Internet Archive breached again through stolen access tokens
bleepingcomputer.com
Internet Archive breached again through stolen access tokens
1–10 of 376 posts
Re: Internet Archive breached again through stolen access tokens
#2Ouch. Once can happen, twice in a row...
Re: Internet Archive breached again through stolen access tokens
#3Ouch. Once can happen, twice in a row...
Once makes the second time more likely. Shows you are a soft target.
Re: Internet Archive breached again through stolen access tokens
#4> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor.
This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that there were a variety of different bad security practices.
Re: Internet Archive breached again through stolen access tokens
#5We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.
Re: Internet Archive breached again through stolen access tokens
#6I don't know what their funding model looks like but if they have some cash I'd say hiring a security team would be on top of the list of things to invest in.
Re: Internet Archive breached again through stolen access tokens
#7Is it the same email spoofing attack vector of zendesk which was disclosed last week?
Re: Internet Archive breached again through stolen access tokens
#8I'd like to imagine a world where every lawyer, when their case is helped by a Wayback Machine snapshot of something, flips a few bucks to IA. They could afford a world-class admin team in no time flat.
Re: Internet Archive breached again through stolen access tokens
#9Is it the same email spoofing attack vector of zendesk which was disclosed last week?
Article says API token was stolen in original breach.
Re: Internet Archive breached again through stolen access tokens
#10Restating my love for Internet Archive and my plea to put a grownup in charge of the thing.
Washington Post: The organization has “industry standard” security systems, Kahle said, but he added that, until this year, the group had largely stayed out of the crosshairs of cybercriminals. Kahle said he’d opted not to prioritize additional investments in cybersecurity out of the Internet Archive’s limited budget of around $20 million to $30 million a year.