Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

321–330 of 648 posts

Re: Internet Archive: Security breach alert

#321

I’m feeling extremely conflicted on all of this with IA right now. On one hand, I love IA On the other hand…I’m in a long thread with their support right now on removing old snapshots of a social media account I have. Creeps are actively using the old snapshots to dox me and send me death threats using my PII. It’s incredibly frustrating and IA keeps insisting they cannot do anything about it. A small part of me hope…

Here in Australia we've had so many large data leaks I just assume all my PII is accessible to anyone motivated to find it. I'd guess folks from many other countries are in the same boat.

Not downplaying or excusing; just adding context that IA aren't the only ones and it's difficult to prevent (since the cause can be well outside of the individual's control).

Re: Internet Archive: Security breach alert

#322

I’m feeling extremely conflicted on all of this with IA right now. On one hand, I love IA On the other hand…I’m in a long thread with their support right now on removing old snapshots of a social media account I have. Creeps are actively using the old snapshots to dox me and send me death threats using my PII. It’s incredibly frustrating and IA keeps insisting they cannot do anything about it. A small part of me hope…

Isn't the point of IA to retain information? How can you, without hypocrisy, love IA if you don't agree with it happening to you, that you benefit from happening to others. There's a conflict here. Sucks to hear you are getting doxxed still

It's an uncommon opinion for someone to be in favor of IA to retain all information, and it's also not their stated purpose.

It's a perfectly reasonable opinion to wish for retention of old sources of knowledge without retaining pages containing personal information of non-public people, or sensitive non-newsworthy information about anyone at all.

Re: Internet Archive: Security breach alert

#323
post #90

Earlier quoted context omitted.

I think the existing collateral damage examples were pretty actual already. By burying terrorist headquarters under civilian apartment buildings, Hezbollah guarantees collateral damage.

The type of logic leads to schools in the US being valid targets so long as a drone pilot drops off their kids to school on the way to work.

No it doesn't. The US does not deliberately hide it's drone pilots among civilians and targeting their place of work or the drone storages would not harm civilians.

Re: Internet Archive: Security breach alert

#324
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

Great until you need to give someone an email address in real life and awkwardness ensues. Cashier: "What's your email?" Me: "walmart@somedomain.com" Cashier: "No I meant YOUR email address." Me: "Yeah walmart@somedomain.com" Cashier: "Oh do you work for Walmart???" Me: "No see I set up my email so... oh nevermind, 420BLAZEIT@GMAIL.COM"

Zero problem. I have used this exact setup with my domain for over 23 years. First, it's rare that I had to give my email over the phone or something. And in the couple of times someone raised an eyebrow, it was an opportunity to educate the person that yes, "donotspamYOURCOMPANY@" is indeed a valid address (not exactly what I use, but similar).

The advantages are numerous: tracking who leaked my data (many times before the company even noticed it), easier to spot spam (20 years ago spam filters were a lot less sophisticated), minimize credential stuffing (before Pwd Managers became the norm), etc.

Re: Internet Archive: Security breach alert

#325
post #214

One of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach

Great until you need to give someone an email address in real life and awkwardness ensues. Cashier: "What's your email?" Me: "walmart@somedomain.com" Cashier: "No I meant YOUR email address." Me: "Yeah walmart@somedomain.com" Cashier: "Oh do you work for Walmart???" Me: "No see I set up my email so... oh nevermind, 420BLAZEIT@GMAIL.COM"

I have this same setup and this conversation happens often, you get used to it happening and navigating it.

ON only one occasion in ~20 years, someone refused to do business with me because they thought I was impersonating them and told me I was being disrespectful by using their brand as my email, and even after explaining how it works they weren't happy.

Re: Internet Archive: Security breach alert

#326
post #57

Earlier quoted context omitted.

It's all good, as long as you're not in that recent AI Girlfriend breach which exposed a ton of users who were trying to coax it into generating CSAM images. https://x.com/troyhunt/status/1843788319785939422

“I went to the site to jerk off (to an adult scenario, to be clear) and noticed that it looked like it [the Muah.ai website] was put together pretty poorly,” the hacker told 404 Media. “It's basically a handful of open-source projects duct-taped together. I started poking around and found some vulnerabilities relatively quickly. At the start it was mostly just curiosity but I decided to contact you once I saw what wa…

Not sure if you're being sarcastic or not, but pentesting is not a particularly evil activity — and you often have to look at data to see if you actually found something.

What is evil is the way that he's ensured that the predators in the dataset will never face any consequences by making the data available to HaveIBeenPwned, making it trivial for predators to protect themselves (the method through which this is possible intentionally left as an exercise for the reader), and making the data available to a news website for...some reason, but it's bound to ensure that the vulnerability will be patched out quickly and no one else will be able to access the data.

I find it much more likely that this hacker who sought out a website for uncensored AI erotica isn't actually a good guy, and might even have something to hide within the dataset. Hopefully, I'm wrong and we'll see more of this.

Re: Internet Archive: Security breach alert

#327
post #296

Earlier quoted context omitted.

100% the result of boredom. Visit website, notice its design is old and crusty and you start to dig deeper. That's all it takes. Funny how we just expect hackers to have a manifesto now.

nah. its politically motivated hacktivists that are pro Palestinian. See their Twitter https://x.com/Sn_darkmeta could also just be RU larping under another flag.

> nah. its politically motivated hacktivists that are pro Palestinian.

This is... the most obvious false flag I've ever seen

Re: Internet Archive: Security breach alert

#328

Earlier quoted context omitted.

Great until you need to give someone an email address in real life and awkwardness ensues. Cashier: "What's your email?" Me: "walmart@somedomain.com" Cashier: "No I meant YOUR email address." Me: "Yeah walmart@somedomain.com" Cashier: "Oh do you work for Walmart???" Me: "No see I set up my email so... oh nevermind, 420BLAZEIT@GMAIL.COM"

Zero problem. I have used this exact setup with my domain for over 23 years. First, it's rare that I had to give my email over the phone or something. And in the couple of times someone raised an eyebrow, it was an opportunity to educate the person that yes, "donotspamYOURCOMPANY@" is indeed a valid address (not exactly what I use, but similar). The advantages are numerous: tracking who leaked my data (many times bef…

I recently started getting "targeted" bitcoin extortion emails that have your home address (or what they scraped from public records) and a picture of Google Street view, but they're all going to the email I used for a now-defunct online grocery

Re: Internet Archive: Security breach alert

#329
post #90
post #79

Earlier quoted context omitted.

A demonstration of what collateral damage actually means. The bracker was a terrorist so we killed the candle stick makers family.

I think the existing collateral damage examples were pretty actual already. By burying terrorist headquarters under civilian apartment buildings, Hezbollah guarantees collateral damage.

[dead]
Post reply on HN