Someone is trying to steal archive.is's domain
twitter.com
twitter.com
Also, although I don’t think there is 100% agreement on this in the community, use LONG ttl’s. No reason to make yourself vulnerable by constantly reaching out to DNS every 5 minutes. Also makes you more likely to pick up a spoofing / hijacking attempt.
NOTE: also quick shout out to GCP here. I make all my money within AWS so if anything should not be saying this but there DNS security is amazing. They have DNSSEC + the crazy obscure records like IPSECKEY and TLSA and SSHFP. Wow.
It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.
Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again this is debatable advice but worth considering. All of the major cloud providers have GeoIP Blocking or are rolling it out.
What is a user supposed to do when a random website blocks him because it uses an outdated database?
That is terribly shortsighted. I'm located long way away from many tiny shops I'm using for presents for friends and family. Local gov's published development plans are likely interesting to foreign investors. There are many other cases surely...
You could literally take public transit across Reykjavik and go knock on the door of the persons responsible.
My guess is that they are using a virtual business address service that is commonly used by spam/fraud organizations (e.g., fake pharmaceuticals), and maybe ISNIC is cracking down on this due to abuse. They don't want their TLD to be known as a junk TLD like .ck, .gq, .info, etc. Or someone is attempting to take legal action against the owner of the domain and ISNIC can't comply because they just have a fake address with no known physical entity.
Disclaimer: building https://namebase.io which is a registrar for seizure-resistant names on the Handshake blockchain.
Seriously, though, imagine a public, distributed, append-only log, containing the hashes of the content stored by archive.is, with the data effectively signed by a (e.g. wallet) private key of the archive maintainers. People could volunteer to locally store copies of all the data that was archived, but only serve the data that goes "missing" from archive.is.
With such a dead man's switch in place, there would be no harm in archive.is taking down any content that they were threatened (legally or otherwise) over, and then other sites (hopefully too many to attack) could publish the taken down content, alongside the cryptographic proof that the data was originally published by archive.is.
You're right though that there would still be disruption, as the original archive.is links would (in the worst case) return unhelpful error pages.
I suppose I'm inspired by this idea:
https://www.reddit.com/r/Bitcoin/comments/6aiysw/the_whole_i...
You're also right that there is a huge cost to creating a secure blockchain from scratch, but the incremental cost of using an already secure public blockchain (such as Ethereum's) can be lower than the amount of value it brings to the table.
Proving the existence of data, at specific timestamps in the past, when keys may have later been compromised, does seem like a use case that requires tamper-proof distributed consensus between untrusted parties. Whether that use case is particularly valuable or not is harder to judge, though, I admit.
31 Jan 2018, "I will make a donation every month. Please delete what we ask": https://twitter.com/archiveis/status/958760127359840257
So what is the middle ground here, or how should one view this dilema?
There's a strong case to be made that we're actually substantially better off with certain kinds of information having a generally ephemeral and hard-to-collect nature.
It might have been unfortunate for some things to have ben made public in the first place, but once it's done, there is no value in letting just some people still know the truth while everyone else is subject to manipulation by a few who know some truth.
It's about equalizing the power to harm and the power to defend against harm. The reason to preserve and re-publish something that was once known, is so that no single party gets to use it, or use it's absense, against everyone else. All deleting something does is reduce the number of people with the power to use it. It does not make it actually go away. It just makes it go away from you, while someone else who you may not like still has it.
While there are reasons to forget history, the reasons for preserving it far far far outweigh the reasons for forgetting it. And there is NO valid reason to allow editing history. Selective forgetting allows for substitution, revision, balkanization, manipulation, and at the very least, doubt.
Just because my SSN got leaked to a few people doesn't mean it needs to be leaked to the world. Most people aren't going to take advantage of my SSN, so having it leaked to a few arbitrary people is a relatively minor risk. And if it does get abused, there's a very small pool of suspects. Having my SSN get publicly broadcast to the world pretty much guarantees I'll be plagued by identity theft forever and gives me no suspects when it happens.
Same goes for plenty of other private information. Just because it's leaked to some people doesn't remotely justify giving it to the whole world.
> The reason to preserve and re-publish something that was once known, is so that no single party gets to use it, or use it's absense, against everyone else.
We're not talking about secret cheat codes that give the owner power over everyone else. We're talking about private information. If a "single party" has my private information, they have power over me, but that doesn't give them power over anyone else. In this scenario your argument seems to be "if one person has power over me, that's unfair to everyone else who doesn't, so they should be given the same power over me as well", which is of course complete nonsense.
I don't understand this argument. If, say, my credit card information is published, it can only be used to harm me. Removing it causes no harm to anyone else, so leaving it published _only_ causes more harm.
Whatever the reason, it's terrible.
DNS wasn’t built to support the growth it has experienced. Both it’s security model (Certificate Authorities)and governance model (ICANN) are highly flawed. The internet needs to switch to a better system as it becomes an increasingly important part of our lives.
Disclosure: building https://namebase.io which is a registrar for seizure-resistant domain names on the Handshake blockchain.