Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

581–590 of 648 posts

Re: Internet Archive: Security breach alert

#581

Earlier quoted context omitted.

Jokes on them... I'm already on HIBP countless of times...

I'm also on HIBP over 10x. What are we supposed to do? Create a new email address for every service we sign up for? I don't know what the best practice is for keeping our personal data safe anymore.

Yep. ~300 addresses on my domain, 0 breaches across all of them on HIBP domain search over >6 years.

I guess internet security is not as bad these days. :)

Re: Internet Archive: Security breach alert

#582
post #540

Earlier quoted context omitted.

This was a problem already before the generative AI era, it just got less expensive. The only way to reduce it is to have two work addresses: one that you rarely check and is exposed to the public, listed on your profile etc., and the real internal one just to get the work done.

>it just got less expensive Quantity is a quality. Add that the AI can profile you and do a decent job spear phishing and you're talking about a sea change. >and the real internal one “Three can keep a secret, if two of them are dead.” There is no such thing as an 'internal' email you communicate to other people outside your company with. It's just an email address. Someone at some point will leak it by accident or m…

> There is no such thing as an 'internal' email you communicate to other people outside your company with. It's just an email address. Someone at some point will leak it by accident or malice.

Sure, so personally I never use it to communicate with people outside. Also, I make sure it's never used to register with external licenses like Docker Desktop etc. as they subscribe me to their spamlist and send the usual semi-personalized messages - but as far as I can tell most of these bigger companies don't sell them outside (for a good reason). Startups, however, will do what they want and will make sure to squeeze the last drop from the info that such-and-such person works and that company and does X.

Re: Internet Archive: Security breach alert

#583
post #128

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

I have always thought about this. It would be interesting to have users actually store small amounts of redundant info on a device connected to the internet. Very similarly to what a torrent does but with more peers (more data shards than full copies) and less seeds. And try and keep a huge database for everyone. Obviously open source and it would end up something like tor where they just assist the network with secu…

Are you, by any chance, named Richard Hendricks?

Re: Internet Archive: Security breach alert

#585
post #437

What kind of asshole attacks the Internet Archive of all places on the web??

Pro-palestine activists: https://x.com/Sn_darkmeta/status/1844080692772401399 & https://x.com/Sn_darkmeta/status/1844104165192253945

>They are under attack because the archive belongs to the USA, and as we all know, this horrendous and hypocritical government supports the genocide that is being carried out by the terrorist state of “Israel”.

Ah yes, known arm of the US military-industrial complex, The Internet Archive

Re: Internet Archive: Security breach alert

#586
post #95

Earlier quoted context omitted.

That's a strange thing to read on Hacker news. Isn't that description the definition of hack value? As in http://www.catb.org/jargon/html/H/hack-value.html Now, it depends what the "it" is referring to here, but so far all I've heard is about an alert() message saying the usernames will be sent to a breach alerting site. If they're doing it just for the heck of it, it's still costing a lot of people a lot of time tha…

Did you miss the part about the DDOS attack?

I did actually, since the quote didn't specify and the submission's link changed after I opened the comments. Thanks for pointing it out in case I hadn't seen it in the meantime!

Re: Internet Archive: Security breach alert

#588
post #53

Earlier quoted context omitted.

Ok, let's switch to that link. Thanks! Submitted URL was https://archive.org/ .

The verge generally is clickbait, another site choice would have been better.

That class of sites generally is, yes. But on HN we go by article quality, not site quality (https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...) and I didn't see a better specific article on this. If there is a better one, we can change the link again.

Re: Internet Archive: Security breach alert

#589

Earlier quoted context omitted.

> the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service Do they? Why?

If Troy authenticates the data, they can use that as an 'endorsement' when trying to sell it.

Is there a way to modify the HIBP reporting process to avoid aiding the sale of stolen data?

Re: Internet Archive: Security breach alert

#590
post #385

Earlier quoted context omitted.

Yes, without exception. I want to know who is leaking/selling my address, and usually stop doing business with those who do. It also makes filtering really easy. People sometimes have strange reactions when I verbally give them an email address with their company name in it, especially when I'm a new customer. All you need is a domain and an email provider that allows catch-all addresses, both of which are easy and c…

I always see people claiming they use this strategy, but I never ever ever see people blaming services saying "this and this company sold my data to spammers". Where are the name-and-shame people? Have you ever caught anybody doing anything?

It's hard to distinguish between leaking and selling, but I think leaking is much more common. Dropbox famously leaked a lot of emails in ~2012, including mine - I was never a paying customer and that put me off becoming one or using them (to this day most spam sent to my domain is to that Dropbox address). Two local PC parts companies leaked or sold my email. I confronted one about it and they claimed they hadn't had a data breach, so either they sold it, or they were too incompetent to know they'd been hacked, or they lied - I suspect incompetence but whatever happened they lost my business. A couple more incidents long ago too.

Real estate agents can be pretty aggressive with emailing, but IME respect unsubscribes and don't seem to share/leak emails. I kind of wish I'd used an address per agent instead of per company to see what was happening better.

Non-company uses can also reveal issues. I had an address scraped from a flatmate finding site, and one apparently lifted from a relative's contact list somehow (I only have one I use for family, so that was a concern, but spam to it petered out quickly).

Post reply on HN