Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

51–60 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#51
post #27

Earlier quoted context omitted.

Some people are motivated by more than just financial incentive.

That's true, but something like archiving the internet is very costly, IA has an annual budget in the tens of millions.

Yes, it's a good point. Though they could take that money and reward people for hosting the data as well, couldn't they? They don't have to be in charge of hosting.

Re: Internet Archive breached again through stolen access tokens

#53
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.

Do you have any examples?

Re: Internet Archive breached again through stolen access tokens

#55
post #46

Earlier quoted context omitted.

IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.

I support archival of films, books, and music, but those items need to be write-only until copyright expires. The purpose of the Internet Archive is to achieve a wide-reaching, comprehensive archival, not provide easy and free read access to commercial works. Website caches can be handled differently, but bulk collection of commercial works can't have this same public access treatment. It's crazy to think this wouldn…

> I support archival of films, books, and music, but those items need to be write-only until copyright expires.

Which means no one alive today would ever be able to see them out of copyright. It also requires an unfounded belief that major copyright owning companies won't extend copyright lengths beyond current lengths which are effectively "forever".

Re: Internet Archive breached again through stolen access tokens

#56
post #21

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

> nowhere near enough people actually put their storage where their mouths are.

Typically because most people who have the upload, don't know that they can. And if they come to the notion on their own, they won't know how.

If they put the notion to a search engine, the keywords they come up with probably don't return the needed ELI5 page.

As in: How do I [?] for the Internet Archive?, most folks won't know what [?] needs to be.

Re: Internet Archive breached again through stolen access tokens

#57

Earlier quoted context omitted.

IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.

Do you have any examples?

[flagged]

Re: Internet Archive breached again through stolen access tokens

#58

Earlier quoted context omitted.

That's true, but something like archiving the internet is very costly, IA has an annual budget in the tens of millions.

Yes, it's a good point. Though they could take that money and reward people for hosting the data as well, couldn't they? They don't have to be in charge of hosting.

[deleted]

Re: Internet Archive breached again through stolen access tokens

#59

A genuine question to commenters asking to "put a grownup in charge of the thing" and saying that "Kahle shouldn't be running things": he built the thing, why exactly he can't run it the way he sees fit?

He is. But at the cost of the greater good.

Most of us care mainly about the Wayback Machine and archiving webpages; not borrowing books still under copyright and fighting publishers.

Re: Internet Archive breached again through stolen access tokens

#60

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

Lots of Copies Keeps Stuff Safe https://www.lockss.org/ This is a brilliant system relying on a randomised consensus protocol. I wanted to do my info sec dissertation on it, but its security model is extremely well thought out. There wasn't anything I felt I could add to it.

High Costs Makes Lots of Copies Unfeasible
Post reply on HN