to many different entities out there attacking sites and getting them taken down. Unfortunately Archive.today complies with these attack requests in some situations, but is still usually better than others.
- ValdikSS 8mo ago>Unfortunately Archive.today complies with these attack requests in some situations, but is still usually better than others. Use Onion version :D
- Ms-J 8mo agoThanks so much for the tip. Placing the link for others: archiveiya74codqgiixo33q62qlrqtkgmcitqx5u2oeqnmn5bpcbiyd.onion Fingers crossed that it works!
- blell 8mo agoI reported a few times to the owner of archive.is/archive.today that he was hosting dox of a friend and he never cared. So, too fucking bad that he's the one getting doxxed now. A bit of karma.
- acureau 8mo agoYep, I have heard of many such cases and I know someone affected personally. For someone who refuses to take down the personal information of others this is extremely hypocritical.
- karel-3d 8mo agoI feel bad for the archive.is guy/girl. It's clear the doxxing attempts are getting closer now to his/her real identity. On the other hand, they do something that's really useful to so many, and it will be sad if it's gone.
- direwolf20 8mo agoIsn't that the same hand twice?
- 8cvor6j844qw_d6 8mo agoRegardless, archive.today does fine with some sites that blocks archive.org archiver somehow. Thank you for keeping this up, whoever you are.
- chrisjj 8mo ago> somehow robots.txt. It is that simple.
- geetee 8mo agoMy tinfoil guess is archive.today is compromised by a state actor. Simply shutting it down would cause too much drama. Instead turn it into villain, and then take it down.
- j45 8mo agoTemporarily see if you can put the blog behind a cloudflare or something using their DNS service.
- pietervdvn 8mo agoStupid question, but CORS is designed explicitly to defend against this type of side-surf attack. Adding a strict cors policy should fix this, or am I missing something?
- VTuberTTV 8mo ago[dead]
- deathanatos 8mo agoNot here, though. The exact code: fetch("https://gyrovague.com/?s="+Math.random().toString(36).substring(2,3+Math.random()*8),{ referrerPolicy:"no-referrer",mode:"no-cors" }); "no-cors" means the request will not be preflighted, but also that JS will be denied access to the body. But the body doesn't matter here — the attack only requires the request be sent. But more to the point, so long as the request meets the requirements of a "simple request", CORS won't preflight it. GETs qualify as a simple request so long as no non-CORS-safelisted headers are sent; since the sent headers are attacker-controlled, we can just assume that to be the case. In a non-preflighted request, the CORS "yes, let JS do this" are just on the response headers of the actual request itself. Since GETs are idempotent, the browser assumes it safe to make the request. CORS could/would be used to deny JS access to the response. Things are this way b/c there are, essentially, a myriad of other ways to make the same request. E.g., <img src="https://gyrovague.com/?s=…"> in the document would, for all intents and purposes, emit the same request, and browsers can't ban such requests, or at least, such a ban would be huge breaking change in browsers.
- deleted 8mo ago[deleted]
- what-if 8mo ago[dead]