Anonfiles is shutting down
anonfiles.com
anonfiles.com
Recently, the last CP addict idiot basically killed us. We always remove those posts when we get a report (we can't see them by our-self, that's the point), but we were swamped by other things, and we didn't catch this one in time. It's a free volunteer project after all.
Our host took down our server and our backup server. We didn't have an offline backup because it makes taking down bad content more work.
We are still struggling to go back up.
This is why you can't have nice things.
(and also, don't host your backup server with the same host)
I hope you figure things out in a way that causes less of a headache for you.
cheap way to get some resiliancy is to host a hot-spare/replika at another provider/isp and failover at the dns level with an alternative record
Internet progress seems to resoundingly be going backwards. Remember when pastebin used to be super active? Hell, remember when google had informative search results?
The view of “the global village” with betterment for human society has become another rent seeker “getting my own” hustle culture. It’s the way people are I guess on the whole.
Theres something deeper thats causing things like Google search refusing to show more than 12 or so results and them being lower quality. Causing YouTubes algorithm to recommend things you've already watched or just recommending a video over and over for weeks until you watch it to get rid of it.
I guess the thing is that the push is on for ever higher extraction and yields for managers/stakeholders/CEOs and to show it to shareholders and investors and the like. And with higher interest rates where money costs its only amplified I reckon.
I promote a video ad campaign for a client and its insane how much it is being shown for a few clicks. Ad revenue is probably going down in relative terms (or more effort for same results)
That something is - wait for it - capitalization.
Google, YouTube and the rest of the Internet are drowning in low-quality, automated, yet monetized dreck. The signal-to-noise ration on the web has never been lower, and it's getting lower still.
But maybe we'll see a renaissance of sorts? When the only sites that work on Firefox are fediverse and a few hobbyist sites and people need to go out of their way to find computers that they actually control we might undo the eternal September of the web as a whole.
I blame JavaScript.
If you can't promptly handle take down requests don't put yourself in a position where you're required to promptly handle take down requests.
- https://web.archive.org/web/20230801/https://anonfiles.com/
- https://web.archive.org/web/20230801/https://bayfiles.com/
- https://web.archive.org/web/20230801/https://file.bz/
- https://web.archive.org/web/20230801/https://filechan.org/
- https://web.archive.org/web/20230801/https://forumfiles.com/
- https://web.archive.org/web/20230801/https://hotfile.io/
- https://web.archive.org/web/20230801/https://letsupload.cc/
- https://web.archive.org/web/20230801/https://lolabits.se/
- https://web.archive.org/web/20230801/https://megaupload.nz/
- https://web.archive.org/web/20230801/https://myfile.is/
- https://web.archive.org/web/20230801/https://openload.cc/
- https://web.archive.org/web/20230801/https://rapidshare.nu/
- https://web.archive.org/web/20230801/https://share-online.is...
- https://web.archive.org/web/20230801/https://upload.st/
- https://web.archive.org/web/20230801/https://uplovd.com/
- https://web.archive.org/web/20230801/https://upvid.cc/
- https://web.archive.org/web/20230801/https://vshare.is/
- https://web.archive.org/web/20230801/https://zippysha.re/
All of them were hosted by a single IP in svea.net, with a couple of associated IPs at the same host for "cdn##" subdomains.
There never appeared to be more than a few at a time and I did not find too many in total.
https://web.archive.org/web/20220620143327/https://bayfiles....
https://web.archive.org/web/20220623051910/https://openload....
https://web.archive.org/web/20220620170814/https://myfile.is...
https://web.archive.org/web/20230401012418/https://filechan....
https://web.archive.org/web/20230401012318/https://letsuploa...
They also started advertising ovpn.com as a "court-proven VPN" on June 23rd 2022: https://web.archive.org/web/20220623173752/https://anonfiles...
It looks like from June 24th 2022 through August 10th 2023 (or 16th, likely whenever they changed their index to announce the shutdown) they only listed filechan.org and letsupload.cc.
On July 4th 2022 they dropped ovpn.com: https://web.archive.org/web/20220704154732/https://anonfiles...
All of the file sharing sites listed do appear to be parodies of other popular websites, some of them file sharing. They also appear to all be identical except for the site name and styling. All of the file sharing sites except for anonfiles.com now return NXDOMAIN. (ovpn.com appears to still exist.)
The obvious parodies of file sharing websites does call into question their assertion that they didn't want abuse.
You say honeypot, I say free government-provided cloud storage, w00t!
I dealt with one case that was completely horrific, and two minor. The horrific case involves the PRODUCTION of CP using other service members children via the spouses daycare, then distribution from our network. The other two were relatively simple storage/redistribution via workstations.
It happens, but from my viewpoint if it’s that rare it must be extremely rare elsewhere if your statement is true.
I dont know where the servers were, but i feel like it was used for less lovely purposes by the owners and a lack of identifiers & internet curated mess would obfuscate law enforcement's efforts
Edit: my theory however falls flat if there were multiple websites, since having a one large database would be in their best interest. You could argue that there were multiple entities self-hosting the same thing, but why would they link to eachother? Coupled with the VPN ad, sounds like data harvesting all around (honeypot or not)
If they're all hosted on the same server -- which, to all appearances, they were -- there's little practical distinction.
I will say that, though I hadn't heard of this site, it seems like they were trying to do something decent and not profit-driven (free file sharing without advertising, badgering you to make an account, etc) and I'm metaphorically pouring one out for another nice service that the world had to go and mess up.
For anyone wanting to know what the site used to look like, here's a random Wayback Machine snapshot from 2021:
http://web.archive.org/web/20210309013336/https://anonfiles....
Some people just need to execute on an idea to learn. I don't quite get the pessimistic comments here. I don't really blame anonfiles for trying. It certainly provided a lot of experience and certainly opened their eyes on how difficult it is to offer a service like this. This experience will help them to build something better in the future even if the next thing they build has nothing to do with distributing files for anonymous users.
How so? Atleast one guy did something that made you shut it down. What insight does that give? Surely you knew there is at least one bad guy using the internets before the experiment?
Yes, I knew that there could be abuse, but I didn't know how the abuse would come. As I said, I learned, it cost me very little to do.
> What insight does that give?
For one, how do you maintain a service that actually has traffic. At the time I had very little experience with mass amounts of users. You can build personal websites all day long and still never know what it is like to handle high levels of traffic.
Additionally, given the type of content I received on the service, how could I handle the patterns of use better and encourage the sharing I wanted from users? Given the type of content I got very clear patterns developed that if I wanted to expand I could have.
> Surely you knew there is at least one bad guy using the internets before the experiment?
Yea, there are people with ill intent on the internet and they are constantly attempting to break into my servers as we speak. Why would I use that as a reason to not offer something online? This reason alone, shouldn't be a deterrent.
I ran a Tor exit node once. However I pulled out once I realized what kind of traffic I could be relaying. I guess it is a similar learning experience.
The proportion of disreputable things on Tor might be higher, but it's a difference in degree, not in kind. And the proportion of dissidents trying not to be killed by their own government and Ukrainians trying not to be killed by Russians is higher too.
Because the other examples you mention, are corporations with lawyers. They (usually) won’t get a random police raid, and even if, it’d not be as potentially disastrous as it would be for a random person.
But in any event that seems like more of an argument for not running one at your house than for having some moral objection in this case but not to any of those corporations transferring the same content.
And I guess you could interpret GP’s comment as moral, I was reading it as legal, but there’s no real sign one way or the other.
I found it funny. I'd go in and be like "oh look, I've been looking for that software. Thanks hackers!"
Probably nothing would happen but it would be interesting.:)
The world, famous for its love of all things disgusting and vile: Throws disgusting vile bytes into the hole.
Oh no! How could I have foreseen this?!
I’m sure they had good intentions, but I’m sorry, I would never make this, ever.
I'm writing this after finding the site closed. Now I am going to pay for some space to send large files to people who are struggling to use Dropbox on their shiny silver laptops.
And I will not offer a penny for the domain.
> This is not the kind of work we imagine when acquiring it and recently our proxy provider shut us down.
Really? You created a website where people could anonymously upload files to share with others. What did you really expect was going to happen? It's kinda naive to think a service like this would be all happy times in the world we have today.
If you offer anonymous and free image uploading it's not wrong to assume that not 100% of your traffic will be pornographic uploads and I also don't think it's wrong that if after years of your offering, if you get to the point where all of your uploads are porn, that you feel the need to shutdown your service.
Nobody is entitled to do bad things with good tools.
Why is child porn bad...
And, why will the government punish you out of existence if you allow the trafficking of it?
Its not like anonymous file hosting on the internet was a new thing two years ago. It very much is a major oversight to offer (or acquire) a service in an existing, established segment and have no idea what the usage patterns and challenges in that segment are.
> If you offer anonymous and free image uploading it's not wrong to assume that not 100% of your traffic will be pornographic uploads
Its file, not just image, hosting, but, yeah, you should probably assume that the stuff that the most controversial aspect of it is that it is just porn will be toward the milder end. And their piece doesn't say “porn” it says “abuse”.
I'm guessing CP (technically porn, sure; probably not what you meant), death/gore videos, pirated software/media, etc were the main issue.
Saw a company that accidently DMZ'd their printer with a public IP, and this had to be over 15 years ago at this point. Had anony ftp open on it, and yea, exactly what you expect happened.
I think it's much more likely that people used it to host CP and malware....
The operators don't know what's being posted. This is a problem because it's what's called "inducement of a crime" - it's like if you say "We are a bar that doesn't check IDs" - you have a responsibility that comes with the operations. If you have a bunch of underage people in the bar because of your policy of not checking IDs, that responsibility falls on you. When you choose to forego responsibilities, you get that secondary liability.
See Kim Dotcom, MGM Studios, Inc. v. Grokster, Ltd., 545 U.S. 913 and Arista Records LLC v. Lime Group LLC. The courts have spoken many times on this and with a single voice.
You can have a service, then turn your head close your eyes and say "we'll just let freedom happen" but that doesn't excuse you from being responsible for what happens.
> See Kim Dotcom.
Megaupload got in trouble because their employees actively knew about and participated in infringement. Mega.com, which encrypts everything by default so they don't know what it is, is... still there?
The point wasn't that encryption is possible but instead that it's a de facto practice so the operators don't actually know the breakdown of the content being uploaded unless they're only considering the cleartext.
Furthermore, this doesn't protect them from being responsible for the content.
You can disagree, but until you can form a majority opinion on the SCOTUS, your thoughts don't actually matter.
I'm not a lawyer but I did a few podcast episodes on this topic a few years ago so I did about a month of research on it. The hosting providers are responsible for the content within some reasonable expectation of how the site is structured.
Okay, so they apparently moved it to mega.nz.
> those domains were seized in 2012 by the us doj.
The ones where they weren't encrypting the stuff.
> Furthermore, this doesn't protect them from being responsible for the content.
Laws commonly have knowledge requirements. If you go to the UPS store and ask them to deliver a metal cage clearly containing a screaming woman who has been kidnapped, and they do it, they're going to be in trouble. If you go and ask them to deliver a brown cardboard box of contents unspecified, that's a different matter, even if unbeknownst to them it turns out to contain some contraband.
If I build a filesharing site with clearly-good intentions, my employees don't promote piracy, and the content is encrypted, as long as I take shit down when authorities tell me it's Bad I should be in the clear, surely...?
There's plenty of long lived providers.
That's different from if you had a service called, say, pirate-share with a search function that has options like "artist" and "director". These difference matter.
As far as I know, the courts have looked at anonymous file sharing sites as closer to the second group than the first.
I remember when the internet was basically only anonymous and I think it was a better time and that's kinda why I like tor. The problem is most people seem to only go there for crime as opposed to some weird ideological commitment to how online engagement should exist.
It'd be nice if there could be a more healthy balance between anonymity and crime that's more encouraging for people to be anonymous but somehow less supportive of criminal activity.
Basically I think "influencer culture" and branding oneself has destroyed things
Perversely, though.
Grokster and BitTorrent are largely used for the same things and they both have infringing and non-infringing uses. Grokster lost because they promoted the infringing uses. But why do we actually care about this?
It's not as if copyright infringement never existed before Grokster and nobody has been able to figure out how to use BitTorrent for it because Bram Cohen never mentioned it.
So all the rule does is impose censorship. Because otherwise the creators of these technologies would be outspoken proponents of copyright reform. But then their lawyers tell them to STFU, because if they say that existing copyright terms are morally unjustifiable and the RIAA is a pack of vultures who deserve to go bankrupt and things to that effect, plaintiffs will argue that they're promoting infringement and sue them for their political opinions. Especially if they fail to be perfectly articulate and precise while expressing that sentiment.
Is it not a de facto prohibition on developers and businesses expressing public support for the Pirate Party?
Obviously operating on another level but what's the difference with Whatsapp saying we can't read your messages, and the other even more privacy focused alternatives?
Does WA check if CP.zip is being sent through groups ?
But, with a company that hosts files you are liable for checking those files. There's also nuance here: you can't check everything all the time. You also can't check encrypted shit. But if you make no effort (see: the bar example) then that rises to inducement. Anonfiles, for example, is negligent in this regard. There's no law preventing you from allowing people to store encrypted files but there should be a way to not only comply with valid, warrant-provided, law enforcement requests but also keep track of such "prolific" uploaders as they are most likely uploading shit you don't want.
Source: I work in an industry that, unfortunately, has to deal with this stuff all the time. The internet is a sick place. Our legal team briefed us on our responsibility (in terms of storage and processing) along with the correct chain-of-command should something come up. Of course, we also have therapy available which is used more often than you'd think. In our case there's also some protection afforded to us for the things that may be stored because we comply with various law enforcement agencies when necessary. Posted further up you see:
> Recently, the last CP addict idiot basically killed us. We always remove those posts when we get a report (we can't see them by our-self, that's the point), but we were swamped by other things, and we didn't catch this one in time. It's a free volunteer project after all.
Which tells you they had zero idea what they were doing. If you're not hosting your anonymous service on an derelict oil platform deep in international waters you have a responsibility to get the correct legal counsel and set up a system for handling chomos. Ignorance is not an excuse, "volunteer" is not an excuse, AND you shouldn't make a service that protects chomos.
Did the current owner not create the site? Did they acquire an anonymous file sharing site and are now shutting it down for the predictable anonymous file sharing issues?
Perhaps it's an English translation issue or something, but, in common parlance, the word "acquire" means to buy or obtain from elsewhere. (I don't think they are referring to the domain name itself, because that has nothing to do with the complaints listed.)
> We have auto banned contents of hundreds of thousands files.
> Banned file names and also banned specific usage patterns ...
Nothing about banned IPs.
By default, blocking an IP or IP range prevents users from those IPs from making edits, with or without an account, or creating accounts. Similarly, if an account is blocked, any IPs they've edited from recently get blocked as well.
All of these functions can be customized on a per-block basis; blocks on shared IP ranges are usually configured to allow account creation and logged-in edits.
It did not last very long when it became clear what kind of stuff would be rolling down the screen.
> Known illegal md5s
Yeah, no. Those lists (of known formats and of known illegal files) will quickly grow unmanageable.
So I don't think bloom filters have a significant impact on the manageability of those lists. Though I doubt the storage size will be the main concern, compared to the effort of adding entries to that list.
When a public file link is shared publicly, the following is embedded into the public link:
https://mega.nz/#! || Base64( File Handle ) || ! || Base64( Obfuscated File Key )
This is enough information to find the file identified by its File Handle on the server, then download it, verify the Condensed MAC of the overall file, unobfuscate the File Key, then decrypt the file using the File Key and IV.
It should be noted that everything after an anchor hash (#) in the URL is not sent to the MEGA servers and is kept locally in the client’s browser[0]
Didn't think of that. So I guess my idea isn't adding too much. Just a lot of compute without so much in return. It still simplifies moderating the files, however.
I've often thought about offering a similar service, but the abuse potential has always stopped me.
I've noodled with a blockchain type system which allows blob uploads as part of the chain, but I haven't really deployed it and publicized it, because of the abuse potential.
whois anonfiles.com | grep Creation
Creation Date: 2011-03-23T13:07:29ZSomeone couldn’t pay me a hundred thousand dollars to operate and manage a site like this.
But even so there were several alerts per week. For comparison, we were doing around 40 million transfers per month at the time, so ~10 million per week.
Kind of like when Bitcoin was used primarily for the drug trade in the silk road days.
Let's hope the potentially new domain owners are great people.
Does anyone have any recommendations for anonymous file hosts? Thanks.
could always use additional gateways and CDNs
people pay subscribing for pinning, even if you don’t do the pinning yourself
in this system design, anonfiles wouldn't be hosting it, any Section 230 exception problem would be the IPFS node's problem
and its not even about the legal aspect? its about working smarter not harder. what you are saying, to me, sounds similar to "this person made an online store to get around the zoning procedures of a brick and mortar store" never considering that they never ever considered making a brick and mortar store to begin with and would find the administration entirely unappealing and unrelated to fulfilling their vision