The Internet Archive Suffers Alleged Security Breach

1728508861728.png


Starting at 5pm on October 9th, Internet Archive users began reporting a popup message when trying to load the website, as well as an ongoing DDoS attack. The message foreshadows the data of 31 million users being leaked, and telling people to check haveibeenpwned.

1728508963082.png

(image from twitter)

This comes after IA founder Brewser Kahle mentioned a DDoS attack on the 7th and 8th.


As of writing this archive.org's services do not appear to work, though the message still appears. There has been no official response yet. When any news comes out this news thread will be updated.




Update: The Internet Archive has been taken offline as of 5:30pm

Twitter account Sn_darkmeta is claiming responsibility for the outage (as well as past outages), citing that they started the attach because of the American government's association with Israel.
They are under attack because the archive belongs to the USA, and as we all know, this horrendous and hypocritical government supports the genocide that is being carried out by the terrorist state of “Israel”.


IA has been actively working on preserving Palestinian history, as IA's Jason Scott outlined in his twitter thread. This attack is completely contradictory to the attacker's values and makes no sense (assuming Sn_darkmeta is actually involved).





At 5:50pm Brewster Kahle made a twitter post acknowledging the DDoS attack, however there was no comment on the security breach.





This has now been confirmed to be a breach. Thank you @SylverReZ for dropping the article link.
https://www.bleepingcomputer.com/ne...-hacked-data-breach-impacts-31-million-users/
 
Last edited by rvtr,
Your email probably isn't compromised if you didn't use the same password here as you use for your email account. You're probably fine to keep using that email
If yall see me acting nice and respectful, it's not me, I got hacked.
 
If yall see me acting nice and respectful, it's not me, I got hacked.
I work in cybersecurity so I have a pretty good grasp on what attackers go after. If someone seriously targets you, they'll get to you breach or not. The attackers in this scenario will have tons of email/password combinations that are reused across multiple sites though and that's what they'll go for. Unfortunately, before I worked in cybersecurity I was a stupid kid on the internet so I still have a lot of work ahead of me to clean up my digital presence. I've made good headway on securing my crucial accounts (financial, health, and shopping), but I've still got a long way to go.
 
Forgot to ask, but were the passwords hashed? Surely they weren't stored in plaintext. If passwords were stored as salted hashes, it's gonna take a while to reverse engineer those which should buy everyone affected some time to change their passwords
 
Forgot to ask, but were the passwords hashed? Surely they weren't stored in plaintext. If passwords were stored as salted hashes, it's gonna take a while to reverse engineer those which should buy everyone affected some time to change their passwords
Yes, all the passwords are bcrypt salted hashes, as mentioned in the article linked in the original post.
 
if you use the password in other accounts, specially with the same email combination, yeah. (YOU ARE ABLE TO DO THIS AND EVERYONE ELSE DOES)
I personally discourage password reuse. Lots of people may do it, but it doesn't mean you should.
Good security practices constitute having a good password manager and generating a random password for each site you sign up on, ideally also with some form of app-based 2FA. Reusing passwords leaves you vulnerable to credential stuffing, especially after breaches like this.
 
  • Like
Reactions: rvtr
I personally discourage password reuse. Lots of people may do it, but it doesn't mean you should.
Good security practices constitute having a good password manager and generating a random password for each site you sign up on, ideally also with some form of app-based 2FA. Reusing passwords leaves you vulnerable to credential stuffing, especially after breaches like this.
What about people like me that have a terrible memory?
 
What about people like me that have a terrible memory?
What do you mean? The entire concept of a password manager is that it manages your passwords for you and the only one you ever need to remember is the master password.
 
  • Like
Reactions: rvtr
What do you mean? The entire concept of a password manager is that it manages your passwords for you and the only one you ever need to remember is the master password.
I meant to say that i'm always forgetting most of my passwords. Also the only password manager I tried aside of the one in the browser was only paid with a free trial
 
I meant to say that i'm always forgetting most of my passwords. Also the only password manager I tried aside of the one in the browser was only paid with a free trial
Try Bitwarden, it's free and open source, and self-hostable if you so choose.
 
  • Like
Reactions: rvtr and Xdqwerty
Yeah, used an email that I had used in other sites... and asked ChatGPT to generate a password, so I'm not sure.
I think I'll just delete the email address altogether.
…please don’t use ChatGPT, or any AI bot, as a password generator. Everything you tell them stays in a database, including your password.

https://passwordsgenerator.net/

Or just mash your keyboard like this 7336)Hdbdisirrh01826:eheifxabeHRdCioeowf
 
  • Like
Reactions: CoolMe and Xdqwerty
I work in cybersecurity so I have a pretty good grasp on what attackers go after. If someone seriously targets you, they'll get to you breach or not. The attackers in this scenario will have tons of email/password combinations that are reused across multiple sites though and that's what they'll go for. Unfortunately, before I worked in cybersecurity I was a stupid kid on the internet so I still have a lot of work ahead of me to clean up my digital presence. I've made good headway on securing my crucial accounts (financial, health, and shopping), but I've still got a long way to go.
They will also use the security breaches to scam you through e-mail or phone, pretending to be your bank or any other company if you're primarily an American, as thousands of Americans fall victim to scams like these each year.
 
What about people like me that have a terrible memory?
Password managers can be breached just like everything else. What if your hdd or os fails also?

Write your password on a peice of paper and keep it somewhere near and safe. They cant hack your house or table.
 
…please don’t use ChatGPT, or any AI bot, as a password generator. Everything you tell them stays in a database, including your password.

https://passwordsgenerator.net/

Or just mash your keyboard like this 7336)Hdbdisirrh01826:eheifxabeHRdCioeowf
Just generate your password with a password generator. If you're unsure whether they're stored in a database, then I guess you save the site and disable your internet connection whilst doing it. That way no traffic or data is sent.
 
From what I understand the passwords were encrypted. Reset your IA password and email password and enable 2FA where possible.
 

Site & Scene News

Popular threads in this forum