Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

131–140 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#132

Earlier quoted context omitted.

To make the web distributed-archive-friendly I think we need to start referencing things by hash and not by a path which some server has implied it will serve consistently but which actually shows you different data at different times for a million different reasons. If different data always gets a different reference, it's easy to know if you have enough backups of it. If the same name gets you a pile of snapshots t…

Done. It is called IPFS. The IA already supports it. https://github.com/internetarchive/dweb-archive/blob/master/...

Right, what I'm saying is that now we need to get the rest of the web (or at least the parts we want to keep) on board.

Re: Internet Archive breached again through stolen access tokens

#133

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

Not defending attacker, because I see IA as common good. That said one of the messages from this particular instance reads almost as if they were trying to help by pointing out issues that IA clearly missed:

"Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine your data is now in the hands of some random guy. If not me, it'd be someone else."

I am starting to wonder if the chorus of 'maybe one org should not be responsible for all this; it is genuinely too important' has a point.

Re: Internet Archive breached again through stolen access tokens

#134

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

Yes, I was quite shocked when I found out that all their DCs are within driving distance.

Re: Internet Archive breached again through stolen access tokens

#135

Does anyone know who is targeting the Internet Archive, and why? I get the impression the attacks are too sophisticated for it to just be vandal punks.

It strikes me as reasonable to assume (or at least strongly bet on) -- I'm not sure of the right phrase for it -- but like a mercenary type operation on behalf of some larger old media company?

There's just too much "means, motive and opportunity" there.

Re: Internet Archive breached again through stolen access tokens

#136

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

anything with tons of traffic going to it is a target. it has nothing to do with what the entity does, more with what potential reach it has. criminal behaviour is what it is. people pulling loads of visitors need to properly secure their shit, to prevent their their customers becoming their victims.

Re: Internet Archive breached again through stolen access tokens

#137

Earlier quoted context omitted.

To make the web distributed-archive-friendly I think we need to start referencing things by hash and not by a path which some server has implied it will serve consistently but which actually shows you different data at different times for a million different reasons. If different data always gets a different reference, it's easy to know if you have enough backups of it. If the same name gets you a pile of snapshots t…

Done. It is called IPFS. The IA already supports it. https://github.com/internetarchive/dweb-archive/blob/master/...

IPFS has shown that the protocol is fundamentally broken at the level of growth they want to achieve and it is already extremely slow as it is. It often takes several minutes to locate a single file.

Re: Internet Archive breached again through stolen access tokens

#138

Earlier quoted context omitted.

Give it a good reputation then. What are some legal torrent trackers?

archive.org to name one

That's debatable. Most of their torrents are for things under copyright, though any other decentralized archive would have the same problem.
Post reply on HN