Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

archive.today doesn't use a real recaptcha, the cloudflare page isn't real either. it serves that as a punishment for using 1.1.1.1 DNS because the owner doesn't like that 1.1.1.1 doesn't send EDNS client subnets.
 help



They're definitely trying to mimic the cloudflare captcha page, but...

>archive.today doesn't use a real recaptcha

How? It's loading the script from google, and the images/responses are from google to.


I recall that the 1.1.1.1 block page doesn't serve the real one,, but the challenge page that they serve normally does. Maybe I'm misremembering? or maybe they changed it.

I just tested and it's the "real" recaptcha, with requests to google and everything. It still might be "fake" in the sense that the server rejects any response, even valid ones, which is probably what's actually happening.

What do you mean by "a real recaptcha"? I just went to an archive.is page, and it's trying to load a script from www.google.com. Doesn't Google still own reCAPTCHA?

> On 14 January 2026, it emerged that archive.today had silently modified its CAPTCHA page to send repeated requests to Gyrovague, thereby causing visitors to unwittingly contribute to a DDOS attack against the blog.

https://en.wikipedia.org/wiki/Archive.today#2026_attack_on_G...


It is telling that HN moderators allow links to archive.is/today

Rather than telling us that it is telling, perhaps you should tell us what it tells you and why?

Better to just ignore the anti-Russian and hasbara spam. It's being posted opportunistically. The chance to attack archive.is in an organically posted thread is probably the only reason an intermittent outage (common) of archive.is was upvoted enough to make it to the front page. Look at the top comment.

Why does it feel like everyone has just ignored/memory-holed this?

https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-a...

That whole debacle is even specifically relevant to this thread because the operator of archive.today (aka archive.is) was caught using a script on its captcha page to make visitors' browsers connect to the blog they were mad at. That's how their DDOS attack worked. They used their own visitors, who naturally trusted the captcha page, to commit a crime.

For whatever reason, with the exception of Wikipedia (bless the editors), they seem to have gotten away with this, as well as with deliberately falsifying the content of "archived" pages (as described in the arstechnica article), without consequences.

So, call me crazy or a Russian bot if you want, but I think it's reasonable to be suspicious of any weird captcha behavior from this website in particular.


And HN users are being used as part of these attacks?

It tells us that the moderators of HN support copyright infringement and DDOS attacks. They are actively moderating this forum and choosing to do nothing.

They also choose to do nothing about uncharitable interpretations of their inactions. Should they act there too? Or do you prefer the hands-off approach when it suits you?

I can't control their behavior nor can you. But if you don't want to respond to the substance of my comment then perhaps you shouldn't respond?

I don't think it's very interesting even if true. I'm not that fussed about copyright infringement myself and I don't consider using archive.is (infrequently) to be condoning their DDOS.

Presumably you are and do. We differ.


This isn't about you personally. There is a public interest here.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: