Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

121–130 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#121

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

A different framing is: be grateful that it's these types of people breaching IA and being vocal about it & asking IA to fix their systems. Others might just nuke them, or subtly alter content, or do whatever else bad thing you can think of.

They're providing a public service by pointing out that a massive organization controlling a lot of PII doesn't care about security at all.

Re: Internet Archive breached again through stolen access tokens

#122

Earlier quoted context omitted.

>"It's dispiriting to see that even after being made aware of the breach weeks ago..." These people are not dispirited whatsoever, if anything they are half-cocked that these script kiddies found an easy target.

I highly doubt they are script kiddies. More than likely they are state actors or mercenaries of state actors attempting to bring down the free transmittal of information between regular folks. IA evidently has not so good security and wikipedia must be doing pretty well I guess? I can’t recall the last time one of these attacks worked on Wiki.

Why would they publicly call them out and lay open the way they breached them if they were "attempting to bring down the free transmittal of information between regular folks"?

They could have done much worse but they chose not to and instead made it public. Which state actor does that?

Re: Internet Archive breached again through stolen access tokens

#123
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.

[flagged]

Re: Internet Archive breached again through stolen access tokens

#124
post #111

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

Blame bad leadership.

Is there a reason to blame the victim, rather than the attackers?

I’m asking seriously - did IA do shitty things that make them a worthy cause for politically/ideologically motivated hacking?

Re: Internet Archive breached again through stolen access tokens

#126

Earlier quoted context omitted.

I don't believe IA itself takes down pages that kiwifarms archives/links to. Rather they get a request to take it down and comply with it (correct me if I'm wrong here). I think IA is actually in a tough spot on this issue because they might be able to be sued eg. for defamation if they don't take down pages with personal info after a request to do so is made. Lastly, I doubt any new leadership would be less harsh on…

There was no illegal content on kiwi farms. Even then, I’d say taking down a single page by request is understandable. However, they surrendered to the mob and chose to stop archiving the entire site. This was to censor any criticism of the people involved, but as a result, we lost all of the other information on the rest of the site as well. It’s clear this organization cannot handle pressure, and is relying on peop…

They chose to stop serving archives of a site that had started explicitly using tham as a distribution mechanism to get around much a much broader attempt to censor them.

I'm curious what other information on that site you think was valuable to have available to the general public? Nothing has been lost in terms of historical data, it's only the immediate disemmination that has been slowed.

I'm really trying to understand why I should disagree with the IA's choice here. The IA is an archival service, not a distribution platform and it is not their job to help you distribute content that other people find objectionable. Their job is to make and keep an archive of internet content so that we don't lose the historical record. Blocking unrestricted public access to some of that content doesn't harm that mission and can even support it.

Re: Internet Archive breached again through stolen access tokens

#127
post #26
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Keep in mind the IA archives a lot of garbage. If it could be more focused it would be more likely to work.

personally I love all the random crap on IA!

Re: Internet Archive breached again through stolen access tokens

#128
post #124
post #111

Earlier quoted context omitted.

Blame bad leadership.

Is there a reason to blame the victim, rather than the attackers? I’m asking seriously - did IA do shitty things that make them a worthy cause for politically/ideologically motivated hacking?

I imagine they're referring to the fact that the leadership showed extremely bad judgement in deciding to pick a battle with the major publishing companies that everyone knew they would lose before it even began [0].

I don't think that justifies blaming the victim here, and from what I can see the attacker doesn't seem to be motivated by anything other than funsies, but I absolutely lost a lot of faith in their leadership when they pulled the NEL nonsense. The IA is too valuable for them to act like a young activist org—there's too much for us to lose at this point. They need to hold the ground they've won and leave the activism to other organizations.

[0] https://www.wired.com/story/internet-archive-loses-hachette-...

Re: Internet Archive breached again through stolen access tokens

#129

Does anyone know who is targeting the Internet Archive, and why? I get the impression the attacks are too sophisticated for it to just be vandal punks.

> I get the impression the attacks are too sophisticated for it to just be vandal punks.

What gives that impression? Everything I've seen about the attacker's messaging says "vandal punk(s)" to me, and nothing in what I've seen of the IA's systems screams Fort Knox. It wouldn't surprise me if they actually had a pretty lax approach to security on the assumption that there's very little reason to target them.

Re: Internet Archive breached again through stolen access tokens

#130

Earlier quoted context omitted.

The problem with torrents is they have a bad reputation since people use it to steal and redistribute other people’s content without their consent.

Give it a good reputation then. What are some legal torrent trackers?

archive.org to name one
Post reply on HN