The FBI sleeps when libraries burn

  • huginn@feddit.it
    link
    fedilink
    English
    arrow-up
    66
    ·
    1 month ago

    This guy is outing the archive for terrible security posture by bringing attention to it because they received disclosures and did not fix them.

    Don’t get shit twisted - he’s the hero here. IA fucked up and has been vulnerable to manipulation by any number of corporate or national actors this entire time.

    • ComradeSharkfucker@lemmy.ml
      link
      fedilink
      English
      arrow-up
      56
      ·
      1 month ago

      If this was genuinely done out of love I could understand but due to the legal battles the internet archive is currently being dragged through, I harbor suspicion of their intent.

    • Zagorath@aussie.zone
      link
      fedilink
      English
      arrow-up
      48
      ·
      1 month ago

      If they were really “the hero”, they’d follow the bare minimum of responsible disclosure best practices, and allow 90 days between privately alerting them of the issue and going public with it. Two weeks is absurd.

      • Ashelyn
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 month ago

        90 days to cycle private tokens/keys?

        • Zagorath@aussie.zone
          link
          fedilink
          English
          arrow-up
          8
          ·
          1 month ago

          90 days is just the standard timeframe for responsible disclosure. And normally that’s just a baseline with additional time being given if there’s genuine communication going on and signs they’re addressing the problem.

          • ITGuyLevi@programming.dev
            link
            fedilink
            English
            arrow-up
            5
            ·
            1 month ago

            90 days is standard for “you’re code is fucked when someone presses this…”; if the issue is Dave left the keys in the parking lot and someone copied them, two weeks is more than enough time for them to recieve the notice, create a ticket to rotate the keys and a ticket to trigger an investigation (gotta document anytime an org fucks up so it doesn’t happen again, right?). Maybe I’m over simplifying it though, I don’t know how their org operates.

            • Zagorath@aussie.zone
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 month ago

              I agree in general, but

              Maybe I’m over simplifying it though, I don’t know how their org operates.

              This is exactly why just sticking to the 90 day standard is better. For the supposed security researcher it’s a CYA move at worst.

        • LukácsFan1917@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          It’s not uncommon for hackers to sell cures for problems they cause. This includes law enforcement, which can have broader goals like promoting their own cybersecurity outfits, even just promoting deoendency on HIBP if it’s a fed thing would be useful here, making the joke they left on the page telling people to check out the site itself suspect. The internet archive is a large and beloved outlet for piracy and depaywalling, maybe the security enhancements being billed to them could help the industry bring them to heel a bit. Just speculating.

          • Ajen@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            30 days ago

            Are you saying the person who sent the zendesk email is going to try to get IA to hire them for something? I’m not sure I follow…

            • LukácsFan1917@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              30 days ago

              No I think it’s about “context creation” as they call it. Like a protetection racket where payment is made in dependence on certain tools, that is intended to be used later. Good way to popularize leaks themselves

              • Ajen@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                30 days ago

                Still not sure what you’re talking about… Is someone going to ask IA for payment related to the zendesk email?

                • LukácsFan1917@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  29 days ago

                  I said it was about fostering dependence on the cybersecurity community. To what end, I do not kniw. But getting people to cloudflare their sites is great for surveillance. Cybersecurity outlets are intensely political and pro west.

                  Private security contractors have noted that leftists use the internet archive more than anyone. I have been reading their papers about online extremism. Very bad people