When somebody requests an article, Sci-hub will try and see if it already has it. If not, it will attempt to use some of the donated credentials to gain access, download it and store it for further download requests.
When somebody requests an article, Sci-hub will try and see if it already has it. If not, it will attempt to use some of the donated credentials to gain access, download it and store it for further download requests.
I'm neutral on the matter, but there are some obvious paths of recourse for publishers who don't want people sharing their credentials.
(Disclaimer: I work for Crossref, which is an organisation in the scholarly publishing space.)
I'm asking because a friend of mine who's enrolled in 2 colleges, just downloaded the same scholarly PDF (one that's also available through sci-hub) with 2 different college credentials and they had the same sha256sum.
Then when he tried it through sci-hub, he also got the same sha256sum.
Sorry if my disclaimer wasn't clear. I was just pointing out affiliation as standard on HN.
Storing the documents on Sci-hub controlled machines also makes sure that repeated requests don't actually hit the publishers, which significantly lowers what would otherwise be suspiciously high traffic.
As for geographic location, academics tend to travel a lot. Last I heard (from reading the court docs in Elsevier's lawsuit against Sci-Hub), they stopped using proxy connections a few years ago. They just log in using stored credentials, grab an auth token that lasts X minutes/hours, and download articles from whatever IP is convenient.
We do keep logs for a period of time, but the library administration's policy is to only investigate them when a publisher contacts us with a claim of abuse (we do not proactively monitor for unusual activity, although we do take steps like limiting the number of concurrent sessions per user and blacklisting IP addresses/ranges with a history of suspicious activity).
The publisher generally supplies examples of timestamps and URLs that were part of the alleged abuse. We use that information to identify the "abusing" user in the log.
Usually there is pretty clear evidence that the user is not conducting legitimate personal research (e.g. the user is a freshman early childhood education major at the local rural branch campus, but they're downloading thousands of chemistry papers from an IP address in China or Russia). Typically the user does not seem like an information freedom warrior, or even to have a clue what is going on, so it seems most likely the credentials were phished.
These cases may or may not be phishing. When corporations are hacked for their user credentials, those databases sometimes end up in dark web markets. It would be easy to extract email addresses with .edu domains ... so if a student used their university address for some service and reused the password, there's your login.
Moral of the story: Encourage students to use a password manager and 2FA.