And for the record, z library gets its books from libgen? Correct me if I'm wrong, but it was just a frontend?
And for the record, z library gets its books from libgen? Correct me if I'm wrong, but it was just a frontend?
Also, consider your risks more holistically:
* Honeypots can and do have valid https certificates, what matters is who controls the site (for example, when the FBI took over a kiddie porn site, it changed the site to deliver over https a zero-day exploit for Tor Browser that broke out of the browser sandbox and deanonymised the visitor) * Eavesdroppers can tell you visited a specific HTTPS site by looking at your TLS1.2 SNI in cleartext. Even if you're using TLS1.3 (which fixes that leak, but is currently up to the browser/site to negotiate), eavesdroppers can still correlate site access with your DNS requests. Even if you use DNS-over-HTTPS/TLS, you don't know if your DNS provider is in cahoots with the eavesdropper. You have to trust someone
Where your actual risks lie in visiting an HTTP-only site:
* If the site has forms/cookies, an eavesdropper can see them. In this case, https buys you nothing; your concern is that someone can tell if you visited this site once, not that they can tell you're a repeat visitor * Eavesdroppers can see any headers that your browser hands out (mainly user-agent) that could more granuarly identify you vs just your IP address * Active attackers with the ability to control your traffic can place anything they want on the website by spoofing its responses. With https they could only deny you access to the site
The benefits of HTTPS over HTTP are enormous, but you have to understand what its limits are. If you're concerned about web surveillance, you should be something like Tor Browser to visit websites, and understand that even it has limitations.
but in this case, couldn't you just use an offshore dns provider that's in a jurisdiction that won't cooperate with judicial system? (assuming here adversary is getting sued by copyright holder, not govt agency)
In the case of _this_ site, it has nothing a copyright holder could complain about, so it doesn't matter if you visit it. It says "We don't link to it from here, but just Google for 'Pirate Library Mirror'". Yup, why not tell Google what you're doing? Once you've done that, and visited the (also HTTP only) "Pirate Library Mirror" site, you'll find it doesn't have any .torrent files. But it does have a link to a .onion site available only in Tor Browser. And the onion site _does_ have .torrent files you can download and add it to your Bittorrent client and begin infringing copyrights.
The two HTTP sites involved have nothing that could get you legally into trouble, even if an eavesdropper saw _all_ your traffic. It's certainly good practise to make all sites HTTPS, but for these specific sites, it isn't a downside that they're HTTP-only. The only situation I can think where HTTPS vs HTTP would make a difference is quite unlikely: if an active attacker, able to modify your traffic, substituted a link to a different .onion site, with different .torrent files specifically for you
How does TLS vs No TLS weight in on your suspicious if something is a honeypot or not? It's as trivial for three-letter agencies/black hats to setup as for trusty individuals/corporations.
Keep in mind, the first post on this site was in 2022. 2022, and no https... is this some kind of joke?
And in this case the adversary isn't necessarily the three letters, it's the copyright holders and legal system. No https makes ISP logs even more useful
Couldn't you just use ech/esni, ISP wouldn't see the domain only IP (and dns provider)?