Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

341–350 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#341

Earlier quoted context omitted.

We agree in that if my client distributes illegal content, I am responsible, at least in part. On the other hand I also believe that a tracker that hosts hashes of illegal content, provides search facilities for and facilitates their download, is responsible, in a big way. That's my personal opinion and I think it's backed in cases like the pirate bay and sci hub. That 0 knowledge tracker is interesting, my first rea…

> That 0 knowledge tracker is interesting, Most actual trackers are zero knowledge. A tracker (bit of central software that handles 100+ thousand connections/second) is not a "torrent site" such as TPB, EZTV, etc. A tracker handshakes torrent clients and introduces peers to each other, it has no idea nor needs an idea that "SomeName 1080p DSPN" maps to D23F5C5AAE3D5C361476108C97557F200327718A All it needs is to store…

Are you sure open.stealth.si is a zero knowledge tracker? Some trackers reject unregistered torrents.

Re: Internet Archive breached again through stolen access tokens

#342

Earlier quoted context omitted.

I don’t like the idea of infinite ownership, which is the current problem of copyright. The public may never be able to own these ideas and build off of them. Further, just because you own something in one country doesn’t mean you can own it in another country. For a physical example, you can’t own a gun in the US and take it to Australia. If publishers didn’t engage in tactics like “library pricing” and preventing p…

Protesting copyright and enabling pirate-like access to materials is orthogonal to archiving the world's data and recording our history. Internet Archive should focus on its mission of archival. Let other groups figure out copyright. By taking on both tasks, IA risks everything and could stumble in its goal to be an archivist platform. We need an entity dedicated to recording history. IA is that. They're just biting…

And what, we are just supposed to trust that they're actually archiving these things instead of relaxing on a beach somewhere pretending they are? If they were to only focus on archiving, nobody would know if anything has actually been archived for nearly 100 years; after we are all dead.

By making the archive public, sure, we have a bit of a "piracy" issue. However, we can also verify they are actually archiving the things they say they are, point out mistakes, and ask them to remove things from the archive.

Re: Internet Archive breached again through stolen access tokens

#343

Earlier quoted context omitted.

For these parameters, yes. If you have a raid, then you have 2 copies with like 99.99% availability and 5 mean time years to failure. With a volunteer drive you have like ?% availability and ?% years to failure? You can't depend on it. Also the average value of data is very low, you don't want to be making many copies of for no reason.

That would mean that even with a million volunteer drives storing a file, you still wouldn't be able to depend on them, which is plainly wrong. > Also the average value of data is very low, you don't want to be making many copies of for no reason. The reason is that the value of that data is high to the archivist, since they want to preserve it.

A million is out of the parameters of the case.

Realistically you won't get enough volunteer-storage to cover one IA. And even if you did, it wouldn't satisfy the mission requirements, which is to store reliably for decades all of the data.

Re: Internet Archive breached again through stolen access tokens

#344

Earlier quoted context omitted.

But internet archive doesn't do this? It's a key based search (url keys)

Internet archive allows full text search of books, newspapers, etc.. Or anyway it did, before being breached.

It does transcribe books (through imperfect OCR) so I guess that's possible. Never relied on it as I search by title and author.

But anyways not the case for the wayback product which is the unique core to IA.

Re: Internet Archive breached again through stolen access tokens

#345
post #240

Earlier quoted context omitted.

A non-grownup analysis is to criticize a decision in hindsight. If Internet Archive shifted funds to security, it would mean cutting something from its mission. Given their history, it makes sense IMHO to spend on the mission and take the risk. As long as they have backups, a little downtime won't hurt them - it's not a bank or a hospital.

Downtime aside, best practices for running a library generally include not leaking usernames, email addresses, and eight years of front desk correspondence. They sell paid services to universities and governments, so downtime isn't a great look either. > it's not a bank They tried that too. Didn't go well. https://ncua.gov/newsroom/press-release/2016/internet-archiv...

> best practices for running a library generally include not leaking usernames, email addresses, and eight years of front desk correspondence

That's incorrect IMHO: You are describing outcomes; practices are about procedures. In particular, necessary to the understanding and use of best practices is that do not guarantee outcomes.

Any serious management balances risks, which includes the inevitability, though unpredictable, of negative outcomes. It's impossible to prevent them - not NASA, airlines, surgeons, etc, can prevent them all, and they accept that.

It's a waste of resources to spend more preventing them than you lose overall. Best practices do not provide perfect outcomes; they provide the most reduced trade-offs in risk and cost.

Re: Internet Archive breached again through stolen access tokens

#346

Earlier quoted context omitted.

That would mean that even with a million volunteer drives storing a file, you still wouldn't be able to depend on them, which is plainly wrong. > Also the average value of data is very low, you don't want to be making many copies of for no reason. The reason is that the value of that data is high to the archivist, since they want to preserve it.

A million is out of the parameters of the case. Realistically you won't get enough volunteer-storage to cover one IA. And even if you did, it wouldn't satisfy the mission requirements, which is to store reliably for decades all of the data.

This isn't meant to be storage for IA, it's meant to be a distributed backup.

Re: Internet Archive breached again through stolen access tokens

#347

The Internet Archive has a management problem. They seem to be more comfortable disrupting libraries than managing an online, publicly accessible database of disputed, disorganized material. Despite all of the positive self-talk, I don't know if they realize how important they are, or how easy it would be for them to find good help and advice if their management were transparent and everything was debated in public.…

> Debian is a good model to follow. While I have no idea how Debian is actually funded I'd agree. One issue might be that The Internet Archive actually need to have people on staff, not sure if Debian has that requirement. You're not going to get people to man scanner or VHS players 8 hours a day without pay, at least not at this scale. The Internet Archive needs a better funding strategy that asking for money on the…

I believe the monastic model would fit best. Tireless, thankless work for the greater good. Maintaining old records for decades and centuries for the sake of beyond ourselves. I imagine people who join up would eschew both profit maximizing (for profit) and moral adventurism (non profit/Internet Archive). a real vocation, not a career.

Sadly, SQlite is the only software organization I know of that has this spirit.

Re: Internet Archive breached again through stolen access tokens

#348

Earlier quoted context omitted.

> there's too much for us to lose at this point Feeling entitled?

"Us" means all of humankind for hopefully many generations to come. It's not about my personal entitlement, it's that the IA serves a vital role for humanity (one which they fought hard to make permissible).

IA is sooooo important we can't even undo the clusterfuck that is the disney-bought copyright system.

The black woman on the bus refusing to give up her seat was also 100% legally obviously in the wrong. IA lost not because what they were doing was morally wrong, but because each and every one of us continually refuses to agitate for the kind of change that would benefit the world.

If you want the public to have a library, you must enshrine that library's right to exist and operate in law, or it will never survive legal challenges from IP holders. Physical libraries would never be allowed to exist in modern America, not without 100 years of precedence of the first sale doctrine. You can bet your ass disney would have tried to kill such a thing. Freely watch our movies? No chance.

Re: Internet Archive breached again through stolen access tokens

#349

Earlier quoted context omitted.

> You can distribute less popular websites with more used ones to avoid losing it? So long as this distributed protocol has the concept of individual files, there _will_ be clients out there that allow the user to select `popular-site.archive.tar.gz` and not `less-popular.tar.gz` for download. And what one person doesn't download... they can't seed back. Distributed stuff is really good for low cost, high scale distr…

That is fundamentally the problem, no one wants to donate storage to host stuff they're not interested in.

More concretely, nobody wants to donate anything. They just want it to exist. Charity has never been a functional solution to normal coordination problems. We have centuries of evidence of this.

Re: Internet Archive breached again through stolen access tokens

#350

Earlier quoted context omitted.

Torrents have a bad reputation due to malicious executables, I have never met someone who genuinely saw piracy as stealing, only as dangerous. In fact, stealing as a definition cannot cover digital piracy, as stealing is to take something away, and to take is to possess something physically . The correct term is copying, because you are duplicating files. And that’s not even getting into the cultural protection pirac…

What does this have to do with torrents? If you get an executable from the internet it is widely known not to execute it if not trusted. You can get malicious executables from websites too. If this is what people think we need to work on education...

Piracy also is not unique to torrents, and yet that was what GP used.

The average person, in my experience, can barely work a non-cellphone filesystem and actively stresses when a terminal is in front of them, especially for a brief moment. Education went out the window a decade ago.

Post reply on HN