Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

311–320 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#311

What kind of vandal attacks a library? We really need to find the people responsible.

These kinds of internet attacks happen all the time to children who host Minecraft servers, small businesses, amateur programmers, etc. Finding the responsible party is often difficult if not impossible, and usually the FBI and other powers-that-be have bigger fish-to-fry (i.e., drug traffickers, cyber criminals who focus on extortion, etc) and are unable to devote resources to finding these types of attackers.

The sad reality is that a lot of people are unfairly attacked on the internet and many go unpunished due to lack of investigative focus, resources, etc.

Re: Internet Archive breached again through stolen access tokens

#312

Earlier quoted context omitted.

You're correct, but even then you've still the problem of storage - the torrents are only useful (and there's a lot of them) if a sustainable number of seeds remain available.

How abiut torrenting a collection of websites in one collection? You can distribute less popular websites with more used ones to avoid losing it? And Torrents are good with transfering large files in my experience.

> You can distribute less popular websites with more used ones to avoid losing it?

So long as this distributed protocol has the concept of individual files, there _will_ be clients out there that allow the user to select `popular-site.archive.tar.gz` and not `less-popular.tar.gz` for download.

And what one person doesn't download... they can't seed back. Distributed stuff is really good for low cost, high scale distribution of in-demand content. It's _terrible_ for long term reliability/availability, though.

Re: Internet Archive breached again through stolen access tokens

#313

Earlier quoted context omitted.

I'm not sure what the argumentative line is here. But file uploading and downloading needs to have accountability for hosting, which p2p obscures. The bad reputation is inherent to the tech, not a random quirk.

It doesn't really, you can host a server off a raw IP. Downloading from example.com is just peer to peer with someone big. There's lots of hosting providers and DNS providers that are happy to host illegal-in-some-places content.

Incorrect.

The protocols for downloading from example.com are assymettrical client server architectures, not symmetrical decentralized peer to peer.

Re: Internet Archive breached again through stolen access tokens

#314
post #234

Earlier quoted context omitted.

It's a matter of numbers, if tens of thousands of criminals use tech X, and it has few genuine uses, it's going to be restricted. This has precedent in illegal drug categorization, it's not just about the damage, but its ratio of noxious to helpful use.

That precedent was and still is legally used to federally regulate marijuana harsher than fentanyl, a precedent I strongly disagree with, so you'll have to forgive me for believing that the degree to which something causes harm matters more than the amount of misuse

Marihuana ruins millions of young minds.

Re: Internet Archive breached again through stolen access tokens

#315
post #275

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

LigGen / SciHub are model citizens in this regard. Use the best tech for the job . Torrents + IPFS + simple http mirrors all over . While their data is big its not as big as Archive.org https://libgen.is/repository_torrent/ so I guess one still needs the funding to go to these decentralized nodes and they are there mostly for resiliancy

If so, why do they keep jumping from one dubious domain and TLD from another?

Re: Internet Archive breached again through stolen access tokens

#316

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

I designed a system where you could say "donate this spare 2 TB of my disk space to the Internet Archive" and the IA would push 2 TB of data to you. This system also has the property that it can be reconstructed if the IA (or whatever provider) goes away. Unfortunately, when I talked to a few archival teams (including the IA) about whether they'd be interested in using it, I either got no response or a negative one.

Hosting something at a volunteer's drive, without any guarantees, is pretty useless. They can cease hosting, or have disk damage, and you lose data

Re: Internet Archive breached again through stolen access tokens

#318

Earlier quoted context omitted.

Copyright is copyright. If you don't like the idea of a publisher owning the rights to content they published doesn't mean you have a right to their content. Let alone worldwide distribution of that content. What makes you feel entitled to the content of the publisher before the copyright expires? Do you feel that you deserve access to everything because you've deemed the concept of ownership around book publishing i…

I don’t like the idea of infinite ownership, which is the current problem of copyright. The public may never be able to own these ideas and build off of them. Further, just because you own something in one country doesn’t mean you can own it in another country. For a physical example, you can’t own a gun in the US and take it to Australia. If publishers didn’t engage in tactics like “library pricing” and preventing p…

Protesting copyright and enabling pirate-like access to materials is orthogonal to archiving the world's data and recording our history.

Internet Archive should focus on its mission of archival. Let other groups figure out copyright.

By taking on both tasks, IA risks everything and could stumble in its goal to be an archivist platform. We need an entity dedicated to recording history. IA is that. They're just biting off way too much to chew and making powerful enemies along the way.

Re: Internet Archive breached again through stolen access tokens

#319

Earlier quoted context omitted.

How abiut torrenting a collection of websites in one collection? You can distribute less popular websites with more used ones to avoid losing it? And Torrents are good with transfering large files in my experience.

> You can distribute less popular websites with more used ones to avoid losing it? So long as this distributed protocol has the concept of individual files, there _will_ be clients out there that allow the user to select `popular-site.archive.tar.gz` and not `less-popular.tar.gz` for download. And what one person doesn't download... they can't seed back. Distributed stuff is really good for low cost, high scale distr…

That is fundamentally the problem, no one wants to donate storage to host stuff they're not interested in.

Re: Internet Archive breached again through stolen access tokens

#320
post #183

Earlier quoted context omitted.

I collect, archive, and host data. Haven't gotten any threats or attacks. Not one. The average r/selfhosted user hiding their personal OwnCloud behind the DDoS maffia seems more afraid than one needs to be even for hosting all sorts of things publicly. I guess this fearmongering comes from tech news about breaches and DDoS attacks on organisations, similar to regular news impacting your regular worldview regardless o…

Its not a problem until it suddenly is, and by the time it becomes a problem its too late. Its not fear mongering, its risk management and the laws are draconian and fail fundamental basis for a "rule of law", we have a "rule by law".

And that's how you get preppers: it's a remote problem until it's too late, let's prepare for every eventuality before it's suddenly too late!

Risk management is a balance, not fearmongering as you say. That's why I'd rather use advice from people with daily experience than look at the newsworthy experiences ("nothing happened today, again; regular security patches working fine" you'll never see) and conclude you'd attract threats and cyber attacks just by hosting backup copies of parts of the Internet Archive

Post reply on HN