{"id":45323,"date":"2024-10-10T16:10:53","date_gmt":"2024-10-10T20:10:53","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=45323"},"modified":"2024-10-21T09:51:33","modified_gmt":"2024-10-21T13:51:33","slug":"internet-archive-hacked","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/10\/10\/internet-archive-hacked\/","title":{"rendered":"Internet Archive Hacked"},"content":{"rendered":"<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/internet-archive-hacked-data-breach-impacts-31-million-users\/\">Lawrence Abrams<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41792500\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.bleepingcomputer.com\/news\/security\/internet-archive-hacked-data-breach-impacts-31-million-users\/\"><p>Internet Archive&rsquo;s &ldquo;The Wayback Machine&rdquo; has suffered a data breach after a threat actor compromised the website and stole a user authentication database containing 31 million unique records.<\/p><p>[&#8230;]<\/p><p>Hunt told BleepingComputer that the threat actor shared the Internet Archive&rsquo;s authentication database nine days ago and it is a 6.4GB SQL file named &ldquo;ia_users.sql.&rdquo; The database contains authentication information for registered members, including their email addresses, screen names, password change timestamps, Bcrypt-hashed passwords, and other internal data.<\/p><p>[&#8230;]<\/p><p>While the Internet Archive is facing both a data breach and DDoS attacks at the same, it is not believed that the two attacks are connected.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/news.ycombinator.com\/item?id=41795324\">Springtime<\/a>:<\/p>\n<blockquote cite=\"https:\/\/news.ycombinator.com\/item?id=41795324\"><p>Just in terms of privacy, it&rsquo;s worth noting that anyone who has uploaded something on IA already has their email address publicly viewable.<\/p><p>This isn&rsquo;t something that commonly known (even judging by comments here) but in the publicly viewable metadata of every upload it contains the uploader&rsquo;s IA account email address. So from a security perspective it&rsquo;s bad but from a privacy perspective a lot of users probably weren&rsquo;t aware of this detail if they&rsquo;ve uploaded anything.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/09\/19\/google-search-adds-links-to-internet-archive\/\">Google Search Adds Links to Internet Archive<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/09\/19\/lost-internet-archive-accounts\/\">Lost Internet Archive Accounts<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/08\/17\/book-publishers-v-internet-archive\/\">Book Publishers v. Internet Archive<\/a><\/li>\n<\/ul>\n\n<p id=\"internet-archive-hacked-update-2024-10-21\">Update (2024-10-21): <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/internet-archive-breached-again-through-stolen-access-tokens\/\">Lawrence Abrams<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41895764\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.bleepingcomputer.com\/news\/security\/internet-archive-breached-again-through-stolen-access-tokens\/\">\n<p>The Internet Archive was breached again, this time on their Zendesk email support platform after repeated warnings that threat actors stole exposed GitLab authentication tokens.<\/p>\n<p>[&#8230;]<\/p>\n<p>In the case of the Internet Archive, there was no money to be made by trying to extort the organization. However, as a well-known and extremely popular website, it definitely boosted a person's reputation amongst this community.<\/p>\n<\/blockquote>\n\n<p>We need a fully separate Internet archive as a backup.<\/p>","protected":false},"excerpt":{"rendered":"<p>Lawrence Abrams (Hacker News): Internet Archive&rsquo;s &ldquo;The Wayback Machine&rdquo; has suffered a data breach after a threat actor compromised the website and stole a user authentication database containing 31 million unique records.[&#8230;]Hunt told BleepingComputer that the threat actor shared the Internet Archive&rsquo;s authentication database nine days ago and it is a 6.4GB SQL file named [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-10-10T20:10:55Z","apple_news_api_id":"56915d42-008f-47ca-9f14-8aff0b990472","apple_news_api_modified_at":"2024-10-21T13:51:35Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAQ==","apple_news_api_share_url":"https:\/\/apple.news\/AVpFdQgCPR8qfFIr_C5kEcg","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1755,1127,355,96],"class_list":["post-45323","post","type-post","status-publish","format-standard","hentry","category-technology","tag-breach","tag-internet-archive","tag-privacy","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/45323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=45323"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/45323\/revisions"}],"predecessor-version":[{"id":45441,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/45323\/revisions\/45441"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=45323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=45323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=45323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}