Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

171–180 of 648 posts

Re: Internet Archive: Security breach alert

#171
post #50
post #34

That's a shame. We need not one but many internet archives. Just one and we will repeat the outcome of the Library of Alexandria.

The Library of Alexandria wasn't that significant and likely wasn't destroyed in one cataclysmic event, but rather centuries of neglect.

Here is a great video on the subject in case folks want to learn more: https://m.youtube.com/watch?v=M4WU8gqrgsQ

Re: Internet Archive: Security breach alert

#172

Earlier quoted context omitted.

It's been tried several times, but it's hard because it's such a massive quantity of data. The IPFS backup never really got off the ground. They have their own backups which I think is good enough for now unless someone plans on donating a few hundred million.

Oh no! I didn't know their IPFS initiative didn't pan out. What happened to it? I am surprised how hard it is to google. I remember interviewing for a role on that team at the archive to help move it to filecoin. Was so happy to hear that the effort was underway to decentralize their datastore. We need this more than ever.

There are people still working on trying to make it happen but it's just a collosal amount of data and filesystems are notoriously hard, so it's very slow going.

From my own personal experience doing distributed archiving with no relation to Archive.org, Filecoin/IPFS's UX isn't quite there yet. They still don't let you serve data to the network from a normal filesystem, you have to let their system ingest all of your stuff so you end up double-storing data or you have to give into everything being stored as inscrutable binary blobs.

That's why I still haven't integrated ArchiveBox with IPFS/Filecoin/Storj, let my data live in a normal filesystem dammit!

Re: Internet Archive: Security breach alert

#173
post #151

Earlier quoted context omitted.

> The data will soon be added to HIBP My unique-to-archive.org email address is not there yet.

How do they get a hold of all these leaks so fast?

Voluntary sharing, since afaik they don't pay the criminals to get the data. Either the criminals share it directly (fat chance, usually), or someone else bought it and shared it either publicly, privately with HIBP, or privately with someone who then reported it to HIBP

How this specific instance unfolded, time will have to tell. The leak may have occurred in 2020 for all we know at this point

Re: Internet Archive: Security breach alert

#174
post #87
post #65

Earlier quoted context omitted.

50 PB * $0.014/GB = $0.7M. $0.014/GB is from[1], bare drive cost without chassis, power, or redundancy. 1: https://www.backblaze.com/blog/hard-drive-cost-per-gigabyte/

How long does an average hard drive last? You'd have to spend that 700k every that many years (plus the extra bits you mentioned). Quite an operation actually

If this is a backup, you don't need it to be powered up and available 24x7.

So the question becomes more like "how long does an average hard drive last while powered down and still reliably be able to power back up and be read?".

I'm fairly sure that is a lot longer than the single digit years that'd be the probably answer to your question.

I wonder if there are useful guidelines for long term storage of powered down hard drives? My gut feel is the major failure modes would be electrolytic capacitor failure, bearings sticking as the lubrication ages, and obseleting of the interfaces. I wonder how hard it'd be to find hardware that'd read my Mac SCSI hard drives from 25 years ago?

Re: Internet Archive: Security breach alert

#176
post #140

A few minutes ago (22:48 UTC), I got three emails from HIBP about accounts of mine breached on the Internet Archive. Troy is quick! And I'm surprised the author of that alert() actually had the data as well as followed through Bit of a shame the emails contain an ad for a password manager, saying there's two easy steps to become more secure: Step 1: use our password manager (fair enough), "Step 2: Enable 2 factor aut…

I was going to disagree with you (and I sort of do about password managers and storing 2FA in them, but I also unlock my password manager with a yubikey).

But, doesn't a DB compromise mean that the attacker would have the TOTP seed as well? It can only increase your account security elsewhere, but also not re-using password prevents the IA leak from hurting you elsewhere as well?

Re: Internet Archive: Security breach alert

#177
post #87
post #65

Earlier quoted context omitted.

50 PB * $0.014/GB = $0.7M. $0.014/GB is from[1], bare drive cost without chassis, power, or redundancy. 1: https://www.backblaze.com/blog/hard-drive-cost-per-gigabyte/

How long does an average hard drive last? You'd have to spend that 700k every that many years (plus the extra bits you mentioned). Quite an operation actually

> How long does an average hard drive last? You'd have to spend that 700k every that many years (plus the extra bits you mentioned). Quite an operation actually

You'd have to spend a lot more, because with that many drives, you need redundancy now.

Re: Internet Archive: Security breach alert

#178
post #164

More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-arch...

Friendly reminder to generate a unique password for every account you create so database leaks like this one don't bother you (besides on the site they're used).

MFA

Re: Internet Archive: Security breach alert

#180
post #95

“According to their twitter, they’re doing it just to do it. Just because they can. No statement, no idea, no demands.” A special place in Hell…

That's a strange thing to read on Hacker news. Isn't that description the definition of hack value? As in http://www.catb.org/jargon/html/H/hack-value.html Now, it depends what the "it" is referring to here, but so far all I've heard is about an alert() message saying the usernames will be sent to a breach alerting site. If they're doing it just for the heck of it, it's still costing a lot of people a lot of time tha…

True hackers probably have a special place in hell, but, in a good sense.
Post reply on HN