Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

331–340 of 648 posts

Re: Internet Archive: Security breach alert

#332
post #128

Earlier quoted context omitted.

I have always thought about this. It would be interesting to have users actually store small amounts of redundant info on a device connected to the internet. Very similarly to what a torrent does but with more peers (more data shards than full copies) and less seeds. And try and keep a huge database for everyone. Obviously open source and it would end up something like tor where they just assist the network with secu…

The main issue that such hosting faces is that it's less efficient and more expensive than just regular centralized servers.

Anything would be better than the current system where you basically just have one source.

Independently ran mirrors all over the world, along with snapshots.

Have the occasional fork or two. Say your from a small town in Northern Illinois. If you have 2 TB of image archives from a defunct local newspaper, it might be good for photography forks even if it wouldn't make sense for the main archive.

Re: Internet Archive: Security breach alert

#333

Earlier quoted context omitted.

True hackers probably have a special place in hell, but, in a good sense.

If god is the good guy and satan is the bad guy - why do bad people sent to hell? They would just chill with the devil laughing about all the DDoS they did for the lulz.

Satan is canonical for one thing in particular out of most things - he does not like humanity. Getting sent there isn't a fun field trip where you get to hang out with your buddies/partners in crime after the game is over, presumably.

Think of it more along the lines of you having a blinding hatred of mosquitos, and then they keep getting sent to you, and at the same time you're a very powerful, capable individual who can deal with hordes of mosquitos in fantastically wicked ways.

Re: Internet Archive: Security breach alert

#334
post #2

Just noticed the site now alerts this: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!

Jokes on them... I'm already on HIBP countless of times...

I'm also on HIBP over 10x. What are we supposed to do? Create a new email address for every service we sign up for?

I don't know what the best practice is for keeping our personal data safe anymore.

Re: Internet Archive: Security breach alert

#335

Probably not the best time to say this, but it's surprisingly easy to go through a collection with items and grab every email along with the usernames. https://archive.org/metadata/naturally_a_girl/metadata One way or another, there was going to be someone who would take loads of emails with a username attached to it. A bit intrigued by how the hacker compromised the database and got the passwords.

Yeah, they have ignored everyone's concerns about the email thing. https://github.com/internetarchive/iaux/issues/892

Re: Internet Archive: Security breach alert

#336
post #57

Earlier quoted context omitted.

It's all good, as long as you're not in that recent AI Girlfriend breach which exposed a ton of users who were trying to coax it into generating CSAM images. https://x.com/troyhunt/status/1843788319785939422

“I went to the site to jerk off (to an adult scenario, to be clear) and noticed that it looked like it [the Muah.ai website] was put together pretty poorly,” the hacker told 404 Media. “It's basically a handful of open-source projects duct-taped together. I started poking around and found some vulnerabilities relatively quickly. At the start it was mostly just curiosity but I decided to contact you once I saw what wa…

True penetration testing.

Re: Internet Archive: Security breach alert

#337
post #151

More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-arch...

> The data will soon be added to HIBP My unique-to-archive.org email address is not there yet.

Out of curiosity, do you use a unique email address for every single service?

Re: Internet Archive: Security breach alert

#338

Earlier quoted context omitted.

To be even easier, you can just have Apple or Google hold your domain and provide mail.

I'm not 100% sure that that gets you wildcard email addresses that all point to the same inbox, but if they support that, sure!

Google has it, though I think you need the paid Workspace version? I’m paying around $15/month now ever since google killed the free tier for custom domains.

Re: Internet Archive: Security breach alert

#339
post #173

Earlier quoted context omitted.

Voluntary sharing, since afaik they don't pay the criminals to get the data. Either the criminals share it directly (fat chance, usually), or someone else bought it and shared it either publicly, privately with HIBP, or privately with someone who then reported it to HIBP How this specific instance unfolded, time will have to tell. The leak may have occurred in 2020 for all we know at this point

There is a strange dynamic between the threat actors who conduct these breaches and researchers. When not used for extortion and for "status" in the hacking community, they share them with researchers (commonly HIBP) to warn people about a site's security and so that site is forced to fix things. Definitely a strange dynamic.

A form of ‘counting coup’ I imagine. [https://en.m.wikipedia.org/wiki/Counting_coup]
Post reply on HN