Old Vidme embeds turn into porn after domain purchase
theverge.com
theverge.com
(And you can help keep them there, too https://archive.org/donate But honestly, using the Archive more keeps the bigger donors involved, so don't feel guilty or anything. Just use the Archive!)
Why not. Is it really impossible
I read a significant percentage of HN submissions through archive.org. Saves me DNS lookups. Recent pages look exactly the same to me as their "live" versions, the retrieval time is rarely bad.^1
Its probably the best "CDN" as it has the largest amount and variety of content
There should be more than one archive.org (and more than one ArchiveTeam). These projects work and they are standing the test of time. archive.org is older than Google. Much, much older in "internet time".
1. I use a text-only browser though so not sure how tolerable it would through Javascript-enabled graphical browser
(It's too bad the tax deduction isn't eligible in Canada :( )
Looks like openBSD isn't deductible either for Canadian donoUrs. Theo's registered address has lots of cool wifi links though. I count 4! (one is on the gutter)
https://www.google.com/maps/place/812+23+Ave+SE,+Calgary,+AB...
This is one of the reasons I created a proof-of-concept web extension that verifies links and pages using PGP. On a mismatch, it flags the page and offers a web archive link instead.
It was pretty fun to make, but currently due to performance, Web Extensions API doesn't provide the features to do this perfectly. Firefox provides just about enough additional APIs to hack it together.
In a lot of the peer-to-peer distributed hash table designs, all you need to retrieve a file is its hash.
Basically, little segments of the video have to have a signature which is continuously validated. Or something like that.
Multiple levels of the tree can be stored throughout the video file. The first level after the root can be for major sections, like 5 minute segments. The next levels are then at the start of each 5 minute segment, giving hashes for one second chunks.
If the root hash checks out, we get the 5-min hashes. If they check out, we get the hashes for the first 5-min block, and if those hashes check out, we start to play the video, validating every second of it against a one second hash from the 5 min block. Then we get the next 5-min hash block and so on.
Kind of thing.
The most egregious is if I'm an attacker and I have the file you request I can hash the appropriate portion you'd use to verify it but fill the rest with junk or exploits. You'd receive the file, it would emit the correct hash, yet be not what you were expecting.
For video especially what you receive isn't necessarily predictable by the client. With HLS or MPEG DASH streaming the video you receive could be one of a number of different encoding e.g. lower or higher bitrates to deal with changing network conditions. The actual m3u8/mpd file you might receive could change arbitrarily as the video provider adds or drops different encodings. The hash of such a file today isn't guaranteed to match the hash tomorrow for entirely banal non-malicious reasons.
Fun fact: the UUHash algorithm used by the FastTrack network (Kazaa, Morpheus, etc) only hashed the first bit of a file. Hashing a large file took forever on hardware of the day. Even hashing small files was non-trivial. The RIAA through various fronts would insert spoofed files where the first portion of the file was legitimate but the content of the file would be junk or annoying sounds. The files would be named like any other MP3 someone was searching for and even have seemingly good IDv3 tags.
The first 300KiB plus a series of 300KiB chunks at exponentially-increasing offsets, per Wikipedia. But still a small fraction of thw file.
[1]: https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Also, while IPNS covers the issue of linking to dynamic content, it's worth mentioning IPFS will have similar issues with DNS as DNSLink and similar domain-driven solutions are used to cover its usability issues (long, random URIs).
If you could "permalink" certain content for embeds, that'd probably solve the issues, right?
[1] - https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Say I link to an article by Author A that has comments in it (or even a footer, relative timestamp, sidebar, etc.). Hashing won't work as the page is always changing. I want the link to always go to Author A but I don't care if the content changes. That's the sort of use case signed webpages and hyperlinks with enforced authorship covers. It's less about what's on the page and more about who created it.
There was a ietf or similar registry that used your domain and registration date to carve out your namespace, ie dns.2021.07.26.com.example would be your prefix. Pretty robust. Can’t remember what it was anymore
Of course, the devil’s in the details (infrastructure/organizational changes can trigger false positives; shared hosting setup can cause false negatives; it presumes that if the original entity abandons a domain they’d revoke the cert; etc.), but IMO it wouldn’t be worthless as it is.
But other than that, if I have a cert fo xyz.com, and I abandon the domain, even if you buy it you’ll be forced to issue another cert for it.
If it was recorded somewhere that xyz.com = my cert, it could serve as a mechanism to verify that given URL is at least is supposed to be under my control and a warning could be shown if another certificate is being served now.
Kind of like HPKP, but with longer lifetime (longer than domain name registration term) and a centralized registry tracking certificate:domain mappings rather than each individual user agent cache.
Obviously, no one would adopt it due to being a devops nightmare.
Domains need to be short to be memorized, which makes them scare and valuable.
And having two forms of URLs is undesirable; just look at AMP.
https://developers.google.com/web/updates/2018/11/signed-exc...
You can use 301/308 redirect for either new page/path or new domain, or both. It's pretty flexible. If you're interested to learn more, Google has a pretty good "best practices" page at https://developers.google.com/search/docs/advanced/crawling/...
Ask any uMatrix user how much fun it is to get a video to play on some websites and just how much external crap you have to allow before you see the first frame.
Why?!
Never gonna give you up...
Genius
to monitor interesting domains being expired and to also find interesting domains that are available.
twitter.accountant? what about twitter.beauty?
Domains are not exactly available when they expire, but this helps me to check if any of them become available.
Well, it's an argument against using embeds without having any way to validate their authenticity.
This is analogous to having a software distro (e.g. package manager) which downloads upstream tarballs or git repos without checking any hashes.
Is there a solution for this? Say you want to embed a video from some third party sites; what tools are there for ensuring that the embedding will somehow lapse if the video at that URL has been replaced or altered?
Ideally, you'd be notified if that happened. While not showing porn is good, but videos not working is bad. You can't be checking an entire site all the time for non-working external content.
Edit: Seems like there's a 10 year limit in many places? I wonder if that's broad convention or an actual rule.
Okay, apparently an ICANN limit for .com domains:
"The expiration date of the domain registration is extended by the number of years, up to a maximum of ten years, as specified by the Registrar's requested Extend operation."
https://www.icann.org/en/registry-agreements/com/com-registr...
Though, I can see that navy.us has an expiry in 2053, so it's likely per registry.
Edit: CSC, Markmonitor and similar shops will contract to keep your name available for long periods, too, but that's a bit different.
Yearly at least keeps me on my toes a bit.
Also most registrars will send you an email when it's about to expire. If it does get dropped, there's a grave period to recover it.
Edit: It seems to vary. Some places cite an ICANN limit of 10 years.
They are betting that they will earn more than enough from investing your up front 100 year payment to more than cover future increases in the cost of those one year extensions.
Their customers are betting that Network Solutions or some successor will be around long enough and that domain names will work like the do now long enough that this will be worth it.
Sorry that doesn’t answer your question more than “it depends on the entity”.
Isn't that a lot of work for almost no gain?
They are the porn (the new owner is a porn firm), so, yes. I haven't seen the actual linked content, but I assume its something like free samples with directions telling people where to get more; its a move that gets porn ads placed for free in a lot of places that would never choose to allow porn ads.
At least it's only pr0n. As a vector for malware / spyware injection, this could be even more interesting.
Relevant xkcd, of course: https://xkcd.com/1698/
h/t Elda King @ Mastodon https://weirder.earth/@eldaking/106626603001624730
Owning the domain doesn't give them a right to intentionally interfere with the requested content; they should simply decline to serve the expired URLs.
A domain could cost a fixed amount of X per month. So you could pay 100 years upfront and be sure to not lose it in that timeframe.
To move a domain,the registrar and the owner could have to sign the move. So it would not be possible anymore to lose a domain due to the regsitrar making a mistake.
The same problem it solves for finance: That someone else can move your money.
So they could do so out of malice or because they get tricked into believing you gave them the go or because they got hacked or got ordered to do so by some governmental institution or or or ...