Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

471–480 of 648 posts

Re: Internet Archive: Security breach alert

#471

Earlier quoted context omitted.

...or someone attempting to blame palestinian activists. This smells a lot more like someone trying to ape activist language.

It may not even be that nefarious — perhaps they did the hack “for the lulz” then had pangs of conscience afterward and scrabbled around for a (false) excuse. In any case, the IA was in some cases the only public host of important documents about Palestinian history, which are currently inaccessible, to say nothing about how important the Wayback Machine has been over the past year.

Sounds more like they hacked it for the lulz and then put up the tweets for even more lulz. Attacking the IA to support palestine is about as nonsensical as you can get.

Re: Internet Archive: Security breach alert

#472

Earlier quoted context omitted.

[flagged]

Alarm didn't go off - Russia. Missed the bus - Russia. Stubbed my toe - FFS why is it always Russia? Not excusing it, Russia, China and Iran do make my honeypot's top ten list every month. But then again so do the US, UK and France....

Such is the nature of a top 10. If you'd said all 6 make it to the top 3, I would have been surprised.

Re: Internet Archive: Security breach alert

#473
post #447

Earlier quoted context omitted.

RIAA, MPAA, etc...

I don't think they'd post cringe messages on Twitter though.

The script kiddies their contractor hired might though. I see no reason to believe that this was the doing of those organizations but if they did want to see the IA hacked then surely the ones doing the actual deed would be far removed.

Re: Internet Archive: Security breach alert

#475
post #437

What kind of asshole attacks the Internet Archive of all places on the web??

Pro-palestine activists: https://x.com/Sn_darkmeta/status/1844080692772401399 & https://x.com/Sn_darkmeta/status/1844104165192253945

Or, equally valid, pro-zionist activists who want something that is normally easily accessible in the IA to be censored.

Re: Internet Archive: Security breach alert

#476
post #394

Earlier quoted context omitted.

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

Whether the email is considered private or not is completely orthogonal to whether you are allowed / should tie an action to your email. And then again completely orthogonal whether you can/should make that connection public. Even if your email is public information and even if what is uploaded is public information that doesn't imply that the email address behind the account that uploaded that information should be…

i agree. if "user contacting another user" is a feature, there should be the option to (optionally) supply a different email address than your account email or use an online form that keeps your account email hidden.

Re: Internet Archive: Security breach alert

#477

Earlier quoted context omitted.

Not the author but yes, I do. It’s trivially easy so why not?

Curious, how trivially easy is that?

1. Register domain on Cloudflare

2. Configure a catch-all forwarding address to your private GMail

Done.

Re: Internet Archive: Security breach alert

#479

Earlier quoted context omitted.

Hold on. Why do you need a dc rackspace and a /24 just to have your email ?

This is hacker news, we're all either founders who have 2 billion dollars in (illiquid) stock options, or FAANG employees making 600k/year, what else are we going to do if we want email? Sure, you could pay fastmail $40/year for this, but that's not really the hacker news spirit, and no one on this site knows how to count as low as $40. The real justifications you can give yourself: Shared VPS hosting pretty much all…

> Shared VPS hosting pretty much all bans email, AWS, DO, etc all have ToS that say "no email" as anti-spam measures.

Complete FUD.

Here is DO's acceptable use policy:

https://www.digitalocean.com/legal/acceptable-use-policy

You can see that they explicitly have policies for email hosts.

Here is a guide they host on how to setup a mail server:

https://www.digitalocean.com/community/tutorials/how-to-run-...

They forbid spamming, not all mail.

> Shared IP space will go straight to spam due to people having spammed on it in the past. Buy a /24 to ensure you don't go straight to spam.

I have had no problems with deliverability to Google from an IP on a shared block. I don't send marketing mails or any other kind of spam though. Microsoft blocks my IP but they are too small (outside businesses) for me to care to give them special snowflake treatment.

Deliverability of your own mails is also irrelevant for the original discussion about using unique email addresses for signing up to services - you don't need to be able to send at all for that.

Post reply on HN