Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

521–530 of 648 posts

Re: Internet Archive: Security breach alert

#521

Earlier quoted context omitted.

Alarm didn't go off - Russia. Missed the bus - Russia. Stubbed my toe - FFS why is it always Russia? Not excusing it, Russia, China and Iran do make my honeypot's top ten list every month. But then again so do the US, UK and France....

[flagged]

> Its always russia

Ah the only conspiracy theory we’re encouraged to believe. Wouldn’t that be convenient. A perpetual enemy far away that’s responsible for all of our failures, infiltrating and puppeteering western democracies on the other side of the world. Even the Russian propaganda machine loves this narrative – it makes them seem powerful and dangerous. Not like a corrupt and broken former empire sending off their young to the meat grinder for a bit of loot and territorial ambitions from a lost era.

Re: Internet Archive: Security breach alert

#524
post #385

Earlier quoted context omitted.

Out of curiosity, do you use a unique email address for every single service?

Yes, without exception. I want to know who is leaking/selling my address, and usually stop doing business with those who do. It also makes filtering really easy. People sometimes have strange reactions when I verbally give them an email address with their company name in it, especially when I'm a new customer. All you need is a domain and an email provider that allows catch-all addresses, both of which are easy and c…

I love doing that, when someone asks me for an email address, it’s always their-name@my.domain - always gets strange looks!

Edit: even more fun with catch all domains then it’s company-name@spam.my.domain

Re: Internet Archive: Security breach alert

#525

Earlier quoted context omitted.

If Troy authenticates the data, they can use that as an 'endorsement' when trying to sell it.

Doesn't the value drop dramatically if it has already been shared with Troy and the HIBP database? Or is there a time frame where it has been authenticated by Troy but not yet added to the database?

I don't think so.

Troy isnt publicly sharing the credentials and that's what's valuable — especially having "exclusive" access.

He blogged or tweeted about this at some point. Sadly, I can't find the link.

Re: Internet Archive: Security breach alert

#526

Just in terms of privacy, it's worth noting that anyone who has uploaded something on IA already has their email address publicly viewable. This isn't something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader's IA account email address. So from a security perspective it's bad but from a privacy perspective a lot of users probably weren…

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

> This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts.

There are several ways to look at that.

The organization that I work for considers anything that ties two pieces of information about a person together as private information. That is to say that a person's name is not private and a phone number is not private, but connecting a phone number to a name is private. In one form or another, an email is frequently tied to a name (e.g. the email address is based on their name, or an account record includes both a name and an email address).

Another way is to consider how accessible the information is. There was a lot of information that was not considered as private prior to the widespread adoption of the internet. One issue that I remember popping up in the early 1990's involved property (i.e. land) records. Historically, people had to go to a government office to access them but they were publicly available. Since they were publicly available, some governments made them available online. Once they were available online, the barriers to access were removed (e.g. having to physically visit an office) and the ability to abuse that information was vastly increased. All of a sudden, people started considering something that used to be considered as public information as private information.

Re: Internet Archive: Security breach alert

#527
post #501

Earlier quoted context omitted.

There is a lot of embarassing pro-Zionist material archived on IA, but scrubbed elsewhere from the Internet: https://www.google.com/search?client=safari&rls=en&q=zionist... So just to play devils advocate, since Zionism is being critically received all across the Internet - it is more likely that IA was attacked in order to censor those materials, and then a sockpuppet was created to shift the blame to pro-palestinia…

Is there more embarrassing pro-Zionist material on IA than there is embarrassing pro-Palestine (for lack of a better term for whatever "the opposite" is) material?

I would not know a mathematically accurate response to this question - but I did see a lot of references to embarrassing pro-Zionist (i.e. historically racist, colonialist, pro-Zionist) materials at the IA in the last week in various other forums, which are now no longer able to discuss the materials as they are unavailable.

If there is "pro-Palestinian" materials at the IA, I would imagine it being based on materials collected over the past year documenting the genocide, war crimes, and crimes against humanity being committed against them.

There is a definite effort to censor any and all reporting of Israeli crimes against humanity on the Internet - IA was probably a last refuged for those collecting this material.

Re: Internet Archive: Security breach alert

#528

More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-arch...

My question is: How did Scott Helme end up with a password hash that features his own name?

He didn't. If you break down that field you see:

    $2a$
    10$
    Bho2e2ptPnFRJyJKIn5Bie
    hIDiEwhjfMZFVRM9fRCarKXkemA3Pxu
    ScottHelme
2a = bcrypt, 10 = 2^10 rounds, Bho2e2ptPnFRJyJKIn5Bie is the 22 character salt, hIDiEwhjfMZFVRM9fRCarKXkemA3Pxu is the 31 character hash value, and then there's ScottHelme. Best guess is that the archive.org folks just appended the user name to the stored hash. Maybe once upon a time they didn't have a username column in their table and this was a creative way of adding it.

Re: Internet Archive: Security breach alert

#529

Earlier quoted context omitted.

[flagged]

Alarm didn't go off - Russia. Missed the bus - Russia. Stubbed my toe - FFS why is it always Russia? Not excusing it, Russia, China and Iran do make my honeypot's top ten list every month. But then again so do the US, UK and France....

The UK, US, France etc. all have their serious problems and are far from perfect.

But they are democracies, not some kind of real life Sacha Baron Cohen sketch..

Re: Internet Archive: Security breach alert

#530

I have had an IA account for a number of years, with a gmail address. Nine months ago, I changed the email address to a masked address using my own domain. Now I find that my gmail address was still stored, and was involved in the breach. Why? I get that they might store change history, but why? BTW, for the current account details, I changed the password to another random string generated by my password manager, and…

I have a similar situation, where I signed up with my main account and later changed IA's email to a more private address. It was the first email I checked on HaveIBeenPwned and it doesn't show up in this leak. The other couple IA accounts I have, whose emails and passwords are exclusive to them, they all show in this leak alright. I have no explanation to your situation but this was also my immediate though and I also wanted to give the opposite perspective.
Post reply on HN