If it identifies itself as archive.is, then other people could identify themselves the same way.
Theoretically, they could just publish the list of IP ranges that canonically "belongs" to archive.is. That would allow websites to distinguish if a request identifying itself as archive.is is actually from them (it fits one of the IP ranges), or is a fraudster.
It would be far better and more secure for archive.is to publish a public key on its site and then sign requests from its private key, which sites could optionally verify.
Comments
Theoretically, they could just publish the list of IP ranges that canonically "belongs" to archive.is. That would allow websites to distinguish if a request identifying itself as archive.is is actually from them (it fits one of the IP ranges), or is a fraudster.
It would be far better and more secure for archive.is to publish a public key on its site and then sign requests from its private key, which sites could optionally verify.
You just described client certificate auth
+1 on this!
In theory, this might work. But is it true? Do lots of sites have an archive.is whitelist?
I really don't see why they would, if they're using a paywall in the first place.
Follow the magnolia trail...