Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

31–40 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#31
post #26
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Keep in mind the IA archives a lot of garbage. If it could be more focused it would be more likely to work.

The attempts have actually been focused on specific types of content, such as historical videos.

Re: Internet Archive breached again through stolen access tokens

#32

Earlier quoted context omitted.

That's a terrible solution. The Wayback Machine takes down their snapshots at the request of whoever controls the domain. That's not archival. If the state of a webpage in the past matters to you, you need a record that won't cease to exist when your opposition asks it to. This is the concept behind perma.cc.

Ooo, excellent. Yes, hiding items is imperfect, but I understood that it was legally required or something. (IANAL and IDFK, TBH) I wonder how perma.cc gets around that.

I'm afraid that it just hasn't been tested in court yet.

I haven't read this paper yet, but...

https://www.tesble.com/10.1080/0270319x.2021.1886785

from the abstract:

> The article concludes that Perma.cc's archival use is neither firmly grounded in existing fair use nor library exemptions; that Perma.cc, its "registrar" library, institutional affiliates, and its contributors have some (at least theoretical) exposure to risk

It seems that the article is about copyright, but of course there are several other reasons that might justify takedown of content stored on perma.cc:

- Right to be forgotten... perma.cc might be able to ignore it, but could this lead to perma.cc being blocked by european ISPs

- ITAR stuff

- content published by entities recognized by $GOVERNMENT as terrorist organizations

- revenge porn

- CSAM

Re: Internet Archive breached again through stolen access tokens

#33
post #30

Earlier quoted context omitted.

In security, industry standard seems to be about the same as military grade: the cheapest possible option that still checks all the boxes for SOC.

Hot take, this is the way it should be. If you want better security then you update the requirements to get your certification. Security by its very nature has a problem of knowing when to stop. There's always better security for an ever increasing amount of money and companies don't sign off on budgets of infinity dollars and projects of indefinite length. If you want security at all you have bound the cost and have…

Yep. And worse, now matter how much you pay for security it is still possible for someone to make a mistake and publish a credential somewhere public.

Re: Internet Archive breached again through stolen access tokens

#34

The Internet Archive has a management problem. They seem to be more comfortable disrupting libraries than managing an online, publicly accessible database of disputed, disorganized material. Despite all of the positive self-talk, I don't know if they realize how important they are, or how easy it would be for them to find good help and advice if their management were transparent and everything was debated in public.…

> Debian is a good model to follow.

While I have no idea how Debian is actually funded I'd agree. One issue might be that The Internet Archive actually need to have people on staff, not sure if Debian has that requirement. You're not going to get people to man scanner or VHS players 8 hours a day without pay, at least not at this scale.

The Internet Archive needs a better funding strategy that asking for money on their own site. People aren't visiting them frequently enough for that to work. They need a fundraising team, and a good one.

Finding managers are probably even worse. They can't get a normal CEO type person, because they aren't a company and the type of people who apply to or are attracted to running non-profit, server the community, don't be evil organisation are frequently bat-shit crazy.

Re: Internet Archive breached again through stolen access tokens

#35

The Internet Archive has a management problem. They seem to be more comfortable disrupting libraries than managing an online, publicly accessible database of disputed, disorganized material. Despite all of the positive self-talk, I don't know if they realize how important they are, or how easy it would be for them to find good help and advice if their management were transparent and everything was debated in public.…

> Confucian-style libertarian aphorisms that is running the credibility of Wikipedia

Can you elaborate? I'm aware of Wikipedia having very particular rules and lots of very territorial editors, but I'm not sure how this runs their credibility into the ground aside from pissing off the far right when they come in with an agenda to push.

Re: Internet Archive breached again through stolen access tokens

#36
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

>"It's dispiriting to see that even after being made aware of the breach weeks ago..." These people are not dispirited whatsoever, if anything they are half-cocked that these script kiddies found an easy target.

The words came from a message written by the people you are calling script kiddies, rather than being editorializing by bleepingcomputer, as you seem to believe.

Re: Internet Archive breached again through stolen access tokens

#37

I'd like to imagine a world where every lawyer, when their case is helped by a Wayback Machine snapshot of something, flips a few bucks to IA. They could afford a world-class admin team in no time flat.

That's a terrible solution. The Wayback Machine takes down their snapshots at the request of whoever controls the domain. That's not archival. If the state of a webpage in the past matters to you, you need a record that won't cease to exist when your opposition asks it to. This is the concept behind perma.cc.

That's correct, but only for present evidence - what about the past evidence, that you didn't know you needed until it was too late? IA is broad enough to cover the past five times out of ten.

Re: Internet Archive breached again through stolen access tokens

#38
post #30

Earlier quoted context omitted.

In security, industry standard seems to be about the same as military grade: the cheapest possible option that still checks all the boxes for SOC.

Hot take, this is the way it should be. If you want better security then you update the requirements to get your certification. Security by its very nature has a problem of knowing when to stop. There's always better security for an ever increasing amount of money and companies don't sign off on budgets of infinity dollars and projects of indefinite length. If you want security at all you have bound the cost and have…

This ^

We can’t all have the latest EPYC processors with the latest bug fixes using Secure Enclaves and homomorphic encryption for processing user data while using remote attestation of code running within multiple layers of virtualization. With, of course, that code also being written in Rust, running on a certified microkernel, and only updatable when at least 4 of 6 programmers, 1 from each continent, unite their signing keys stored on HSMs to sign the next release. All of that code is open source, by the way, and has a ratio of 10 auditors per programmer with 100% code coverage and 0 external dependencies.

Then watch as a kid fakes a subpoena using a hacked police account and your lawyers, who receive dozens every day, fall for it.

Re: Internet Archive breached again through stolen access tokens

#40
post #29

Earlier quoted context omitted.

That's a terrible solution. The Wayback Machine takes down their snapshots at the request of whoever controls the domain. That's not archival. If the state of a webpage in the past matters to you, you need a record that won't cease to exist when your opposition asks it to. This is the concept behind perma.cc.

No, they don’t delete the archived content. When the domain’s robots.txt file bans spidering, then the Wayback Machine _hides_ the content archived at that domain. It is still stored and maintained, but it isn’t distributed via the website. The content will be unhidden if the robots.txt file stops banning spiders, or if an appropriate request is made.

In some cases they do appear to delete, on request.

edit: "Other types of removal requests may also be sent to info@archive.org. Please provide as clear an explanation as possible as to what you are requesting be removed for us to better understand your reason for making the request.", https://help.archive.org/help/how-do-i-request-to-remove-som...

Post reply on HN