The interesting thing is it looks like the DNS servers are offline. I suspect instead of going after the site they went after the 2 DNS servers(DDOS maybe?). Still seems reachable with a hosts file.
Is it recommended that people modify their hosts files too now, or is the IP situation pessimistic enough to not make it worth it?
Do I need to keep a list of DNS provider IPs
to cycle through just in case they start nullrouting KF or is keeping the onion links resilient enough?
I wrote this on Telegram, but I will repost it here:
I propose a great Kiwi Farms cleansing. Ban all accounts created before 2022 with 4 posts or less. verified accounts and people of interest excluded. Also, keep the registrations invite only permanently.
Opinions? Do you think that this is a retarded idea?
EDIT: The alternative would be to ban all accounts that haven't logged in for a year or longer, again verified accounts and people of interest excluded.
I'm biased as my post count is low, but I will say no, please. I'd be ok with being quarantined to read/sticker/bookmark only mode in most subforums until I prove I'm
dumb but not malicious, however.
As for why I didn't post before if I cared about the site? You know the scary warning you get when you register to not be a dumbass and link KF to your other identities? I've heard stories about people being similarly dumb and linking their tor identities to their real identities based on temporal correlation or something. I'm probably still doing opsec wrong, but I figure I should at least segregate onion posts, so I only post when forced to onion.
I've a question that I think people should consider-
Is the warrant canary still active on the site?
Just clicked on the canary and it seems to be dead. RIP canary.
Anyone got Null's public key handy just in case? Obviously I'd have preferred to download it directly if I had had the foresight, but I'm dumb.
2FA compromises anonymity.
How? The options here are app generation (no other accounts required) and email (which you already gave up to register). We don't have text based verification.
Not an expert on the matter, but what if you use Guerrillamail for that? They save emails at most for an hour and they don't need registration. You can even visit their website via TOR. Take a look yourself, if you're not familiar with them.
Guerrillamail. Click the "WTF?"-Button, to get an explanation of what they are doing.
NO. Dunno where but I know Null has said at least once to use a real inbox that only you control so that you can be contacted in case of major service disruptions and so nobody else can recover your account.
Get a burner tier real inbox like cock.li or lolcow.email. If you can afford to spend some money on it, maybe something like simplelogin or anonaddy which are forwarders that can encrypt any emails you receive so your email provider can't read them. Of course major fine print with forwarders however - you have to trust them to not scan your emails before encrypting them, and they might not hide the metadata/headers. Or if you self host the forwarder then you have to dox yourself to the domain registrar to get your domain. Or if you use one of the privacy focused domain registrars, what they actually do is buy the domain in their name and let you use it, so you don't really own it and it can be seized.
... Yeah, email is a mess. It's impossible to have something be secure, reliable and anonymous, and trying is expensive.