Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

31–40 of 648 posts

Re: Internet Archive: Security breach alert

#31
post #26
post #23

Earlier quoted context omitted.

You mean the IA included some JS polyfill from a subdomain and that's what's compromised / where the alert is coming from?

yes, " https://polyfill.archive.org/v3/polyfill.min.js?features=fet... " is the URL with the malicious code

It looks like it is running the service that was part of the supply chain attacker earlier this year. https://github.com/polyfillpolyfill/polyfill-service/issues/...

Re: Internet Archive: Security breach alert

#32

Archive.org is now down. Could anyone explain what it used to show?

A pop-up that said,

"Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!"

Re: Internet Archive: Security breach alert

#35
post #32

Archive.org is now down. Could anyone explain what it used to show?

A pop-up that said, "Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!"

I had to look it up, but I guess HIBP refers to https://haveibeenpwned.com/

Re: Internet Archive: Security breach alert

#39
post #3

Earlier quoted context omitted.

Is it a genuine alert, or hacking artifact? Sometimes with friendly / attempt-at-humorous error messages it’s difficult to tell

It's a literal window.alert()

But was that code placed there by IA or by the malicious party?
Post reply on HN