Publishers blocking IPs for alleged sci-hub use
twitter.com
twitter.com
Why would they do that based on IP-addresses and not based on accounts? Maybe they're actually combining those. So when an account used the same IP-Address like a "ripper" account, it will get associated with it. And the blocking message shows the old address. This can easily happen at a university where a lot of accounts access the journal through the same IP-Address.
Well... Sci-Hub doesn't have these blocks. So just use that service if you want to get work done.
Also, WHOIS says the IP-Address 86.168.188.188 is used by British Telecom: AS2856 BT Public Internet
Sounds like a fun way to piss of universities who pay for access: Block their gateway!
Depends on the journal/resource. Many resources purchased by universities are authenticated by IP. It's less friction for students when trying to access something, and provides psuedo-anonymity.
There is some push to move to something like OpenAthens for all authentication/authorization, but universities do not want to lose the privacy aspect for their students.
Or shibboleth - we treat shib as a gateway to our auth service at this here journal publishing salt mine.
Seems to work well enough - at least, the roof doesn't fall in on us when an IDP entity (federation of universities, et al) goes offline denying their collective users access.
A "have you switched it off and on again" message to the federations IT bods usually works.
I've always wondered how it ended up catching on in seemingly exclusively academia.
I'm guessing in part it's the name, which ordinary people probably find hard to remember, spell, and pronounce. (The original shibboleth "shibboleth" was meant to be hard to pronounce!)
Oh, Scott knows how to configure it, the problem is he's the only one. I'm a developer at the university works/created it at, and anything that needs to use shibb goes through him. Fortunately, he manages all the configuration (I'm assuming because no one else here knows how), requesting shibb for a new site or whatever is dreaded. It's almost a rite of passage for devs to get a scathing email back from him (almost always in less that 5 minutes) because your request wasn't filled out correctly, the worst part is he will only tell you what you screwed up and not give much help (or any) as to how fix it, and then indirectly (or I've heard directly too) to not waste his time.
As a user, shibb isn't really that bad. As a developer, I hate it so much. Scott, from what I can tell, is a strictly Java developer. So that means we're stuck with Apache and a shitload of XML, there exists a module on GitHub to integrate shibb with Nginx which I think literally every dev here I've talked to would love to be using rather than Apache, but that's probably not going to happen here unfortunately. And Apache with all the XML crap wouldn't be all that terrible if the documentation wasn't extremely vague or just plain missing.
I wanted to get some extra information about the user on signin that, according to the docs, would be available but wasn't clear enough that I felt I could just go in to even our staging servers and monkey around with. So, I figured I throw together some docker containers tinker with before I did it on anything real. It took me an entire week, to get a working shibb setup in docker since the docs literally only got me as far as getting things installed before they stopped being helpful. But, I'm now the only one in my department (at least) that knows how to get shibb up from scratch -- but I wouldn't trust it outside development.
Apologies for the rant, but shibb is probably my least favorite thing I have to deal with here -- when you hear the guy that made it works here, you'd at least think we'd get some good/helpful information about it from the source, but he seems quite happy being the only one that knows anything about it.
In that latter case, you're exposing your personal IP to the publisher and your university who validate your login, which is probably logged.
For example, you can also connect to sites via eduroam globally, but your access (I think) depends on the specific location that you're piggybacking. Sometimes you can download stuff, other times you still need to login to your home institution.
I think so. most universities have well known static ips
I imagine things are not different on most places. This can end very badly for everybody.
The ease of implementation and the anonymity it gives individual academic users are the driving factors. Of course, the sheer inertia and tradition of this solution is virtually impossible to alter, despite all the problems it obviously causes.
Others on this thread mentioned OpenAthens, which is more common in Europe, but not the US. But OpenAthens is a full blown identity provider, which is obviously more complex to set up than simple IP auth.
And from articles like https://scholarlykitchen.sspnet.org/2018/09/18/guest-post-th... there seems to be some connection between Sci-Hub and the cyber underworld, although perhaps it's just the cyber thieves sending Sci-Hub papers and Sci-Hub isn't an active participant.
People being forced to cover their asses due to a broken copyright system does absolutely nothing to tarnish Sci-Hub's image.
> articles like [...]
Well, you'll have to excuse me if I don't take the allegations of a publishing industry mouthpiece like SSP seriously.
Just read some ezproxy mailing list posts then, there’s a plenty of edu sysadmins who have discussed this and don’t work for the publishing industry.
What do you mean "some connection"? Scihub is the best cyber underground has to offer. I love their "brazen scheme to gather and redistribute scholarly content".
Besides, I doubt sci-hub would extensively verify if the access they’re “donated” is stolen or not.
(From Michigan)
Of course, and even in more force and enthusiasm! Bullying does never work in the long term. And extreme bullying like the one Aaron suffered requires an extreme response.
I would be somewhat unsurprised if they (probably not directly) (or people contributing logins to them) were buying hacked or compromised credentials for university VPNs, and culturally this seems to be kind of a norm in a few CIS countries - there are giant craigslist/ebay-like markets where people sell credentials like this, hacked game/google ads/twitch/google accounts "with warranty" for a dollar (the warranty is that they just give you another user/pass pair if the original owner resets it), etc., that are just considered normal to use -- they aren't on Tor or anything, just a regular site with regular payment processing, cards, PayPal, somehow for 99% stolen goods (crypto not required)
Ah, great.
Scihub obviously isn’t concerned with the law, there’s no reason for them to make this any harder than they need to.
Putting people at risk by letting them donate their personal access would just be silly.
I’m not a professor, I’m just familiar with ezproxy admins dealing with these issues.
Individual solutions to collective problems are immoral in my belief system. Thanks for your messages, though! they motivated me to donate 50 EUR to scihub. Even the smallest donation counts!
But buying credentials for a dollar or two to supply sci-hub solves the problem for the collective.
>Thanks for your messages, though! they motivated me to donate 50 EUR to scihub. Even the smallest donation counts!
Where’d you do this? I’d love to donate too. I don’t think sci-hub has been soliciting donations lately.
E: I guess I found it: http://www.sci-hub.tw/donate
I wonder if scihub.org is making lots of money from people trying to donate to sci-hub.
I haven’t used scihub, but it sounds like the best tool for this purpose. Any hints on how to proceed? Has someone written a script to do this or something?
It's not even just about the access restrictions... Even if I have access to a paper, grabbing it via scihub is so much faster and more reliable than via the publisher's garbage website.