Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

61–70 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#61
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.

It's the least worst option. Remember when that happened with Mozilla? Now they're an ad company. Take the bad (some bad mis-steps re:multiple lending during the pandemic, not rotating keys immediately after a hack) with the good (staying true to the human centric mission and not the money flows).

Re: Internet Archive breached again through stolen access tokens

#62
post #57

Earlier quoted context omitted.

Do you have any examples?

[flagged]

I don't believe IA itself takes down pages that kiwifarms archives/links to. Rather they get a request to take it down and comply with it (correct me if I'm wrong here). I think IA is actually in a tough spot on this issue because they might be able to be sued eg. for defamation if they don't take down pages with personal info after a request to do so is made. Lastly, I doubt any new leadership would be less harsh on kiwifarms.

Re: Internet Archive breached again through stolen access tokens

#63
post #21

Earlier quoted context omitted.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

> nowhere near enough people actually put their storage where their mouths are. Typically because most people who have the upload, don't know that they can. And if they come to the notion on their own, they won't know how. If they put the notion to a search engine, the keywords they come up with probably don't return the needed ELI5 page. As in: How do I [?] for the Internet Archive? , most folks won't know what [?]…

This is literally torrents. Just give up

Re: Internet Archive breached again through stolen access tokens

#64
post #59

A genuine question to commenters asking to "put a grownup in charge of the thing" and saying that "Kahle shouldn't be running things": he built the thing, why exactly he can't run it the way he sees fit?

He is. But at the cost of the greater good. Most of us care mainly about the Wayback Machine and archiving webpages; not borrowing books still under copyright and fighting publishers.

Speak for yourself, the internet archive successfully increased its scope and made creative contributions to case law (although it lost at the appeals court)

Re: Internet Archive breached again through stolen access tokens

#66

Earlier quoted context omitted.

That's true, but something like archiving the internet is very costly, IA has an annual budget in the tens of millions.

Yes, it's a good point. Though they could take that money and reward people for hosting the data as well, couldn't they? They don't have to be in charge of hosting.

Yes, they could, that's not much different than a single company distributing the archive to multiple storage centers though. My original comment was about it being more cost effective for a single company to do that than coordinating with a bunch of disjoint entities.

Re: Internet Archive breached again through stolen access tokens

#67
post #60

Earlier quoted context omitted.

Lots of Copies Keeps Stuff Safe https://www.lockss.org/ This is a brilliant system relying on a randomised consensus protocol. I wanted to do my info sec dissertation on it, but its security model is extremely well thought out. There wasn't anything I felt I could add to it.

High Costs Makes Lots of Copies Unfeasible

That was actually one of the key constraints in the LOCKSS system, since it was designed to be run by libraries that don't have big budgets.

The design is really very good.

Re: Internet Archive breached again through stolen access tokens

#68
post #30

Earlier quoted context omitted.

Hot take, this is the way it should be. If you want better security then you update the requirements to get your certification. Security by its very nature has a problem of knowing when to stop. There's always better security for an ever increasing amount of money and companies don't sign off on budgets of infinity dollars and projects of indefinite length. If you want security at all you have bound the cost and have…

This ^ We can’t all have the latest EPYC processors with the latest bug fixes using Secure Enclaves and homomorphic encryption for processing user data while using remote attestation of code running within multiple layers of virtualization. With, of course, that code also being written in Rust, running on a certified microkernel, and only updatable when at least 4 of 6 programmers, 1 from each continent, unite their…

[flagged]

Re: Internet Archive breached again through stolen access tokens

#69
post #21

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

And it's guaranteed not to happen if the efforts don't continue.

Re: Internet Archive breached again through stolen access tokens

#70

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

To make the web distributed-archive-friendly I think we need to start referencing things by hash and not by a path which some server has implied it will serve consistently but which actually shows you different data at different times for a million different reasons.

If different data always gets a different reference, it's easy to know if you have enough backups of it. If the same name gets you a pile of snapshots taken under different conditions, it's hard to be sure which of those are the thing that we'd want to back up for that particular name.

Post reply on HN