The Internet Archive Suffers Alleged Security Breach

1728508861728.png


Starting at 5pm on October 9th, Internet Archive users began reporting a popup message when trying to load the website, as well as an ongoing DDoS attack. The message foreshadows the data of 31 million users being leaked, and telling people to check haveibeenpwned.

1728508963082.png

(image from twitter)

This comes after IA founder Brewser Kahle mentioned a DDoS attack on the 7th and 8th.


As of writing this archive.org's services do not appear to work, though the message still appears. There has been no official response yet. When any news comes out this news thread will be updated.




Update: The Internet Archive has been taken offline as of 5:30pm

Twitter account Sn_darkmeta is claiming responsibility for the outage (as well as past outages), citing that they started the attach because of the American government's association with Israel.
They are under attack because the archive belongs to the USA, and as we all know, this horrendous and hypocritical government supports the genocide that is being carried out by the terrorist state of “Israel”.


IA has been actively working on preserving Palestinian history, as IA's Jason Scott outlined in his twitter thread. This attack is completely contradictory to the attacker's values and makes no sense (assuming Sn_darkmeta is actually involved).





At 5:50pm Brewster Kahle made a twitter post acknowledging the DDoS attack, however there was no comment on the security breach.





This has now been confirmed to be a breach. Thank you @SylverReZ for dropping the article link.
https://www.bleepingcomputer.com/ne...-hacked-data-breach-impacts-31-million-users/
 
Last edited by rvtr,
From what I understand the passwords were encrypted. Reset your IA password and email password and enable 2FA where possible.
Bcrypt is what they're using to encrypt passwords, it would be a lot harder to crack for an average user. As long as you change your password you'll be fine.

In regards to 2FA, the Internet Archive does not have this built-in yet, but I hope they could implement this feature to prevent future breaches.
 
Password managers can be breached just like everything else. What if your hdd or os fails also?

Write your password on a peice of paper and keep it somewhere near and safe. They cant hack your house or table.

1) Any important data should be backed up anyway, ideally a '321' scheme
2) A password manager will make using longer, stronger passwords easier
3) I know someone who used this method and it was a PITA waiting forever for him to find the account details and it was still weak.
4) Burglarys, fires, etc. can still happen
 
  • Like
Reactions: Lostbhoy
I have over 300 accounts so writing those on paper isn't practical. I use KeePassXC and backup many copies of my databases to different storage devices so I'm not worried about losing access to my own database. I generate unique passwords for all of my accounts 18+ characters including special characters. I use TOTP 2FA when possible.
 
  • Like
Reactions: rvtr
1) Any important data should be backed up anyway, ideally a '321' scheme
2) A password manager will make using longer, stronger passwords easier
3) I know someone who used this method and it was a PITA waiting forever for him to find the account details and it was still weak.
4) Burglarys, fires, etc. can still happen
Its whatevers best for the individual isn't it however...

1. Obvs
2. Still vulnerable
3. Your problem?
4. Absolutely nowhere near the frequency of the discussion or you have serious bad luck!

Everything stated is not wrong tho, people have to find what works for them. If you use a password manager and feel comfortable I ain't trying to tell you not to. I do feel we shoud all know especially in this day and age that anything and everything digital is highly vulnerable.
 
  • Like
Reactions: Ettino
Its whatevers best for the individual isn't it however...

1. Obvs
2. Still vulnerable
3. Your problem?
4. Absolutely nowhere near the frequency of the discussion or you have serious bad luck!

Everything stated is not wrong tho, people have to find what works for them. If you use a password manager and feel comfortable I ain't trying to tell you not to. I do feel we shoud all know especially in this day and age that anything and everything digital is highly vulnerable.

1) Offsets the main issue with an offline password manager
2) Even an offline one?
3) Ignoring convenience, or lack thereof, read the last part, that's where it's still an issue
4) Still an vulnerability, especially if it's your only copy

To me, if you don't like an online password manager because as you say there are risks, use an offline one.
 
Data breaches aside. This makes no sense whatsoever to DDOS Archive, "belongs to the USA" is a weak ass reason to just being a dickhead. It's like some idiot jammed a lock at the public library.

As someone who support Archive and use it a whole bunch this is just next level stupidity.
 
I understand Nintendo is too harsh with DMCA takedowns and emulation but they're still pretty successful.
it's more over pal world but ok
Post automatically merged:

Bully. Nothing else to it. Picking on someone who can't fight back.
as i mentioned above perfect example
 
Password managers can be breached just like everything else. What if your hdd or os fails also?

Write your password on a peice of paper and keep it somewhere near and safe. They cant hack your house or table.
Nah, Writing passwords down physically is much worse than a password manager. A reputable password manager has eyes on their vaults (servers) 24/7 and redundancy in case of disaster. Your passwords disappear with a house fire if you write them down.

They will also use the security breaches to scam you through e-mail or phone, pretending to be your bank or any other company if you're primarily an American, as thousands of Americans fall victim to scams like these each year.
Your bank will never call you people! Especially not asking for a reset over the phone.
 
I personally discourage password reuse. Lots of people may do it, but it doesn't mean you should.
Good security practices constitute having a good password manager and generating a random password for each site you sign up on, ideally also with some form of app-based 2FA. Reusing passwords leaves you vulnerable to credential stuffing, especially after breaches like this.
Good measures is having different passwords for each login and using your brain to store them. Period, that's it man.

Yes, that's what I said
Yes, the cyber terrorists are pro terrorists ;), agreeing with me for once, congrats.
 
Nah, Writing passwords down physically is much worse than a password manager.
I will never understand writing passwords... especially when you get cases like the photo. This password was visible to tons of random volunteers. You just had to look on top of the desktop.
IMG_7024.jpeg
 
  • Like
Reactions: SecureBoot
Use an offline password manager that has passed security audits, like KeePassXC. You won't be remembering secure passwords. They're too long and use too many random characters. Use 2FA everywhere you can. Keep backups of your databases. If you become aware of a breach, change the password for all accounts and associated accounts (such as email). Afaik this is about all you can do.

Edit: One other thing. This has nothing to do with cybersecurity directly, but I highly recommend everyone freeze their credit. There have been so many SSN leaks that are directly outside of our control.
 
  • Love
Reactions: Pismire

Site & Scene News

Popular threads in this forum