Restating my love for Internet Archive and my plea to put a grownup in charge of the thing. Washington Post: The organization has “industry standard” security systems, Kahle said, but he added that, until this year, the group had largely stayed out of the crosshairs of cybercriminals. Kahle said he’d opted not to prioritize additional investments in cybersecurity out of the Internet Archive’s limited budget of around…
In security, industry standard seems to be about the same as military grade: the cheapest possible option that still checks all the boxes for SOC.
Internet Archive breached again through stolen access tokens
81–90 of 376 posts
Re: Internet Archive breached again through stolen access tokens
#82Re: Internet Archive breached again through stolen access tokens
#83Earlier quoted context omitted.
IA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.
Do you have any examples?
Re: Internet Archive breached again through stolen access tokens
#84It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.
Re: Internet Archive breached again through stolen access tokens
#85> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…
Re: Internet Archive breached again through stolen access tokens
#86Re: Internet Archive breached again through stolen access tokens
#87Restating my love for Internet Archive and my plea to put a grownup in charge of the thing. Washington Post: The organization has “industry standard” security systems, Kahle said, but he added that, until this year, the group had largely stayed out of the crosshairs of cybercriminals. Kahle said he’d opted not to prioritize additional investments in cybersecurity out of the Internet Archive’s limited budget of around…
Re: Internet Archive breached again through stolen access tokens
#88A genuine question to commenters asking to "put a grownup in charge of the thing" and saying that "Kahle shouldn't be running things": he built the thing, why exactly he can't run it the way he sees fit?
Re: Internet Archive breached again through stolen access tokens
#89A genuine question to commenters asking to "put a grownup in charge of the thing" and saying that "Kahle shouldn't be running things": he built the thing, why exactly he can't run it the way he sees fit?
Re: Internet Archive breached again through stolen access tokens
#90I'd like to imagine a world where every lawyer, when their case is helped by a Wayback Machine snapshot of something, flips a few bucks to IA. They could afford a world-class admin team in no time flat.