Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

401–410 of 648 posts

Re: Internet Archive: Security breach alert

#402
post #164

More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-arch...

Friendly reminder to generate a unique password for every account you create so database leaks like this one don't bother you (besides on the site they're used).

I use login with google, idk if it is safe

Re: Internet Archive: Security breach alert

#403

Earlier quoted context omitted.

There is software which is intended to e.g. locate the GitHub profiles of people working at companies, then scrape all public repositories they've contributed to for their email address and the emails of their coworkers - to enable targeted advertising to those individuals. Very common in enterprise sales. With ChatGPT, this can be extended to create emails that look very personal - as if someone has followed all of…

About AI slurping all information. I bet one of the first ideas organisations that spy on population had when the recent AI boom happened was: How about we just train our AI on all the intercepted data and just ask it? Is John Smith a terrorist (for our definition of terrorist)? And the AI would reply: Yes he it, he searched on Google where to buy these ingredients that can be used to make explosives. So then they go…

[deleted]

Re: Internet Archive: Security breach alert

#404

That sucks, I was reading my email in the morn and saw the news from haveibeenpwned.com, and I'm indeed effected by it. Consolation is that I used a randomly generated unique password, tried to reset my credentials and see of any 2FA options but the site is overloaded throwing 504s.

I’ve been mentioning this a lot lately but it’s also a good idea to use email forwarding services like Firefox relay, icloud/apple “hide my email”, duckduckgo has a free one, simplelogin you can host yourself… In an email breach you can confirm who was breached if you used a unique email, and it also means your actual email remains at least as secure as those services I mentioned

Re: Internet Archive: Security breach alert

#405

Earlier quoted context omitted.

The type of logic leads to schools in the US being valid targets so long as a drone pilot drops off their kids to school on the way to work.

No it doesn't. The US does not deliberately hide it's drone pilots among civilians and targeting their place of work or the drone storages would not harm civilians.

I'm sorry that your governments rules of engagement are what you'd consider terrorism.

Maybe you should do something about it?

Re: Internet Archive: Security breach alert

#406

Earlier quoted context omitted.

Jokes on them... I'm already on HIBP countless of times...

I'm also on HIBP over 10x. What are we supposed to do? Create a new email address for every service we sign up for? I don't know what the best practice is for keeping our personal data safe anymore.

> Create a new email address for every service we sign up for?

Yes! Just get a domain and have every email it go to you. Mine is something like “@super-secure-no-viruses.email”

Re: Internet Archive: Security breach alert

#407

Just in terms of privacy, it's worth noting that anyone who has uploaded something on IA already has their email address publicly viewable. This isn't something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader's IA account email address. So from a security perspective it's bad but from a privacy perspective a lot of users probably weren…

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

This question could not be more academic

Re: Internet Archive: Security breach alert

#408

Earlier quoted context omitted.

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

An issue is for most sites/services an email has just become a standard authentication method, rather than something that can easily be more unique per account. So any usernames across sites/services that share it identify that user as being the same person (for data broker profiling, doxxing, etc), which is the privacy issue (not the email address per se, unless it perhaps contained one's real name). For contrast tr…

Proton Mail and iCloud’s hide my e-mail feature allow users to have unlimited e-mail addresses. You can also get unlimited e-mail addresses by running your own e-mail server or using something like Office 365’s business e-mail (costs about $4 per month).

Re: Internet Archive: Security breach alert

#409

Earlier quoted context omitted.

Same here, only issue I’ve ever had was when my email address had the name of the company in it in the format of spamlklcompanyname@domain.com CS people are sometimes confused by that and I’ve been accused of attempting to hack them by a small shop online because of my email.

Major SMTP provider refused my email address as login because of this. Luckily my moaning eventually made its way to one of their developers who fixed it. You can't sign up for a Samsung account with the name Samsung anywhere in your e-mail address. Aliexpress another offender. There my email is just spam@domain.

I used ali@domain for aliexpress, which was accepted.

Re: Internet Archive: Security breach alert

#410

Earlier quoted context omitted.

An issue is for most sites/services an email has just become a standard authentication method, rather than something that can easily be more unique per account. So any usernames across sites/services that share it identify that user as being the same person (for data broker profiling, doxxing, etc), which is the privacy issue (not the email address per se, unless it perhaps contained one's real name). For contrast tr…

> One could create entirely separate accounts but it's high friction and IIRC the > same phone number (now a requirement) can only be used for 2-3 accounts. I've wondered about this. Every Android/ChromeOS device I've ever bought, I had a new Google account created for it (during setup, instead of using an existing account), and only a few actually had phone numbers (I don't generally use smartphones for telephony).…

Why did you do that? Android doesn't require an account to work.
Post reply on HN