Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

331–340 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#331

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

Not defending attacker, because I see IA as common good. That said one of the messages from this particular instance reads almost as if they were trying to help by pointing out issues that IA clearly missed: "Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine your data is now in the hands of some random guy. If not me, it'd be someone else." I am startin…

> I am starting to wonder if the chorus of 'maybe one org should not be responsible for all this; it is genuinely too important' has a point.

I agree this probably needs to be run more professionally but I think the "chorus" is missing the key fact that no one has stepped up to pay for or build an alternate and driving this one to insolvency just leaves us poorer.

Re: Internet Archive breached again through stolen access tokens

#332

Earlier quoted context omitted.

Hosting something at a volunteer's drive, without any guarantees, is pretty useless. They can cease hosting, or have disk damage, and you lose data

You're essentially saying that having an extra copy of data is equally as reliable as not having an extra copy of data. I would encourage you to think about this a bit more.

For these parameters, yes.

If you have a raid, then you have 2 copies with like 99.99% availability and 5 mean time years to failure.

With a volunteer drive you have like ?% availability and ?% years to failure? You can't depend on it.

Also the average value of data is very low, you don't want to be making many copies of for no reason.

Re: Internet Archive breached again through stolen access tokens

#333

Earlier quoted context omitted.

Oh ok, it seems to be a misconception of mine then. Mathematically a tracker would offer a function that given a hash, it returns you a list of peers with that file. While a "torrent site" like TPB or SH, would offer a search mechanism, whereby they would host an index, content hashes and english descriptors, along with a search engine. A user would then need to first use the "torrent site" to enter their search term…

> A user would then need to first use the "torrent site" to enter their search terms, and find the hash, then they would need to give the hash to a tracker, which would return the list of peers? > Is that right? More or less. > In any case, each party in the transaction shares liability. That's exactly right Bob. Just as a telephone exchange shares liability for connecting drug sellers to drug buyers when given a pho…

Interesting. That's a good point.

I'll restate the principle of good usage to bad usage ratio, telephone providers are a well established service with millions of legitimate users and uses. Furthermore they are a recognized service in law, they are regulated, and they can comply with law enforcement.

They are closer to the ISP, which according to my theory has some liability as well.

It's just a matter of the liability being small and the service to society being useful and necessary.

To take a spin to a similar but newer tech, consider crypto. My position is that its legality and liability for illegal usage of users (considering that of exchanges and online wallets, since the network is often not a legal entity) will depend on the ratio of legitimate to ilegitimate use that will be given to it.

There's definitely a second system effect, were undesirables go to the second system, so it might be a semantical difference unrelated to the technical protocols. Maybe if one system came first, or if by chance it were the most popular, the tables would be turned.

But I feel more strongly that there's design features that make law compliance, traceability and accountability difficult. In the case of trackers perhaps the microservice/object is a simple key-value store, but it is semantically associated with other protocols which have 'noxious' features described above AND are semantically associates with illegal material.

Re: Internet Archive breached again through stolen access tokens

#334

Earlier quoted context omitted.

You're essentially saying that having an extra copy of data is equally as reliable as not having an extra copy of data. I would encourage you to think about this a bit more.

For these parameters, yes. If you have a raid, then you have 2 copies with like 99.99% availability and 5 mean time years to failure. With a volunteer drive you have like ?% availability and ?% years to failure? You can't depend on it. Also the average value of data is very low, you don't want to be making many copies of for no reason.

That would mean that even with a million volunteer drives storing a file, you still wouldn't be able to depend on them, which is plainly wrong.

> Also the average value of data is very low, you don't want to be making many copies of for no reason.

The reason is that the value of that data is high to the archivist, since they want to preserve it.

Re: Internet Archive breached again through stolen access tokens

#335

Earlier quoted context omitted.

When there are plenty of people who are steeped in the dogma of Imaginary Property, and whose lives depend on it, it's not too surprising.

Was the hacker motivated by IP? The article appears to say no.

I/P not IP, as in Israel/Palestine.

Re: Internet Archive breached again through stolen access tokens

#336

Earlier quoted context omitted.

FYI: "Money" is imaginary property. Not sure you want to call people supporting "imaginary property" dogmatic. It's what our society is built on.

Money is not imaginary. You can touch and interact with it.

The vast majority of money is not physical, by likely 2 orders of magnitude, so you cannot touch it. It's a value in a ledger that can be moved electronically (or copied by hand).

https://en.wikipedia.org/wiki/Money_supply

Re: Internet Archive breached again through stolen access tokens

#337
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Nearly every entry in the library has a torrent file (which is a distributed storage system), but with the index pages down, they're not accessible.

It's not abnormal for their torrents to be missing most of their direct downloads on the same page

Re: Internet Archive breached again through stolen access tokens

#338

Earlier quoted context omitted.

Not defending attacker, because I see IA as common good. That said one of the messages from this particular instance reads almost as if they were trying to help by pointing out issues that IA clearly missed: "Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine your data is now in the hands of some random guy. If not me, it'd be someone else." I am startin…

> I am starting to wonder if the chorus of 'maybe one org should not be responsible for all this; it is genuinely too important' has a point. I agree this probably needs to be run more professionally but I think the "chorus" is missing the key fact that no one has stepped up to pay for or build an alternate and driving this one to insolvency just leaves us poorer.

I think this is why I am kinda debating what personally I can do about it ( in a reasonably efficient way ). And I admit I am on the fence. I try to donate funds to some worthy causes ( like EFF ) every so often and IA might be getting some offers of help now that is in the spotlight ( and can I reasonably compare to someone steeped in the subject? likely no ).

I do advocate for some variant of digital prepping in my social circle, but the response has been similar to my talk about privacy. The ones that do care, have already taken steps or are in the process of some sort of solution for their use-case. Those people do not need convincing or even much help.. they mostly simply know what they want and/or need.

As for a more systemic solution.. I honestly don't know. HN itself seems pretty divided and I can absolutely understand why.

All that said, I think I agree with you. There is no real alternative now so IA needs our support at the very least until we can figure out how to preserve what was already gathered. I said the following on this forum before. Wikipedia is not hurting for money, but IA, being in legal crosshairs and whatnot, likely will.

Re: Internet Archive breached again through stolen access tokens

#339
post #234

Earlier quoted context omitted.

That precedent was and still is legally used to federally regulate marijuana harsher than fentanyl, a precedent I strongly disagree with, so you'll have to forgive me for believing that the degree to which something causes harm matters more than the amount of misuse

Marihuana ruins millions of young minds.

[deleted]

Re: Internet Archive breached again through stolen access tokens

#340

Earlier quoted context omitted.

A tracker is a centralized authority.

But legality doesn't have a central authority. What is illegal in one jurisdiction is ok in another

Just track things that are legal everywhere or in most jurisdictions then.
Post reply on HN