> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…
IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.
Internet Archive breached again through stolen access tokens
61–70 of 376 posts
Re: Internet Archive breached again through stolen access tokens
#62Earlier quoted context omitted.
Do you have any examples?
[flagged]
Re: Internet Archive breached again through stolen access tokens
#63Earlier quoted context omitted.
This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.
> nowhere near enough people actually put their storage where their mouths are. Typically because most people who have the upload, don't know that they can. And if they come to the notion on their own, they won't know how. If they put the notion to a search engine, the keywords they come up with probably don't return the needed ELI5 page. As in: How do I [?] for the Internet Archive? , most folks won't know what [?]…
Re: Internet Archive breached again through stolen access tokens
#64A genuine question to commenters asking to "put a grownup in charge of the thing" and saying that "Kahle shouldn't be running things": he built the thing, why exactly he can't run it the way he sees fit?
He is. But at the cost of the greater good. Most of us care mainly about the Wayback Machine and archiving webpages; not borrowing books still under copyright and fighting publishers.
Re: Internet Archive breached again through stolen access tokens
#65I sent them a resume almost a year ago, and got nothing back in response until yesterday. Looks like they are going through their backlog right now to find more hands.
Re: Internet Archive breached again through stolen access tokens
#66Earlier quoted context omitted.
That's true, but something like archiving the internet is very costly, IA has an annual budget in the tens of millions.
Yes, it's a good point. Though they could take that money and reward people for hosting the data as well, couldn't they? They don't have to be in charge of hosting.
Re: Internet Archive breached again through stolen access tokens
#67Earlier quoted context omitted.
Lots of Copies Keeps Stuff Safe https://www.lockss.org/ This is a brilliant system relying on a randomised consensus protocol. I wanted to do my info sec dissertation on it, but its security model is extremely well thought out. There wasn't anything I felt I could add to it.
High Costs Makes Lots of Copies Unfeasible
The design is really very good.
Re: Internet Archive breached again through stolen access tokens
#68Earlier quoted context omitted.
Hot take, this is the way it should be. If you want better security then you update the requirements to get your certification. Security by its very nature has a problem of knowing when to stop. There's always better security for an ever increasing amount of money and companies don't sign off on budgets of infinity dollars and projects of indefinite length. If you want security at all you have bound the cost and have…
This ^ We can’t all have the latest EPYC processors with the latest bug fixes using Secure Enclaves and homomorphic encryption for processing user data while using remote attestation of code running within multiple layers of virtualization. With, of course, that code also being written in Rust, running on a certified microkernel, and only updatable when at least 4 of 6 programmers, 1 from each continent, unite their…
Re: Internet Archive breached again through stolen access tokens
#69We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.
This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.
Re: Internet Archive breached again through stolen access tokens
#70We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.
If different data always gets a different reference, it's easy to know if you have enough backups of it. If the same name gets you a pile of snapshots taken under different conditions, it's hard to be sure which of those are the thing that we'd want to back up for that particular name.