Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

421–430 of 648 posts

Re: Internet Archive: Security breach alert

#421

Earlier quoted context omitted.

Jokes on them... I'm already on HIBP countless of times...

I'm also on HIBP over 10x. What are we supposed to do? Create a new email address for every service we sign up for? I don't know what the best practice is for keeping our personal data safe anymore.

> Create a new email address for every service we sign up for?

Exactly that, yes! Various services like icloud or proton offer "hide-my-email" addresses, or you can use any email service and just leverage a dedicated email aliasing service like SimpleLogin (paid but cheaper).

This way your email addresses are always random, and since these are shared services, the fact that it's random doesn't identify you either. In proton's / simplelogin's case, you can even set the display name used and email first, so from the outside it's not going to appear as strange, or have any real limitations.

If you think about it, modern email services don't really allow for easily testing if an email address is valid or not, so pretty much the only way your email is ever found out is if you share it on. So never share it on. Always share an alias instead. With automated systems, you may even want to rotate it every so often, so that if there's a leak, you can identify not just who leaked, but also roughly when.

Fixed identifiers, like an email address, are terrible, as their lifetime is always significantly longer than whatever context they're being used in for.

Re: Internet Archive: Security breach alert

#422

Earlier quoted context omitted.

> This raises an interesting question: should email addresses be private? I sadly don't think that's viable. What might be, in our current world, would be having a mail server/client setup where you can generate random addresses for yourself like Wf1JJUBHLu@domain.com and never re-use an e-mail address, much like with passwords, while being able to see all of the incoming mail in the same place and respond with the c…

Yes, but privacy suffers with this approach, because if one of emails ending in @domain.com is tied to your identity, all are.

That's not really my use case, but seems like an important concern for many!

At that point, you probably want to use whatever features one of the big providers use, like: https://proton.me/support/aliases-mail

Maybe even something that'd sit in front of a mail server that you yourself control, I wonder what the variety of options out there is.

Re: Internet Archive: Security breach alert

#423

Earlier quoted context omitted.

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

> should email addresses be private? I dunno. Should your personal phone number be private? Or your home address? Would you be okay if I knew it and shared it with a stranger? Or would you rather be asked permission to share it first? Seems pretty cut and dry to me. Yeah, there's going to be someone out there (there always is) who doesn't care, but I'd wager the majority would be pretty ticked off if you gave those p…

The missing part is the action part.

An email (or phone number, or address) is an identifier. Asking whether this identifier is public or private misses the important thing, which is the action that can be paird with the identifier.

So therefore, there's no universal answer to whether the identifier should be public or private. It's a case by case basis, when paired with an action.

For example, i don't want a shop to see me buying condoms, so shops shouldn't get my email address (or phone number).

Re: Internet Archive: Security breach alert

#424

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

A decentralized solution, doesn't that scream internet archive on blockchain? What could go wrong.

Re: Internet Archive: Security breach alert

#425

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

It's called torrent protocol and it doesn't work, no one wants to spend money and bandwidth hosting a god forsaken movie or book that only a handful of people care about.

In addition to the costs, I'd say it's also that no one wants to risk getting sued like the IA is getting.

Re: Internet Archive: Security breach alert

#426
I have had an IA account for a number of years, with a gmail address. Nine months ago, I changed the email address to a masked address using my own domain. Now I find that my gmail address was still stored, and was involved in the breach. Why? I get that they might store change history, but why?

BTW, for the current account details, I changed the password to another random string generated by my password manager, and also deleted the masked email address and generated another one, so going forward this sort of thing isn't that much of an issue for me.

Re: Internet Archive: Security breach alert

#427

Earlier quoted context omitted.

Not the author but yes, I do. It’s trivially easy so why not?

Same here, only issue I’ve ever had was when my email address had the name of the company in it in the format of spamlklcompanyname@domain.com CS people are sometimes confused by that and I’ve been accused of attempting to hack them by a small shop online because of my email.

"Are you from corporate?" is what I often get when I need to give my email to a store associate.

Re: Internet Archive: Security breach alert

#428

Earlier quoted context omitted.

Not the author but yes, I do. It’s trivially easy so why not?

Curious, how trivially easy is that?

I have an even easier approach:

- have an iphone/mac w/ icloud+

- go into settings

- add custom email

- get redirected to login to cloudflare

- buy/pick a domain for $12

- icloud+ automatically sets up the MX records on the domain via cloudflare

- enable catch-all emails in icloud settings

- Done!

Takes about 10 minutes & icloud provides the email hosting without any additional fees

Re: Internet Archive: Security breach alert

#429

Earlier quoted context omitted.

Yup. If browsers built in support for magnet links and (on desktop) defaulted to seeding with some capped bandwidth then a lot of centralized hosting platforms would become unnecessary.

You can build something very similar with WebRTC. Browsers already have P2P networking capability, it's just not immediately interoperable with BitTorrent clients. Standardizing some sort of BitTorrent over WebRTC bridge and adding it to BT clients would fix this problem. That being said, please do not host content this way . P2P blows away the already thin privacy guarantees that the web provides. Anyone seeding the…

I hadn't considered the privacy implications. For this to be workable, you'd need to pair it with near-ubiquitous use of some anonymizing overlay network.

Re: Internet Archive: Security breach alert

#430

Earlier quoted context omitted.

This. Typically HIBP attribution includes the email of the "submitter". Various data aggregators will contact them and buy the stolen data. Everybody wins* . * Exceptions apply.

Where on HIBP can I see the email of the submitter?

It's not available in this case, or every case. When available, you can search "The data was provided by" in https://haveibeenpwned.com/PwnedWebsites
Post reply on HN