5 ms·
Just noticed the site now alerts this: > Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic
by ewenjo 2y ago
Just noticed the site now alerts this:
> Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!
- uticus 2y agoIs it a genuine alert, or hacking artifact? Sometimes with friendly / attempt-at-humorous error messages it’s difficult to tell
- n_i_k_h_i_l 2y agoIt's a literal window.alert()
- PLenz 2y agoBut was that code placed there by IA or by the malicious party?
- seanw444 2y agoSounds snarky to me. I'll bet it was the malicious party.
- abracadaniel 2y agoVerge reports someone has taken credit for an ongoing DDOS against IA. "An account on X called SN_Blackmeta said it was behind the attack and implied that another attack was planned for tomorrow" https://www.theverge.com/2024/10/9/24266419/internet-archive-ddos-attack-pop-up-message https://www.theverge.com/2024/10/9/24266419/internet-archive...
- dang 2y agoOk, let's switch to that link. Thanks! Submitted URL was https://archive.org/ https://archive.org/.
- silexia 2y agoThe verge generally is clickbait, another site choice would have been better.
- dang 2y agoThat class of sites generally is, yes. But on HN we go by article quality, not site quality (https://hn.algolia.com/?dateRange=all&page=0&prefix=false&sort=byDate&type=comment&query=%22article%20quality%22%20%22site%20quality%22%20by:dang https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...) and I didn't see a better specific article on this. If there is a better one, we can change the link again.
- varun_ch 2y agoThis bad actor has videos of them supposedly “ddosing” Spotify by pinging 1.1.1.1 in two terminal windows on their Twitter. Is there any link between them and the real attack or are they just unrelated people claiming credit for it?
- whimsicalism 2y agoit wouldn’t be a window.alert if it were IA
- jrochkind1 2y agoI feel like it's safe to assume the official Internet Archive would not write a "friendly"/attempt-at-humurous/unprofessional/confusing/delivered-by-popup message advertising a devastating security breach. Oh also while announcing that nowhere else. Obv an attackers ability to insert a message does imply a breach beyond a DoS. But I am pretty confident that message was not from the IA.
- mendym 2y agoI assume that if this is a bad actor, then account email/name will be leaked?
- mewpmewp2 2y agoJokes on them... I'm already on HIBP countless of times...
- jsheard 2y agoIt's all good, as long as you're not in that recent AI Girlfriend breach which exposed a ton of users who were trying to coax it into generating CSAM images. https://x.com/troyhunt/status/1843788319785939422 https://x.com/troyhunt/status/1843788319785939422
- mrkramer 2y ago“I went to the site to jerk off (to an adult scenario, to be clear) and noticed that it looked like it [the Muah.ai website] was put together pretty poorly,” the hacker told 404 Media. “It's basically a handful of open-source projects duct-taped together. I started poking around and found some vulnerabilities relatively quickly. At the start it was mostly just curiosity but I decided to contact you once I saw what was in the database.” What a nice guy.
- throwaway73583 2y agoNot sure if you're being sarcastic or not, but pentesting is not a particularly evil activity — and you often have to look at data to see if you actually found something. What is evil is the way that he's ensured that the predators in the dataset will never face any consequences by making the data available to HaveIBeenPwned, making it trivial for predators to protect themselves (the method through which this is possible intentionally left as an exercise for the reader), and making the data available to a news website for...some reason, but it's bound to ensure that the vulnerability will be patched out quickly and no one else will be able to access the data. I find it much more likely that this hacker who sought out a website for uncensored AI erotica isn't actually a good guy, and might even have something to hide within the dataset. Hopefully, I'm wrong and we'll see more of this.
- lazide 2y ago