NF The Internet Archive Has Been Hacked

Non-Fiction
"I'm mad about something activism" so let me wreck the internet and expose people's personal private information to cause further harm 👍 …… yea for this current world

There's also the good ol' fashioned griefers: "This brings joy to people; therefore, if I break it many people will be sad or mad, and that makes me happy."

As long as there are people who take joy in the suffering of others things like this will happen, even without us living in heightened political times. The internet didn't create griefing, it just gave it new avenues.
 
What a ridiculous hack. I hope Karma pays a visit very soon. Or, better yet, turn the folks posting on reddit loose on the hacker. They are madder than mad.

"Update 10/10/24: Internet Archive founder Brewster Kahle shared an update on X last night, confirming the data breach ....."

The security breech that allowed access to 31 million user's data is one issue. The second issue is, as of tonight, the ongoing DDoS attack on the website. This has caused the website to go offline. According to bleepingcomputer.com, "the Internet Archive suffered a DDoS attack, which has now been claimed by the Black Me ta hack ti vist (spaces inserted intentionally) group, who says they will be conducting additional attacks."

Brewster Kahle stated that for now they are able to fend off the DDoS attack.

About the data breach, the bad guys now have our email addresses. Wow, who doesn't. And hashed (salted) encrypted passwords, using bcrypt. This means they do not have the password in plain text that would enable them to read it. To "decrypt" 31 million passwords, or just a few thousand, would take an enormous amount of time and computer resources. But, they may hope to luck up upon an account that used a lame simple password. And, they are hoping that the account uses the same password and email address for all, or many, websites, like online banking!

There are some accounts on the Internet Archives that contain personal information. If you have contributed information your account may be more detailed.

As of today, I think, maybe yesterday, all the account information for each user has been released by the hacker to the website HBIP (Have I Been Pwned). You can search their website to see if your email address appears.

There is speculation about why the hack occurred. The hacker made no mention of how the data would be used (abused). If you suddenly begin receiving an increase in spam email or any email that contains a link to a website then it may be a sign they have sold your email address to spammers and phishers. But, if you've spent more than 24 hours on the Internet, that has probably already been done. :frown:

If you are someone who uses the same username and password for all websites, or simple passwords that do not contain numbers, capital letters and symbols then you need to change your wicked ways. You need to change all your passwords and create a new email address that you use for website registrations, not personal correspondence. Also, take advantage of your browser generated passwords. However, BE SURE your computer, laptop or tablet is password protected, with a strong password.

I did read where some recommend changing your password to the Internet Archives. It certainly won't hurt.
 
If you are someone who uses the same username and password for all websites, or simple passwords that do not contain numbers, capital letters and symbols then you need to change your wicked ways. You need to change all your passwords and create a new email address that you use for website registrations, not personal correspondence. Also, take advantage of your browser generated passwords. However, BE SURE your computer, laptop or tablet is password protected, with a strong password.

I'm saying any of this is wrong, but internet security is often impractical.

Yes, the random gibberish of a browser-generated password is impossible to guess, but it's also impossible to remember. So when some software update logs you out you'll have to go through the password recovery process and hope it works smoothly.
 
The Social Security number was never supposed to be used for general identification. It says so on the bottom of the card: "For Social Security and Tax Purposes - Not for Identification." But somehow, by 1972, it became your "name" in college so professors could post grades on their office doors and not embarrass anyone. It only went downhill from there. Even the Government couldn't follow their own rules. The VA began to use it as your medical record number until HIPAA came along and they had to change their system. Even then, it took them about 15 years.
 
I'm saying any of this is wrong, but internet security is often impractical.

Yes, the random gibberish of a browser-generated password is impossible to guess, but it's also impossible to remember. So when some software update logs you out you'll have to go through the password recovery process and hope it works smoothly.
What seems impractical is, unfortunately, necessary. The bad actors in the world are never going to stop.

Because your browser stores the generated passwords for future use, you should never need to remember them. I certainly could not.

I have never had this problem related to updates and it should not happen unless you are allowing automatic updates while you are active online. They should be set to install when you are offline and/or to ask you before installing. The update is only related to the app or software, possibly hardware, and it does not affect your browser so the saved passwords should not ever be effected.

The only time I know of that you would need to run password recovery on Windows is following a system crash and you need to recover the administrative password.

I hope something I have said gives you a little more faith in and comfort about using auto generated passwords.
 
That sucks. I was trying to research a contemporary (WW II) subject and learned it was down. It's still down today.

Why would anyone want to hack a site like that (unless they're trying to rewrite history)?
 
Am I the only one who doesn't save passwords except on paper?

I learned that password books (like pocket-size address books) are available now. I got one and have been using it as a backup, especially for infrequently used passwords.

Because your browser stores the generated passwords for future use, you should never need to remember them.
I have never had this problem related to updates and it should not happen unless you are allowing automatic updates while you are active online. They should be set to install when you are offline and/or to ask you before installing. The update is only related to the app or software, possibly hardware, and it does not affect your browser so the saved passwords should not ever be effected.

I have had occasional problems on my desktop computer browser forgetting login information for some sites, and frequent problems with apps on my smartphone logging me out.
 
I learned that password books (like pocket-size address books) are available now. I got one and have been using it as a backup, especially for infrequently used passwords.




I have had occasional problems on my desktop computer browser forgetting login information for some sites, and frequent problems with apps on my smartphone logging me out.
Since the mid-90s, I've kept every password to every site I've ever been on in a Walgreens folder. If the house goes up in flames, it'd probably be just as well 😆
 
Unfortunately, getting hacked is not the only problem the Internet Archive is having.

They've been sued for massive copyright infringement by several publishers and have lost the initial case.


They're also being sued by major record labels for massive copyright infringement specifically related to The Great 78 Project.


 

Learn About Us
About CivilWarTalk
Contact the Webmaster
Meet the Staff
Link to CivilWarTalk
Join Our Community
Register
Browse Forums
View Today's Discussions
Search the Forum
Get Help
FAQ
Student Guide
Forum Rules & Etiquette
Copyright / DMCA

     Contact Us CivilwarTalk on Facebook CivilWarTalk on YouTube CivilWarTalk on Twitter RSS Feed

Bringing the American Civil War and More to Life.
© 1999 - , CIVILWARTALK, LLC - Site Version 10.0

SlaveryTalk.com - SecessionTalk.com - CivilWarTalk.com - ReconstructionTalk.com
Back
Top