Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

341–350 of 648 posts

Re: Internet Archive: Security breach alert

#341
post #151

Earlier quoted context omitted.

> The data will soon be added to HIBP My unique-to-archive.org email address is not there yet.

Out of curiosity, do you use a unique email address for every single service?

Not the author but yes, I do. It’s trivially easy so why not?

Re: Internet Archive: Security breach alert

#342

Earlier quoted context omitted.

Jokes on them... I'm already on HIBP countless of times...

I'm also on HIBP over 10x. What are we supposed to do? Create a new email address for every service we sign up for? I don't know what the best practice is for keeping our personal data safe anymore.

Password manager + unique password per site + 2FA for anything of value.

Re: Internet Archive: Security breach alert

#343

Earlier quoted context omitted.

“I went to the site to jerk off (to an adult scenario, to be clear) and noticed that it looked like it [the Muah.ai website] was put together pretty poorly,” the hacker told 404 Media. “It's basically a handful of open-source projects duct-taped together. I started poking around and found some vulnerabilities relatively quickly. At the start it was mostly just curiosity but I decided to contact you once I saw what wa…

Not sure if you're being sarcastic or not, but pentesting is not a particularly evil activity — and you often have to look at data to see if you actually found something. What is evil is the way that he's ensured that the predators in the dataset will never face any consequences by making the data available to HaveIBeenPwned, making it trivial for predators to protect themselves (the method through which this is poss…

How would that protect predators?

Re: Internet Archive: Security breach alert

#344
post #123

Earlier quoted context omitted.

The undertone was intended to be: that's an insane amount of money, something one with quadruple that amount of experience would maybe earn in a for-profit organisation, but I guess your reaction further proves it's different where you're from

The IA is located in the Inner Richmond, which is a ~ medium income area of SF. Rent alone is ~ $4K, or ~ $60K of your income before taxes.

They might be there, but the position was remote-friendly.

Re: Internet Archive: Security breach alert

#345

Earlier quoted context omitted.

Can I ask why they're trying to dox you? I have literally never inspired this kind of passion on the internet--and I'm usually pretty blunt. I'm genuinely curious what it takes.

Attacks like that tend to have little to do with bluntness. They occur when you've touched something they consider to be theirs, and you are not entitled to. Usually that's some matter of group identity, where they feel the need to show off for each other just how angry they are at you. It has less to do with what you say or how you say it, but with who you are.

It sounds like it takes a lot of effort by intelligent people. Why would someone go to effort like that unless it was for something they believed was really important (I can't accept that it's just to show off your cronies / jelousy).

Re: Internet Archive: Security breach alert

#346
post #164

Earlier quoted context omitted.

Friendly reminder to generate a unique password for every account you create so database leaks like this one don't bother you (besides on the site they're used).

https://xkcd.com/2176/

I hadn't seen that one, I love it!

Re: Internet Archive: Security breach alert

#347

Earlier quoted context omitted.

Jokes on them... I'm already on HIBP countless of times...

I'm also on HIBP over 10x. What are we supposed to do? Create a new email address for every service we sign up for? I don't know what the best practice is for keeping our personal data safe anymore.

Using unique email addresses makes phishing attempts extremely obvious…

(No, this official looking email from my bank is fake since it was sent to Grocery@my.domain …)

Re: Internet Archive: Security breach alert

#348
post #123
post #101

Earlier quoted context omitted.

It's a non profit. You're probably not choosing to work for the IA for high compensation.

The undertone was intended to be: that's an insane amount of money, something one with quadruple that amount of experience would maybe earn in a for-profit organisation, but I guess your reaction further proves it's different where you're from

To put the reaction into context, the individual low income threshold in that area is 105k USD [0].

[0] https://www.hcd.ca.gov/sites/default/files/docs/grants-and-f...

Re: Internet Archive: Security breach alert

#350
post #95

“According to their twitter, they’re doing it just to do it. Just because they can. No statement, no idea, no demands.” A special place in Hell…

That's a strange thing to read on Hacker news. Isn't that description the definition of hack value? As in http://www.catb.org/jargon/html/H/hack-value.html Now, it depends what the "it" is referring to here, but so far all I've heard is about an alert() message saying the usernames will be sent to a breach alerting site. If they're doing it just for the heck of it, it's still costing a lot of people a lot of time tha…

Accessing the data is one (hackery) thing, haphazardly publishing it and not responsibly disclosing it is another (criminal) thing.
Post reply on HN