Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

611–620 of 648 posts

Re: Internet Archive: Security breach alert

#611

Considering the hacker's motive: https://x.com/Sn_darkmeta/status/1844358501952618976 Is it safe to assume the hacker want to erase the evidence? Forcing the service offline also means they want to prevent people from archiving evidence in the next how-ever-long hours. Combining with the spoken language they used in that video, are they planning some online disinformation campaign? ---- Edit: some more info about thi…

Possible false flag?

How is someone stupid enough to post this? Warrant for the account's IP is probably already issued. I don't know how many proxies the guy is behind, but it's playing with fire.

Also at some point the account of a malicious hacker has to be banned right?

Re: Internet Archive: Security breach alert

#612

Just in terms of privacy, it's worth noting that anyone who has uploaded something on IA already has their email address publicly viewable. This isn't something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader's IA account email address. So from a security perspective it's bad but from a privacy perspective a lot of users probably weren…

This raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then t…

I think it just needs to be communicated. Some websites allow login only by login name and not by email, some people have identifying last name, others hardly identifying full name and whatnot. There's no universal or universally agreed answer to that, so it needs to be said whether your service _consider_ it public information or not.

Re: Internet Archive: Security breach alert

#613

Considering the hacker's motive: https://x.com/Sn_darkmeta/status/1844358501952618976 Is it safe to assume the hacker want to erase the evidence? Forcing the service offline also means they want to prevent people from archiving evidence in the next how-ever-long hours. Combining with the spoken language they used in that video, are they planning some online disinformation campaign? ---- Edit: some more info about thi…

Possible false flag? How is someone stupid enough to post this? Warrant for the account's IP is probably already issued. I don't know how many proxies the guy is behind, but it's playing with fire. Also at some point the account of a malicious hacker has to be banned right?

Check my edited comment for more info on that account. In short, typical russian shenanigans.

>Also at some point the account of a malicious hacker has to be banned right?

You can try ask musk about it.

Re: Internet Archive: Security breach alert

#614

Earlier quoted context omitted.

What are you "borrowing" from the Archive?

Books. (Until they're vanished by publishers. https://www.techdirt.com/2024/06/20/500000-books-have-been-d... )

How is viewing some bytes on your monitor "borrowing"? Whose copy of the book goes missing when you do that?

Re: Internet Archive: Security breach alert

#615

Earlier quoted context omitted.

Curious, how trivially easy is that?

It's quite trivial. 1. Buy a domain. About $10/year for a .com 2. Buy a /24 ipv4 block with good reputation (maybe like $10k) 3. Get a rack in a nearby datacenter, rack up a BGP-capable router and your servers for redundancy to run email. Takes about $30k initial setup costs if you buy all new, and about $5k initial setup costs if you cut corners and buy used. It'll be $2k/mo after that, so less than the cost of 1 $1…

Hold on.

Where are you finding $100 avocado toast?

Re: Internet Archive: Security breach alert

#616

Earlier quoted context omitted.

> One could create entirely separate accounts but it's high friction and IIRC the > same phone number (now a requirement) can only be used for 2-3 accounts. I've wondered about this. Every Android/ChromeOS device I've ever bought, I had a new Google account created for it (during setup, instead of using an existing account), and only a few actually had phone numbers (I don't generally use smartphones for telephony).…

Why did you do that? Android doesn't require an account to work.

(For both Android and ChromeOS) I thought it would be significantly easier to let it use a Google account, than it would be to make it proceed without one. Was I wrong? Serious question.

Links to information would be appreciated, even/especially if it's a complex task to do this.

(I never put a lot of effort into this, because having the Google account be anonymous/fake-named was generally tolerable for my privacy standards)

Re: Internet Archive: Security breach alert

#617

Earlier quoted context omitted.

It's called torrent protocol and it doesn't work, no one wants to spend money and bandwidth hosting a god forsaken movie or book that only a handful of people care about.

I've been seeding some unpopular torrents for ten years (would have done for even longer if I did not change the torrent client a decade ago). "No one" is too strong a word, as usual with these absolutist things.

Agree, shouldn't have said no one. But you got to recognize that some torrent are most popular than other.

I would have absolutely no trouble downloading the latest marvel movie but if you are looking for some old Soviet movie, Iranian movie or even old American movie then you're in bad luck. I've never seen more than 0 seeder on thepiratebay.

Re: Internet Archive: Security breach alert

#619

Earlier quoted context omitted.

Where on HIBP can I see the email of the submitter?

It's not available in this case, or every case. When available, you can search "The data was provided by" in https://haveibeenpwned.com/PwnedWebsites

Thanks! Slight correction: only 2 breaches say "provided by" with a source, but a ton of breaches say "provided to" HIBP with a source.
Post reply on HN