Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

281–290 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#281

Earlier quoted context omitted.

I designed a system where you could say "donate this spare 2 TB of my disk space to the Internet Archive" and the IA would push 2 TB of data to you. This system also has the property that it can be reconstructed if the IA (or whatever provider) goes away. Unfortunately, when I talked to a few archival teams (including the IA) about whether they'd be interested in using it, I either got no response or a negative one.

Is this open source or do you have any design docs? I love the idea and would love to learn more about it.

The idea is that it'll be open source, I have a rough design doc here:

https://docs.google.com/document/d/1qKgIjUTef-I-BLWjn4sEIbYo...

I'll write up a more detailed article on it, though, it'll be good to at least have the doc public somewhere.

Re: Internet Archive breached again through stolen access tokens

#282
post #64
post #59

Earlier quoted context omitted.

He is. But at the cost of the greater good. Most of us care mainly about the Wayback Machine and archiving webpages; not borrowing books still under copyright and fighting publishers.

Speak for yourself, the internet archive successfully increased its scope and made creative contributions to case law (although it lost at the appeals court)

Internet Archive certainly made creative arguments, all of which were soundly rejected under Summary Judgment. This had the opposite effect on the future we both want.

Under discovery in the case, it turned out that Internet Archive didn't keep accurate records of what they loaned out either. Another example of sloppy engineering that directly impacts their core mission.

The fate of the organization now rests on the outcome of other lawsuits. In one, Internet Archive argues that they are allowed to digitize and publish Frank Sinatra records because the pops and crackles on them makes it Fair Use.

If they did all this cleanly under a different LLC, I'd sit back and enjoy the show. But they didn't.

Re: Internet Archive breached again through stolen access tokens

#283
post #29

Earlier quoted context omitted.

That's a terrible solution. The Wayback Machine takes down their snapshots at the request of whoever controls the domain. That's not archival. If the state of a webpage in the past matters to you, you need a record that won't cease to exist when your opposition asks it to. This is the concept behind perma.cc.

No, they don’t delete the archived content. When the domain’s robots.txt file bans spidering, then the Wayback Machine _hides_ the content archived at that domain. It is still stored and maintained, but it isn’t distributed via the website. The content will be unhidden if the robots.txt file stops banning spiders, or if an appropriate request is made.

That distinction becomes nearly moot in lots of cases:

* it prevents victims from performing discovery (gathering evidence) before starting a trial or confiding to an expensive lawyer whose loyalty may turn out to systematically lie with the perpetrators or highest bidders.

* it prevents people who requested a snapshot (and thus know a specific URL with relevant knowledge) from proving their version of events to acquaintances, say during or after a court case in the event their lawyers just spin a random story instead of submitting the evidence as requested, since disloyal lawyer will have informed counterparty and counterparties will have requested "removal" of the page at IA, resulting in psychological isolation of the victim since victim can no longer point to the pages with direct and or supporting evidence.

Anyone with even basic understanding of cryptographic hashes and signatures would understand that:

1) for a tech-savvy entity (which an internet archival entity automatically is expected to be)

2) in the face changing norms and values (regardless of static or changing laws: throughout history violations were systematically turned a blind eye to)

3) given the shameless nature of certain entities, self-describing their criminal behavior on their commercial webpages

Any person understanding above 3 points concludes that such an archival company can impossibly assume some imaginary "middle ground" between:

A) Defender of truth and evidence, freedom fighter, human rights activist, so that humanity can learn from mistakes and crimes

or

B) Status quomplicit opressor of evidence

Because any imaginary hypothetical "middle ground" entity would quickly be inundated by legal requests for companies hiding their suddenly permanently visible crimes, and simultaneously for reinstantiations by victims pleading public access to the evidence.

Once we know its either A or B, and recalling point "tech savvy" (point 1), we can summarily conclude that a class A archival entity would helpfully assist victims as follows: don't just provide easy page archival buttons, but also provide attestations: say zip files of the pages, with an autogenerated legalese PDF, with hashes of the page and the date of observation, cryptographically signed by the IA. This way a victim can prove to police, lawyers, judges, or in case those locally work against them, prove to friends, family, ... that the IA did in fact see the information and evidence.

I leave it to the reader to locate the attestation package zips for these pages, in order to ascertain that the IA is a class A organization, and not a class B one.

Re: Internet Archive breached again through stolen access tokens

#284
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Nearly every entry in the library has a torrent file (which is a distributed storage system), but with the index pages down, they're not accessible.

If we want it to be distributed across laymen, we need something easier than opening torrent files (or inputting magnet URI) over a thousand times. Perhaps https://github.com/ipfs/in-web-browsers?

Re: Internet Archive breached again through stolen access tokens

#285
post #238

Earlier quoted context omitted.

Copyright only regulates the distribution of copies of copyrighted works. Possessing copies and distributing copies to other people are two different things. If you were photocopying a textbook and giving it to your classmates, the publisher could have their lawyer send you a Cease and Desist letter telling you to stop (or else). But if they told you to burn your copy of the textbook then they would be overreaching,…

> Legal reasoning from made‐up examples is generally a bad idea What? That's the only way to do legal reasoning, and as an obvious consequence it's how both lawyers and judges do it.

I would be better to quote the actual text of the law than to make up a silly hypothetical on the spot, but that would be more work.

Even better would be to quote from some case where a judge has applied the law to actual events.

Re: Internet Archive breached again through stolen access tokens

#286

Earlier quoted context omitted.

Their torrents suck and IME don’t update to changes in the archive.

Torrents are immutable in principle, which is good for preserving things. A new version of a set of files should be a new torrent.

> Torrents are immutable in principle

In practice, that's mostly how they're being used.

But the protocol does support mutation. The BEP describing the behavior even has archive.org as an example...

> The intention is to allow publishers to serve content that might change over time in a more decentralized fashion. Consumers interested in the publisher's content only need to know their public key + optional salt. For instance, entities like Archive.org could publish their database dumps, and benefit from not having to maintain a central HTTP feed server to notify consumers about updates.

http://www.bittorrent.org/beps/bep_0046.html

Re: Internet Archive breached again through stolen access tokens

#287
post #240

Restating my love for Internet Archive and my plea to put a grownup in charge of the thing. Washington Post: The organization has “industry standard” security systems, Kahle said, but he added that, until this year, the group had largely stayed out of the crosshairs of cybercriminals. Kahle said he’d opted not to prioritize additional investments in cybersecurity out of the Internet Archive’s limited budget of around…

A non-grownup analysis is to criticize a decision in hindsight. If Internet Archive shifted funds to security, it would mean cutting something from its mission. Given their history, it makes sense IMHO to spend on the mission and take the risk. As long as they have backups, a little downtime won't hurt them - it's not a bank or a hospital.

Downtime aside, best practices for running a library generally include not leaking usernames, email addresses, and eight years of front desk correspondence.

They sell paid services to universities and governments, so downtime isn't a great look either.

> it's not a bank

They tried that too. Didn't go well.

https://ncua.gov/newsroom/press-release/2016/internet-archiv...

Re: Internet Archive breached again through stolen access tokens

#288
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.

Hot take, but the intersection of people with sufficient LIS / archival experience to run the place and who can live under constant legal peril without capitulating to adversarial interests is probably, what, a hundred in the world?

I'd say they need support. They didn't abandon or pervert their mission, they relied on people they trusted who weren't equipped to also handle security. If your house were broken into, I wouldn't start a neighborhood petition for you to move out, because you didn't cause it.

They may be in a rut, but short of you or someone else building an IA replacement that settles all of your concerns and commiting to it for twenty five years with no serious compromises, you're probably punching a little above your weight on the topic.

Re: Internet Archive breached again through stolen access tokens

#289
post #26

Earlier quoted context omitted.

Keep in mind the IA archives a lot of garbage. If it could be more focused it would be more likely to work.

Archives generally purposefully don’t have a strong editorial streak. My trash is your treasure.

They have to if they don't want to use infinite space.

Re: Internet Archive breached again through stolen access tokens

#290

Earlier quoted context omitted.

The problem with torrents is they have a bad reputation since people use it to steal and redistribute other people’s content without their consent.

Torrents have a bad reputation due to malicious executables, I have never met someone who genuinely saw piracy as stealing, only as dangerous. In fact, stealing as a definition cannot cover digital piracy, as stealing is to take something away, and to take is to possess something physically . The correct term is copying, because you are duplicating files. And that’s not even getting into the cultural protection pirac…

What does this have to do with torrents? If you get an executable from the internet it is widely known not to execute it if not trusted. You can get malicious executables from websites too.

If this is what people think we need to work on education...

Post reply on HN