The Internet Archive is stillunder attack two weeks after suffering a data breach and DDoS attacks that took the website down.
How do we know?
Because the hacker just responded to Mashable's email that we went to the Internet Archive to find out more about the hack. The hacker was able to respond via Internet Archive's Zendesk, an online service that helps companies respond to users' support queries.
Earlier this month, Internet Archive suffered multiple cyberattacks that ended up taking the entire platform, including The Wayback Machine which archives websites throughout the years, offline.
While a group known as SN-Blackmeta took responsibility for the DDoS attacks, the attacker behind the data breach has remained anonymous. It's unconfirmed whether that anonymous hacker is also behind the latest Internet Archive breach.
The attacker claims that they have access to all of the more than 800,000 support tickets sent to Internet Archive since 2018.
"It's dispiriting to see that even after being made aware of the breach 2 weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," the hacker wrote on Sunday through Zendesk to our email that we sent to Internet Archive on October 10.
"As demonstrated by this message, this includes a Zendesk token with perms to access 800K+ support tickets sent to [email protected] since 2018," they continued.
Chief Security Officer Chris Hickman of the cybersecurity company Keyfactorexplained to Mashable why the rotating API key issue played such an important role here.
"This is a security oversight as tokens that are not rotated regularly have longer lifespans, increasing the window of opportunity for attackers to steal and misuse them," Hickman said. "If a malicious actor obtains an unrotated token, they could use it to gain unauthorized access to systems or services."
And it appears that's what happened.
In the initial attack earlier this month, the hacker shared that they had accessed emails, screen names, and encrypted passwords for 31 million Internet Archive users. However, in this most recent attack, the attacker now shared that they have more than 800,000 support tickets shared between Internet Archive users and the non-profit group. These support tickets could contain even further sensitive information as users who requested that their content be removed from the Internet Archive had to oftentimes provide identification.
In an age where everyone seems to disagree about everything on the internet, there's one thing that mostpeople seem to agree with: The Internet Archive is an amazing tool that provides online library services at no-cost to users. Many were shocked when their site was attacked earlier this month.
The Internet Archive was able to get parts of its website back up and runninglast week. However, it seems like significant damage has been done.
"Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine—your data is now in the hands of some random guy. If not me, it'd be someone else," the hacker said in its reply to Mashable's contact. "Here's hoping that they'll get their shit together now."
Copyright © 2023 Powered by
Internet Archive hacked again: The hacker responded to our email to the Archive.-声闻过情网
sitemap
文章
98277
浏览
93813
获赞
53
Artists on Twitter are drawing their favorite shipping dynamics for this new meme
Once you've binge-watched enough Netflixshows, you start to see a pattern in the characters you getOpenAI brings video to ChatGPT Advanced Voice Mode
ChatGPT's Advanced Voice Mode now has video and screenshare capabilities. The feature was last May wOpenAI Sora release: It's officially here
OpenAI has officially launched Sora. On Monday, CEO Sam Altman immediately kicked off the livestream'Marvel Rivals' characters: See the full list of playable options
Tired of Overwatch? Marvel has an alternative out that you can play for free right now.Marvel RivalsFitbit has developed a ventilator to help COVID
Just like Dyson and NASA before it, Fitbit has now designed a ventilator in response to the coronaviX's declining user base: Platform projected to lose millions of users in 2025
By now, you've likely heard all about the post-election exodus from Elon Musk's X, formerly known asYouTube Kids app now actually looks like YouTube
Your small children being on YouTube is inevitable at this point. From experience, I know kids masteGoogle announces 'agentic' Gemini 2.0 with image and audio support
Not to be outdone by OpenAI's Sora drop, Google just released its new AI model Gemini 2.0. On WednesMarvel Studios president has an extremely hilarious reaction to reporter's question
We're down to the wire, counting the final hours until everyone collectively lose their minds over ABest earbud deal: Get a pair of Samsung Galaxy Buds3 Pro with a $20 Amazon gift card
SAVE $80 + FREE $20 GIFT CARD:As of Dec. 11, get a pair of Samsung Galaxy Buds3 Pro for $189.99 at A'Marvel Rivals' characters: See the full list of playable options
Tired of Overwatch? Marvel has an alternative out that you can play for free right now.Marvel RivalsX got a new AI image generator called Aurora
X is going in even moreon AI.A new AI image generator called Aurora started rolling out for X usersHere's that creepy Rami Malek ad mashed with music from Jordan Peele's 'Us'
It's been an entire month since Rami Malek's promotional video for Mandarin Oriental hotels made theApple's iOS 18.2 arrives: Here's 4 new features to be excited about
After weeks of waiting, Apple's iOS 18.2 update is almost here.Expected to launch on Monday, Dec. 9,Best earbuds deal: Save $10 on Apple AirPods 4
SAVE $10: As of Dec. 5, the Apple AirPods 4 are on sale at Amazon for $119. That's a saving of 8% on