Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

511–520 of 648 posts

Re: Internet Archive: Security breach alert

#512
post #501

Earlier quoted context omitted.

Sounds more like they hacked it for the lulz and then put up the tweets for even more lulz. Attacking the IA to support palestine is about as nonsensical as you can get.

There is a lot of embarassing pro-Zionist material archived on IA, but scrubbed elsewhere from the Internet: https://www.google.com/search?client=safari&rls=en&q=zionist... So just to play devils advocate, since Zionism is being critically received all across the Internet - it is more likely that IA was attacked in order to censor those materials, and then a sockpuppet was created to shift the blame to pro-palestinia…

Is there more embarrassing pro-Zionist material on IA than there is embarrassing pro-Palestine (for lack of a better term for whatever "the opposite" is) material?

Re: Internet Archive: Security breach alert

#514

Earlier quoted context omitted.

Pro-palestine activists: https://x.com/Sn_darkmeta/status/1844080692772401399 & https://x.com/Sn_darkmeta/status/1844104165192253945

...or someone attempting to blame palestinian activists. This smells a lot more like someone trying to ape activist language.

This isn't some 4D-chess. Reads more like you feel attacked because they share the same opinion as you and you just want to deflect.

Re: Internet Archive: Security breach alert

#515

Earlier quoted context omitted.

Proton Mail and iCloud’s hide my e-mail feature allow users to have unlimited e-mail addresses. You can also get unlimited e-mail addresses by running your own e-mail server or using something like Office 365’s business e-mail (costs about $4 per month).

is running your own e mail server a good idea in 2024? Security issues aside, you are at the mercy of the big email providers and whatever rules they want you to follow

For e-mail addresses as an authentication tool, you don't really need to be able to send emails at all, just receive them, and I think that is pretty feasible to not run afoul of the usual shenanigans.

Re: Internet Archive: Security breach alert

#516

Earlier quoted context omitted.

There is no US, there are just a bunch of interest groups. Some interest group definitely wants IA down. I wouldn't be surprised this is a paid attack.

I'd probably believe attribution to either Israel or the MPA with only a little evidence. (I still haven't forgiven Sony for the album on CD I bought with a rootkit on it...)

Just curious why Israel? MPA is reasonable though... And a rootkit on CD? Interesting...

Re: Internet Archive: Security breach alert

#517

Earlier quoted context omitted.

> the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service Do they? Why?

If Troy authenticates the data, they can use that as an 'endorsement' when trying to sell it.

Doesn't the value drop dramatically if it has already been shared with Troy and the HIBP database? Or is there a time frame where it has been authenticated by Troy but not yet added to the database?

Re: Internet Archive: Security breach alert

#519
post #151

More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-arch...

> The data will soon be added to HIBP My unique-to-archive.org email address is not there yet.

Many hackers will remove addresses that are obviously unique, including tags, to keep silent which database has been hacked, but it seems inconsistent.

I have checked and known my address was in a hack and it isn't there, while other times it is there. I also wonder if they start filtering out by domain, as they see a domain across multiple databases with unique addresses in each database exactly one time.

Re: Internet Archive: Security breach alert

#520
post #164

Earlier quoted context omitted.

Friendly reminder to generate a unique password for every account you create so database leaks like this one don't bother you (besides on the site they're used).

https://xkcd.com/2176/

I think pretty much the same argument for old-world POTS. While nothing was encrypted, nothing was recorded and someone had to physically access the local copper, which in reality provided more privacy than the future (today) where everything is recorded forever and you can bribe, extort, hack, blackmail, or just for fun leak everything recorded.
Post reply on HN