Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

271–280 of 648 posts

Re: Internet Archive: Security breach alert

#271
I was disappointed to discover that https://haveibeenpwned.com does not report an email as pwned if it is subaddressed/plus addressed. myemail@gmail.com is reported as still safe, but myemail+archive@gmail.com is pwned. I wonder if my email has been leaked by any other websites without me knowing.

Re: Internet Archive: Security breach alert

#273
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

I used to do this, now I use icloud and the 'hide my email' tool and it works without any hassle. Even asks me when signing up for something if I want to hide my email. It is easier than adding it to my old setup. Even easier than when I was using my free Google for Business setup. The rest of apple's email landscape sucks. It is pretty poor at managing spam, the client is terrible, it doesn't sync rules between the…

I recently ran into an issue where Toyota’s app/site was detecting and refusing Apple iCloud hide-my-email addresses when trying to sign up.

The error message was very clear: hide-my-email was not permitted.

I was just trying to check for available service appointments near me and didn’t want the spam. But I guess sending spam is very very important to Toyota.

Re: Internet Archive: Security breach alert

#274

Earlier quoted context omitted.

In case anyone would like these benefits but doesn't want to actually run an email server: All you actually need to accomplish this is a domain name and a decent provider. Fastmail is what I use and it's been great for me.

To be even easier, you can just have Apple or Google hold your domain and provide mail.

I'm not 100% sure that that gets you wildcard email addresses that all point to the same inbox, but if they support that, sure!

Re: Internet Archive: Security breach alert

#275

The reported alert on the site states: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP! But is this an official message from the company? It sounds odd and unprofessional, especially the "See 31 million of you on HIBP!" part, which jokingly refers to a huge privacy issue for users.…

Troy Hunt's tweet mentions the IA getting breached, defaced AND DDoSed. Here it is, in case you don't want to use that site: >>> Let me share more on the chronology of this: 30 Sep: Someone sends me the breach, but I'm travelling and didn't realise the significance 5 Oct: I get a chance to look at it - whoa! 6 Oct: I get in contact with someone at IA and send the data, advising it's our goal to load within 72 hours 7…

> The timing on the last point seems to be entirely coincidental. It may also be multiple parties involved and when we're talking breach + defacement + DDoS, it's clearly not just one attack.

It could also be that the attacker has compromised IA communication channels and timed it for maximum dramatic effect and confusion.

Re: Internet Archive: Security breach alert

#276

Earlier quoted context omitted.

In case anyone would like these benefits but doesn't want to actually run an email server: All you actually need to accomplish this is a domain name and a decent provider. Fastmail is what I use and it's been great for me.

To be even easier, you can just have Apple or Google hold your domain and provide mail.

[deleted]

Re: Internet Archive: Security breach alert

#277
As of 01:09 GMT on October 10, the Internet Archive is back up.

In fact, the Wayback Machine and the book archives are responding more quickly than they did for me a week ago, when I showed the Archive to the students in an online class I teach. I gave the students a homework assignment that involves accessing some old books at the Archive. That assignment is due in about 12 hours, and I was just getting ready to e-mail the students about the outage when I saw that the site is working again.

Re: Internet Archive: Security breach alert

#278
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

The only drawback being that all of your outgoing email is sent directly to the receiver’s spam folder..?

I often use custom domains for email and haven't encountered this. From what I know, the best practice is to use a domain that you have had for a while and to use nameservers or MX records from an established service (basically). I don't run my own server but I am sure there are tricks to getting it to work that way too.

Re: Internet Archive: Security breach alert

#279
post #260
post #254

Earlier quoted context omitted.

yea, but now i rely on cloudflare which is no-go for me.

Would you elaborate why it’s a no-go for you? Just curious for my own sake

decentralization.

I don’t want these massive entities (Google, MS, CF) controlling my data.

Re: Internet Archive: Security breach alert

#280
post #260
post #254

Earlier quoted context omitted.

yea, but now i rely on cloudflare which is no-go for me.

Would you elaborate why it’s a no-go for you? Just curious for my own sake

I don't know their reasons, but for me, I do use cloudflare, but only in a way that I have a transfer-off plan.

So far as I can tell, Cloudflare seems to still be in the early stages of enshittification [1], and while I as a business customer am probably going to be taken for a ride later than most customers, I'm also small fry, so I'm guessing at some point in the next 5 years, some of the "for free" features like zero trust / tunnels are going to become prohibitively expensive for me.

[1] https://pluralistic.net/2023/01/21/potemkin-ai/#hey-guys

I assume Cloudflare will enshittify because too much of its services are free or too cheap to make sense, so my guess is they're trying to achieve massive market capture and dependency so they can later start squeezing customers for way more money.

I prefer more transparent cost structures, like what I get through Migadu for example.

Post reply on HN