Internet Archive: Security breach alert
331–340 of 648 posts
Re: Internet Archive: Security breach alert
#332Earlier quoted context omitted.
I have always thought about this. It would be interesting to have users actually store small amounts of redundant info on a device connected to the internet. Very similarly to what a torrent does but with more peers (more data shards than full copies) and less seeds. And try and keep a huge database for everyone. Obviously open source and it would end up something like tor where they just assist the network with secu…
The main issue that such hosting faces is that it's less efficient and more expensive than just regular centralized servers.
Independently ran mirrors all over the world, along with snapshots.
Have the occasional fork or two. Say your from a small town in Northern Illinois. If you have 2 TB of image archives from a defunct local newspaper, it might be good for photography forks even if it wouldn't make sense for the main archive.
Re: Internet Archive: Security breach alert
#333Earlier quoted context omitted.
True hackers probably have a special place in hell, but, in a good sense.
If god is the good guy and satan is the bad guy - why do bad people sent to hell? They would just chill with the devil laughing about all the DDoS they did for the lulz.
Think of it more along the lines of you having a blinding hatred of mosquitos, and then they keep getting sent to you, and at the same time you're a very powerful, capable individual who can deal with hordes of mosquitos in fantastically wicked ways.
Re: Internet Archive: Security breach alert
#334Just noticed the site now alerts this: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!
Jokes on them... I'm already on HIBP countless of times...
I don't know what the best practice is for keeping our personal data safe anymore.
Re: Internet Archive: Security breach alert
#335Probably not the best time to say this, but it's surprisingly easy to go through a collection with items and grab every email along with the usernames. https://archive.org/metadata/naturally_a_girl/metadata One way or another, there was going to be someone who would take loads of emails with a username attached to it. A bit intrigued by how the hacker compromised the database and got the passwords.
Re: Internet Archive: Security breach alert
#336Earlier quoted context omitted.
It's all good, as long as you're not in that recent AI Girlfriend breach which exposed a ton of users who were trying to coax it into generating CSAM images. https://x.com/troyhunt/status/1843788319785939422
“I went to the site to jerk off (to an adult scenario, to be clear) and noticed that it looked like it [the Muah.ai website] was put together pretty poorly,” the hacker told 404 Media. “It's basically a handful of open-source projects duct-taped together. I started poking around and found some vulnerabilities relatively quickly. At the start it was mostly just curiosity but I decided to contact you once I saw what wa…
Re: Internet Archive: Security breach alert
#337More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-arch...
> The data will soon be added to HIBP My unique-to-archive.org email address is not there yet.
Re: Internet Archive: Security breach alert
#338Earlier quoted context omitted.
To be even easier, you can just have Apple or Google hold your domain and provide mail.
I'm not 100% sure that that gets you wildcard email addresses that all point to the same inbox, but if they support that, sure!
Re: Internet Archive: Security breach alert
#339Earlier quoted context omitted.
Voluntary sharing, since afaik they don't pay the criminals to get the data. Either the criminals share it directly (fat chance, usually), or someone else bought it and shared it either publicly, privately with HIBP, or privately with someone who then reported it to HIBP How this specific instance unfolded, time will have to tell. The leak may have occurred in 2020 for all we know at this point
There is a strange dynamic between the threat actors who conduct these breaches and researchers. When not used for extortion and for "status" in the hacking community, they share them with researchers (commonly HIBP) to warn people about a site's security and so that site is forced to fix things. Definitely a strange dynamic.