16 ms·
Internet Archive breached again through stolen access tokens
- wkat4242 2y agoOuch. Once can happen, twice in a row...
- fallingknife 2y agoOnce makes the second time more likely. Shows you are a soft target.
- TheFreim 2y ago> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that there were a variety of different bad security practices.
- galleywest200 2y ago>"It's dispiriting to see that even after being made aware of the breach weeks ago..." These people are not dispirited whatsoever, if anything they are half-cocked that these script kiddies found an easy target.
- chrisrhoden 2y agoThe words came from a message written by the people you are calling script kiddies, rather than being editorializing by bleepingcomputer, as you seem to believe.
- compootr 2y agoscript kiddie or blackhat hacker is irrelevant. IA has shit security practices, and that's a fact regardless of who figures that out
- EasyMark 2y agoI highly doubt they are script kiddies. More than likely they are state actors or mercenaries of state actors attempting to bring down the free transmittal of information between regular folks. IA evidently has not so good security and wikipedia must be doing pretty well I guess? I can’t recall the last time one of these attacks worked on Wiki.
- luckylion 2y agoWhy would they publicly call them out and lay open the way they breached them if they were "attempting to bring down the free transmittal of information between regular folks"? They could have done much worse but they chose not to and instead made it public. Which state actor does that?
- Aachen 2y agoSubtitling: half clocked means not fully prepared
- ghostly_s 2y agoIA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.
- echelon 2y agoI support archival of films, books, and music, but those items need to be write-only until copyright expires. The purpose of the Internet Archive is to achieve a wide-reaching, comprehensive archival, not provide easy and free read access to commercial works. Website caches can be handled differently, but bulk collection of commercial works can't have this same public access treatment. It's crazy to think this wouldn't be a huge liability. Battling for copyright changes is valiant, but orthogonal. And the IA by trying to do both puts its main charter--archival--at risk. The IA should let some other entity fight for copyright changes. I say this as an IA proponent and donor.
- withinboredom 2y agoI'd agree with you if you live in a country where you can walk into your local library and read these for "free." For people who live where there may not even be a library, your argument makes no sense except to make the publishers richer. They typically price some of these books at "library prices" so normal people won't be able to afford them, but libraries will.
- sieabahlpark 2y agoCopyright is copyright. If you don't like the idea of a publisher owning the rights to content they published doesn't mean you have a right to their content. Let alone worldwide distribution of that content. What makes you feel entitled to the content of the publisher before the copyright expires? Do you feel that you deserve access to everything because you've deemed the concept of ownership around book publishing immoral? You can't just take a digital copy of a physical book and give it to everyone worldwide. That isn't your choice or decision to make nor is it ethical to ascribe malice to simply retaining distribution rights to content they own. "Make publishers richer", it's actually just honoring the concept of ownership...
- deleted 2y ago[deleted]
- tgsovlerkhgsel 2y agoThere are many "first things" you need to do if breached, and good luck identifying and doing them all in a timely fashion if you're a small organization, likely heavily relying on volunteers and without a formal security response team...
- absence5875 2y ago[dead]
- trompetenaccoun 2y agoWe need archives built on decentralized storage. Don't get me wrong, I really like and support the work Internet Archive is doing, but preserving history is too important to entrust it solely to singular entities, which means singular points of failure.
- oytis 2y agoWe'll need to find even more people willing to expose themselves to legal threats and cyberattacks then.
- trompetenaccoun 2y agoThe legal side is a big issue, true. The simplest and best workaround that I'm aware of is how the Arweave network handles it. They leave it up to the individual what parts of the data they want to host, but they're financially incentivized to take on rare data that others aren't hosting, because the rarer it is the more they get rewarded. Since it's decentralized and globally distributed, if something is risky to host in one jurisdiction, people in another can take that job and vice versa. The data also can not be altered after it's uploaded, and that's verifiable through hashes and sampling. Main downside in its current form is that decentralized storage isn't as fast as having central servers. And the experience can vary of course, depending on the host you connect to. As for technical attacks, I'm not an expert but I'd assume it's more difficult for bad actors to bring down decentralized networks. Has the BitTorrent network ever gone offline because it was hacked for example? That seems like it would be extremely hard to do, not even the movie industry managed to take them down.
- Aachen 2y ago> decentralized storage isn't as fast as having central servers. With the 30-second "time to first byte" speed we all know and love from IA, I'm pretty sure it'd only get faster when you're the only person accessing an obscure document on a random person's shoebox in Korea as compared to trying to fetch it from a centralised server that has a few thousand other clients to attend to simultaneously
- _fat_santa 2y agoI don't know what their funding model looks like but if they have some cash I'd say hiring a security team would be on top of the list of things to invest in.
- brendoelfrendo 2y agoI believe that, at this point in time at least, IA's funding model consists of sweating profusely while awaiting a colossal legal judgement.
- udev4096 2y agoIs it the same email spoofing attack vector of zendesk which was disclosed last week?
- steffanA 2y agoArticle says API token was stolen in original breach.
- deleted 2y ago[deleted]
- myself248 2y agoI'd like to imagine a world where every lawyer, when their case is helped by a Wayback Machine snapshot of something, flips a few bucks to IA. They could afford a world-class admin team in no time flat.
- thaumasiotes 2y agoThat's a terrible solution. The Wayback Machine takes down their snapshots at the request of whoever controls the domain. That's not archival. If the state of a webpage in the past matters to you, you need a record that won't cease to exist when your opposition asks it to. This is the concept behind perma.cc.
- myself248 2y agoOoo, excellent. Yes, hiding items is imperfect, but I understood that it was legally required or something. (IANAL and IDFK, TBH) I wonder how perma.cc gets around that.
- immibis 2y agoMost likely by breaking the law.
- berdario 2y agoI'm afraid that it just hasn't been tested in court yet. I haven't read this paper yet, but... https://www.tesble.com/10.1080/0270319x.2021.1886785 https://www.tesble.com/10.1080/0270319x.2021.1886785 from the abstract: > The article concludes that Perma.cc's archival use is neither firmly grounded in existing fair use nor library exemptions; that Perma.cc, its "registrar" library, institutional affiliates, and its contributors have some (at least theoretical) exposure to risk It seems that the article is about copyright, but of course there are several other reasons that might justify takedown of content stored on perma.cc: - Right to be forgotten... perma.cc might be able to ignore it, but could this lead to perma.cc being blocked by european ISPs - ITAR stuff - content published by entities recognized by $GOVERNMENT as terrorist organizations - revenge porn - CSAM
- badlibrarian 2y agoRestating my love for Internet Archive and my plea to put a grownup in charge of the thing. Washington Post: The organization has “industry standard” security systems, Kahle said, but he added that, until this year, the group had largely stayed out of the crosshairs of cybercriminals. Kahle said he’d opted not to prioritize additional investments in cybersecurity out of the Internet Archive’s limited budget of around $20 million to $30 million a year. https://archive.ph/XzmN2 https://archive.ph/XzmN2
- semicolon_storm 2y agoIn security, industry standard seems to be about the same as military grade: the cheapest possible option that still checks all the boxes for SOC.
- incahoots 2y agoBasically, whatever the liability insurance wants for you to be in compliance, than that’s the standard.
- Spivak 2y agoHot take, this is the way it should be. If you want better security then you update the requirements to get your certification. Security by its very nature has a problem of knowing when to stop. There's always better security for an ever increasing amount of money and companies don't sign off on budgets of infinity dollars and projects of indefinite length. If you want security at all you have bound the cost and have well-defined stopping points. And since 5 security experts in a room will have 10 different opinions on what those stopping points should be— what constitutes "good-enough" they only become meaningful when there's industry wide agreement on them.
- db48x 2y agoYep. And worse, now matter how much you pay for security it is still possible for someone to make a mistake and publish a credential somewhere public.
- 2y ago
- pessimizer 2y agoThe Internet Archive has a management problem. They seem to be more comfortable disrupting libraries than managing an online, publicly accessible database of disputed, disorganized material. Despite all of the positive self-talk, I don't know if they realize how important they are, or how easy it would be for them to find good help and advice if their management were transparent and everything was debated in public. That may have protected it to some extent; as a counterexample, Wikipedia has been extremely fragile due to its transparency and accessibility to everyone. With IA being driven by its creator's ideology, maybe that ideology should be formalized and set in stone as bylaws, and the torch passed to people openly debating how IA should be run, its operations, and what it should be taking on. I don't mean they should be run by the random set of Confucian-style libertarian aphorisms that is running the credibility of Wikipedia into the ground, but Debian is a good model to follow. Or maybe do better than both?
- avazhi 2y agohttps://www.wired.com/story/internet-archive-memory-wayback-machine-lawsuits/ https://www.wired.com/story/internet-archive-memory-wayback-... I appreciate their ethos and I've used the site many times (and donated!), but clearly it's at the point where Kahle et al just aren't equipped either personally (as a matter of technical expertise) or collectively (they are just a handful of people) to be dealing with what are probably in many cases nation-state attacks. Kahle's attitude towards (and misunderstanding of) copyright law is IMO proof that he shouldn't be running things, because his legal gambles (gambles that a first year law student could have predicted would fail spectacularly) have put IA at long term risk (see: Napster). And this information coming out over the past few weeks about their technical incompetence is arguably worse, because the tech side of things are what he and his team are actually supposed to be good at. It's true that Google and Microsoft and others should be propping up the IA financially but that isn't going to solve the IA's lack of technical expertise or its delusional hippie ethos.
- badlibrarian 2y agoDon't forget the time Brewster tried to run a bank -- Internet Archive Federal Credit Union. Or that the physical archives are stored on an active fault line and unlikely to receive prompt support during an emergency. Or that, when someone told him that archives are often stored in salt mines he replied, "cool, where can I buy one?"
- MarcoZavala 2y ago[dead]
- notmysql_ 2y agoI sent them a resume almost a year ago, and got nothing back in response until yesterday. Looks like they are going through their backlog right now to find more hands.
- sirolimus 2y agoIt’s incredibly sad to see threat actors attack something as altruistic as an internet library. Truly demoralizing to see such degeneracy.
- codezero 2y agoThere are many state actors that attack targets of opportunity just to cause chaos and asymmetric financial costs.
- croes 2y agoSeems like the actor did it only for the street credit and the second breach is only a reminder that IA didn’t properly fixed it after the first breach. Could be worse.
- userbinator 2y agoWhen there are plenty of people who are steeped in the dogma of Imaginary Property, and whose lives depend on it, it's not too surprising.
- boplicity 2y agoFYI: "Money" is imaginary property. Not sure you want to call people supporting "imaginary property" dogmatic. It's what our society is built on.
- userbinator 2y agoMoney is not imaginary. You can touch and interact with it.
- gruez 2y agoThat's like saying movies aren't imaginary either because there's blu-rays. Even if we take that point at face value though, the vast majority of money is imaginary, only existing on ledgers. When the fed "prints money", it's just adjusting an entry on a database somewhere.
- gweinberg 2y agoDoes anyone know who is targeting the Internet Archive, and why? I get the impression the attacks are too sophisticated for it to just be vandal punks.
- deleted 2y ago[deleted]
- xyst 2y agoIs it sophisticated if IA leaves the door wide open? I blame shit leadership.
- lolinder 2y ago> I get the impression the attacks are too sophisticated for it to just be vandal punks. What gives that impression? Everything I've seen about the attacker's messaging says "vandal punk(s)" to me, and nothing in what I've seen of the IA's systems screams Fort Knox. It wouldn't surprise me if they actually had a pretty lax approach to security on the assumption that there's very little reason to target them.
- jrm4 2y agoIt strikes me as reasonable to assume (or at least strongly bet on) -- I'm not sure of the right phrase for it -- but like a mercenary type operation on behalf of some larger old media company? There's just too much "means, motive and opportunity" there.
- dokyun 2y agoThe group that claimed to be responsible for the first hack was said to be Russian-based, anti-U.S., pro-Palestine, and their reasoning for the attack was because of IA's violation of copyright.... I think you should draw your own more informed conclusions, but it smells a lot like feds to me.
- MathMonkeyMan 2y agoWhat do Palestine, Russia, and the U.S. have to do with the Internet Archive? The Internet Archive is a supremely boring target politically.
- alexey-salmin 2y agoA genuine question to commenters asking to "put a grownup in charge of the thing" and saying that "Kahle shouldn't be running things": he built the thing, why exactly he can't run it the way he sees fit?
- et-al 2y agoHe is. But at the cost of the greater good. Most of us care mainly about the Wayback Machine and archiving webpages; not borrowing books still under copyright and fighting publishers.
- TZubiri 2y agoSpeak for yourself, the internet archive successfully increased its scope and made creative contributions to case law (although it lost at the appeals court)
- badlibrarian 2y agoInternet Archive certainly made creative arguments, all of which were soundly rejected under Summary Judgment. This had the opposite effect on the future we both want. Under discovery in the case, it turned out that Internet Archive didn't keep accurate records of what they loaned out either. Another example of sloppy engineering that directly impacts their core mission. The fate of the organization now rests on the outcome of other lawsuits. In one, Internet Archive argues that they are allowed to digitize and publish Frank Sinatra records because the pops and crackles on them makes it Fair Use. If they did all this cleanly under a different LLC, I'd sit back and enjoy the show. But they didn't.
- deleted 2y ago[deleted]
- carapace 2y ago> the greater good (Hot Fuzz reference. https://www.youtube.com/watch?v=oQzrR6nOkYg https://www.youtube.com/watch?v=oQzrR6nOkYg )
- deleted 2y ago
- anthk 2y agoThe Internet Archive had legal gems such as the Jamendo Album Collection, a huge CC haven. Yes, most of it under NC licenses, but for non-commercial streaming radio with podcasts, these have been invaluable. Do you know Nanowar? They began there. Also, as commercal music has been deliberately dumbed down for the masses (in paper, not by cheap talking), discovering Jamendo and Magnatune in late 00's has been like crossing a parallel universe.
- 999900000999 2y agoDo any organizations have a mirror of this? Even if it's not publicly available...
- butz 2y agoIs there any way IA could be mirrored in read-only mode, while security concerns are addressed?
- trod123 2y agoDepends on the topology, my guess would be no though. Generally speaking, a compromise requires a lot of non-public work to be done in a very short time period. If they don't know how they were initially compromised (and you can't take attacker's word on things), simply throwing up another copy isn't going to fix the issue and often eggs them on to continue. You basically have to re-perimeterize your topology with known good working security, and re-examine trusted relationships starting with a core group of servers and services, and then expanding outwards, ensuring proper segmentation along the way. Its a lot easier with validated zero trust configurations, but even then its a real pain (especially when there is a hidden flaw in your zero-trust config somewhere) and its very heavy on labor. Servers and services also need to ensure they have not deviated from their initial known desired states. Some bad guys set traps in the data/services as timebombs, that either cross-polinate, or re-compromise later. There are quite a lot of malicious ****s out there.
- kleiba 2y agoPeople with solid info sec knowledge: this is a good opportunity to offer your expertise pro-bono for a good cause!
- xyst 2y ago[flagged]
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- kyleyeats 2y agoThey're buried in these offers right now.
- op00to 2y agoI wonder how many offers are legitimate.
- TZubiri 2y agoAn org amidst an attack might not be the most open to giving credentials and access to strangers.
- deleted 2y ago[deleted]
- knowitnone 2y ago[flagged]
- deleted 2y ago[deleted]
- black_13 2y ago[dead]
- RcouF1uZ4gsC 2y agoThe Library of Congress should be archiving the Internet and it should have the budget required to do so. This is in line with its mission as the "Library of Congress". Being able to have an accurate record of what was on the Internet at a specific point in time would be helpful when discussing legislation or potential regulation involving the internet.
- awkwardpotato 2y agoThe Library of Congress does currently archive limited collections of the internet[0]. They have a blog post[1] breaking down the effort, currently it's 8 full time staff with a team of part time members. According to Wikipedia[2], it's built on Heritrix and Wayback which are both developed by the Internet Archive (blog post also mentions "Wayback software"). Current archives are available at: http://webarchive.loc.gov/ http://webarchive.loc.gov/ [0] https://www.loc.gov/programs/web-archiving/about-this-program/ https://www.loc.gov/programs/web-archiving/about-this-progra... [1] https://blogs.loc.gov/thesignal/2023/08/the-web-archiving-team-answers-questions-about-the-web-archives/ https://blogs.loc.gov/thesignal/2023/08/the-web-archiving-te... [2] https://en.m.wikipedia.org/wiki/List_of_Web_archiving_initiatives https://en.m.wikipedia.org/wiki/List_of_Web_archiving_initia...
- tokai 2y agoAs awkwardpotato write they do. Many national libraries all over the word treat the internet as covered by their requirements of legal deposit, and crawl their respective TLD.
- arresin 2y ago> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor. With everything that’s going on, it’s highly suspicious that this is happening right after they upset some very rich rent seekers.
- deleted 2y ago[deleted]
- karlgkk 2y ago[flagged]
- ianeigorndua 2y agoYou don’t think you’re being a bit harsh here?
- meowface 2y agoConspiracy theorists exhaust many.
- knighthack 2y ago> Absolutely moronic and unbased implication. The "rent-seekers" won their case and have zero interest in being implicated in dumb palace-intrigue style hacking. I mean, fuck those guys, but to bring up allegations like that is big stupid. That makes no sense. The fact that they won their case gives even greater cause in ensuring that what they want goes through. Doesn't mean they have to be classy about it, or that Internet-based means of sabotage are impossible implications (given that the IA literally is about putting things up on the Internet that some want to be taken down).
- lolinder 2y ago> The fact that they won their case gives even greater cause in ensuring that what they want goes through. Which is why they will continue their attack through the court system until they get everything they want, up to and including shutting down the archive for good. There's zero reason for them to risk being implicated in a crime when their opponent is already down for the count.
- throwaway984393 2y ago[dead]
- nonamepcbrand1 2y agoWaiting for trufflehog and gitguardian vendors to come up with article, tweets on how their tools would have stopped this incident :sweatsmile:
- nchmy 2y agoIt's Matt Mullenweg trying to erase the vast records of his deranged megalomania.
- rbanffy 2y agoWhat kind of vandal attacks a library? We really need to find the people responsible.
- Shank 2y agoThese kinds of internet attacks happen all the time to children who host Minecraft servers, small businesses, amateur programmers, etc. Finding the responsible party is often difficult if not impossible, and usually the FBI and other powers-that-be have bigger fish-to-fry (i.e., drug traffickers, cyber criminals who focus on extortion, etc) and are unable to devote resources to finding these types of attackers. The sad reality is that a lot of people are unfairly attacked on the internet and many go unpunished due to lack of investigative focus, resources, etc.
- gomizari 2y agoWho profits from this attack? Who forced to remove books from IA?
- bowsamic 2y agoHonestly I'm totally on the side of the hackers in all this. The IA is the most important thing on the internet and the fact it has such bad security is absolutely inexcusable. Thank you to the hackers for bringing attention to this
- amai 2y agoSomebody is trying hard to change the history of the internet.
- excerionsforte 2y agoHow do you donate to them?
- Ajedi32 2y ago[flagged]
- deleted 2y ago[deleted]
- 256_ 2y agoQui bono?
- steeeeeve 2y agoTo everyone who wants a better alternative to IA, who thinks they have a different solution, who thinks it should be run by a different organization, etc. Nobody has ever stopped a competitive alternative from existing. Feel free to give it a shot. You have a head start with all the work that they've done and shared.