What are the consequences of executing from cdnjs.cloudflare.com? I don't trust CF in general & try not to connect to them, so then I went to this link instead of the original: web.archive.org/web/www.ran.or That avoids . But why did the PDF load?

The original URL would not give the PDF without running CF JS. Yet archive.org avoids CF JS. Is archive.org simply delivering copies of the CF JS as though it's first-party ?

Show thread

@resist1984 Archive.org archives the whole website including stylesheets, script files and images. So you load the same JS file from web.archive.org instead of CF.

@resist1984 Actually it's not exactly the same, archive.org seems to make some modifications.

@t0k well it seems there is no viable option. Once I knew the full PDF URL, it's fine because the js doesn't block a direct download (i can load the PDF in a non-js browser). But apparently executing the js is mandatory if you only know the parent URL that contains the pdf link (ran.org/bankingonclimatechaos2)

@resist1984 I just managed to. Again, open the source code of the page, search for 'pdf'. Then right-click on the desired link -> Copy Link Location. Paste the link in the URL bar and enjoy the PDF :)

@t0k when viewing this: view-source:ran.org/bankingonclimatechaos2 searching for pdf only has 3 hits, and none of them are "Banking-on-Climate-Chaos-2021.pdf"

@resist1984 Hmm.. true. So yes, seems like the link is loaded or generated by some script. Regarding trackers that site is horrible anyway.

Follow

@t0k what's eye-opening for me is that as uMatrix defaults to trusting 1st party javascript (which most users probably accept), but in the case of archive.org all 3rd party js gets repackaged as 1st party. i guess i'll setup uMatrix to refuse all js from archive.org

Sign in to participate in the conversation
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!