Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

211–220 of 648 posts

Re: Internet Archive: Security breach alert

#211

More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-arch...

> the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service Do they? Why?

Anyone who buys it or finds it in the wild can also upload it.

Re: Internet Archive: Security breach alert

#212
post #89

Reporting on security issues is always so terrible. Is it a data breach or is it a DDoS? (Or both). Those are opposite things. One is trying to release secret information one is trying to make the site inaccessible.

It is both. They got attacked by a DDOS after the security breach.

Which is pretty common. While the org is running around dealing with the DDoS, they're not doing anything to fix their systems. In this case, I can't even get to my account page on IA to change my password.

Re: Internet Archive: Security breach alert

#213
Probably not the best time to say this, but it's surprisingly easy to go through a collection with items and grab every email along with the usernames.

https://archive.org/metadata/naturally_a_girl/metadata

One way or another, there was going to be someone who would take loads of emails with a username attached to it. A bit intrigued by how the hacker compromised the database and got the passwords.

Re: Internet Archive: Security breach alert

#214
One of the many benefits of owning my own email server:

- I have a catch all setup to forward all emails to specific user on mail server

- able to setup adhoc email addresses for each online service (ie, iarch@example.com)

- able to claim example.com in haveibeenpwned

Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

Re: Internet Archive: Security breach alert

#215
post #87

Earlier quoted context omitted.

How long does an average hard drive last? You'd have to spend that 700k every that many years (plus the extra bits you mentioned). Quite an operation actually

If this is a backup, you don't need it to be powered up and available 24x7. So the question becomes more like "how long does an average hard drive last while powered down and still reliably be able to power back up and be read?". I'm fairly sure that is a lot longer than the single digit years that'd be the probably answer to your question. I wonder if there are useful guidelines for long term storage of powered down…

> I wonder how hard it'd be to find hardware that'd read my Mac SCSI hard drives from 25 years ago?

Easy… that original Mac is sitting in my basement and it worked like a charm last time it was powered on 4 years ago.

Re: Internet Archive: Security breach alert

#216
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

I do the same thing. Absolutely worth the small hassle.

Re: Internet Archive: Security breach alert

#217
post #135
post #132

Earlier quoted context omitted.

> I'm not sure that placing free long distance calls isn't harmful to the org whose infrastructure you're using for your own benefit, If there's a call you wouldn't make unless it was free, the infrastructure isn't at capacity, and you're not acting otherwise in a detrimental fashion to other users of the infrastructure-- there's no harm to that organization.

Certainly a fair point, but it also costs a lot of person-hours to patch up that infrastructure's security and trace who's placing the calls when one could just choose not to do this fraud in the first place. I am not old enough to know whether carriers also charged each other back then, but at least nowadays it could also incur charges for the originating party; costs which the caller isn't covering Toying with the…

[flagged]

Re: Internet Archive: Security breach alert

#218
The reported alert on the site states:

> Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!

But is this an official message from the company? It sounds odd and unprofessional, especially the "See 31 million of you on HIBP!" part, which jokingly refers to a huge privacy issue for users. Could it also be that the site was hacked, with hackers posting that message in addition to the data breach and DDoS attack?

Re: Internet Archive: Security breach alert

#219
post #173

Earlier quoted context omitted.

How do they get a hold of all these leaks so fast?

Voluntary sharing, since afaik they don't pay the criminals to get the data. Either the criminals share it directly (fat chance, usually), or someone else bought it and shared it either publicly, privately with HIBP, or privately with someone who then reported it to HIBP How this specific instance unfolded, time will have to tell. The leak may have occurred in 2020 for all we know at this point

"Breach date: 28 September 2024" - I'm assuming they've checked with some recent signups to confirm the timeframe.

https://haveibeenpwned.com/PwnedWebsites#InternetArchive

Re: Internet Archive: Security breach alert

#220

The reported alert on the site states: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP! But is this an official message from the company? It sounds odd and unprofessional, especially the "See 31 million of you on HIBP!" part, which jokingly refers to a huge privacy issue for users.…

It's a thankless job to be always begging for donations to keep something working when the Internet at large doesn't value it as much as it should. And now getting targeted like that? I wouldn't judge them if this is an official communication coming from exhausted and frustrated staff.
Post reply on HN