11 ms·
Internet Archive: Security breach alert
- max_ 2y agoIs Internet Archive teh same as Archive.is?
- stephen_g 2y agoNo. It’s not clear who runs Archive.is (there are domains registered by a ‘Denis Petrov’ with an address in Prague), but the Internet Archive (archive.org) is run by a non-profit foundation.
- EKSolutions 2y agoIt looks like someone has compromised one of their subdomains for Polyfill Update: Subdomain seems to be returning normal responses again now.
- Aachen 2y agoYou mean the IA included some JS polyfill from a subdomain and that's what's compromised / where the alert is coming from?
- mendym 2y agoYup. https://news.ycombinator.com/item?id=41792651 https://news.ycombinator.com/item?id=41792651
- EKSolutions 2y agoCorrect. The source subdomain of the popup seems to be hxxps[:]//polyfill[.]archive[.]org
- qnsc 2y agoyes, "https://polyfill.archive.org/v3/polyfill.min.js?features=fetch,IntersectionObserver,ResizeObserver,globalThis,Element.prototype.getAttributeNames,String.prototype.startsWith,Array.prototype.flat,Element.prototype.closest,Element.prototype.scroll,Element.prototype.remove,Object.entries,Object.values,Object.fromEntries https://polyfill.archive.org/v3/polyfill.min.js?features=fet..." is the URL with the malicious code
- Shadow1337 2y agoIt looks like it is running the service that was part of the supply chain attacker earlier this year. https://github.com/polyfillpolyfill/polyfill-service/issues/2890 https://github.com/polyfillpolyfill/polyfill-service/issues/...
- abracadaniel 2y agoThat was a DNS hack of polyfill.io though right? This looks like it was/is self hosted.
- jsheard 2y agoThe service was fine, it was the "official" hosted instance of the service which was compromised. IA appears to be running their own instance.
- __jonas 2y agoYeah I'm getting this exact response from the above URL now: https://sourcegraph.com/github.com/polyfillpolyfill/polyfill-service/-/blob/library/src/get_polyfill_string.rs?L415 https://sourcegraph.com/github.com/polyfillpolyfill/polyfill... Seems like they self hosted that service
- jrochkind1 2y agoThat would perhaps explain how they managed to inject the JS alert popup, right?
- TZubiri 2y agoYeah, but the leak has been confirmed by HIBP, I found my address in there.
- jrochkind1 2y agoDOH. I hadn't heard this.
- joshchernoff 2y agoWhat an asshole, honestly this is a good public service they offer.
- Nurbek-F 2y agosolution: MFA
- ewenjo 2y agoJust noticed the site now alerts this: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!
- uticus 2y agoIs it a genuine alert, or hacking artifact? Sometimes with friendly / attempt-at-humorous error messages it’s difficult to tell
- n_i_k_h_i_l 2y agoIt's a literal window.alert()
- PLenz 2y agoBut was that code placed there by IA or by the malicious party?
- seanw444 2y agoSounds snarky to me. I'll bet it was the malicious party.
- abracadaniel 2y agoVerge reports someone has taken credit for an ongoing DDOS against IA. "An account on X called SN_Blackmeta said it was behind the attack and implied that another attack was planned for tomorrow" https://www.theverge.com/2024/10/9/24266419/internet-archive-ddos-attack-pop-up-message https://www.theverge.com/2024/10/9/24266419/internet-archive...
- dang 2y agoOk, let's switch to that link. Thanks! Submitted URL was https://archive.org/ https://archive.org/.
- Nathans220 2y agoStrange I just received this message when going to the archive.org website I thought I might have misspelled the url
- haha112 2y agoDamn I get the notice too
- haha112 2y agoI saw it too
- pityJuke 2y agoThis thread is looking like it'll be one of the first places this incident will be documented (seems to be on the top of Google). Already there are two new users just for this.
- mendym 2y agoi see more than 2
- ewenjo 2y agoYeah, I was looking around, but saw no mention of it anywhere until I realized it just happened.
- quart 2y ago[flagged]
- quart 2y agonow internet archive is offline. uh-oh?
- Nathans220 2y ago[flagged]
- meow_catrix 2y agoBet it’s just a stored XSS alert from a poisoned cache.
- TZubiri 2y agoTroy Hunt received the leak, tested it and confirmed it. You can find emails on HIBP now
- 19h00 2y agoThey reported a DDOS attack yesterday, wonder if this is their alert as they manage the fallout?
- Nathans220 2y agoAfter this error 504 Gateway Time-out Now 503 Service Unavailable No server is available to handle this request. Not looking good
- Krasnol 2y agoThis is why humanity can't have nice things.
- carloslfu 2y ago"You are all cooked" vibes from that message hahaha
- mendym 2y agoNow it shows a 'Temporarily Offline' message
- Aachen 2y agoShould we be linking to the site that is very likely to be breached? Could start to host any type of malware until the access can be definitively revoked
- btown 2y agoThis - dang/mods is there a policy for this?
- deleted 2y ago[deleted]
- abracadaniel 2y agoVerge article as possible replacement: https://www.theverge.com/2024/10/9/24266419/internet-archive-ddos-attack-pop-up-message https://www.theverge.com/2024/10/9/24266419/internet-archive...
- dang 2y agohttps://news.ycombinator.com/item?id=41793081 https://news.ycombinator.com/item?id=41793081
- Aachen 2y agoThat's just about article quality though. Is there a policy about linking to known compromised sites? Should one flag the submission for moderator attention?
- dang 2y agoWe don't have policies really, but the way to get moderator attention is hn@ycombinator.com.
- btown 2y agoAs a first step, it might be a good idea to add an indication to https://news.ycombinator.com/submit https://news.ycombinator.com/submit or https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html to not submit links to sites that are known to be hacked/compromised, and to use a text post instead if making a public service announcement! Even if we assume folks are using up-to-date browsers (and many aren't!), a compromised site could deliver payloads to browsers ranging from zero-days to phishing content to browser extension compromises (esp. for crypto wallets etc.), that might be delivered differently to different viewers. We don't want to amplify the spread of an attack, especially to our community!
- Nathans220 2y agoWhy go for the Internet Archive go for something else not the fucking archive!
- mewpmewp2 2y agoWe all need our easily accessible decentralized archive of some sort...
- Nathans220 2y agoyes
- MarcoZavala 2y ago[dead]
- nioj 2y agoRelated submission: https://news.ycombinator.com/item?id=41792614 https://news.ycombinator.com/item?id=41792614
- Wowfunhappy 2y agoArchive.org is now down. Could anyone explain what it used to show?
- Mr-Hyde 2y agoA pop-up that said, "Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!"
- midnight_shaman 2y agoI hope it will be back again soon
- msephton 2y agoI just got a Discord "breaking news" notification about this from a server I am, said it may not show on Have I Been Pwned as it is so new.
- TZubiri 2y agoshows now
- tomrod 2y agoThat's a shame. We need not one but many internet archives. Just one and we will repeat the outcome of the Library of Alexandria.
- deleted 2y ago[deleted]
- kiba 2y agoThe Library of Alexandria wasn't that significant and likely wasn't destroyed in one cataclysmic event, but rather centuries of neglect.
- eikenberry 2y agoThe metaphor takes precedence over the fact.
- Arnt 2y agoIf an attractive story takes precedence over fact, then we will repeat the story of a James Bond film. Maybe the one with that bikini scene, bikinis are attractive after all.
- tdeck 2y agoHere is a great video on the subject in case folks want to learn more: https://m.youtube.com/watch?v=M4WU8gqrgsQ https://m.youtube.com/watch?v=M4WU8gqrgsQ
- hammock 2y agohttps://archive.today/ https://archive.today/ is another one
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- AdmiralAsshat 2y agoWell this should be fun. Now I'll have to dig through my IA account and remember if I donated to them directly via credit card (and if they stored it), or if it was through PayPal.
- gaudystead 2y agoGood point and thank you for the reminder. Time to go check my email archives...
- KerrAvon 2y agothey use Stripe
- steve_taylor 2y agoIf you're a blackhat and you want to be annoying, you can use Stripe tokens to charge your target's customers. The target is the payee, so you won't make any money, but it'll add to the chaos.
- jszymborski 2y agoIf Stripe hasn't already, it won't be long until they revoke all of IA's tokens in the event they start using them.
- zelse 2y agoHaveIbeenpwnd says it was just passwords/usernames/emails, so seemingly not. (My company just got an email from them about the breach and I confirmed I'm in there with a quick search on their website.)
- bigiain 2y agoThat's what Troy got sent. It's not necessarily all the attacker took.
- 2y ago
- pastureofplenty 2y agoMaybe this will make Google reconsider relying on them for cached versions of webpages.
- marviel 2y agohttps://www.reddit.com/r/DataHoarder/comments/h02jl4/lets_say_you_wanted_to_back_up_the_internet/ https://www.reddit.com/r/DataHoarder/comments/h02jl4/lets_sa... I found this reddit thread from /r/DataHoarder about backing up the internet archive particularly interesting, given the circumstances
- numpad0 2y ago50 PB * $0.014/GB = $0.7M. $0.014/GB is from[1], bare drive cost without chassis, power, or redundancy. 1: https://www.backblaze.com/blog/hard-drive-cost-per-gigabyte/ https://www.backblaze.com/blog/hard-drive-cost-per-gigabyte/
- Aachen 2y agoHow long does an average hard drive last? You'd have to spend that 700k every that many years (plus the extra bits you mentioned). Quite an operation actually
- everforward 2y agoI actually find that fairly tame. For a point of comparison, Wikipedia gets ~$150M in revenue a year, an "asset rise" (I presume this is what non-profits call profit?) of ~$15M a year, and is sitting on about a quarter billion in the bank. Not that they want to, but I think Wikipedia could fund this using their current donations if they wanted. Hell, I almost wonder if one of the big storage providers would do it for free if they could do it in their staging environment so they get real traffic. It would be less good than real backups, but extra copies are still extra copies even if they're unreliable.
- Aachen 2y agoYou're right, I guess it is tame and achievable so far as organisations go. I was imagining trying to get some friends together to have a decent percentage of the IA backed up, but that seems out of reach based on this napkin math. Not that that is necessarily demotivating, but it's going to depend on a lot of people intuitively seeing the value and keeping up their share
- adfm 2y agoThey're hiring, if you're looking for a job. https://www.indeed.com/viewjob?jk=3bb8222ccd9a88ea https://www.indeed.com/viewjob?jk=3bb8222ccd9a88ea
- Aachen 2y ago> Software Engineer, Archiving & Data Services (Remote) [...] Preliminary duties of the role will primarily focus on developing Archive-It That is. Paying over 100k at the lower end of the range for 3y experience as software engineer
- jjice 2y agoIt's a non profit. You're probably not choosing to work for the IA for high compensation.
- Aachen 2y agoThe undertone was intended to be: that's an insane amount of money, something one with quadruple that amount of experience would maybe earn in a for-profit organisation, but I guess your reaction further proves it's different where you're from
- tdeck 2y agoIt's not high for bay area software jobs; there are new grads who were paid more than that 10 years ago and I assume new grad wages have gone up since. Of course cost of living (particularly rent) and taxes are high there too, but if you don't blow it all on renting a higher-end place or luxuries you can still save a lot. For context someone making less than $105k is classified as "low income" in San Francisco. https://www.sfgate.com/local/article/under-100k-low-income-san-francisco-18168899.php https://www.sfgate.com/local/article/under-100k-low-income-s...
- metadat 2y agoThe way you worded it was confusing to read, I thought it was a complaint about "only 100k". Thanks for clarifying your intent.
- Narhem 2y ago[flagged]
- RGamma 2y agoLet's hope it was someone dumb enough to be extraditable.
- popcalc 2y agoNo one gets extradited when the attack aligns with US interests abroad.
- bawolff 2y agoWhat weird conspiracy is this? US interests dont involve taking down archive.org
- markus_zhang 2y agoThere is no US, there are just a bunch of interest groups. Some interest group definitely wants IA down. I wouldn't be surprised this is a paid attack.
- bigiain 2y agoI'd probably believe attribution to either Israel or the MPA with only a little evidence. (I still haven't forgiven Sony for the album on CD I bought with a rootkit on it...)
- markus_zhang 2y agoJust curious why Israel? MPA is reasonable though... And a rootkit on CD? Interesting...
- mrguyorama 2y ago>https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk... The bad old days before music companies just gave up and started selling un-DRMd mp3 files, and then Spotify solved THAT problem for them.
- msephton 2y agoThey seem to roll out the we're being DDOS'd every time there's some other thing happening.
- msephton 2y agoSo, it seems there are multiple things potentially including DDOS.
- Mr-Hyde 2y agohttps://x.com/Sn_darkmeta/status/1844080692772401399?t=j3xDzkZ_H8FWA3f2TtXx1w&s=19 https://x.com/Sn_darkmeta/status/1844080692772401399?t=j3xDz... Annoying
- Aeolun 2y agoWhat are they looking for here? Negative karma?
- Mr-Hyde 2y ago[flagged]
- adastra22 2y agoThis makes absolutely no sense.
- steve_taylor 2y agoIt makes sense when you look at the age of the commenter's account.
- dumpsterdiver 2y agoBy "working idea" do you mean something that you made up in your head which has no basis in reality, but works for you? Edit: I had only seen the one post on X in which responsibility for the attack was claimed when I made this comment, but looking at the account further they do make many politically motivated comments. With this new insight my comment now seems unnecessarily dismissive because it's not completely unreasonable to suspect false flag attacks when political motivations are being broadcast. To be clear I'm not making any assumptions for this specific case one way or the other, but I am acknowledging that the political speech presented by the attackers does add some merit to your suspicion.
- navigate8310 2y agoProbably want it wants to purge incriminating documents against a nation state?
- ErikAugust 2y ago“According to their twitter, they’re doing it just to do it. Just because they can. No statement, no idea, no demands.” A special place in Hell…
- Mr-Hyde 2y ago[flagged]
- llm_trw 2y agoA demonstration of what collateral damage actually means. The bracker was a terrorist so we killed the candle stick makers family.
- Sabinus 2y agoI think the existing collateral damage examples were pretty actual already. By burying terrorist headquarters under civilian apartment buildings, Hezbollah guarantees collateral damage.
- llm_trw 2y agoThe type of logic leads to schools in the US being valid targets so long as a drone pilot drops off their kids to school on the way to work.
- Sabinus 2y agoNo it doesn't. The US does not deliberately hide it's drone pilots among civilians and targeting their place of work or the drone storages would not harm civilians.
- llm_trw 2y agoI'm sorry that your governments rules of engagement are what you'd consider terrorism. Maybe you should do something about it?
- xproot 2y ago[flagged]
- Mr-Hyde 2y ago[flagged]
- deleted 2y ago[deleted]
- anigbrowl 2y agoThey have a Telegram channel and there's some blurb about it being pushback on US support of Israel, but it reads as bullshit. Probably a script kiddie.
- n3uman 2y agohttps://blog.archive.org/2021/02/04/thank-you-ubuntu-and-linux-communities/ https://blog.archive.org/2021/02/04/thank-you-ubuntu-and-lin... "The Internet Archive is wholly dependent on Ubuntu and the Linux communities that create a reliable, free (as in beer), free (as in speech), rapidly evolving operating system. It is hard to overestimate how important that is to creating services such as the Internet Archive." Maybe CUPS?
- bawolff 2y agoReporting on security issues is always so terrible. Is it a data breach or is it a DDoS? (Or both). Those are opposite things. One is trying to release secret information one is trying to make the site inaccessible.
- Aachen 2y agoThat's like complaining the reporting on the weather forecast channel is so often wrong. This news broke about an hour ago and the IA is down, what witchcraft do you expect news media to practice! Nobody yet has the answers you're looking for, give it some time and log files will be audited and the reporting becomes useful :)
- bawolff 2y agoActually figure out what is happening, or at least say how confident they are in what they know. They aren't predicting the future, they are reporting on an ongoing event.
- Aachen 2y ago> or at least say how confident they are in what they know This I can very much underwrite. Error bars or rough confidence indicators are missing far too often, also from sites reporting on e.g. benchmark values of hardware they've been testing... such professional organisations yet such basic omissions
- odo1242 2y agoIt is both. They got attacked by a DDOS after the security breach.
- treesknees 2y agoWhich is pretty common. While the org is running around dealing with the DDoS, they're not doing anything to fix their systems. In this case, I can't even get to my account page on IA to change my password.
- 999900000999 2y agoA pulled an old friends website down from Internet Archive. He's moved on the next stage, but I was glad I was able to put his site back up. It'll be a shame if IA goes down permanently, but we need a decentralized solution anyway. Having a single mega organization in charge of our collective heritage isn't a good idea.
- gabeio 2y agoI have always thought about this. It would be interesting to have users actually store small amounts of redundant info on a device connected to the internet. Very similarly to what a torrent does but with more peers (more data shards than full copies) and less seeds. And try and keep a huge database for everyone. Obviously open source and it would end up something like tor where they just assist the network with security patches but they don’t actually have any real “control” (admin dashboard control) over the network at large. We already do something smaller but like that with website static file caching, but at much smaller scale. Obviously security implications of this would be very hard but maybe not impossible to overcome. ipfs comes close but it again does more seeds then peers. if anyone knows something like what I'm suggesting, I'd love to hear about it!
- pbhjpbhj 2y agoIIRC there were a few storage based projects that popped up using alt coins to encourage people to offer excess storage space for other randos on there internet. The possibility you might be storing illegal content might have been what killed it/them. https://en.wikipedia.org/wiki/Cooperative_storage_cloud https://en.wikipedia.org/wiki/Cooperative_storage_cloud gives a few examples, like Filecoin.
- fwip 2y agoIn my opinion, IPFS was killed by a few things: 1) wedding itself to crypto with FileCoin. 2) terrible performance due to architectural choices (basically: too much pointer-chasing, except every pointer was back out to the DHT). 3) No serious attempts to integrate with existing software distribution strategies. I think it's still a good core idea.
- markus_zhang 2y agoWouldn't be surprised if the service was purchased by some publishing empires. This kind of things usually costs some $$$.
- sirolimus 2y agoTruly unnecessary
- steffanA 2y agoMore details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/ https://www.bleepingcomputer.com/news/security/internet-arch...
- ano-ther 2y ago> the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service Do they? Why?
- richbell 2y agoIf Troy authenticates the data, they can use that as an 'endorsement' when trying to sell it.
- ianhawes 2y agoThis. Typically HIBP attribution includes the email of the "submitter". Various data aggregators will contact them and buy the stolen data. Everybody wins*. * Exceptions apply.
- Thorrez 2y agoWhere on HIBP can I see the email of the submitter?
- ramimac 2y agoIt's not available in this case, or every case. When available, you can search "The data was provided by" in https://haveibeenpwned.com/PwnedWebsites https://haveibeenpwned.com/PwnedWebsites
- Thorrez 2y agoThanks! Slight correction: only 2 breaches say "provided by" with a source, but a ton of breaches say "provided to" HIBP with a source.
- Aachen 2y agoA few minutes ago (22:48 UTC), I got three emails from HIBP about accounts of mine breached on the Internet Archive. Troy is quick! And I'm surprised the author of that alert() actually had the data as well as followed through Bit of a shame the emails contain an ad for a password manager, saying there's two easy steps to become more secure: Step 1: use our password manager (fair enough), "Step 2: Enable 2 factor authentication and store the codes inside your [password manager]" ehh now it's back to 1 factor or am I missing something? Edit: according to https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/ https://www.bleepingcomputer.com/news/security/internet-arch... (via https://news.ycombinator.com/item?id=41793669 https://news.ycombinator.com/item?id=41793669), Troy Hunt / HIBP already received and verified this "three days ago" as of yesterday 6pm AoE
- nixosbestos 2y agoI was going to disagree with you (and I sort of do about password managers and storing 2FA in them, but I also unlock my password manager with a yubikey). But, doesn't a DB compromise mean that the attacker would have the TOTP seed as well? It can only increase your account security elsewhere, but also not re-using password prevents the IA leak from hurting you elsewhere as well?
- Aachen 2y ago> I was going to disagree with you (and I sort of do about password managers and storing 2FA in them Note I'm quoting HIBP's advice from the email they've sent me! I'm absolutely not recommending to store one's 2FA secrets in the same place as the password! Even if one uses 2FA for the password manager, it stops proving "something you have" in addition to something you know and you're one unlock away from malware vacuuming it all up. The point of 2FA is to be on a separate device you need to have on hand Of course, the same logic goes for a password manager in the first place, but password reuse is a big enough problem that (for most people's threat model) it seems to be a net positive. 2FA tokens don't have that reuse issue
- almyk 2y agoI think it is safer to have 2FA in your password manager than not using 2FA at all. Because even if they got your password, if they don't have access to your password manager they can't login. If you protect your password manager with a yubikey or any other hardware key, then your 2FA inside your password manager is quite secure and convenient. But this is very individual, what your threat model is and how secure you want/need to be.
- tap-snap-or-nap 2y agoAny information on SN_Blackmeta?
- wasabinator 2y agoSome people on this planet add such negative value. What does this clown hope to gain, apart from costing us all an incredibly useful shared resource?
- squarefoot 2y agoWhat if the clown is actually someone hired by one of the many enemies that IA made during the years?
- tinktank 2y agoHe or she is still a clown. What difference does it make who hired him or her? At an individual level one can always disagree to do things that only destroy value.
- squarefoot 2y ago> He or she is still a clown. What difference does it make who hired him or her? We completely agree about the perpetrator. My point was if that is the case, it would implicate that IA enemies were going beyond lawsuits.
- colinsane 2y agoreasonable people disagree on whether some things are positive or negative value. IA is one of the go-to examples for that. is it good to make every book ever written freely downloadable (as they were trying with their library project a while back), or is that bad? you and i might think the answer is obvious. we might even agree on it. but we would occupy a rather different world if even a supermajority agreed on that question, in either direction.
- Apocryphon 2y agoHachette Book Group or Hack-it Boot Group?
- deleted 2y ago[deleted]
- godshatter 2y agoThe conspiracy theorist in me wonders what was accidentally copied into the archive that powerful interests want removed and if this is all smoke and mirrors while they make that happen.
- Levitating 2y agoI just received my haveibeenpwned.com email...
- xproot 2y agoI've made a timeline of events: https://gist.github.com/xproot/b574dc868a9db012bbe07252a1f7f2d5 https://gist.github.com/xproot/b574dc868a9db012bbe07252a1f7f... Fun fact! Troy actually got this database back in Sep. 30th.
- PenguinRevolver 2y agoProbably not the best time to say this, but it's surprisingly easy to go through a collection with items and grab every email along with the usernames. https://archive.org/metadata/naturally_a_girl/metadata https://archive.org/metadata/naturally_a_girl/metadata One way or another, there was going to be someone who would take loads of emails with a username attached to it. A bit intrigued by how the hacker compromised the database and got the passwords.
- fewgrehrehre 2y agoDamn, I had no idea about this. Definitely would've changed some things had I known that emails were public. This honestly seems like a bit of a design flaw.
- Gingeas 2y agoYeah, they have ignored everyone's concerns about the email thing. https://github.com/internetarchive/iaux/issues/892 https://github.com/internetarchive/iaux/issues/892
- xyst 2y agoOne of the many benefits of owning my own email server: - I have a catch all setup to forward all emails to specific user on mail server - able to setup adhoc email addresses for each online service (ie, iarch@example.com) - able to claim example.com in haveibeenpwned Now I get breach emails from hibp for the whole domain. Unfortunately, I was exposed in this IA breach
- appendix-rock 2y agoAll things that aren’t remotely unique to running your own mail server.
- CobaltFire 2y agoI do the same thing. Absolutely worth the small hassle.
- yonixw 2y agoGoogle workspace lets you do it if they mange emails for your domain (and it will cost ~5-10$/month if you are the only user) https://support.google.com/a/answer/12943537?hl=en https://support.google.com/a/answer/12943537?hl=en
- xyst 2y agoit “works”, but handing over this control to Google is a no-go for me.
- srhngpr 2y agoYou can do this easily (and for free) via Cloudflare [1]. Works great, I've been using it across several domains for quite some time. Migrated from Google. [1] https://www.cloudflare.com/en-ca/developer-platform/email-routing/ https://www.cloudflare.com/en-ca/developer-platform/email-ro...
- xyst 2y agoyea, but now i rely on cloudflare which is no-go for me.
- pentagrama 2y agoThe reported alert on the site states: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP! But is this an official message from the company? It sounds odd and unprofessional, especially the "See 31 million of you on HIBP!" part, which jokingly refers to a huge privacy issue for users. Could it also be that the site was hacked, with hackers posting that message in addition to the data breach and DDoS attack?
- gtirloni 2y agoIt's a thankless job to be always begging for donations to keep something working when the Internet at large doesn't value it as much as it should. And now getting targeted like that? I wouldn't judge them if this is an official communication coming from exhausted and frustrated staff.
- appendix-rock 2y agoJust a reminder that AI tried pivoting to much more clear-cut legitimate piracy, presumably because they got bored or something, and certainly put ‘donations’ toward that effort. IA is an incredibly valuable resource, but let’s not put them on a pedestal.
- colinsane 2y agoheh, if they went 100% "we're operating our service from international waters and won't be taking any DMCA requests" i would donate $1000 on the spot (anonymously, of course, but entirely serious).
- Nemo_bis 2y agoWhat's "legitimate piracy"? As a reminder, the scheme was designed to work exactly like typical lending libraries. Publishers were unable to show any harm, and the only evidence available proved they actually benefited from better sales thanks to the Internet Archive. Authors were clearly benefited. https://www.techdirt.com/2024/09/05/second-circuit-says-libraries-disincentivize-authors-to-write-books-by-lending-them-for-free/ https://www.techdirt.com/2024/09/05/second-circuit-says-libr... But I agree, no need to put them on a pedestal. Nobody is perfect.
- crispair 2y agoI wonder how they got access the their database? I read in this thread that they likely used a supply chain attack by replacing some polyfill scripts. So they could've injected malicious code (XSS) that logged email and password to a remote server which they could have gone through. With a bit of luck they couldve gotten access to an admin account or whatever…
- TZubiri 2y agoThat much is not clear yet. It's possible the polyfill is an unrelated red herring, but it's also possible they somehow managed to elevate permissions. Seems the polyfill use was self hosted as well. Maybe they managed to convince some critical service like an SSL cert provider that they were the owners of the subdomain? I don't know still wouldn't explain access to user and password database.
- lordfrito 2y agoConfused about this breach... I received a notification from HIBP about this hack, but I don't recall ever creating an account on archive.org (was creating an account there even a thing?). What info does archive.org have on people? Is this info scraped from other websites and stored in the archive.org database? Or is this info related to personal archive.org accounts (as I said I don't recall making an account)?
- floam 2y agoThey are actual archive.org accounts. Maybe you made an account to upload something, or to check out a digitized book from their library?
- lordfrito 2y agoThank you.. was worried at first as I didn't understand the true scope of the breach. For such a vital website, the info gleaned seems relatively harmless (for those of us who don't reuse passwords that is)
- db48x 2y agoYea, it is pretty harmless. I suppose someone might be interested in any books you currently have checked out, but beyond that there isn't much.
- 1024core 2y agoWhy should an Archive need accounts anyways? This is like a public library: you don't need to authenticate yourself to enter a public library, do you?
- r721 2y agoI created an account there because https://web.archive.org/save https://web.archive.org/save requires an account to set "Save outlinks" checkbox on.
- ct0 2y agoHow do you think they keep track of late fees?
- ileonichwiesz 2y agoDon’t you? That’s what a library card is.
- nevster 2y agoAnyone who contributes by uploading material needs an account
- acherion 2y agoTo enter? No. To borrow? Yes.
- 1024core 2y agoWhat are you "borrowing" from the Archive?
- Nemo_bis 2y agoBooks. (Until they're vanished by publishers. https://www.techdirt.com/2024/06/20/500000-books-have-been-deleted-from-the-internet-archives-lending-library/ https://www.techdirt.com/2024/06/20/500000-books-have-been-d... )
- 2y ago
- worstspotgain 2y agoIn unrelated news, apparently most world leaders in the Internet era, from Thatcher to GHWB to Mitterand to Rabin, expressed great admiration for Vladimir Putin.
- anon115 2y agoI wouldn't be surprised if it has something to do Israel
- lionkor 2y ago... Why? How so?
- boffinAudio 2y agoThere is/was plenty of anti-Zionist material available in the IA.
- angelorue 2y agoThe hackers are pretty openly anti-Zionist script kiddies.
- themingus 2y agoI was disappointed to discover that https://haveibeenpwned.com https://haveibeenpwned.com does not report an email as pwned if it is subaddressed/plus addressed. myemail@gmail.com is reported as still safe, but myemail+archive@gmail.com is pwned. I wonder if my email has been leaked by any other websites without me knowing.
- TonyTrapp 2y agoI don't think they can do that, because they do not store plaintext addresses in their database, merely hashes. It certainly reduces the impact of someone hacking HIBP.
- tkgally 2y agoAs of 01:09 GMT on October 10, the Internet Archive is back up. In fact, the Wayback Machine and the book archives are responding more quickly than they did for me a week ago, when I showed the Archive to the students in an online class I teach. I gave the students a homework assignment that involves accessing some old books at the Archive. That assignment is due in about 12 hours, and I was just getting ready to e-mail the students about the outage when I saw that the site is working again.
- testfrequency 2y agoI’m feeling extremely conflicted on all of this with IA right now. On one hand, I love IA On the other hand…I’m in a long thread with their support right now on removing old snapshots of a social media account I have. Creeps are actively using the old snapshots to dox me and send me death threats using my PII. It’s incredibly frustrating and IA keeps insisting they cannot do anything about it. A small part of me hoped IA didn’t recover from today because I knew my info would be finally deleted :/
- cortesoft 2y agoOnce you have been doxed, isn’t the cat kinda out of the bag at that point? Creeps already have the snapshots now, deleting them from IA is just closing the barn door after the livestock has already escaped.
- ocdtrekkie 2y agoBear in mind that is the doxxing and doxxers that have happened now. There are plenty of future opportunities to be doxxed and plenty of other potential victims. Not that I'd cheer for the loss of IA, but it'd probably be nice if they took down PII on request.
- hackernewds 2y agoStill worth deleting future instances. What's your point?
- arresin 2y agoCan I ask why they're trying to dox you? I have literally never inspired this kind of passion on the internet--and I'm usually pretty blunt. I'm genuinely curious what it takes.
- jfengel 2y agoAttacks like that tend to have little to do with bluntness. They occur when you've touched something they consider to be theirs, and you are not entitled to. Usually that's some matter of group identity, where they feel the need to show off for each other just how angry they are at you. It has less to do with what you say or how you say it, but with who you are.
- driver8_ 2y agoThat sucks, I was reading my email in the morn and saw the news from haveibeenpwned.com, and I'm indeed effected by it. Consolation is that I used a randomly generated unique password, tried to reset my credentials and see of any 2FA options but the site is overloaded throwing 504s.
- left-struck 2y agoI’ve been mentioning this a lot lately but it’s also a good idea to use email forwarding services like Firefox relay, icloud/apple “hide my email”, duckduckgo has a free one, simplelogin you can host yourself… In an email breach you can confirm who was breached if you used a unique email, and it also means your actual email remains at least as secure as those services I mentioned
- arresin 2y agoThe recent news on IA has made me worried about it. It seems to be a fragile thing and if it goes it'll be something we'll all regret.
- deleted 2y ago[deleted]
- muppetman 2y agoGreat. Bunch of pricks. Refuse to remove any of my data they scraped.
- excalibur 2y agoThe overall state of cybersecurity in 2024 depends to an astonishing degree on Troy Hunt's schedule.
- indus 2y agoI mistakenly read HIBP as Half Price Books..wait what?
- Springtime 2y agoJust in terms of privacy, it's worth noting that anyone who has uploaded something on IA already has their email address publicly viewable. This isn't something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader's IA account email address. So from a security perspective it's bad but from a privacy perspective a lot of users probably weren't aware of this detail if they've uploaded anything.
- hunter2_ 2y agoThis raises an interesting question: should email addresses be private? Addresses of buildings aren't private, and they're somewhat analogous as with many computing concepts. (Aside: Before spam filters were quite good, it was typical to avoid scraping of addresses by mild obfuscation, but I think those days are gone, and this is distinct from privacy anyway.) If someone wants to upload and never be found out, then they need to use a throwaway address in any case, lest they be providing their "private" address to the administrators of the service without explicitly forbidding further disclosure. If I say something to Alice without demanding that Alice keep it from Bob, then I implicitly don't mind if Alice tells Bob what I said.
- fortyseven 2y ago> should email addresses be private? I dunno. Should your personal phone number be private? Or your home address? Would you be okay if I knew it and shared it with a stranger? Or would you rather be asked permission to share it first? Seems pretty cut and dry to me. Yeah, there's going to be someone out there (there always is) who doesn't care, but I'd wager the majority would be pretty ticked off if you gave those pieces of information out to a rando on the street.
- amszmidt 2y agoThere are plenty of countries where all that is public information, back in the day there even used to be a phone book with .. name, phone number, and address. And many countries have this now in digital form.
- EchoReflection 2y agoshouldn't info about this breach be ON the IA landing page??
- Ekaros 2y agoSo now the data also has off-site third-party archive. Isn't this along the goals of organization. It is less likely now to be destroyed in many eventualities.
- EasyMark 2y agoThey use bcrypt and I always use a really long password so I’m not gonna freak out over this one for once.
- bjourne 2y agoAre bcrypt password hashes difficult to crack? I signed up for IA over 10 years ago with a much weaker password than those I use today.
- nicce 2y agoIf you don't reuse that password anymore, does it matter tho. Some services might use older hashing for older passwords without updating the hash algorithm. But I don't know what is the case here. brypt passwords are very slow to crack.
- Jach 2y agoI would hope that a system competent enough to migrate to bcrypt would also be competent enough to rehash the entire database as well. Logins check bcrypt(oldHash(pw)); if it matters they can be updated to bcrypt(pw). Of course, "Hope is not a strategy".
- Tepix 2y agoThe difficulty is configurable. You can play around with it at https://bcrypt-generator.com/ https://bcrypt-generator.com/ I found this, not sure if it's still up-to-date: ◉ PHP's default implementation of bcrypt uses 10 rounds. ◉ Python's bcrypt library uses 12 rounds by default. ◉ Node.js's bcrypt library uses 10 rounds by default. See also: https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb422222fd#file-rtx_4090_v6-2-6-benchmark-L8 https://gist.github.com/Chick3nman/32e662a5bb63bc4f51b847bb4...
- Jach 2y agoBesides being slow, there's also an implicit salt, so rainbow tables to quickly check every account for "password" don't exist. Still, if you just used a simple dictionary word present in e.g. /usr/share/dict/words (my system has 234,937 entries), you don't have as much time. I have a Ryzen 9 5900X, 12 cores; using a random Go implementation of bcrypt I found with default work factor of 10 and going through that dictionary with 24 threads, it takes my machine about 18 minutes to get through every entry. A thousand years if I wanted to go through 31 million accounts and each one was a worst-case at-the-end value. But there are quite a few more than a thousand of my CPU or better out there, some surely part of botnets which routinely number in the thousands of devices, and probably faster bcrypt implementations. Earlier this year, the FBI dismantled a botnet with 19 million infected devices globally and over 600,000 US IP addresses. Surely some of those were weak IoT devices, but still, there's a lot of compute available to bad actors such that you shouldn't necessarily rely on bcrypt et al. to protect a very weak password. (They are rather good at protecting normally weak and mid passwords, though, and there's opportunity cost for all that compute.)
- EasyMark 2y agoOne of those instances when you really wish curses worked on whoever was pulling this stunt “may you and your descendants suffer the bites of 10000 fleas for 10000 nights as punishment for your misdeeds”
- dt3ft 2y agoImagine if we could get rid of passwords. Entirely. Forever.
- haha112 2y agoWhere to see dump data?
- iamtedd 2y agoI have had an IA account for a number of years, with a gmail address. Nine months ago, I changed the email address to a masked address using my own domain. Now I find that my gmail address was still stored, and was involved in the breach. Why? I get that they might store change history, but why? BTW, for the current account details, I changed the password to another random string generated by my password manager, and also deleted the masked email address and generated another one, so going forward this sort of thing isn't that much of an issue for me.
- account42 2y agoIt's also possible that the breach was earlier or going on for longer than reported.
- keybpo 2y agoI have a similar situation, where I signed up with my main account and later changed IA's email to a more private address. It was the first email I checked on HaveIBeenPwned and it doesn't show up in this leak. The other couple IA accounts I have, whose emails and passwords are exclusive to them, they all show in this leak alright. I have no explanation to your situation but this was also my immediate though and I also wanted to give the opposite perspective.
- lloydatkinson 2y agoDeeply disappointing. The only reason I have a IA account is to upload correct book covers to obviously wrong or poor quality books on the Library.
- account42 2y agoGood. Maybe this will get them to reconsider their website changes that make the IA unusable without javascript.
- elyetln 2y ago[dead]
- kleiba 2y agoWhat kind of asshole attacks the Internet Archive of all places on the web??
- deleted 2y ago[deleted]
- Onavo 2y agoProbably funded by some bored executive at a publishing house.
- phplovesong 2y ago[flagged]
- swarnie 2y agoAlarm didn't go off - Russia. Missed the bus - Russia. Stubbed my toe - FFS why is it always Russia? Not excusing it, Russia, China and Iran do make my honeypot's top ten list every month. But then again so do the US, UK and France....
- tgv 2y agoSuch is the nature of a top 10. If you'd said all 6 make it to the top 3, I would have been surprised.
- phplovesong 2y ago[flagged]
- klabb3 2y ago> Its always russia Ah the only conspiracy theory we’re encouraged to believe. Wouldn’t that be convenient. A perpetual enemy far away that’s responsible for all of our failures, infiltrating and puppeteering western democracies on the other side of the world. Even the Russian propaganda machine loves this narrative – it makes them seem powerful and dangerous. Not like a corrupt and broken former empire sending off their young to the meat grinder for a bit of loot and territorial ambitions from a lost era.
- 0xedd 2y ago[dead]
- phplovesong 2y agoWHY would you attack IA? Whats the point?
- meindnoch 2y agoHow much of the archive is affected? Could be a targeted effort to tamper with historical records.
- EamonnMR 2y agoIf they wanted to do that they'd probably not try to draw this much attention.
- el_jay 2y agoAnd only weeks before a US election.
- yreg 2y agoWhat's the connection?
- Uptrenda 2y agoThe funny thing is the internet archive is more connected to hacker culture than cracking a website will ever be. I hate posers more than anything. Hopefully the internet archive comes back stronger than ever.
- TZubiri 2y agoYeah, this is hacker news, not hacking news
- silexia 2y agoWhy does this link to the verge (garbage clickbait site) and not to the original source of the internet archive?
- daveoc64 2y agoThat was an intentional choice: https://news.ycombinator.com/item?id=41792698 https://news.ycombinator.com/item?id=41792698
- 1970-01-01 2y agoArchive.org is completely down
- consumer451 2y agoYeah, the fact that it's still down is a bit depressing. I hope that this event makes some forward-thinking benevolent rich folks step up, or alternative solution.
- jl6 2y agoDoes the IA publish hashes of its data to a 3rd party, so we could (in principle) verify that nothing has been tampered with?
- honeybadger1 2y agoLets attack one of the bastions of information freedom...in the name of Palestine, sigh. Ass-hat hackers.
- mynameyeff 2y agohuh i thought everyone already knew this
- alkonaut 2y agoDoes IA have much information on users? I’ve been in dozens of these HIBP leaks (including this one) but still none have concerned me, since they were mostly just email/password and nothing else. Does IA store anything sensitive for any users?p physical addresses, credit cards, etc?
- odo1242 2y agoFun fact: this is the first time using a password manager (Bitwarden) protyected me from a security breach! Now I only have to update my archive.org password instead of all of them lol
- firen777 2y agoConsidering the hacker's motive: https://x.com/Sn_darkmeta/status/1844358501952618976 https://x.com/Sn_darkmeta/status/1844358501952618976 Is it safe to assume the hacker want to erase the evidence? Forcing the service offline also means they want to prevent people from archiving evidence in the next how-ever-long hours. Combining with the spoken language they used in that video, are they planning some online disinformation campaign? ---- Edit: some more info about this group: https://old.reddit.com/r/technology/comments/1g0kupb/hacktivists_claim_responsibility_for_taking_down/lr9kbmo/ https://old.reddit.com/r/technology/comments/1g0kupb/hacktiv... ---- This group claims to be pro palestinian and it's entirely based on Russia. [https://therecord.media/middle-east-financial-institution-6-day-ddos-attack](https://therecord.media/middle-east-financial-institution-6-day-ddos-attack) https://therecord.media/middle-east-financial-institution-6-... >SN\_BLACKMETA has operated its Telegram channel since November 2023, boasting of DDoS incidents and cyberattacks on infrastructure in Israel, the Palestinian Territories and elsewhere. While all of the group’s messages focus on the Palestinian Territories and perceived opponents to Palestine, many of its posts are written in Russian. >The group’s account on X also shows that it was created by someone in Staraya, a town in Novgorod Oblast, Russia. The account’s initial language was also set to Russian. >The researchers added that analysis of timestamps and activity patterns showed possible evidence that the actors within the group are operating in a timezone “close to Moscow Standard Time (MSK, UTC+3) or other Middle Eastern or Eastern European time zones (UTC+2 to UTC+4).” ~~Attacks include pro palestine sites and groups, so~~ take that "pro palestine" with a grain of salt. EDIT: edited for clarity on what is actually in the article and not in outside anonymous sources. If you want to read more, [there's a clearer report on one of their attacks and their usual targets.](https://www.radware.com/security/threat-advisories-and-attack-reports/six-day-web-ddos-attack-campaign/ https://www.radware.com/security/threat-advisories-and-attac...)
- TZubiri 2y agoPossible false flag? How is someone stupid enough to post this? Warrant for the account's IP is probably already issued. I don't know how many proxies the guy is behind, but it's playing with fire. Also at some point the account of a malicious hacker has to be banned right?
- pmontra 2y agoDoes anybody know the details of the attack via the JS library? Was that the exploit of a bug that could affect every site or a chain of supply attack targeted at the Internet Archive?
- jenlopez080 2y ago[dead]