Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

261–270 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#261

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. With everything that’s going on, it’s highly suspicious that this is happening right after they upset some very rich rent seekers.

[flagged]

> Absolutely moronic and unbased implication. The "rent-seekers" won their case and have zero interest in being implicated in dumb palace-intrigue style hacking. I mean, fuck those guys, but to bring up allegations like that is big stupid.

That makes no sense.

The fact that they won their case gives even greater cause in ensuring that what they want goes through. Doesn't mean they have to be classy about it, or that Internet-based means of sabotage are impossible implications (given that the IA literally is about putting things up on the Internet that some want to be taken down).

Re: Internet Archive breached again through stolen access tokens

#262

Earlier quoted context omitted.

There's a mutable torrent extension (BEP-46) but unfortunately I don't think it's widely supported. I think IPFS/IPNS is the more likely direction.

Which IA has moved into and hasn’t found much luck in, unfortunately.

How come?

Re: Internet Archive breached again through stolen access tokens

#263

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

Is anyone using ArchiveBox regularly? It's a self-hosted archiving solution. Not the ambitious decentralized system I think this comment is thinking of but a practical way for someone to run an archive for themselves. https://archivebox.io/

I am self-hosting ArchiveBox through yunohost, for the odd blog article I come across and like. Not a heavy user per se, but it's doing its thing reliably.

Re: Internet Archive breached again through stolen access tokens

#264

Earlier quoted context omitted.

You already can, they have torrents for everything.

Their torrents suck and IME don’t update to changes in the archive.

Torrents are immutable in principle, which is good for preserving things. A new version of a set of files should be a new torrent.

Re: Internet Archive breached again through stolen access tokens

#266

Earlier quoted context omitted.

> there's too much for us to lose at this point Feeling entitled?

"Us" means all of humankind for hopefully many generations to come. It's not about my personal entitlement, it's that the IA serves a vital role for humanity (one which they fought hard to make permissible).

If it's so important to us, perhaps we should support it then?

The discussion around IA nowadays seems a lot like random users ranting at open source maintainers in Github issues.

Re: Internet Archive breached again through stolen access tokens

#267
post #237

Earlier quoted context omitted.

What’s the reasoning behind hiding content upon request? Doesn’t that defeat the purpose of archival? My intuition would say there are 3 cases when content ceases to become available at the original site: - The host becomes unable to host the content for some reason (bankruptcy, death, etc.) in which case I assume the archive persists. - The host is externally required to remove the content (copyright, etc.) in which…

It’s all about copyright. Copyright law in the US gives a monopoly on distribution of copies of things (hand‐waving because the definitions are hard, basically artistic works) to their author. Of course authors usually delegate that right to their publisher for practical and financial reasons. There are some fair use exceptions, but this basically makes it illegal for anyone else to make and distribute copies of the…

Thanks for the detailed response, very informative. This sounds similar to DMCA takedown requests, though I’m not knowledgable enough to know the distinction. It’s a shame that to view hidden archives one needs to visit the archive in person, but I guess if IA were to respond to email requests for such archives they would be guilty of breaking the same distribution rule. The major difference between the rare books or museum examples and content on IA is that the digital artifacts are infinitely reproducible and transportable so the physical visit required to view them seems totally unnecessary on its face.

It’s a shame that to be able to run an above-board _Internet_ Archive one needs to bend to the whim of anachronistic copyright law and forego all the benefits of the internet in the first place. This seems like it would inevitably mean that any _internet_ archive that is truly accessible over the _internet_ would be forced to operate illegally in a similar manner to SciHub.

I know I hold a rather strong opinion regarding copyright law (I’m not looking to debate it here as I know others hold different opinions which is totally fine), but IMHO copyright law has been a major blight on humanity at large and especially the internet. Major reform is in order at the very least, if not total abolishment.

Re: Internet Archive breached again through stolen access tokens

#269
post #238

Earlier quoted context omitted.

Claiming to have deleted something while just having hidden from public view… that’s basically begging content owners to sue and very easily win damages.

Copyright only regulates the distribution of copies of copyrighted works. Possessing copies and distributing copies to other people are two different things. If you were photocopying a textbook and giving it to your classmates, the publisher could have their lawyer send you a Cease and Desist letter telling you to stop (or else). But if they told you to burn your copy of the textbook then they would be overreaching,…

> Legal reasoning from made‐up examples is generally a bad idea

What? That's the only way to do legal reasoning, and as an obvious consequence it's how both lawyers and judges do it.

Re: Internet Archive breached again through stolen access tokens

#270
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Nearly every entry in the library has a torrent file (which is a distributed storage system), but with the index pages down, they're not accessible.

You're correct, but even then you've still the problem of storage - the torrents are only useful (and there's a lot of them) if a sustainable number of seeds remain available.
Post reply on HN