Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

131–140 of 648 posts

Re: Internet Archive: Security breach alert

#132
post #115
post #103

Earlier quoted context omitted.

There is a big difference between doing something for pure curiosity, love, or exploration and doing something directly harmful to other people for the same reasons. One is art; the other is sadism.

I'm not sure that placing free long distance calls isn't harmful to the org whose infrastructure you're using for your own benefit, but 2600 (Hz) is a respected hacker magazine and phreaking and Cap'n crunch whistles are seen as cool Hacking the Internet Archive and only placing an alert with a provocative message, I could see my teenage self do that. My judgment of the character is going to depend on what it turns o…

> I'm not sure that placing free long distance calls isn't harmful to the org whose infrastructure you're using for your own benefit,

If there's a call you wouldn't make unless it was free, the infrastructure isn't at capacity, and you're not acting otherwise in a detrimental fashion to other users of the infrastructure-- there's no harm to that organization.

Re: Internet Archive: Security breach alert

#133

“According to their twitter, they’re doing it just to do it. Just because they can. No statement, no idea, no demands.” A special place in Hell…

>No statement, no idea, no demands. A special place in Hell…

I mean... would it be better if the hackers had asked for money or did it to protest global warming or something?

Re: Internet Archive: Security breach alert

#134
post #83
post #67

Earlier quoted context omitted.

What are they looking for here? Negative karma?

[flagged]

By "working idea" do you mean something that you made up in your head which has no basis in reality, but works for you?

Edit: I had only seen the one post on X in which responsibility for the attack was claimed when I made this comment, but looking at the account further they do make many politically motivated comments.

With this new insight my comment now seems unnecessarily dismissive because it's not completely unreasonable to suspect false flag attacks when political motivations are being broadcast. To be clear I'm not making any assumptions for this specific case one way or the other, but I am acknowledging that the political speech presented by the attackers does add some merit to your suspicion.

Re: Internet Archive: Security breach alert

#135
post #132
post #115

Earlier quoted context omitted.

I'm not sure that placing free long distance calls isn't harmful to the org whose infrastructure you're using for your own benefit, but 2600 (Hz) is a respected hacker magazine and phreaking and Cap'n crunch whistles are seen as cool Hacking the Internet Archive and only placing an alert with a provocative message, I could see my teenage self do that. My judgment of the character is going to depend on what it turns o…

> I'm not sure that placing free long distance calls isn't harmful to the org whose infrastructure you're using for your own benefit, If there's a call you wouldn't make unless it was free, the infrastructure isn't at capacity, and you're not acting otherwise in a detrimental fashion to other users of the infrastructure-- there's no harm to that organization.

Certainly a fair point, but it also costs a lot of person-hours to patch up that infrastructure's security and trace who's placing the calls when one could just choose not to do this fraud in the first place. I am not old enough to know whether carriers also charged each other back then, but at least nowadays it could also incur charges for the originating party; costs which the caller isn't covering

Toying with the system, learning how it works and finding what you can make it do, there's a certain art to it and I'd encourage anyone to at least tinker with the systems they own (and everything else within reason and ethics), but there's two sides to nearly everything

Re: Internet Archive: Security breach alert

#136
post #55

https://www.reddit.com/r/DataHoarder/comments/h02jl4/lets_sa... I found this reddit thread from /r/DataHoarder about backing up the internet archive particularly interesting, given the circumstances

It's been tried several times, but it's hard because it's such a massive quantity of data. The IPFS backup never really got off the ground. They have their own backups which I think is good enough for now unless someone plans on donating a few hundred million.

Oh no! I didn't know their IPFS initiative didn't pan out. What happened to it? I am surprised how hard it is to google. I remember interviewing for a role on that team at the archive to help move it to filecoin. Was so happy to hear that the effort was underway to decentralize their datastore. We need this more than ever.

Re: Internet Archive: Security breach alert

#137

“According to their twitter, they’re doing it just to do it. Just because they can. No statement, no idea, no demands.” A special place in Hell…

>No statement, no idea, no demands. A special place in Hell… I mean... would it be better if the hackers had asked for money or did it to protest global warming or something?

"Say what you will about the tenets of National Socialism, but at last it's an ethos."

Re: Internet Archive: Security breach alert

#139

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

It's called torrent protocol and it doesn't work, no one wants to spend money and bandwidth hosting a god forsaken movie or book that only a handful of people care about.

It does work, when you don't notice it. We need sane limits and permanent seeders. This is why so many regular people get hit with ISP notices, they don't know they've seeded Captain America for the last six months every time they started their PC.

Re: Internet Archive: Security breach alert

#140
A few minutes ago (22:48 UTC), I got three emails from HIBP about accounts of mine breached on the Internet Archive. Troy is quick! And I'm surprised the author of that alert() actually had the data as well as followed through

Bit of a shame the emails contain an ad for a password manager, saying there's two easy steps to become more secure: Step 1: use our password manager (fair enough), "Step 2: Enable 2 factor authentication and store the codes inside your [password manager]" ehh now it's back to 1 factor or am I missing something?

Edit: according to https://www.bleepingcomputer.com/news/security/internet-arch... (via https://news.ycombinator.com/item?id=41793669), Troy Hunt / HIBP already received and verified this "three days ago" as of yesterday 6pm AoE

Post reply on HN