Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

221–230 of 648 posts

Re: Internet Archive: Security breach alert

#221
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

Google workspace lets you do it if they mange emails for your domain (and it will cost ~5-10$/month if you are the only user)

https://support.google.com/a/answer/12943537?hl=en

Re: Internet Archive: Security breach alert

#223

The reported alert on the site states: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP! But is this an official message from the company? It sounds odd and unprofessional, especially the "See 31 million of you on HIBP!" part, which jokingly refers to a huge privacy issue for users.…

The alert is gone now. It appears the attacker compromised their front end deployment

Re: Internet Archive: Security breach alert

#224

The reported alert on the site states: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP! But is this an official message from the company? It sounds odd and unprofessional, especially the "See 31 million of you on HIBP!" part, which jokingly refers to a huge privacy issue for users.…

Troy Hunt's tweet mentions the IA getting breached, defaced AND DDoSed. Here it is, in case you don't want to use that site:

>>>

Let me share more on the chronology of this:

30 Sep: Someone sends me the breach, but I'm travelling and didn't realise the significance

5 Oct: I get a chance to look at it - whoa!

6 Oct: I get in contact with someone at IA and send the data, advising it's our goal to load within 72 hours

7 Oct: They confirm and I ask for a disclosure notice

8 Oct: I follow up on the disclosure notice and advise we'll load tomorrow

9 Oct: They get defaced and DDoS'd, right as the data is loading into HIBP

The timing on the last point seems to be entirely coincidental. It may also be multiple parties involved and when we're talking breach + defacement + DDoS, it's clearly not just one attack.

<<<

Re: Internet Archive: Security breach alert

#225
I wonder how they got access the their database? I read in this thread that they likely used a supply chain attack by replacing some polyfill scripts. So they could've injected malicious code (XSS) that logged email and password to a remote server which they could have gone through. With a bit of luck they couldve gotten access to an admin account or whatever…

Re: Internet Archive: Security breach alert

#226
Confused about this breach... I received a notification from HIBP about this hack, but I don't recall ever creating an account on archive.org (was creating an account there even a thing?).

What info does archive.org have on people? Is this info scraped from other websites and stored in the archive.org database? Or is this info related to personal archive.org accounts (as I said I don't recall making an account)?

Re: Internet Archive: Security breach alert

#227
post #87

Earlier quoted context omitted.

How long does an average hard drive last? You'd have to spend that 700k every that many years (plus the extra bits you mentioned). Quite an operation actually

I actually find that fairly tame. For a point of comparison, Wikipedia gets ~$150M in revenue a year, an "asset rise" (I presume this is what non-profits call profit?) of ~$15M a year, and is sitting on about a quarter billion in the bank. Not that they want to, but I think Wikipedia could fund this using their current donations if they wanted. Hell, I almost wonder if one of the big storage providers would do it for…

They should probably consider it, really.

A good portion of the text on Wikipedia relies on Wayback Machine links to remain verifiable. If they lose that, I guess the editors might have to comb every page for information which would need to be either resourced or deleted.

Re: Internet Archive: Security breach alert

#228
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

All things that aren’t remotely unique to running your own mail server.

Re: Internet Archive: Security breach alert

#229
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

You can do this easily (and for free) via Cloudflare [1]. Works great, I've been using it across several domains for quite some time. Migrated from Google.

[1] https://www.cloudflare.com/en-ca/developer-platform/email-ro...

Re: Internet Archive: Security breach alert

#230
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

The only drawback being that all of your outgoing email is sent directly to the receiver’s spam folder..?
Post reply on HN