Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

211–220 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#211
post #164

Earlier quoted context omitted.

What is your definition of a legal torrent tracker? I was not aware there were even any illegal ones.

> I was not aware there were even any illegal ones. Depends on the jurisdiction. Remember what happened in the The Pirate Bay trial?

My understanding is that that court case did not show that operating a torrent tracker is illegal, but specifically operating a (any) service with the explicit intent of violating copyright... huge difference IMO.

To me that's not even related to it being a torrent tracker, just that they were "aiding and abetting" copyright infringement.

Re: Internet Archive breached again through stolen access tokens

#212

Earlier quoted context omitted.

What is your definition of a legal torrent tracker? I was not aware there were even any illegal ones.

A tracker that only tracks legal torrents, e.g. free software, OCRemix content, etc.

I don't see how that would be enforceable. Policy perhaps, but it would be impossible to absolutely prevent it from being used for that purpose IMO.

Re: Internet Archive breached again through stolen access tokens

#213

Earlier quoted context omitted.

That's debatable. Most of their torrents are for things under copyright, though any other decentralized archive would have the same problem.

That’s a copyright problem. 99% of things made in the last 100 years fall under copyright.

Except when their own employees publicly tell people not to worry about copyright and just upload stuff anyway, they make it their own problem.

Re: Internet Archive breached again through stolen access tokens

#214
post #99

Is there any way IA could be mirrored in read-only mode, while security concerns are addressed?

Depends on the topology, my guess would be no though. Generally speaking, a compromise requires a lot of non-public work to be done in a very short time period. If they don't know how they were initially compromised (and you can't take attacker's word on things), simply throwing up another copy isn't going to fix the issue and often eggs them on to continue.

You basically have to re-perimeterize your topology with known good working security, and re-examine trusted relationships starting with a core group of servers and services, and then expanding outwards, ensuring proper segmentation along the way. Its a lot easier with validated zero trust configurations, but even then its a real pain (especially when there is a hidden flaw in your zero-trust config somewhere) and its very heavy on labor. Servers and services also need to ensure they have not deviated from their initial known desired states.

Some bad guys set traps in the data/services as timebombs, that either cross-polinate, or re-compromise later. There are quite a lot of malicious ****s out there.

Re: Internet Archive breached again through stolen access tokens

#215

Earlier quoted context omitted.

When there are plenty of people who are steeped in the dogma of Imaginary Property, and whose lives depend on it, it's not too surprising.

FYI: "Money" is imaginary property. Not sure you want to call people supporting "imaginary property" dogmatic. It's what our society is built on.

Money is not imaginary. You can touch and interact with it.

Re: Internet Archive breached again through stolen access tokens

#216

Earlier quoted context omitted.

Their torrents suck and IME don’t update to changes in the archive.

Aren't torrents terrible at handling updates in general? If you want to make a change to the data, or even just add our remove data, you have to create a new torrent and somehow get people to update their torrent and data as well.

There's a mutable torrent extension (BEP-46) but unfortunately I don't think it's widely supported. I think IPFS/IPNS is the more likely direction.

Re: Internet Archive breached again through stolen access tokens

#217

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. With everything that’s going on, it’s highly suspicious that this is happening right after they upset some very rich rent seekers.

[deleted]

Re: Internet Archive breached again through stolen access tokens

#218
post #194

Earlier quoted context omitted.

So if the Internet Archive accidentally archived child porn, they wouldn’t delete it? I suspect they DO delete some things.

Don't be asinine; of course there are exceptions. But the general rule is that nothing is deleted. Even if you have a fancy expensive lawyer send them a C&D letter asking them to delete something or else, they’ll just hide it. You can’t tell the difference from the outside. In fact there are monitoring alarms that are triggered if something _is_ deleted.

Claiming to have deleted something while just having hidden from public view… that’s basically begging content owners to sue and very easily win damages.

Re: Internet Archive breached again through stolen access tokens

#219

Earlier quoted context omitted.

To make the web distributed-archive-friendly I think we need to start referencing things by hash and not by a path which some server has implied it will serve consistently but which actually shows you different data at different times for a million different reasons. If different data always gets a different reference, it's easy to know if you have enough backups of it. If the same name gets you a pile of snapshots t…

There was a startup called Space Monkey that sold NAS drives where you got a portion of the space and the rest was used for copies of other people’s content (encrypted). The idea was you could lose your device, plug in a new one and restore from the cloud. They ended up folding before any of their resilience claims could be tested (at least by me). Would be people be willing to buy an IA box that hosted a shard of ra…

What happens when the user base explodes (eg. due to this event), and a few months layer they all get bored and drop out?

Re: Internet Archive breached again through stolen access tokens

#220

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

The internet archive shepherded the early https://getdweb.net/ community, and works with groups like IPFS, so they're well aware and offering operational support to decentralized storage projects. This has been going since at least 2016 when I was involved in some projects involving environmental data archiving during the Trump transition
Post reply on HN