Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

631–640 of 648 posts

Re: Internet Archive: Security breach alert

#631
post #128

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

I have always thought about this. It would be interesting to have users actually store small amounts of redundant info on a device connected to the internet. Very similarly to what a torrent does but with more peers (more data shards than full copies) and less seeds. And try and keep a huge database for everyone. Obviously open source and it would end up something like tor where they just assist the network with secu…

I believe that it would be possible to cost effectively build and implement an architecture for a distributed IA backup—this comment entails some notes.

The system that asks volunteers about their age, sex, location, and storage format details (the model, past use etc. can be used to predict the durability of a single storage) without sharing most of this data anywhere.

The downloaders are then algorithmically allocated pieces of the archive. Exampli gratia such that there is at least limited amount of overlap between the pieces, and two people same country won't provide redunancy for each other.

When a downloader verifies that they have completed the download by giving (unique, to prevent fake-download sabotage) SHA hashes of the data, the information that these pieces have been downloaded in this or that country, plus an estimate of the reliability of the storage, is added to a public database, for the algorithm to use in the future.

Every downloader is then generated a public and private key so that they can give the hash of their download again once in a while or just verify that the piece is still there. The reliability estimates (based on storage / hardware details) would be empirically calibrated based on the data about the actual storage failures.

A public counter, estimating how well the archive is currently backed up via this scheme, could be displayed.

For copyright issues, it would be possible to encrypt some of the data, e.g. such that normally borrowable items become readable files only when X% of downloads are pieced together.

The scheme would be primarily based on existing designs and algorithms but work roughly as depicted above. I am not an expert of what compression, hashing and other algorithms should be used, and it needs lots of good work, to determine how to avoid errors in the scientific part of estimating the reliability of the downloads—and generally a situation where it would turn out that lots of data was lost when attempting to put the pieces back together again.

Remark (engineering): To empirically validate the correctness of the software of the backup architecure by testing it on grids of real hard drives in single places will probably give safety against catastrophic failure. Even better would be to obtain large amount of old hard drives and SSDs kept in a single place for a long time, to validate that the software works over time.

Remark (integrity): That a downloader actually has the downloads can be verified efficiently by IA server adding small part to the piece the downloader has, hashing it again, and requesting the new hash.

Remark (redunancy): It may be possible to develop a social program that analyzes whether a volunteer in certain place can provide more redunancy by buying themselves a hard drive or by supporting the acquisition of hard drives for volunteers who have proved themselves realiable elsewhere. This is speculative and the benefit may be lower than the risks.

Finally, instead of "public database" it may be much more optimal to decide to use a blockchain of some sort. Not a cryptocurrency, but a blockchain. This is because if the idea is to distribute copies over the world to ensure continguency in case of IA main architecture collapse, then the more parts of the distributed backup architecture (which must actually not be "the backup architecture" but "a scheme", that no everyday IA decisions rely upon, and that just exists out there) are on a blockchain network run by a "decentralized" system, the more reliable it will be.

My heuristic plausibility analysis: 0. IA backup would not need to be constantly accessed or changed (this makes storage easier, cheaper and prolongs the maximun age of the storage) 1. Not all IA has to be backed up: a distrobuted backup that successfully recovers 10% of IA in a catastrophe is by all means a great success (consequently priorization of what might / should be stored should probably be part of the algorithm that decides what volunteers download; and what existing "big" archives already store that overlaps with IA should be taken into account in this analysis) 2. I recall you estimated 30-40 M USD ballparks for a single copy: a properly led open source project may be able to develop this for free, and fairly compensated one could be ~ 0.1% to 1% of the cost. 3. The Sia network https://siascan.com/ has space for 7PB; and it's for storage where one can download their own files at any time; and they have had very little publicity. 4. 2TB hard drive costs 50-100 USD and 20PB would be 10 000 humans buying one 2TB hard drive which by itself is possible. Hobbyists and organizations may be able to provide even larger capacities. 5. Most IT projects fail, but since lots of technology already exists and in this we know what we are doing and IA might be able to recruit above talent we can conservatively, give conservatively 50% chance the groundwork development to succeed, or 45% without funding. 6. If the develoment succeeds, then there may already be around ~ 100 potential volunteers. I estimated that 0.1% IA visitors may volunteer, plus 1% from Hacker News traffick were to project to be mentioned there, plus growth over first few years and traffick from elsewhere. Perhaps 75% chance to get 10% of IA backed up by volunteers, given development succeeds. 7. If that much is backed up, there is perhaps 5% of attaining 200 TB in next few decades.

Conservatively, given that open-source development starts, one gets apprx. 33% - 38% chance that 10% backup is achieved & apprx. 1-2% that 100% of what is now in the IA, could be backed up. These are of course rather meaningless numbers, but the fact seems that in the lack of funding to build a complete backup IA can best guarantee continguency by starting to build a distributed one. Perhaps this was needlessly lots of words for a simple proposal.

- X

---

Note: It's probable that at least the NSA has a private full IA backup.

Re: Internet Archive: Security breach alert

#632

Earlier quoted context omitted.

i hate how Zionism has become a bad word, like it's some world domination conspiracy theory. as a Zionist myself, it's not at all likely that IA was attacked to take down Zionist-related material as these material are neither embarrassing nor damaging to Israel. on the contrary, I would like for them to stay up and be archived for all eternity. what is more likely is that these pro-Palestinian hacktivists are once mo…

> as these material are neither embarrassing nor damaging to Israel Yes, but they should be.

i'm keeping an open mind. if you can cite them here, that'd be helpful.

Re: Internet Archive: Security breach alert

#633

Earlier quoted context omitted.

i hate how Zionism has become a bad word, like it's some world domination conspiracy theory. as a Zionist myself, it's not at all likely that IA was attacked to take down Zionist-related material as these material are neither embarrassing nor damaging to Israel. on the contrary, I would like for them to stay up and be archived for all eternity. what is more likely is that these pro-Palestinian hacktivists are once mo…

>i hate how Zionism has become a bad word What do you consider worse? The Genocide of the people of Gaza and the occupation? Or that the Zionism is now a bad word?

what i consider the worse is October 7 when Israel was attacked by the terrorists Hamas. if you can condemn Hamas, then we can have a conversation

Re: Internet Archive: Security breach alert

#634

Earlier quoted context omitted.

Alarm didn't go off - Russia. Missed the bus - Russia. Stubbed my toe - FFS why is it always Russia? Not excusing it, Russia, China and Iran do make my honeypot's top ten list every month. But then again so do the US, UK and France....

The UK, US, France etc. all have their serious problems and are far from perfect. But they are democracies, not some kind of real life Sacha Baron Cohen sketch..

Democratic is a bit of a stretch; two are republics and one has a man appointed by god at the helm

All three have mechanism in place to keep (wrong think) away from any form of power.

Re: Internet Archive: Security breach alert

#635

Earlier quoted context omitted.

It’s a joke ! You can run an email server off your phone

Not sure if mobile carriers would allow the required ports to be routed, and the connection is usually behind CGNAT, so you can't accept connections from the outside to receive emails. Many home ISPs however can give you a (mostly) unfiltered public IP that once paired with a dynamic DNS service can be reached from the outside. Once the network part is solved, a small cheap box (*Pi like board, mini PC, etc) can be s…

I meant just in terms of compute power. Like my isp gives me a static IP with forward and reverse dns, and the box lets me put the phone WiFi ip address in the DMZ so all traffic is handled by the phone. Then the termux app lets me run sshd and other stuff.

And actually I think this is a kind of setup people could get into: an Android dist that focuses on self hosting off an older device.

Re: Internet Archive: Security breach alert

#636

Earlier quoted context omitted.

they use Stripe

If you're a blackhat and you want to be annoying, you can use Stripe tokens to charge your target's customers. The target is the payee, so you won't make any money, but it'll add to the chaos.

If Stripe hasn't already, it won't be long until they revoke all of IA's tokens in the event they start using them.

Re: Internet Archive: Security breach alert

#637
post #521

Earlier quoted context omitted.

[flagged]

> Its always russia Ah the only conspiracy theory we’re encouraged to believe. Wouldn’t that be convenient. A perpetual enemy far away that’s responsible for all of our failures, infiltrating and puppeteering western democracies on the other side of the world. Even the Russian propaganda machine loves this narrative – it makes them seem powerful and dangerous. Not like a corrupt and broken former empire sending off t…

Found Ivan

Re: Internet Archive: Security breach alert

#638
post #470
post #400

Imagine if we could get rid of passwords. Entirely. Forever.

You don't need to daydream, just use a password manager.

I use several, but I dream about a world with no passwords. Managers or not, passwords are always at risk and it is only a matter of time before one of the 300 sites leaks your data.

Re: Internet Archive: Security breach alert

#639

Earlier quoted context omitted.

I see 24 seeders for the entire 72-episode run of the 1991 sitcom "Herman's Head" which was so poorly rated that it's never seen a home media or streaming release, your premise doesn't hold any water at all.

People are pirating comic books and cookbooks from the 30s; there are a lot of people in this world, if something goes on the web and you tell everyone you put it there, it's pretty much preserved. It's only law enforcement that kills free availability of everything all the time online, for better or for worse. With copyright, as individuals we get to trade all of the wonderful stuff already made (and long paid for)…

> With copyright, as individuals we get to trade all of the wonderful stuff already made (and long paid for) for the flood of minute-old shit and sludge inundating us online constantly.

What does this have to do with copyright? People post sludge online even in chaotic meme environments where copyright is irrelevant and people constantly take and repost each others' stuff.

Re: Internet Archive: Security breach alert

#640
post #128

A pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.

I have always thought about this. It would be interesting to have users actually store small amounts of redundant info on a device connected to the internet. Very similarly to what a torrent does but with more peers (more data shards than full copies) and less seeds. And try and keep a huge database for everyone. Obviously open source and it would end up something like tor where they just assist the network with secu…

Does https://ipfs.tech/ fit the bill?
Post reply on HN