Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

561–570 of 648 posts

Re: Internet Archive: Security breach alert

#561
post #137

Earlier quoted context omitted.

>No statement, no idea, no demands. A special place in Hell… I mean... would it be better if the hackers had asked for money or did it to protest global warming or something?

"Say what you will about the tenets of National Socialism, but at last it's an ethos ."

I can't imagine having to experience the world exclusively through WW2 propaganda.

Re: Internet Archive: Security breach alert

#562
post #385

Earlier quoted context omitted.

Out of curiosity, do you use a unique email address for every single service?

Yes, without exception. I want to know who is leaking/selling my address, and usually stop doing business with those who do. It also makes filtering really easy. People sometimes have strange reactions when I verbally give them an email address with their company name in it, especially when I'm a new customer. All you need is a domain and an email provider that allows catch-all addresses, both of which are easy and c…

is each address truly unique or are you doing something like username+archive@gmail.com, username+facebook@gmail.com, etc.

Re: Internet Archive: Security breach alert

#563
Does IA have much information on users? I’ve been in dozens of these HIBP leaks (including this one) but still none have concerned me, since they were mostly just email/password and nothing else.

Does IA store anything sensitive for any users?p physical addresses, credit cards, etc?

Re: Internet Archive: Security breach alert

#564

Just in terms of privacy, it's worth noting that anyone who has uploaded something on IA already has their email address publicly viewable. This isn't something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader's IA account email address. So from a security perspective it's bad but from a privacy perspective a lot of users probably weren…

This is bad enough. This alone is a privacy bug/data leak. Theoretically, someone could scrape the pages and compile a list of exposed email addresses.

> Theoretically, someone could scrape the pages and compile a list of exposed email addresses.

I laughed. Oh no! Anyways…

The people interested in identity theft are probably too busy figuring out what to do with all the SSNs they stole (not from this breach, but from the annual catastrophic breach of a credit bureau or government repository).

And the people who want your email probably already got it from one of the hundreds of other services you have to create an account for now.

I’m not really sure if there are circumstances where donating to the internet archive could be held against you and lead to persecution. Maybe in certain Luddite communities? The Amish? But then, how would they know…

Re: Internet Archive: Security breach alert

#565

Earlier quoted context omitted.

Just a reminder that AI tried pivoting to much more clear-cut legitimate piracy, presumably because they got bored or something, and certainly put ‘donations’ toward that effort. IA is an incredibly valuable resource, but let’s not put them on a pedestal.

What's "legitimate piracy"? As a reminder, the scheme was designed to work exactly like typical lending libraries. Publishers were unable to show any harm, and the only evidence available proved they actually benefited from better sales thanks to the Internet Archive. Authors were clearly benefited. https://www.techdirt.com/2024/09/05/second-circuit-says-libr... But I agree, no need to put them on a pedestal. Nobody…

> As a reminder, the scheme was designed to work exactly like typical lending libraries.

Wasn't the issue precisely that they removed that limitation and then never added it again?

Re: Internet Archive: Security breach alert

#566

Earlier quoted context omitted.

MFA

... is not something your should rely on.

… but something you should do anyway.

Having unique passwords isn’t something you should rely on either. Good MFA practices limits the impact of breaches like this. It isn't an either/or thing, do both.

Re: Internet Archive: Security breach alert

#567
post #2

Just noticed the site now alerts this: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!

Jokes on them... I'm already on HIBP countless of times...

And my SSN's probably available for purchase with 9 types of crypto, too.

Re: Internet Archive: Security breach alert

#568

Earlier quoted context omitted.

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

There is software which is intended to e.g. locate the GitHub profiles of people working at companies, then scrape all public repositories they've contributed to for their email address and the emails of their coworkers - to enable targeted advertising to those individuals. Very common in enterprise sales. With ChatGPT, this can be extended to create emails that look very personal - as if someone has followed all of…

>With ChatGPT, this can be extended to create emails that look very personal - as if someone has followed all of your work and is genuinely interested in what you are up to - with extremely low effort. And people are already doing this, I already get emails like this today.

shit, now i don't feel like sending e-mails to people i'm actually interested in

Re: Internet Archive: Security breach alert

#569
post #139

Earlier quoted context omitted.

It does work, when you don't notice it. We need sane limits and permanent seeders. This is why so many regular people get hit with ISP notices, they don't know they've seeded Captain America for the last six months every time they started their PC.

Yup. If browsers built in support for magnet links and (on desktop) defaulted to seeding with some capped bandwidth then a lot of centralized hosting platforms would become unnecessary.

iirc opera browser tried that

Re: Internet Archive: Security breach alert

#570
post #385

Earlier quoted context omitted.

Out of curiosity, do you use a unique email address for every single service?

Yes, without exception. I want to know who is leaking/selling my address, and usually stop doing business with those who do. It also makes filtering really easy. People sometimes have strange reactions when I verbally give them an email address with their company name in it, especially when I'm a new customer. All you need is a domain and an email provider that allows catch-all addresses, both of which are easy and c…

I always see people claiming they use this strategy, but I never ever ever see people blaming services saying "this and this company sold my data to spammers". Where are the name-and-shame people? Have you ever caught anybody doing anything?
Post reply on HN