Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

361–370 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#361

Earlier quoted context omitted.

In what way? Torrents are used all over for content delivery. Battle.net uses a proprietary version of BitTorrent. It’s now owned by Microsoft. There’s many more legitimate uses as commented by many others. Criminals using tools does not make the tools criminal.

It's a matter of numbers, if tens of thousands of criminals use tech X, and it has few genuine uses, it's going to be restricted. This has precedent in illegal drug categorization, it's not just about the damage, but its ratio of noxious to helpful use.

Literally millions of people use it (whether they know it or not).

Societies should criminalize behavior and then (shocker!) enforce the laws! Let tools be tools.

Re: Internet Archive breached again through stolen access tokens

#362
post #359
post #305

Earlier quoted context omitted.

They’re not making copies either.

So they aren't making copies? How then do they have an archive of internet resources if not by copying said resources? You do realise the "downloading" is implicitly a copy. If you want to actually have a civil discussion then you need to make some reasonable argument than "They're not making copies either." Sounds like whatever role you played at IA when you were there didn't give you any actual insight into what ha…

Ahem. We are discussing items which have been hidden. A hidden item which users of the archive cannot access is not being copied. It’s just sitting there on a drive. Occasionally an automated process comes along and computes its hash to make sure there hasn’t been any bitrot. There’s no warehouse of undistributed copies of the thing that a court can order the Archive to destroy.

Re: Internet Archive breached again through stolen access tokens

#363
post #237

Earlier quoted context omitted.

It’s all about copyright. Copyright law in the US gives a monopoly on distribution of copies of things (hand‐waving because the definitions are hard, basically artistic works) to their author. Of course authors usually delegate that right to their publisher for practical and financial reasons. There are some fair use exceptions, but this basically makes it illegal for anyone else to make and distribute copies of the…

Thanks for the detailed response, very informative. This sounds similar to DMCA takedown requests, though I’m not knowledgable enough to know the distinction. It’s a shame that to view hidden archives one needs to visit the archive in person, but I guess if IA were to respond to email requests for such archives they would be guilty of breaking the same distribution rule. The major difference between the rare books or…

Yea, it’s pretty weird. There’s no technical reason for it, merely a legal one.

Re: Internet Archive breached again through stolen access tokens

#364
post #297
post #29

Earlier quoted context omitted.

No, they don’t delete the archived content. When the domain’s robots.txt file bans spidering, then the Wayback Machine _hides_ the content archived at that domain. It is still stored and maintained, but it isn’t distributed via the website. The content will be unhidden if the robots.txt file stops banning spiders, or if an appropriate request is made.

They ignore robots.txt these days.

Hmm. I’ll have to try to remember that :)

Re: Internet Archive breached again through stolen access tokens

#365

Earlier quoted context omitted.

> A user would then need to first use the "torrent site" to enter their search terms, and find the hash, then they would need to give the hash to a tracker, which would return the list of peers? > Is that right? More or less. > In any case, each party in the transaction shares liability. That's exactly right Bob. Just as a telephone exchange shares liability for connecting drug sellers to drug buyers when given a pho…

Interesting. That's a good point. I'll restate the principle of good usage to bad usage ratio, telephone providers are a well established service with millions of legitimate users and uses. Furthermore they are a recognized service in law, they are regulated, and they can comply with law enforcement. They are closer to the ISP, which according to my theory has some liability as well. It's just a matter of the liabili…

> I'll restate the principle of good usage to bad usage ratio, telephone providers are a well established service with millions of legitimate users and uses

Ditto trackers.

Have a look at the graphs here: https://opentrackr.org/

Over 10 million torrents tracked daily, on the order of 300 thousand connections per second, handshaking between some 200 million peers per week.

That's material from the Internet Archive, software releases, pooled filesharing, legitimate content sharing via embedded clients that use torrents to share load, and a lot of TV and movies that have variable copyright status

( One of the largest TV|Movie sharing sites for decades recent closed down after the sole operator stopped bearing the cost and didn't want to take on dubious revenue sources; that was housed in a country that had no copyright agreements with the US or UK and was entirely legal on its home soil.

Another "club" MVGroup only rip documentaries that are "free to air" in the US, the UK, Japan, Australia, etc. and in 20 years of publicaly sharing publicaly funded content haven't had any real issues )

> the ISP, which according to my theory has some liability as well.

The world's a big place.

The US MPA (Motion Picture Association - the big five) backed an Australian mini-me group AFACT (Australian Federation Against Copyright Theft) to establish ISP liability in a G20 country as a beach head bit of legislation.

That did not go well: Roadshow Films Pty Ltd v iiNet Ltd decided in the High Court of Australia (2012) https://en.wikipedia.org/wiki/Roadshow_Films_Pty_Ltd_v_iiNet...

    The alliance of 34 companies unsuccessfully claimed that iiNet authorised primary copyright infringement by failing to take reasonable steps to prevent its customers from downloading and sharing infringing copies of films and television programs using BitTorrent.
That was a three strikes total face plant:

    The trial court delivered judgment on 4 February 2010, dismissing the application and awarding costs to iiNet.

    An appeal to the Full Court of the Federal Court was dismissed.

    A subsequent appeal to the High Court was unanimously dismissed on 20 April 2012.
It set a legal precedent:

    This case is important in copyright law of Australia because it tests copyright law changes required in the Australia–United States Free Trade Agreement, and set a precedent for future law suits about the responsibility of Australian Internet service providers with regards to copyright infringement via their services.
It's also now part of Crown Law .. ie. not directly part of the core British Law body, but a recognised bit of Commonwealth High Court Law that can be referenced for consideration in the UK, Canada, etc.

> but it is semantically associated with other protocols which have 'noxious' features described above AND are semantically associates with illegal material.

Gosh, semantics hey. Some people feel in their waters that this is a protocol used by criminals and must therefore by banned or policed into non existance?

Is that a legal argument?

Re: Internet Archive breached again through stolen access tokens

#366

Earlier quoted context omitted.

> That 0 knowledge tracker is interesting, Most actual trackers are zero knowledge. A tracker (bit of central software that handles 100+ thousand connections/second) is not a "torrent site" such as TPB, EZTV, etc. A tracker handshakes torrent clients and introduces peers to each other, it has no idea nor needs an idea that "SomeName 1080p DSPN" maps to D23F5C5AAE3D5C361476108C97557F200327718A All it needs is to store…

Are you sure open.stealth.si is a zero knowledge tracker? Some trackers reject unregistered torrents.

The list I gave was of some public trackers, I made no claim that they were zero knowledge trackers, I simply made a statement that trackers needn't be aware of .torrent file manifests in order to share peer lists.

I also indicated above that having knowledge of .torrent manifests is problematic as that doesn't provide real actual knowledge of file contents just knowledge of file names ... LatestActionMovie.mkv might be a rootkit virus and HappyBunnyRabbits.avi might be the worst most exploitative underage pornography you can think of.

Some trackers are also private and require membership keys to access.

I was skating a lot as TZubiri seems unaware of many of the actual details and legitimate use cases, existing law, etc.

Re: Internet Archive breached again through stolen access tokens

#368

Does anyone know who is targeting the Internet Archive, and why? I get the impression the attacks are too sophisticated for it to just be vandal punks.

Maybe some WhiteHat hackers telling IA about all their security issues being ignored so they hacked them to force them to do something about it as nothing seems that have been badly damaged

Re: Internet Archive breached again through stolen access tokens

#369
post #362
post #359

Earlier quoted context omitted.

So they aren't making copies? How then do they have an archive of internet resources if not by copying said resources? You do realise the "downloading" is implicitly a copy. If you want to actually have a civil discussion then you need to make some reasonable argument than "They're not making copies either." Sounds like whatever role you played at IA when you were there didn't give you any actual insight into what ha…

Ahem. We are discussing items which have been hidden. A hidden item which users of the archive cannot access is not being copied. It’s just sitting there on a drive. Occasionally an automated process comes along and computes its hash to make sure there hasn’t been any bitrot. There’s no warehouse of undistributed copies of the thing that a court can order the Archive to destroy.

How did it get to the drive other than having been copied there?

You are once again discussing distribution not copying.

Your distinction might apply to an individual holding one or two copies of some copyrighted material because it isn't worth the legal hassle to go after them.

For someone like the IA holding terabytes, by your claims, of copyrighted material. "Big copyright" absolutely will go after them for that if it is true and it would sink the IA in legal fees.

There's nuance in all things, why I said if you actually care hire a lawyer just like they would. But your comment of "copying is fine, if you don't distribute" only applies where fair use applies which means if I hold terabytes of copies I am not legally allowed to have made, I'm probably going to be spending a large portion of my life repaying that decision, just like any other person would, should I get caught.

Re: Internet Archive breached again through stolen access tokens

#370

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

Not defending attacker, because I see IA as common good. That said one of the messages from this particular instance reads almost as if they were trying to help by pointing out issues that IA clearly missed: "Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine your data is now in the hands of some random guy. If not me, it'd be someone else." I am startin…

the archive would likely agree with you and is in support of supporting the proliferation of archives. imo, their goal was never to be a central hub, but very few others have showed up to do archival in parallel.
Post reply on HN