Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

541–550 of 648 posts

Re: Internet Archive: Security breach alert

#541

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

A decentralized solution, doesn't that scream internet archive on blockchain? What could go wrong.

torrents maybe

Re: Internet Archive: Security breach alert

#543

Just in terms of privacy, it's worth noting that anyone who has uploaded something on IA already has their email address publicly viewable. This isn't something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader's IA account email address. So from a security perspective it's bad but from a privacy perspective a lot of users probably weren…

One solution is to use a unique email address for every website, and change the address if the site gets compromised (with the old address getting added to a spam filter).

Re: Internet Archive: Security breach alert

#544

Just in terms of privacy, it's worth noting that anyone who has uploaded something on IA already has their email address publicly viewable. This isn't something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader's IA account email address. So from a security perspective it's bad but from a privacy perspective a lot of users probably weren…

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

>Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts.

Buildings are analogous to domains, not email addresses.

Re: Internet Archive: Security breach alert

#545

Earlier quoted context omitted.

Proton Mail and iCloud’s hide my e-mail feature allow users to have unlimited e-mail addresses. You can also get unlimited e-mail addresses by running your own e-mail server or using something like Office 365’s business e-mail (costs about $4 per month).

is running your own e mail server a good idea in 2024? Security issues aside, you are at the mercy of the big email providers and whatever rules they want you to follow

I think the cost of paying for a dedicated email service is worth it. (There are plenty of smaller, privacy-oriented services such as Proton Mail or Fast Mail.)

They're better at it than I am, and it means I don't have to fill up my free time maintaining another server.

Re: Internet Archive: Security breach alert

#546

It looks like someone has compromised one of their subdomains for Polyfill Update: Subdomain seems to be returning normal responses again now.

That would perhaps explain how they managed to inject the JS alert popup, right?

Yeah, but the leak has been confirmed by HIBP, I found my address in there.

Re: Internet Archive: Security breach alert

#547

The funny thing is the internet archive is more connected to hacker culture than cracking a website will ever be. I hate posers more than anything. Hopefully the internet archive comes back stronger than ever.

Yeah, this is hacker news, not hacking news

Re: Internet Archive: Security breach alert

#550

I wonder how they got access the their database? I read in this thread that they likely used a supply chain attack by replacing some polyfill scripts. So they could've injected malicious code (XSS) that logged email and password to a remote server which they could have gone through. With a bit of luck they couldve gotten access to an admin account or whatever…

That much is not clear yet. It's possible the polyfill is an unrelated red herring, but it's also possible they somehow managed to elevate permissions. Seems the polyfill use was self hosted as well.

Maybe they managed to convince some critical service like an SSL cert provider that they were the owners of the subdomain? I don't know still wouldn't explain access to user and password database.

Post reply on HN