Live data from Hacker News

Internet Archive breached again through stolen access tokens

bleepingcomputer.com

91–100 of 376 posts

Re: Internet Archive breached again through stolen access tokens

#91

Earlier quoted context omitted.

This ^ We can’t all have the latest EPYC processors with the latest bug fixes using Secure Enclaves and homomorphic encryption for processing user data while using remote attestation of code running within multiple layers of virtualization. With, of course, that code also being written in Rust, running on a certified microkernel, and only updatable when at least 4 of 6 programmers, 1 from each continent, unite their…

[flagged]

No, it’s your demeanor that is unbecoming and not worth engaging with. Villianizing your poor behavior not successfully baiting people into replying as you want is childish too. Take a breather.

Re: Internet Archive breached again through stolen access tokens

#92

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

This has really shown that the be true. I am stuck in a situation right now where I have some lost media I want to upload but they have been down for over a week. I plan to create a torrent in the meantime but that means relying on my personal network connection for the vast majority of downloads up front. I looked into CloudFlare R2, not terrible but not free either.

I was looking into using R2 as a web seed for the torrent but I don't _really_ want to spend much to upload content that is going to get "stolen" and reuploaded by content farms anyway you know?

Re: Internet Archive breached again through stolen access tokens

#93
post #21

We need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.

This seems to get brought at least once in the comments for every one of these articles that pops up. The IA has tried distributing their stores, but nowhere near enough people actually put their storage where their mouths are.

Perhaps one idea is to let people choose what they want to protect. This way people wanting to support it can have their mission.

Re: Internet Archive breached again through stolen access tokens

#94
post #57

Earlier quoted context omitted.

[flagged]

I don't believe IA itself takes down pages that kiwifarms archives/links to. Rather they get a request to take it down and comply with it (correct me if I'm wrong here). I think IA is actually in a tough spot on this issue because they might be able to be sued eg. for defamation if they don't take down pages with personal info after a request to do so is made. Lastly, I doubt any new leadership would be less harsh on…

There was no illegal content on kiwi farms. Even then, I’d say taking down a single page by request is understandable. However, they surrendered to the mob and chose to stop archiving the entire site. This was to censor any criticism of the people involved, but as a result, we lost all of the other information on the rest of the site as well. It’s clear this organization cannot handle pressure, and is relying on people treating it kindly.

Re: Internet Archive breached again through stolen access tokens

#95
post #63

Earlier quoted context omitted.

> nowhere near enough people actually put their storage where their mouths are. Typically because most people who have the upload, don't know that they can. And if they come to the notion on their own, they won't know how. If they put the notion to a search engine, the keywords they come up with probably don't return the needed ELI5 page. As in: How do I [?] for the Internet Archive? , most folks won't know what [?]…

This is literally torrents. Just give up

The problem with torrents is they have a bad reputation since people use it to steal and redistribute other people’s content without their consent.

Re: Internet Archive breached again through stolen access tokens

#97
post #4

> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that…

There are many "first things" you need to do if breached, and good luck identifying and doing them all in a timely fashion if you're a small organization, likely heavily relying on volunteers and without a formal security response team...

Re: Internet Archive breached again through stolen access tokens

#98

It’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.

Seems like the actor did it only for the street credit and the second breach is only a reminder that IA didn’t properly fixed it after the first breach.

Could be worse.

Re: Internet Archive breached again through stolen access tokens

#100
post #65

I sent them a resume almost a year ago, and got nothing back in response until yesterday. Looks like they are going through their backlog right now to find more hands.

Interesting, for a security position?

It was a while ago, I think it was for their general position option, though I did talk about sec experience in it
Post reply on HN