45 ms·
> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys th
by TheFreim 2y ago
> "It's dispiriting to see that even after being made aware of the breach weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," reads an email from the threat actor.
This is quite embarrassing. One of the first things you do when breached at this level is to rotate your keys. I seriously hope that they make some systemic changes, it seems that there were a variety of different bad security practices.
- galleywest200 2y ago>"It's dispiriting to see that even after being made aware of the breach weeks ago..." These people are not dispirited whatsoever, if anything they are half-cocked that these script kiddies found an easy target.
- chrisrhoden 2y agoThe words came from a message written by the people you are calling script kiddies, rather than being editorializing by bleepingcomputer, as you seem to believe.
- compootr 2y agoscript kiddie or blackhat hacker is irrelevant. IA has shit security practices, and that's a fact regardless of who figures that out
- EasyMark 2y agoI highly doubt they are script kiddies. More than likely they are state actors or mercenaries of state actors attempting to bring down the free transmittal of information between regular folks. IA evidently has not so good security and wikipedia must be doing pretty well I guess? I can’t recall the last time one of these attacks worked on Wiki.
- luckylion 2y agoWhy would they publicly call them out and lay open the way they breached them if they were "attempting to bring down the free transmittal of information between regular folks"? They could have done much worse but they chose not to and instead made it public. Which state actor does that?
- Aachen 2y agoSubtitling: half clocked means not fully prepared
- ghostly_s 2y agoIA is in bad need of a leadership change. The content of the archive is immensely valuable (largely thanks to volunteers) but the decisions and priorities of the org have been far off base for years.
- echelon 2y agoI support archival of films, books, and music, but those items need to be write-only until copyright expires. The purpose of the Internet Archive is to achieve a wide-reaching, comprehensive archival, not provide easy and free read access to commercial works. Website caches can be handled differently, but bulk collection of commercial works can't have this same public access treatment. It's crazy to think this wouldn't be a huge liability. Battling for copyright changes is valiant, but orthogonal. And the IA by trying to do both puts its main charter--archival--at risk. The IA should let some other entity fight for copyright changes. I say this as an IA proponent and donor.
- withinboredom 2y agoI'd agree with you if you live in a country where you can walk into your local library and read these for "free." For people who live where there may not even be a library, your argument makes no sense except to make the publishers richer. They typically price some of these books at "library prices" so normal people won't be able to afford them, but libraries will.
- sieabahlpark 2y agoCopyright is copyright. If you don't like the idea of a publisher owning the rights to content they published doesn't mean you have a right to their content. Let alone worldwide distribution of that content. What makes you feel entitled to the content of the publisher before the copyright expires? Do you feel that you deserve access to everything because you've deemed the concept of ownership around book publishing immoral? You can't just take a digital copy of a physical book and give it to everyone worldwide. That isn't your choice or decision to make nor is it ethical to ascribe malice to simply retaining distribution rights to content they own. "Make publishers richer", it's actually just honoring the concept of ownership...
- deleted 2y ago[deleted]
- tgsovlerkhgsel 2y agoThere are many "first things" you need to do if breached, and good luck identifying and doing them all in a timely fashion if you're a small organization, likely heavily relying on volunteers and without a formal security response team...
- absence5875 2y ago[dead]