The Vernost aka Fidelity (2019)Internet Archive is stillunder attack two weeks after suffering a data breach and DDoS attacks that took the website down.
How do we know?
Because the hacker just responded to Mashable's email that we went to the Internet Archive to find out more about the hack. The hacker was able to respond via Internet Archive's Zendesk, an online service that helps companies respond to users' support queries.
Earlier this month, Internet Archive suffered multiple cyberattacks that ended up taking the entire platform, including The Wayback Machine which archives websites throughout the years, offline.
While a group known as SN-Blackmeta took responsibility for the DDoS attacks, the attacker behind the data breach has remained anonymous. It's unconfirmed whether that anonymous hacker is also behind the latest Internet Archive breach.
The attacker claims that they have access to all of the more than 800,000 support tickets sent to Internet Archive since 2018.
"It's dispiriting to see that even after being made aware of the breach 2 weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets," the hacker wrote on Sunday through Zendesk to our email that we sent to Internet Archive on October 10.
"As demonstrated by this message, this includes a Zendesk token with perms to access 800K+ support tickets sent to [email protected] since 2018," they continued.
Chief Security Officer Chris Hickman of the cybersecurity company Keyfactorexplained to Mashable why the rotating API key issue played such an important role here.
"This is a security oversight as tokens that are not rotated regularly have longer lifespans, increasing the window of opportunity for attackers to steal and misuse them," Hickman said. "If a malicious actor obtains an unrotated token, they could use it to gain unauthorized access to systems or services."
And it appears that's what happened.
In the initial attack earlier this month, the hacker shared that they had accessed emails, screen names, and encrypted passwords for 31 million Internet Archive users. However, in this most recent attack, the attacker now shared that they have more than 800,000 support tickets shared between Internet Archive users and the non-profit group. These support tickets could contain even further sensitive information as users who requested that their content be removed from the Internet Archive had to oftentimes provide identification.
In an age where everyone seems to disagree about everything on the internet, there's one thing that mostpeople seem to agree with: The Internet Archive is an amazing tool that provides online library services at no-cost to users. Many were shocked when their site was attacked earlier this month.
The Internet Archive was able to get parts of its website back up and runninglast week. However, it seems like significant damage has been done.
"Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine—your data is now in the hands of some random guy. If not me, it'd be someone else," the hacker said in its reply to Mashable's contact. "Here's hoping that they'll get their shit together now."
Topics Cybersecurity
Announcing Our Fall Issue by Emily StokesWatch Jessica Laser Read “Kings” at the Paris Review Offices by The Paris ReviewOn Friendship: Juliana Leite and Devon Geyelin Recommend by The Paris ReviewDiary, 1994–1999 by Dina NayeriAugust 7–13: What the Review’s Staff is Doing Next Week by The Paris ReviewApparently Personal: On Sharon Olds by Gunnhild ØyehaugAnnouncing Our Summer Issue by Emily StokesMy Lumbago Isn’t Acting Up: On Disney World by Molly YoungSomething Good by Roger ReevesThe Paris Review Wins 2023 Whiting Literary Magazine Prize by The Paris ReviewRear Window, Los Feliz by Claudia Ross“Then Things Went Bad”: How I Won $264 at Preakness by Tarpley HittLooking for Virginia Woolf's Diaries by Geoff DyerDear Mother by Colm TóibínInertia by Kate ZambrenoAt Chloë’s Closet Sale by Sophie KempInertia by Kate ZambrenoThe Green and the Gold by Helen LongstrethMusical Hallucinations by Nancy LemannMaking of a Poem: Michael Bazzett on “Autobiography of a Poet” by Michael Bazzett Building the world of Apple TV+'s 'See' There's a gold statue of Kanye West as Jesus in Los Angeles now, and that seems right Buying new AirPods Pro? Don't throw away your old AirPods, sell them instead. Xiaomi's 108 Grandma sends pics to her granddaughter every day and we're not crying, you're crying Students fight back after diversity posters banned from school for being 'anti Immigration experts share ways to aid undocumented community members Home Depot has up to 50% off select bed and bath basics Hero cashier makes baby's shopping trip the best day ever Can everyone quit hanging out with dolphins while we're stuck in the office? Eating oranges in the shower is a weird trend we can get behind Uber's new self Seth Meyers' Netflix special gives fans a way to skip the Trump jokes Chelsea Clinton remembers the good old days when fake news was about aliens South Korean women will live longer than the rest of us in the future 'For All Mankind' never slows down enough to serve its clever premise Chrissy Teigen is now a YouTuber Blogger learns that it's never OK to talk down pizza This ‘Walking Dead’ shirt was banned from stores for racism BTS collaborates with Casetify to launch tech accessory collection
1.8354s , 10131.8125 kb
Copyright © 2025 Powered by 【Vernost aka Fidelity (2019)】,Evergreen Information Network