Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

81–90 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#81

Restating my love for Internet Archive and my plea to put a grownup in charge of the thing. Washington Post: The organization has “industry standard” security systems, Kahle said, but he added that, until this year, the group had largely stayed out of the crosshairs of cybercriminals. Kahle said he’d opted not to prioritize additional investments in cybersecurity out of the Internet Archive’s limited budget of around…

In security, industry standard seems to be about the same as military grade: the cheapest possible option that still checks all the boxes for SOC.

Checking the boxes for SOC is a lot more than most places do, does IA have SOC compliance? I doubt it.

Re: Internet Archive breached again through stolen access tokens

#83

Earlier quoted context omitted.

IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.

Do you have any examples?

Putting the organisation at risk by playing chicken with large publishing corporations. Trying to stretch fair use a little too far so they had to go to court.

Re: Internet Archive breached again through stolen access tokens

#84

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

There are many state actors that attack targets of opportunity just to cause chaos and asymmetric financial costs.

Re: Internet Archive breached again through stolen access tokens

#85
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

[deleted]

Re: Internet Archive breached again through stolen access tokens

#87

Restating my love for Internet Archive and my plea to put a grownup in charge of the thing. Washington Post: The organization has “industry standard” security systems, Kahle said, but he added that, until this year, the group had largely stayed out of the crosshairs of cybercriminals. Kahle said he’d opted not to prioritize additional investments in cybersecurity out of the Internet Archive’s limited budget of around…

[deleted]

Re: Internet Archive breached again through stolen access tokens

#89

A genuine question to commenters asking to "put a grownup in charge of the thing" and saying that "Kahle shouldn't be running things": he built the thing, why exactly he can't run it the way he sees fit?

A good place to direct that question might be in a reply to the person who made that comment.
Post reply on HN