9 ms·
Archive.today's attack on https://gyrovague.com https://gyrovague.com is still on-going btw. It started just over two months ago. Some IPs get through normally
by stuffoverflow 6mo ago
Archive.today's attack on https://gyrovague.com https://gyrovague.com is still on-going btw. It started just over two months ago. Some IPs get through normally but for example finnish residential IPs get stuck on endless captchas. The JS snippet that starts spamming gyrovague appears after solving the first captcha.
- winkelmann 6mo agoI'm not a web developer, but I've picked up some bits of knowledge here and there, mostly from troubleshooting issues I encounter while using websites. I know there are a number of headers used to control cross-site access to websites, and the linked blog post shows archive.today's denial-of-service script sending random queries to the site's search function. Shouldn't there be a way to prevent those from running when they're requested from within a third-party site?
- deleted 6mo ago[deleted]
- JasonADrury 6mo ago[flagged]
- throwingcookies 6mo ago> The blog is still online and only exists as a part of a harassment campaign targeting archive.today The blog has a lot of more posts on random topics. Why do you imply that the owner of the bloh is part of a harassment campaign and "only" that is the reason for this years old blog to exist?
- JasonADrury 6mo agoBecause all the content in the past 4+ years is about archive.today?
- winkelmann 6mo ago> all the content in the past 4+ years is about archive.today But it's not? This was published between the two posts about archive.today: https://gyrovague.com/2025/02/23/anatomy-of-a-boarding-pass-how-to-detect-fake-flight-tickets-by-scammers/ https://gyrovague.com/2025/02/23/anatomy-of-a-boarding-pass-...
- JasonADrury 6mo agoOkay, there's one filler post I missed. I'm sure it took a lot of time to write the 16739382nd post explaining what the various things on a boarding pass mean.
- ahhhhnoooo 6mo agoThey have posted twice in four years. Once doing some digging into who runs archive today, and a second time to respond to a ddos attack. Writing about being ddos'd seems eminently reasonable. So if you elide that, you are talking about a single article in four years. It's genuinely nothing.
- deleted 6mo ago[deleted]
- JasonADrury 6mo agoThe purpose of a thing is what it does.
- throwingcookies 6mo ago> The purpose of a thing is what it does. What is the purpose of the DDoS JS in the archive website then? Not DDoS?
- JasonADrury 6mo agoI'm sure it's DDoS, just like the purpose of gyrovague.com is to attack archive.today Easy stuff, no?
- 47282847 6mo agoOne side publishes words, the other DDoSes. One side could just ignore the other and go about their business, the other cannot. One is using force, which naturally leads to resistance and additional attention, the other is not. Both sides look like they have been bullied in the past and not found their way out of reproducing the pattern yet.
- croes 6mo agoWords can have bad consequences. We‘ll see what will happen to Banksy after Reuters published words.
- JasonADrury 6mo ago[flagged]
- 47282847 6mo agoWords can have influence and can come from a place of authority, which does carry responsibility. Words of a president are very different from words published on a random blog by some random person, and different yet again from words published by a newspaper. Some presidents words are opinion, the same words in different context are commands and not acting on them comes at a price. Context matters. Which is why also different rules apply, and laws exist to guard these rules. DDoS is not an acceptable response in any jurisdiction, no matter what triggered them. We’re not in the Middle Ages, even if some behave like we are. Violence does not justify violence. Unjust action does not justify unjust responses.
- longislandguido 6mo agoYou think DDoS (which is illegal btw) is okay as long as you don't like the target?
- RobotToaster 6mo agoHarassment an doxing are both illegal.
- hrimfaxi 6mo agoDoxxing is illegal? I am against it but if it's republishing public info I don't think it can be illegal in the US unless there is an intent element.
- RobotToaster 6mo agoThe blog author is in Finland, so it's covered by the Article 8 right to privacy of the ECHR. The exact implementation is country dependent, I don't know how it works in Finland but in the UK we just extended the common law tort of "Breach of confidence" to it.
- hrimfaxi 6mo agoThat is very surprising to me. As far as I know, in Finland details of your income are publicly available, but someone reposting publicly available information is illegal.
- JasonADrury 6mo ago[flagged]
- DaSHacka 6mo agoConsidering the site itself is an illegal archive of websites, I think its obvious most of us don't treat what's 'legal' as a guide to whats 'moral'.
- riedel 6mo agoWhile I would it also better to a bit redact names and details mentioned in the original article in hindsight, I hardly find real defamation. I guess you want to provide random unproven evidence if someone is target of various foreign law enforcement and commercial sites. In the article they even call for donations to archive.today . As far as I read the tone of the post is full of admiration. Funny thing is that IMHO the rather childish JavaScript attack gives credibility to the post after all. In all this I somehow hope that we see a legal solution to all this major global copyright crisis that has been reinforced by LLM training. (If you want conspiracy theory: that I guess would be easy monetization for archive these days selling their snapshots)
- JasonADrury 6mo agoDefamation? No. Doxing? Yes. It's clear that the person running archive.today does not actively publicize their identity. > As far as I read the tone of the post is full of admiration Exactly like an unhinged fan stalking a celebrity.
- riedel 6mo agoTotally agreed. Thanks for raising awareness. Thinking about it, I think we might need better platform rules, maybe even regulations on this. There seems to be pretty much no line of defense, which might explain the rather desperate DoS. If you take anonymity as a right, discussion like ours here on HN are dangerous as well, as they easily make otherwise difficult to find knowledge easily visible. So while a single fan page might go unnoticed, in case of doxing amplification is also a problem. Just my spontaneous thought. Edit: one afterthought. The story about hacking together a response to the GDPR takedown request quoting press rights and freedom of speech using an LLM shows actually the deeper problem. Actually rights come with obligations (at least ethical ones). At least in Europe press standards are typically rather aware of doxing risks. While actually celebraties also successfully use legal defenses, i still think the defenses for activist are weak balancing interest here (at least if you made something of public interest)
- sheept 6mo agoYou can't completely prevent the browser from sending the request—after all, it needs to figure out whether to block the website from reading the response. However, browsers will first send a preflight request for non-simple requests before sending the actual request. If the DDOS were effective because the search operation was expensive, then the blog could put search behind a non-simple request, or require a valid CSRF token before performing the search.
- bawolff 6mo ago> I know there are a number of headers used to control cross-site access to websites Mostly these headers are designed around preventing reading content. Sending content generally does not require anything. (As a kind of random tidbit, this is why csrf tokens are a thing, you can't prevent sending so websites test to see if you were able to read the token in a previous request) This is partially historical. The rough rule is if it was possible to make the request without javascript then it doesn't need any special headers (preflight)
- throwingcookies 6mo agoWhy is archive today attacking that website?
- nailer 6mo agoThe linked blog contains a story about who funds archive today and they presumably don’t like being exposed.
- throwingcookies 6mo agoThanks. I am so confused by this social drama, I feel like I am getting too old for this.
- ryandrake 6mo agoIt’s truly weird and unhinged the extent to which two rando Internet People are willing to grief each other.
- throwingcookies 6mo agoParasocialweb 2.0 I suppose.
- VERIRoot 6mo agowell that exposing is hurting more than 2 for sure
- JasonADrury 6mo ago[flagged]
- drum55 6mo agoShould providing a public service absolve all sins?
- 6mo ago
- riedel 6mo agoWhile you article is insightful. Can the blog author please redact the actual names and nicks from your orginal blog post (including the exact places where to find the information). As this was discussed below. While I think you had good intentions, but it might be good to also reflect on the rights of that person not be identified. Edit: I misread the comment initially as from someone with more insight. However, I guess it is obvious that anyone can see the JavaScript and participates involuntarily in the DoS.
- Anonyneko 6mo agoI've been getting the endless captcha on my Finnish residential IPs, but I've also been getting that (or outright timeouts) when using VPNs, so I cannot use the site altogether. I wish there were alternatives.
- dawnerd 6mo agoI get the endless captcha with a Southern California ip. Something emus either very broken or malicious.
- zahlman 6mo agoTo be clear, if I have JavaScript blocked for archive.today (which is my default with NoScript; and really there is no site functionality that really needs JS on the user's end), then I don't participate in the DDOS, right?