Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

241–250 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#241

Earlier quoted context omitted.

Ok. But what is the case law in hosting illegal content? Sure you may operate a torrent, but if your client is distributing child porn, in my view, you bear responsibility.

I'm backing ranger_danger here. In Law the technicalities matter. Trackers generally do not host any content, just hashcodes and ( sometimes ) meta data descriptions of content. If "your" (ie let's say _you_ TZubiri) client is distributing child pornography content because you have a partially downloaded CP file then that's on _you_ and not on the tracker. The "tracker" has unique hashcode signatures of tens of milli…

We agree in that if my client distributes illegal content, I am responsible, at least in part.

On the other hand I also believe that a tracker that hosts hashes of illegal content, provides search facilities for and facilitates their download, is responsible, in a big way. That's my personal opinion and I think it's backed in cases like the pirate bay and sci hub.

That 0 knowledge tracker is interesting, my first reaction is that it's going to end up in very nasty places like Tor, onion, etc..

Re: Internet Archive breached again through stolen access tokens

#242

Earlier quoted context omitted.

The problem with file transfer is they have a bad reputation since people use it to [insert illegal or immoral activity here]. Then rename it from "torrent" to something else.

I'm not sure what the argumentative line is here. But file uploading and downloading needs to have accountability for hosting, which p2p obscures. The bad reputation is inherent to the tech, not a random quirk.

It doesn't really, you can host a server off a raw IP.

Downloading from example.com is just peer to peer with someone big. There's lots of hosting providers and DNS providers that are happy to host illegal-in-some-places content.

Re: Internet Archive breached again through stolen access tokens

#243

Earlier quoted context omitted.

Is there any form of torrent where you can do a full text search? That, to me, is the more important problem with torrents.

But internet archive doesn't do this? It's a key based search (url keys)

Internet archive allows full text search of books, newspapers, etc.. Or anyway it did, before being breached.

Re: Internet Archive breached again through stolen access tokens

#244

Earlier quoted context omitted.

Perhaps one idea is to let people choose what they want to protect. This way people wanting to support it can have their mission.

I want it to protect all sorts of random obscure documents, mostly kind of crappy, that I can't predict in advance, so I can pursue my hobby of answering random obscure questions. For instance: * What is a "bird famine", and did one happen in 1880? * Did any astrologer ever claim that the constellations "remember" the areas of the sky, and hence zodiac signs, that they belonged to in ancient times before precession s…

My favorite question is: whether or not Bowser took the princess to another castle.

Re: Internet Archive breached again through stolen access tokens

#245

Earlier quoted context omitted.

I'm backing ranger_danger here. In Law the technicalities matter. Trackers generally do not host any content, just hashcodes and ( sometimes ) meta data descriptions of content. If "your" (ie let's say _you_ TZubiri) client is distributing child pornography content because you have a partially downloaded CP file then that's on _you_ and not on the tracker. The "tracker" has unique hashcode signatures of tens of milli…

We agree in that if my client distributes illegal content, I am responsible, at least in part. On the other hand I also believe that a tracker that hosts hashes of illegal content, provides search facilities for and facilitates their download, is responsible, in a big way. That's my personal opinion and I think it's backed in cases like the pirate bay and sci hub. That 0 knowledge tracker is interesting, my first rea…

> That 0 knowledge tracker is interesting,

Most actual trackers are zero knowledge.

A tracker (bit of central software that handles 100+ thousand connections/second) is not a "torrent site" such as TPB, EZTV, etc.

A tracker handshakes torrent clients and introduces peers to each other, it has no idea nor needs an idea that "SomeName 1080p DSPN" maps to D23F5C5AAE3D5C361476108C97557F200327718A

All it needs is to store IP addresses that are interested in that hash and to pass handfuls of interested IP addresses to other interested parties (and some other bookkeeping).

From an actual tracker PoV the content is irrelevant and there's no means of telling one thing from another other than size - it's how trackers have operated for 20+ years now.

Here are some actual tracker addresses and ports

    udp://tracker.opentrackr.org:1337/announce
    udp://p4p.arenabg.com:1337/announce
    udp://tracker.torrent.eu.org:451/announce
    udp://tracker.dler.org:6969/announce
    udp://open.stealth.si:80/announce
    udp://ipv4.tracker.harry.lu:80/announce
    https://opentracker.i2p.rocks:443/announce
Here's the bittorrent protocol: http://bittorrent.org/beps/bep_0052.html

Trackers can hand out .torrent files if asked (bencoded dictionaries that describe filenames, sizes, checksums, directory structures of a torrents contents) but they don't have to; mostly they hand out peer lists of other clients .. peers can also answer requests for .torrent files.

A .torrent file isn't enough to determine illegal content.

Pornography can be contained in files labelled "BeautifulSunset.mkv" and Rick Astley parody videos can frequently be found in files labelled "DirtyFilthyRepubicanFootTappingNudeAfrica.avi"

Given that it's not clear how trackers could effectively filter by content that never actually traverses their servers.

Re: Internet Archive breached again through stolen access tokens

#246
post #46

Earlier quoted context omitted.

I support archival of films, books, and music, but those items need to be write-only until copyright expires. The purpose of the Internet Archive is to achieve a wide-reaching, comprehensive archival, not provide easy and free read access to commercial works. Website caches can be handled differently, but bulk collection of commercial works can't have this same public access treatment. It's crazy to think this wouldn…

> but bulk collection of commercial works can't have this same public access treatment And it doesn't.

The Internet Archive Lending Library did. And there are music, movie, and video game ROMs found throughout the user uploads.

IA should collect these materials, but they shouldn't be playing fast and loose by letting everyone have access to them. That's essentially providing the same services as the Pirate Bay under the guise of archivism.

This puts IA at extreme legal risk. Their mission is too important to play such games.

Re: Internet Archive breached again through stolen access tokens

#247

Earlier quoted context omitted.

I want it to protect all sorts of random obscure documents, mostly kind of crappy, that I can't predict in advance, so I can pursue my hobby of answering random obscure questions. For instance: * What is a "bird famine", and did one happen in 1880? * Did any astrologer ever claim that the constellations "remember" the areas of the sky, and hence zodiac signs, that they belonged to in ancient times before precession s…

My favorite question is: whether or not Bowser took the princess to another castle.

Since the IA had a collection of emulators (some of them running online*), and old ROMs and floppies and such, it could probably help with that one too.

* Strictly speaking, running in-browser, but that sounded like "Bowser" so I wrote online instead.

Re: Internet Archive breached again through stolen access tokens

#248
post #147
post #69

Earlier quoted context omitted.

And it's guaranteed not to happen if the efforts don't continue.

You could say the same thing about perpetual motion. Being realistic about why past efforts have failed is key to doing better in the future: for example, people won’t mirror content which could get them in trouble and most people want to feel some kind of benefit or thanks. People should be thinking about how to change dynamics like those rather than burning out volunteers trying more ideas which don’t change the un…

There are certainly research questions and cost questions and practicality and subsetting and whatnot. Addressed by some ideas and not by others.

What there isn't is a currently maintained and advertised client and plan. That I can find. Clunky or not, incomplete or not.

There are other systems that have a rough plan for duplication and local copy and backup. You can easily contribute to them, run them, or make local copies. But not IA. (I mean you can try and cook up your own duplication method. And you can use a personal solution to mirror locally everything you visit and such.) No duplication or backup client or plan. No sister mirrored institution that you might fund. Nothing.

Re: Internet Archive breached again through stolen access tokens

#249

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. With everything that’s going on, it’s highly suspicious that this is happening right after they upset some very rich rent seekers.

[flagged]

You don’t think you’re being a bit harsh here?

Re: Internet Archive breached again through stolen access tokens

#250

Earlier quoted context omitted.

We agree in that if my client distributes illegal content, I am responsible, at least in part. On the other hand I also believe that a tracker that hosts hashes of illegal content, provides search facilities for and facilitates their download, is responsible, in a big way. That's my personal opinion and I think it's backed in cases like the pirate bay and sci hub. That 0 knowledge tracker is interesting, my first rea…

> That 0 knowledge tracker is interesting, Most actual trackers are zero knowledge. A tracker (bit of central software that handles 100+ thousand connections/second) is not a "torrent site" such as TPB, EZTV, etc. A tracker handshakes torrent clients and introduces peers to each other, it has no idea nor needs an idea that "SomeName 1080p DSPN" maps to D23F5C5AAE3D5C361476108C97557F200327718A All it needs is to store…

Oh ok, it seems to be a misconception of mine then.

Mathematically a tracker would offer a function that given a hash, it returns you a list of peers with that file.

While a "torrent site" like TPB or SH, would offer a search mechanism, whereby they would host an index, content hashes and english descriptors, along with a search engine.

A user would then need to first use the "torrent site" to enter their search terms, and find the hash, then they would need to give the hash to a tracker, which would return the list of peers?

Is that right?

In any case, each party in the transaction shares liability. If we were analyzing a drug case or a people trafficking case, each distributor, wholesaler or retailer would bear liability and face criminal charges. A legal defense of the type "I just connected buyers with sellers I never exchanged the drug" would not have much chance of succeding, although it is a common method to obstruct justice by complicating evidence gathering. (One member collects the money, the other gives the drugs.)

Post reply on HN