(Not yet merged at time of posting.)
Context: Some forms of intentional malicious behavior have been observed.
(Not yet merged at time of posting.)
Context: Some forms of intentional malicious behavior have been observed.
Why should anyone give a damn about what any website doing, the purpose of onion mirror:
Other than this we dont get involved into what the others are talking about.
Merged.
archive.today running DoS, tampered with web snapshots, and drawing controversial attention. Not worth the trouble.
Provide evidence so the public can confirm, we cant just washout services based on claims. Otherwise we are committing injustice.
I see only like TV news bs (wikipedia), no practical confirmation of ddos or tampering.
Yes, and we care very, very, very much about the website giving the correct time. If a website operator does one thing malicious (and especially if they are at least moderately technically skilled), there is usually little reason to believe they wonāt do something else malicious in the future, such as giving intentionally wrong time values.
(Iāve also personally observed strange, semi-malicious misbehavior on archive.today, like being arbitrarily redirected to unrelated news sites when trying to solve a CAPTCHA to save a page, so I have very little trouble believing othersā reports of malicious activity.)
First we need to establish this as a fact, what malicious thing the website is doing that effects me as a user? without giving 123 method in order to check and verify then we are believing whatever blah being written on an online websites like wikipedia and others.
Although this is not malicious what so ever (and fixed), but here is a story: āsomeone hacked the server, the poor operator wasnt aware of it because his mother was sick and he was taking care of her until he noticed that and fixed it later.ā
So how can you prove this is a BS story without establishing real verified evidence? if you cant do that, then we cant give a conclusion based on BS stories done by xyz websites.
Note: For me im not defending the website itself (although i like an alternative to archive.org which deleted tons of important websites and ban many others), but im pointing out the idea of falling into government or people with agenda saying 123 on xyz then i blindly believe without verify?? thats a big problem, and happened in the past to harm many people and projects.. but this is a side discussion to mention them here.
DoS is also misbehavior. In this case, I believe the DoS concern is real, as I have personally validated it.
I do not think this is a good use of developer time. Fully researching this, following every related claim, and then writing detailed statements about which reports I agree or disagree with would take a disproportionate amount of time.
The tampering evidence [1] is also consistent with the operator conduct. The operator confirmed the DoS on their microblog on Tumblr [2] [3]. At the time, I read the statements myself and also saw the DoS JavaScript myself.
[1] Wikipedia:Requests for comment/Archive.is RFC 5 - Wikipedia
[2] https://blog.archive.today/
[3] https://archive-is.tumblr.com/
With that, I have already spent too much time on this issue.
Considering that argument for DoS and tamperingā¦
That is possible. But unless that becomes clear, and even if that turns out to be the truth, I do not think it changes the practical conclusion much. This is just 1 onion source out of dozens, and I do not think it is important enough to justify a deep investigation.
I will even grant that it is possible that the tampering evidence is completely fabricated, and that even the DoS I saw myself was misinterpreted.
In any case, I do not think more investigation here is a good use of developer time.
I do not think removing 1 controversial onion time source rises to the level of injustice.
Itās only 1 onion service. A deep investigation into every controversy around a single source would take too much developer time. If there were 10s of services with similar accusations, and we were running out of onion time sources, then it would be a different issue. But 1 onion being removed in a year or so due to such controversies is not a big deal.
Looking at the evidence itself:
There is a far bigger issue than that though:
Wikipedia does not treat archival efforts as authoritative, they are merely benevolent mirrors at best. I would suggest turning this entire topic around and distrusting alternative time sources in general, onion site or not, and if I had to tackle this convenience issue for the broader public, I would generate a consensus value that all current entriesā timestamps match at regular intervals, and anything inconsistent is permanently dropped.
Thats not called āVerifiable Evidenceā, thats just a written claim, but how to verify it? technical steps must be given and tested locally to see if it can reproduce the same results.
Think about the future, how many people can come forward with similar BS generated by xyz websites claims which i cant verify and they ask please remove this mirror or block this or that..
I hope i dont see such new BS like this.
I think if we want to continue this conversation, it would be best to do it in a new thread. This thread is mostly for users to suggest new time sources or removal of existing ones, and to log when sources are added or removed. Iād suggest that any extended-length conversation about the usefulness and safety of a time source should go in its own sub-thread so it doesnāt get lost.
That seems hypothetical and unlikely to me. Weāll cross that bridge when it comes to that.
Thats not called āVerifiable Evidenceā, thats just a written claim,
That level of evidence is difficult to attain. Iāve personally verified the archive.today DoS at the time and seen the attack code myself. But from a third party viewpoint, my personal confirmation also only collapses to a written claim and not verifiable evidence.
So how would a researcher even provide verifiable evidence? They could use screen sharing and record a video where they visit archive.today in a browser ā view source ā show the attack code. But screen sharing evidence may also be easy to fake nowadays. So use screen sharing plus 2 cameras viewing the monitor because multiple perspectives are quite harder to fake.
But even then itās not 100% reliable. Currently I am running whonix.org locally inside a local VM including functional TLS as a local reproduction stage server: using an ephemeral TLS certificate which is imported into the browserās TLS trust store. There is no visual difference from the website alone. Only browser console ā connections tab may show the different connection path. But even that can be faked with a MitM proxy if someone is motivated enough.
As written in the Wikipedia discussion:
You have no way of knowing if the content of the screenshots hasnāt been doctored, and no evidence that itās suitable for long term storage.
And thatās true. Itās not possible to archive archive.today using archive.org. All that will be archived is the captcha.
The evidence (DoS attack code) or archive tampering may also only be temporarily on archive.today.
So producing evidence admissible in a court of law is very difficult. In practice, law enforcement would likely engage an external computer forensics company. They would reproduce the issue, document their processes, write a report and perhaps even videotape their investigation. Then the court would likely trust that single party. Still, the evidence is imperfect, but unless the defense can show the forensics company to have a history of unreliability or corruption, the evidence would be admissible. Such investigations can easily cost tens of thousands of dollars.
Whonix isnāt an investigative / forensics outlet. Decisions have to be made within a limited amount of time and based on the information reasonably available. A leap of faith is required: that not everyone who reported this is lying, that this isnāt a huge conspiracy against archive.today, and that if it were, someone would likely point it out.
Well, considering how the situation has already developed, the argument is already in favour of removing Archive.today anyways, whether the entire narrative is technically genuine or not is no longer relevant. However, answering the question of verifying every other currently trusted source is a more difficult problem, which was the point I was highlighting. Constantly auditing each of them individually is expensive, whereas the consensus model permits only the majority to exist, but is susceptible to collusion/Sybil, which is why I am in favour of critically thinking beyond both implementations similar to how Wikipedia handles convenience links.
archive.todayrunning DoS, tampered with web snapshots, and drawing controversial attention. Not worth the trouble.
Thatās awful It was really useful in dealing with pages that archive.org canāt or wonāt crawl
Thatās awful It was really useful in dealing with pages that archive.org canāt or wonāt crawl
We can and should keep using it, the idea is about using it as a source for onion mirror.
archive.today still better than archive.org due to the fact it has no (government enforced) limitations bs.