Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. So the mysterious person behind archive.today is very likely to be "Masha Rabinovich."

So the mysterious person behind archive.today is very likely to be "Masha Rabinovich."

Geplant Angeheftet Gesperrt Verschoben Uncategorized
24 Beiträge 7 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • eb@social.coopE eb@social.coop

    The HN thread discovering this covert attempt was posted by no other than "rabinovich", a user which shares the name of the POI: https://news.ycombinator.com/item?id=46624740

    Furthermore, the Masharabinovich Wikipedia account has reactivated for the first time in 10 years to purge their talk page: https://en.wikipedia.org/wiki/Special:Contributions/Masharabinovich

    Now, we still don't know if this Masha Rabinovich is an alias, but the evidence that this person is indeed the creator of archive.is is too great to ignore, and clearly Jani touched a nerve 🧵

    eb@social.coopE This user is from outside of this forum
    eb@social.coopE This user is from outside of this forum
    eb@social.coop
    schrieb zuletzt editiert von
    #3

    But what's really interesting is the motivations.

    1. Why now, after 2 years?
    2. Why run a DDoS, and yet defend Jani in the comments?: https://news.ycombinator.com/item?id=46629823
    3. Why register for a forum using your "name" to draw attention to a DDoS being ran by *your own site*?

    This seems like a ploy for attention. Perhaps the FBI has finally found him and Masha wants to go out on his own terms?: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tries-to-unmask-mysterious-founder-of-archive-today/

    Perhaps Masha is a fake name and the real name leaked so he wants to publicize Masha? 🧵

    eb@social.coopE iampytest1@infosec.exchangeI 2 Antworten Letzte Antwort
    0
    • eb@social.coopE eb@social.coop

      But what's really interesting is the motivations.

      1. Why now, after 2 years?
      2. Why run a DDoS, and yet defend Jani in the comments?: https://news.ycombinator.com/item?id=46629823
      3. Why register for a forum using your "name" to draw attention to a DDoS being ran by *your own site*?

      This seems like a ploy for attention. Perhaps the FBI has finally found him and Masha wants to go out on his own terms?: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tries-to-unmask-mysterious-founder-of-archive-today/

      Perhaps Masha is a fake name and the real name leaked so he wants to publicize Masha? 🧵

      eb@social.coopE This user is from outside of this forum
      eb@social.coopE This user is from outside of this forum
      eb@social.coop
      schrieb zuletzt editiert von
      #4

      I also just wish to stress that by visiting archive.today or related web properties your device is being used as a participent in a DDoS attack against Jani. archive.today is not safe to use. 🧵

      aburka@hachyderm.ioA eb@social.coopE liquidparasyte@app.wafrn.netL semitones@tiny.tilde.websiteS 4 Antworten Letzte Antwort
      0
      • eb@social.coopE eb@social.coop

        I also just wish to stress that by visiting archive.today or related web properties your device is being used as a participent in a DDoS attack against Jani. archive.today is not safe to use. 🧵

        aburka@hachyderm.ioA This user is from outside of this forum
        aburka@hachyderm.ioA This user is from outside of this forum
        aburka@hachyderm.io
        schrieb zuletzt editiert von
        #5

        @eb crap that sucks, it's so useful

        1 Antwort Letzte Antwort
        0
        • eb@social.coopE eb@social.coop

          I also just wish to stress that by visiting archive.today or related web properties your device is being used as a participent in a DDoS attack against Jani. archive.today is not safe to use. 🧵

          eb@social.coopE This user is from outside of this forum
          eb@social.coopE This user is from outside of this forum
          eb@social.coop
          schrieb zuletzt editiert von
          #6

          interestingly the code used in the DDoS has changed between today and yesterday:

          Old:

          𝚏𝚎𝚝𝚌𝚑("𝚑𝚝𝚝𝚙𝚜://𝚐𝚢𝚛𝚘𝚟𝚊𝚐𝚞𝚎.𝚌𝚘𝚖/?𝚜=" + 𝙼𝚊𝚝𝚑.𝚛𝚘𝚞𝚗𝚍(𝚗𝚎𝚠 𝙳𝚊𝚝𝚎().𝚐𝚎𝚝𝚃𝚒𝚖𝚎() % 𝟷𝟶𝟶𝟶𝟶𝟶𝟶𝟶), {
          𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛𝙿𝚘𝚕𝚒𝚌𝚢: "𝚗𝚘-𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛",
          𝚖𝚘𝚍𝚎: "𝚗𝚘-𝚌𝚘𝚛𝚜"
          });

          Today:

          𝚏𝚎𝚝𝚌𝚑("𝚑𝚝𝚝𝚙𝚜://𝚐𝚢𝚛𝚘𝚟𝚊𝚐𝚞𝚎.𝚌𝚘𝚖/?𝚜=" + 𝙼𝚊𝚝𝚑.𝚛𝚊𝚗𝚍𝚘𝚖().𝚝𝚘𝚂𝚝𝚛𝚒𝚗𝚐(𝟹𝟼).𝚜𝚞𝚋𝚜𝚝𝚛𝚒𝚗𝚐(𝟸, 𝟹 + 𝙼𝚊𝚝𝚑.𝚏𝚕𝚘𝚘𝚛(𝙼𝚊𝚝𝚑.𝚛𝚊𝚗𝚍𝚘𝚖() * 𝟾)), {
          𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛𝙿𝚘𝚕𝚒𝚌𝚢: "𝚗𝚘-𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛",
          𝚖𝚘𝚍𝚎: "𝚗𝚘-𝚌𝚘𝚛𝚜"
          });

          jik@federate.socialJ 1 Antwort Letzte Antwort
          0
          • eb@social.coopE eb@social.coop

            interestingly the code used in the DDoS has changed between today and yesterday:

            Old:

            𝚏𝚎𝚝𝚌𝚑("𝚑𝚝𝚝𝚙𝚜://𝚐𝚢𝚛𝚘𝚟𝚊𝚐𝚞𝚎.𝚌𝚘𝚖/?𝚜=" + 𝙼𝚊𝚝𝚑.𝚛𝚘𝚞𝚗𝚍(𝚗𝚎𝚠 𝙳𝚊𝚝𝚎().𝚐𝚎𝚝𝚃𝚒𝚖𝚎() % 𝟷𝟶𝟶𝟶𝟶𝟶𝟶𝟶), {
            𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛𝙿𝚘𝚕𝚒𝚌𝚢: "𝚗𝚘-𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛",
            𝚖𝚘𝚍𝚎: "𝚗𝚘-𝚌𝚘𝚛𝚜"
            });

            Today:

            𝚏𝚎𝚝𝚌𝚑("𝚑𝚝𝚝𝚙𝚜://𝚐𝚢𝚛𝚘𝚟𝚊𝚐𝚞𝚎.𝚌𝚘𝚖/?𝚜=" + 𝙼𝚊𝚝𝚑.𝚛𝚊𝚗𝚍𝚘𝚖().𝚝𝚘𝚂𝚝𝚛𝚒𝚗𝚐(𝟹𝟼).𝚜𝚞𝚋𝚜𝚝𝚛𝚒𝚗𝚐(𝟸, 𝟹 + 𝙼𝚊𝚝𝚑.𝚏𝚕𝚘𝚘𝚛(𝙼𝚊𝚝𝚑.𝚛𝚊𝚗𝚍𝚘𝚖() * 𝟾)), {
            𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛𝙿𝚘𝚕𝚒𝚌𝚢: "𝚗𝚘-𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛",
            𝚖𝚘𝚍𝚎: "𝚗𝚘-𝚌𝚘𝚛𝚜"
            });

            jik@federate.socialJ This user is from outside of this forum
            jik@federate.socialJ This user is from outside of this forum
            jik@federate.social
            schrieb zuletzt editiert von
            #7

            @eb *sigh* I use archive.today quite a bit. Don't have time right now to find someone else that will do what I need, so at least for the time being I'm going to blackhole gyrovague.com on all my devices to prevent it from doing any damage on my account.
            It's interesting that the DDoS code is (apparently) only on the CAPTCHA page, since archive.today doesn't always display its CAPTCHA page. Why didn't they put it on every page? Hmm.

            eb@social.coopE 1 Antwort Letzte Antwort
            0
            • jik@federate.socialJ jik@federate.social

              @eb *sigh* I use archive.today quite a bit. Don't have time right now to find someone else that will do what I need, so at least for the time being I'm going to blackhole gyrovague.com on all my devices to prevent it from doing any damage on my account.
              It's interesting that the DDoS code is (apparently) only on the CAPTCHA page, since archive.today doesn't always display its CAPTCHA page. Why didn't they put it on every page? Hmm.

              eb@social.coopE This user is from outside of this forum
              eb@social.coopE This user is from outside of this forum
              eb@social.coop
              schrieb zuletzt editiert von
              #8

              @jik my best guess is that the captcha page just isn't something people think to inspect. it is a very brief page the user will only ever encounter on a journey, a page that they strive to move through as efficiently as possible. Furthermore it *looks* like a cloudflare captcha so users are very familiar with it (it is not a cloudflare page).

              ferrix@mastodon.onlineF iampytest1@infosec.exchangeI 2 Antworten Letzte Antwort
              0
              • eb@social.coopE eb@social.coop

                @jik my best guess is that the captcha page just isn't something people think to inspect. it is a very brief page the user will only ever encounter on a journey, a page that they strive to move through as efficiently as possible. Furthermore it *looks* like a cloudflare captcha so users are very familiar with it (it is not a cloudflare page).

                ferrix@mastodon.onlineF This user is from outside of this forum
                ferrix@mastodon.onlineF This user is from outside of this forum
                ferrix@mastodon.online
                schrieb zuletzt editiert von
                #9

                @eb @jik a captcha page presents nothing, takes a long time thinking, and is expected to be weird acting. Great cover for a ddos bot

                ferrix@mastodon.onlineF 1 Antwort Letzte Antwort
                0
                • ferrix@mastodon.onlineF ferrix@mastodon.online

                  @eb @jik a captcha page presents nothing, takes a long time thinking, and is expected to be weird acting. Great cover for a ddos bot

                  ferrix@mastodon.onlineF This user is from outside of this forum
                  ferrix@mastodon.onlineF This user is from outside of this forum
                  ferrix@mastodon.online
                  schrieb zuletzt editiert von
                  #10

                  @eb @jik it's like "proof of work" "and by work we mean attack something for us"

                  1 Antwort Letzte Antwort
                  0
                  • eb@social.coopE eb@social.coop

                    I also just wish to stress that by visiting archive.today or related web properties your device is being used as a participent in a DDoS attack against Jani. archive.today is not safe to use. 🧵

                    liquidparasyte@app.wafrn.netL This user is from outside of this forum
                    liquidparasyte@app.wafrn.netL This user is from outside of this forum
                    liquidparasyte@app.wafrn.net
                    schrieb zuletzt editiert von
                    #11

                    Are you saying that the landing page I've been redirected to for the past 5 years on the archive.today network has actually been a DDOS tool the whole time?

                    Or is it just discreetly packaged alongside Google reCAPTCHA?

                    iampytest1@infosec.exchangeI 1 Antwort Letzte Antwort
                    0
                    • eb@social.coopE eb@social.coop

                      @jik my best guess is that the captcha page just isn't something people think to inspect. it is a very brief page the user will only ever encounter on a journey, a page that they strive to move through as efficiently as possible. Furthermore it *looks* like a cloudflare captcha so users are very familiar with it (it is not a cloudflare page).

                      iampytest1@infosec.exchangeI This user is from outside of this forum
                      iampytest1@infosec.exchangeI This user is from outside of this forum
                      iampytest1@infosec.exchange
                      schrieb zuletzt editiert von
                      #12

                      @eb while that is a good guess, and may be part of the reason, the owner told me they only put it on the CAPTCHA page because:

                      We do not want to ddos them to death, just attract attention and increase their hosting bill

                      Read that as you will.

                      eb@social.coopE 1 Antwort Letzte Antwort
                      0
                      • eb@social.coopE eb@social.coop

                        But what's really interesting is the motivations.

                        1. Why now, after 2 years?
                        2. Why run a DDoS, and yet defend Jani in the comments?: https://news.ycombinator.com/item?id=46629823
                        3. Why register for a forum using your "name" to draw attention to a DDoS being ran by *your own site*?

                        This seems like a ploy for attention. Perhaps the FBI has finally found him and Masha wants to go out on his own terms?: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tries-to-unmask-mysterious-founder-of-archive-today/

                        Perhaps Masha is a fake name and the real name leaked so he wants to publicize Masha? 🧵

                        iampytest1@infosec.exchangeI This user is from outside of this forum
                        iampytest1@infosec.exchangeI This user is from outside of this forum
                        iampytest1@infosec.exchange
                        schrieb zuletzt editiert von
                        #13

                        @eb I can't answer #2 and #3, but I emailed the owner and asked why they waiting 3 years, and they gave the fairly strange response that since the person/people mentioned in the article recently became EU citizens, the blog post now violated GDPR.
                        Even taking that at face value, it doesn't really explain why they chose to launch a DDoS attack.

                        https://infosec.exchange/@iampytest1/115905994565109535

                        Just out of curiosity, do you know Jani Patokallio?

                        eb@social.coopE 1 Antwort Letzte Antwort
                        0
                        • liquidparasyte@app.wafrn.netL liquidparasyte@app.wafrn.net

                          Are you saying that the landing page I've been redirected to for the past 5 years on the archive.today network has actually been a DDOS tool the whole time?

                          Or is it just discreetly packaged alongside Google reCAPTCHA?

                          iampytest1@infosec.exchangeI This user is from outside of this forum
                          iampytest1@infosec.exchangeI This user is from outside of this forum
                          iampytest1@infosec.exchange
                          schrieb zuletzt editiert von
                          #14

                          @liquidparasyte No, it hasn't been that way for the last 5 years.
                          The blog post which seemingly sparked this came out 3 years ago, and the malicious code was only added a few days ago.

                          And also, reCAPTCHA is not the source of the malicious code. There is just a small script at the bottom of the page, added by the owner and separate from reCAPTCHA, which performs the DDoS.

                          1 Antwort Letzte Antwort
                          0
                          • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                            @eb while that is a good guess, and may be part of the reason, the owner told me they only put it on the CAPTCHA page because:

                            We do not want to ddos them to death, just attract attention and increase their hosting bill

                            Read that as you will.

                            eb@social.coopE This user is from outside of this forum
                            eb@social.coopE This user is from outside of this forum
                            eb@social.coop
                            schrieb zuletzt editiert von
                            #15

                            @iampytest1 you're in contact with the admin of archive.today? can you put me in contact with them?

                            iampytest1@infosec.exchangeI 1 Antwort Letzte Antwort
                            0
                            • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                              @eb I can't answer #2 and #3, but I emailed the owner and asked why they waiting 3 years, and they gave the fairly strange response that since the person/people mentioned in the article recently became EU citizens, the blog post now violated GDPR.
                              Even taking that at face value, it doesn't really explain why they chose to launch a DDoS attack.

                              https://infosec.exchange/@iampytest1/115905994565109535

                              Just out of curiosity, do you know Jani Patokallio?

                              eb@social.coopE This user is from outside of this forum
                              eb@social.coopE This user is from outside of this forum
                              eb@social.coop
                              schrieb zuletzt editiert von
                              #16

                              @iampytest1 I have had email correspondence with Jani but I do not know them personally.

                              1 Antwort Letzte Antwort
                              0
                              • eb@social.coopE eb@social.coop

                                @iampytest1 you're in contact with the admin of archive.today? can you put me in contact with them?

                                iampytest1@infosec.exchangeI This user is from outside of this forum
                                iampytest1@infosec.exchangeI This user is from outside of this forum
                                iampytest1@infosec.exchange
                                schrieb zuletzt editiert von
                                #17

                                @eb I just emailed webmaster@archive.ph, which is the email listed on their website, and they responded using norapuchreiner@cofed.com.

                                eb@social.coopE 1 Antwort Letzte Antwort
                                0
                                • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                                  @eb I just emailed webmaster@archive.ph, which is the email listed on their website, and they responded using norapuchreiner@cofed.com.

                                  eb@social.coopE This user is from outside of this forum
                                  eb@social.coopE This user is from outside of this forum
                                  eb@social.coop
                                  schrieb zuletzt editiert von
                                  #18

                                  @iampytest1 Thanks.

                                  iampytest1@infosec.exchangeI 1 Antwort Letzte Antwort
                                  0
                                  • eb@social.coopE eb@social.coop

                                    @iampytest1 Thanks.

                                    iampytest1@infosec.exchangeI This user is from outside of this forum
                                    iampytest1@infosec.exchangeI This user is from outside of this forum
                                    iampytest1@infosec.exchange
                                    schrieb zuletzt editiert von
                                    #19

                                    @eb Their email responses were all pretty much 1/2 sentence(s) long.
                                    I posted verbatim quotes here: https://infosec.exchange/@iampytest1/115905846553756281
                                    But if you are curious, I can post/share the full exchange.

                                    They did respond very quickly, sometimes within a minute.

                                    1 Antwort Letzte Antwort
                                    0
                                    • eb@social.coopE eb@social.coop

                                      I also just wish to stress that by visiting archive.today or related web properties your device is being used as a participent in a DDoS attack against Jani. archive.today is not safe to use. 🧵

                                      semitones@tiny.tilde.websiteS This user is from outside of this forum
                                      semitones@tiny.tilde.websiteS This user is from outside of this forum
                                      semitones@tiny.tilde.website
                                      schrieb zuletzt editiert von
                                      #20

                                      @eb I am out of the loop on all this gyrovague doxxing and archive.today, who are these people and what is going on?

                                      eb@social.coopE 1 Antwort Letzte Antwort
                                      0
                                      • semitones@tiny.tilde.websiteS semitones@tiny.tilde.website

                                        @eb I am out of the loop on all this gyrovague doxxing and archive.today, who are these people and what is going on?

                                        eb@social.coopE This user is from outside of this forum
                                        eb@social.coopE This user is from outside of this forum
                                        eb@social.coop
                                        schrieb zuletzt editiert von
                                        #21

                                        @semitones the administrators of archive.today are using the visitor’s browser to spam requests to gyrovague, who they accuse of doxxing them, while simultaneously doxxing themselves in the process

                                        semitones@tiny.tilde.websiteS 1 Antwort Letzte Antwort
                                        1
                                        0
                                        • eb@social.coopE eb@social.coop

                                          @semitones the administrators of archive.today are using the visitor’s browser to spam requests to gyrovague, who they accuse of doxxing them, while simultaneously doxxing themselves in the process

                                          semitones@tiny.tilde.websiteS This user is from outside of this forum
                                          semitones@tiny.tilde.websiteS This user is from outside of this forum
                                          semitones@tiny.tilde.website
                                          schrieb zuletzt editiert von
                                          #22

                                          @eb I am not sure what gyrovague is, but ublock origin blocks it as part of HaGeZi - multi ultimate mini blocklist. Not sure why.

                                          Also not sure what gyrovague said but since the website is blocked and ddg is not helpful I'm still in the dark unfortunately...

                                          eb@social.coopE 1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum