7 ms·
More details here about the data breach. Stolen database contains 31 million records. https://www.bleepingcomputer.com/news/security/internet-archive-hacked-da
by steffanA 2y ago
More details here about the data breach. Stolen database contains 31 million records.
https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/ https://www.bleepingcomputer.com/news/security/internet-arch...
- mkl 2y ago> The data will soon be added to HIBP My unique-to-archive.org email address is not there yet.
- ranger_danger 2y agoHow do they get a hold of all these leaks so fast?
- Aachen 2y agoVoluntary sharing, since afaik they don't pay the criminals to get the data. Either the criminals share it directly (fat chance, usually), or someone else bought it and shared it either publicly, privately with HIBP, or privately with someone who then reported it to HIBP How this specific instance unfolded, time will have to tell. The leak may have occurred in 2020 for all we know at this point
- steffanA 2y agoThere is a strange dynamic between the threat actors who conduct these breaches and researchers. When not used for extortion and for "status" in the hacking community, they share them with researchers (commonly HIBP) to warn people about a site's security and so that site is forced to fix things. Definitely a strange dynamic.
- lazide 2y agoA form of ‘counting coup’ I imagine. [https://en.m.wikipedia.org/wiki/Counting_coup https://en.m.wikipedia.org/wiki/Counting_coup]
- crtasm 2y ago"Breach date: 28 September 2024" - I'm assuming they've checked with some recent signups to confirm the timeframe. https://haveibeenpwned.com/PwnedWebsites#InternetArchive https://haveibeenpwned.com/PwnedWebsites#InternetArchive
- nikisweeting 2y agoI just checked and my unique-to-archive.org email is showing up in the breach as of 2024-08-09.
- Funes- 2y agoMine too.
- SushiHippie 2y agoMine isn't, but I've created my account only a week ago, so maybe I've created the account after the breach. EDIT: Should've read TFA more thoroughly, it says the breach happened before the 30th September. And I created my account around the 2nd October
- mobeigi 2y agoOut of curiosity, do you use a unique email address for every single service?
- buildsjets 2y agoNot the author but yes, I do. It’s trivially easy so why not?
- phantomathkg 2y agoCurious, how trivially easy is that?
- echoangle 2y agoSome providers allow you to use Alias emails (I think google redirects mail to ia+mymail@gmail.com to mymail@gmail.com), and if you use your own domain, you can just use a catchall redirect and enter a random address (ia@mydomain.com which goes to catchall@mydomain.com).
- drsim 2y agoMany providers support plus addresses like bob+servicename@example.com. Servicename can be anything and doesn’t require any setup.
- duggan 2y agoThe +, however is just a comment delimiter. All a service provider or malicious actor has to do is simply not include it when storing or publishing it to evade tracking. Stripping it is not uncommon for services to prevent duplicate accounts.
- TheDong 2y agoIt's quite trivial. 1. Buy a domain. About $10/year for a .com 2. Buy a /24 ipv4 block with good reputation (maybe like $10k) 3. Get a rack in a nearby datacenter, rack up a BGP-capable router and your servers for redundancy to run email. Takes about $30k initial setup costs if you buy all new, and about $5k initial setup costs if you cut corners and buy used. It'll be $2k/mo after that, so less than the cost of 1 $100 avocado toast per day, quite affordable. 4. Setup your mailserver of choice, such as dovecot + postfix. Enable either a catch-all address, or use recipient_delimiters. The former means "anything@domain.com" works, and the latter means "user-anything@domain.com" works (assuming your recipiient_delimiters are '-'). I recommend using a real catchall. 5. Setup your spam setup, this is the hardest part. I have no guidance here. 6. Point your DNS over, setup SPF and DKIM records, test, and off you go! This should all take about 1 to 3 days if you know what you're doing. 7. Find out that some email will go to spam anyway because you're not using one of the big 4 email providers, but it can't be helped, and anyway no one uses email anymore. And after that, for less than $30k/year, you have email with catchall or subadressing support. Nice and easy. You can also pay Fastmail for email and use their "catchall" feature https://www.fastmail.help/hc/en-us/articles/1500000277942-Catch-all-wildcard-aliases https://www.fastmail.help/hc/en-us/articles/1500000277942-Ca... Or Google Apps also has a catchall feature. Then, after you do this, you can simply give internet archive the email address "internet-archive@mydomain.com", or generate a random string. If you forget the email you used, you can search your email history for the first email they sent you, and check the To field.
- paulnpace 2y agoMany hackers will remove addresses that are obviously unique, including tags, to keep silent which database has been hacked, but it seems inconsistent. I have checked and known my address was in a hack and it isn't there, while other times it is there. I also wonder if they start filtering out by domain, as they see a domain across multiple databases with unique addresses in each database exactly one time.
- Funes- 2y agoFriendly reminder to generate a unique password for every account you create so database leaks like this one don't bother you (besides on the site they're used).
- JohnMakin 2y agoMFA
- AStonesThrow 2y agohttps://xkcd.com/2176/ https://xkcd.com/2176/
- voiper1 2y agoI hadn't seen that one, I love it!
- paulnpace 2y agoI think pretty much the same argument for old-world POTS. While nothing was encrypted, nothing was recorded and someone had to physically access the local copper, which in reality provided more privacy than the future (today) where everything is recorded forever and you can bribe, extort, hack, blackmail, or just for fun leak everything recorded.
- haha112 2y agoI use login with google, idk if it is safe
- ano-ther 2y ago> the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service Do they? Why?
- richbell 2y agoIf Troy authenticates the data, they can use that as an 'endorsement' when trying to sell it.
- ianhawes 2y agoThis. Typically HIBP attribution includes the email of the "submitter". Various data aggregators will contact them and buy the stolen data. Everybody wins*. * Exceptions apply.
- Thorrez 2y agoWhere on HIBP can I see the email of the submitter?
- ramimac 2y agoIt's not available in this case, or every case. When available, you can search "The data was provided by" in https://haveibeenpwned.com/PwnedWebsites https://haveibeenpwned.com/PwnedWebsites
- Thorrez 2y agoThanks! Slight correction: only 2 breaches say "provided by" with a source, but a ton of breaches say "provided to" HIBP with a source.
- deleted 2y ago[deleted]
- RamRodification 2y ago
- maltris 2y agoMy question is: How did Scott Helme end up with a password hash that features his own name?
- jgrahamc 2y agoHe didn't. If you break down that field you see: $2a$ 10$ Bho2e2ptPnFRJyJKIn5Bie hIDiEwhjfMZFVRM9fRCarKXkemA3Pxu ScottHelme 2a = bcrypt, 10 = 2^10 rounds, Bho2e2ptPnFRJyJKIn5Bie is the 22 character salt, hIDiEwhjfMZFVRM9fRCarKXkemA3Pxu is the 31 character hash value, and then there's ScottHelme. Best guess is that the archive.org folks just appended the user name to the stored hash. Maybe once upon a time they didn't have a username column in their table and this was a creative way of adding it.