Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

101–110 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#101
post #30

Earlier quoted context omitted.

In security, industry standard seems to be about the same as military grade: the cheapest possible option that still checks all the boxes for SOC.

Hot take, this is the way it should be. If you want better security then you update the requirements to get your certification. Security by its very nature has a problem of knowing when to stop. There's always better security for an ever increasing amount of money and companies don't sign off on budgets of infinity dollars and projects of indefinite length. If you want security at all you have bound the cost and have…

> since 5 security experts in a room will have 10 different opinions

If that happens you need to seriously rethink your hiring process.

Re: Internet Archive breached again through stolen access tokens

#102
post #26
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Keep in mind the IA archives a lot of garbage. If it could be more focused it would be more likely to work.

The IA only works because it archives everything. You don't know what you need until you need it.

Re: Internet Archive breached again through stolen access tokens

#104

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

You say this as if the IA is not already deeply invested in the DWeb movement. If you go to a DWeb event in the Bay Area, there is a good chance it will be held at the IA.

Re: Internet Archive breached again through stolen access tokens

#105

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

When there are plenty of people who are steeped in the dogma of Imaginary Property, and whose lives depend on it, it's not too surprising.

Re: Internet Archive breached again through stolen access tokens

#106
post #82
post #79

Earlier quoted context omitted.

How do you know?

I worked there for a short while.

So if the Internet Archive accidentally archived child porn, they wouldn’t delete it?

I suspect they DO delete some things.

Re: Internet Archive breached again through stolen access tokens

#107
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Perhaps one idea is to let people choose what they want to protect. This way people wanting to support it can have their mission.

I want it to protect all sorts of random obscure documents, mostly kind of crappy, that I can't predict in advance, so I can pursue my hobby of answering random obscure questions. For instance:

* What is a "bird famine", and did one happen in 1880?

* Did any astrologer ever claim that the constellations "remember" the areas of the sky, and hence zodiac signs, that they belonged to in ancient times before precession shifted them around?

* Who first said "psychology is pulling habits out of rats", and in what context? (That one's on Wikiquote now, but only because I put it there after research on IA.)

Or consider the recently rediscovered Bram Stoker short story. That was found in an actual library, but only because the library kept copies of old Irish newspapers instead of lining cupboards with them.

The necessary documents to answer highly specific questions are very boring, and nobody has any reason to like them.

Re: Internet Archive breached again through stolen access tokens

#108

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

To make the web distributed-archive-friendly I think we need to start referencing things by hash and not by a path which some server has implied it will serve consistently but which actually shows you different data at different times for a million different reasons. If different data always gets a different reference, it's easy to know if you have enough backups of it. If the same name gets you a pile of snapshots t…

Done. It is called IPFS. The IA already supports it.

https://github.com/internetarchive/dweb-archive/blob/master/...

Post reply on HN