Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

181–190 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#181
post #15

Earlier quoted context omitted.

We'll need to find even more people willing to expose themselves to legal threats and cyberattacks then.

The legal side is a big issue, true. The simplest and best workaround that I'm aware of is how the Arweave network handles it. They leave it up to the individual what parts of the data they want to host, but they're financially incentivized to take on rare data that others aren't hosting, because the rarer it is the more they get rewarded. Since it's decentralized and globally distributed, if something is risky to ho…

> decentralized storage isn't as fast as having central servers.

With the 30-second "time to first byte" speed we all know and love from IA, I'm pretty sure it'd only get faster when you're the only person accessing an obscure document on a random person's shoebox in Korea as compared to trying to fetch it from a centralised server that has a few thousand other clients to attend to simultaneously

Re: Internet Archive breached again through stolen access tokens

#182

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

Is anyone using ArchiveBox regularly? It's a self-hosted archiving solution. Not the ambitious decentralized system I think this comment is thinking of but a practical way for someone to run an archive for themselves. https://archivebox.io/

Re: Internet Archive breached again through stolen access tokens

#183
post #15

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

We'll need to find even more people willing to expose themselves to legal threats and cyberattacks then.

I collect, archive, and host data. Haven't gotten any threats or attacks. Not one. The average r/selfhosted user hiding their personal OwnCloud behind the DDoS maffia seems more afraid than one needs to be even for hosting all sorts of things publicly. I guess this fearmongering comes from tech news about breaches and DDoS attacks on organisations, similar to regular news impacting your regular worldview regardless of how it's actually going in the world or how things personally affect you

Re: Internet Archive breached again through stolen access tokens

#184
post #15

Earlier quoted context omitted.

We'll need to find even more people willing to expose themselves to legal threats and cyberattacks then.

The legal side is a big issue, true. The simplest and best workaround that I'm aware of is how the Arweave network handles it. They leave it up to the individual what parts of the data they want to host, but they're financially incentivized to take on rare data that others aren't hosting, because the rarer it is the more they get rewarded. Since it's decentralized and globally distributed, if something is risky to ho…

> decentralized storage isn't as fast as having central servers.

Depending on scale that’s not necessarily true. I find even today there are many services that cannot keep up with my residential fiber connection (3Gbps symmetrical), whereas torrents frequently can. IA in particular is notoriously slow when downloading from their servers, and even taking into account DHT time torrents can be much faster.

Now if all of their PBs of data were cached in a CDN, yeah that’s probably faster than any decentralized solution. But that will take a heck of a lot more money to maintain than I think is possible for IA.

Re: Internet Archive breached again through stolen access tokens

#186

The Library of Congress should be archiving the Internet and it should have the budget required to do so. This is in line with its mission as the "Library of Congress". Being able to have an accurate record of what was on the Internet at a specific point in time would be helpful when discussing legislation or potential regulation involving the internet.

As awkwardpotato write they do. Many national libraries all over the word treat the internet as covered by their requirements of legal deposit, and crawl their respective TLD.

Re: Internet Archive breached again through stolen access tokens

#187

Earlier quoted context omitted.

Perhaps one idea is to let people choose what they want to protect. This way people wanting to support it can have their mission.

I want it to protect all sorts of random obscure documents, mostly kind of crappy, that I can't predict in advance, so I can pursue my hobby of answering random obscure questions. For instance: * What is a "bird famine", and did one happen in 1880? * Did any astrologer ever claim that the constellations "remember" the areas of the sky, and hence zodiac signs, that they belonged to in ancient times before precession s…

You could let users choose what to mirror, and one of those choices could be a big bucket of all the least available stuff, for pure preservationists who don't want to focus on particular segments of the data.

Sort of like the bittorrent algorithm that favors retrieving and sharing the least-available chunks if you haven't assigned any priority to certain parts.

Re: Internet Archive breached again through stolen access tokens

#188

Earlier quoted context omitted.

A tracker that only tracks legal torrents, e.g. free software, OCRemix content, etc.

How would you keep the definition of legality without a centralizing authority?

A tracker is a centralized authority.

Re: Internet Archive breached again through stolen access tokens

#190
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

>"It's dispiriting to see that even after being made aware of the breach weeks ago..." These people are not dispirited whatsoever, if anything they are half-cocked that these script kiddies found an easy target.

Subtitling: half clocked means not fully prepared
Post reply on HN