News

The FBI Secretly Created a Coin To Investigate Crypto Pump-and-Dump Schemes

Slashdot - Thu, 2024-10-10 22:42
The FBI created a cryptocurrency as part of an investigation into price manipulation in crypto markets, the government revealed on Wednesday. From a report: The FBI's Ethereum-based token, NexFundAI, was created with the help of "cooperating witnesses." As a result of the investigation, the Securities and Exchange Commission charged three "market makers" and nine people for allegedly engaging in schemes to boost the prices of certain crypto assets. The Department of Justice charged 18 people and entities for "widespread fraud and manipulation" in crypto markets. The defendants allegedly made false claims about their tokens and executed so-called "wash trades" to create the impression of an active trading market, prosecutors claim. The three market makers -- ZMQuant, CLS Global, and MyTrade -- allegedly wash traded or conspired to wash trade on behalf of NexFundAI, an Ethereum-based token they didn't realize was created by the FBI. "What the FBI uncovered in this case is essentially a new twist to old-school financial crime," Jodi Cohen, the special agent in charge of the FBI's Boston division, said in a statement. "What we uncovered has resulted in charges against the leadership of four cryptocurrency companies, and four crypto 'market makers' and their employees who are accused of spearheading a sophisticated trading scheme that allegedly bilked honest investors out of millions of dollars."

Read more of this story at Slashdot.

Categories: Computer, News

The True Cost of Game Piracy: 20% of Revenue, According To a New Study

Slashdot - Thu, 2024-10-10 22:01
A new study suggests game piracy costs publishers 19% of revenue on average when digital rights management (DRM) protections are cracked. Research associate William Volckmann at UNC analyzed 86 games using Denuvo DRM on Steam between 2014-2022. The study, published in Entertainment Computing, found cracks appearing in the first week after release led to 20% revenue loss, dropping to 5% for cracks after six weeks. Volckmann used Steam user reviews and player counts as proxies for sales data.

Read more of this story at Slashdot.

Categories: Computer, News

Windows 11's Big 2024 Update Leaves Behind 9GB of Undeletable Files

Slashdot - Thu, 2024-10-10 21:20
smooth wombat writes: The Windows 11 24H2 update has had a host of issues associated with it including disappearing mouse cursors and blue screens related to Intel drivers. Now comes word that the new update leaves behind over 8 GB of undeletable cache files. According to Windows Latest, attempts to delete the cache via the Control Panel are unsuccessful. Although you can select the cache for deletion and initiate the deletion process, the cache remains. Various other methods to remove the Windows update cache failed, too. It only cleared after a clean Windows installation altogether.

Read more of this story at Slashdot.

Categories: Computer, News

Overshooting 1.5C Risks 'Irreversible' Climate Impact: Study

Slashdot - Thu, 2024-10-10 20:45
Any breach of what climate scientists agree is the safer limit on global warming would result in "irreversible consequences" for the planet, said a major academic study published on Wednesday. From a eport: Even temporarily exceeding 1.5 degrees Celsius before bringing temperatures back down -- a scenario known as an "overshoot" -- could cause sea level rises and other disastrous repercussions that might last millenia. This "does away with the notion that overshoot delivers a similar climate outcome" to a future where more was done earlier to curb global warming, said Carl-Friedrich Schleussner, who led the study co-authored by 30 scientists. The findings, three years in the making, are urgent, as the goal of capping global temperature rises at 1.5C above pre-industrial levels is slipping out of reach. Emissions of heat-trapping greenhouse gases must nearly halve by 2030 if the world is to reach 1.5C -- the more ambitious target enshrined in the 2015 Paris climate accord.

Read more of this story at Slashdot.

Categories: Computer, News

EU Delays New Biometric Travel Checks as IT Systems Not Up To Speed

Slashdot - Thu, 2024-10-10 20:08
The European Union has delayed the introduction of a new biometric entry-check system for non-EU citizens, which was due to be introduced on Nov. 10, after Germany, France and the Netherlands said border computer systems were not yet ready. From a report: "Nov. 10 is no longer on the table," EU Home Affairs Commissioner Ylva Johansson told reporters. She said there was no new timetable, but that the possibility of a phased introduction was being looked at. The Entry/Exit System (EES) is supposed to create a digital record linking a travel document to biometric readings confirming a person's identity, removing the need to manually stamp passports at the EU's external border. It would require non-EU citizens arriving in the Schengen free-travel area to register their fingerprints, provide a facial scan and answer questions about their stay.

Read more of this story at Slashdot.

Categories: Computer, News

Jupiter's Great Red Spot Is Shapeshifting in Ways 'Never Identified Before'

Slashdot - Thu, 2024-10-10 19:25
An anonymous reader writes: A massive storm has been raging on Jupiter for centuries, and, for the most part, has appeared very serious. A new series of detailed images, however, revealed that the famous red cyclone can get a little squiggly, bulging into different shapes and sizes over a short period of time. Astronomers used the Hubble space telescope to look at Jupiter's Great Red Spot (GRS) from December 2023 to March 2024, and they observed the massive storm changing dimensions over the 90-day period. The reason behind this unexpected shapeshifting is unknown, but it revealed that the famous red storm is not as stable as it seemed. The results of the Hubble observations are detailed in a study published Wednesday in The Planetary Science Journal. Using Hubble's observations, the team of astronomers behind the new study measured the Great Red Spot's size, shape, brightness, color, and vorticity over one full oscillation cycle. The combined images act like a time-lapse of the storm's changing behavior, revealing its famous red eye varying in size, while its core gets brighter when the Great Red Spot is at its largest during the 90-day cycle.

Read more of this story at Slashdot.

Categories: Computer, News

Bankruptcy Took Down the Redbox Machine. If Only Someone Could Take Them Away.

Slashdot - Thu, 2024-10-10 18:50
Retailers across the U.S. are grappling with the aftermath of Redbox's bankruptcy, tasked with removing 24,000 abandoned DVD-dispensing machines. CVS, Walgreens, Walmart, and others are facing logistical challenges and potential safety hazards, according to WSJ. The 890-pound kiosks, often hardwired into stores' electrical systems, require specialized removal. Further reading: Redbox App Axed, Dashing People's Hopes of Keeping Purchased Content.

Read more of this story at Slashdot.

Categories: Computer, News

Intel Unveils Arrow Lake Desktop Processors, Promising Power Efficiency Gains

Slashdot - Thu, 2024-10-10 18:14
Intel has announced its new Arrow Lake desktop processors, marking a significant shift in the company's approach to chip design and power efficiency. The Core Ultra 200S series, set to launch on October 24, 2024, introduces a disaggregated architecture manufactured using TSMC's advanced nodes. The flagship Core Ultra 9 285K boasts 24 cores (8 performance, 16 efficiency) and can boost up to 5.7 GHz, priced at $589. Intel claims the new chips offer comparable performance to their predecessors while consuming significantly less power, with reductions of up to 136 watts in some gaming scenarios. Arrow Lake utilizes a tiled design, combining compute, GPU, SoC, and I/O components manufactured by TSMC and packaged using Intel's Foveros technology. The compute tile is built on TSMC's N3B process, while the GPU tile uses TSMC's N5P, and the I/O and SoC tiles are on TSMC's N6. Intel's Roger Chandler stated, "Arrow Lake picks up the mantle of Raptor Lake's top-end gaming performance and delivers parity performance at about half the power." Intel acknowledges that gaming performance may lag slightly behind the previous generation, with a 5% deficit in some benchmarks compared to the Core i9-14900K. The company is positioning Arrow Lake as a balanced solution, emphasizing power efficiency and content creation capabilities. The new processors require a new LGA 1851 socket and Z890 chipset, necessitating motherboard upgrades. Memory support extends to DDR5-6400, with XMP profiles potentially reaching DDR5-8000.

Read more of this story at Slashdot.

Categories: Computer, News

'Automattic is Doing Open Source Dirty,' Ruby on Rails Creator Says

Slashdot - Thu, 2024-10-10 17:24
David Heinemeier Hansson, creator of Ruby on Rails and co-founder and chief technology officer of Basecamp-maker 37signals, has criticized Automattic's demand for 8% of vendor WP Engine's revenues as a violation of open source principles and the GPL license. He argues this, among other things, undermines the clarity and certainty of open source licensing, threatening its integrity beyond WordPress. He writes: Ruby on Rails, the open-source web framework I created, has been used to create businesses worth hundreds of billions of dollars combined. Some of those businesses express their gratitude and self-interest by supporting the framework with dedicated developers, membership of The Rails Foundation, or conference sponsorships. But many also do not! And that is absolutely their right, even if it occasionally irks a little. That's the deal. That's open source. I give you a gift of code, you accept the terms of the license. There cannot be a second set of shadow obligations that might suddenly apply, if you strike it rich using the software. Then the license is meaningless, the clarity all muddled, and certainty lost. Look, Automattic can change their license away from the GPL any time they wish. The new license will only apply to new code, though, and WP Engine, or anyone else, are eligible to fork the project. That's what happened with Redis after Redis Labs dropped their BSD license and went with a commercial source-available alternative. Valkey was forked from the last free Redis version, and now that's where anyone interested in an open-source Redis implementation is likely to go. But I suspect Automattic wants to have their cake and eat it too. They want to retain WordPress' shine of open source, but also be able to extract their pound of flesh from any competitor that might appear, whenever they see fit. Screw that.

Read more of this story at Slashdot.

Categories: Computer, News

Porch Pirates Are Stealing AT&T iPhones Delivered by FedEx

Slashdot - Thu, 2024-10-10 16:47
Porch pirates across the country for months have been snatching FedEx packages that contain AT&T iPhones -- within minutes or even seconds of delivery. From a report: The key to these swift crimes, investigators say: The thieves are armed with tracking numbers. Another factor that makes packages from AT&T particularly vulnerable is that AT&T typically doesn't require signature on delivery. Doorbell camera videos show the thefts in New York, Pennsylvania, Delaware, Virginia, Michigan, Georgia, Florida and Texas. The details are similar: A FedEx driver drops off a box with an iPhone from AT&T. Then a person walks up -- sometimes wearing an Amazon delivery vest -- and plucks the package off the front step. The heist can be so quick that in some videos, the FedEx driver and thief cross paths. "They know what's getting delivered and the location," said Detective Lt. Matt Arsenault from the Gardner Police Department in Massachusetts, which is investigating several recent thefts. "They meet the delivery driver at the front door and take it." Since the pandemic, parcel carriers have reported a rise in porch thefts as workers have returned to offices and fewer people are home during the day to receive packages. Now, a spate of thefts that began a few months ago is targeting FedEx deliveries for AT&T. The two companies said they were working with law enforcement to investigate, and declined to disclose how many such packages have been stolen.

Read more of this story at Slashdot.

Categories: Computer, News

FEMA Adds Misinformation To Its List of Disasters To Clean Up

Slashdot - Thu, 2024-10-10 16:00
The Federal Emergency Management Agency (FEMA) is fighting misinformation on top of a major storm cleanup in Florida as Hurricane Milton rapidly intensifies just after Hurricane Helene rocked the state. From a report: FEMA Administrator Deanne Criswell told reporters on a call Tuesday that misinformation around the storms is "absolutely the worst I have ever seen," according to Politico. FEMA posted a rumor response page about the hurricane, and though it's not the first time it's taken that kind of approach, Criswell said, "I anticipated some of this, but not to the extent that we're seeing." FEMA's rumor response page includes fact-checks to claims made by former President Donald Trump, like that the agency will only provide $750 to disaster survivors. FEMA says that's just the amount provided quickly through "Serious Needs Assistance" for food and emergency supplies, but survivors could still be eligible for other types of funds, too. Other fact-checks include debunking the false claim that FEMA disaster response resources were diverted to border issues. FEMA says "Disaster Relief Fund money has not been diverted to other, non-disaster related efforts."

Read more of this story at Slashdot.

Categories: Computer, News

Chinese Hack of US ISPs Show Why Apple Is Right About Backdoors

Slashdot - Thu, 2024-10-10 12:00
Alypius shares a report from 9to5Mac: It was revealed this weekend that Chinese hackers managed to access systems run by three of the largest internet service providers (ISPs) in the US. What's notable about the attack is that it compromised security backdoors deliberately created to allow for wiretaps by US law enforcement. [...] Apple famously refused the FBI's request to create a backdoor into iPhones to help access devices used by shooters in San Bernardino and Pensacola. The FBI was subsequently successful in accessing all the iPhones concerned without the assistance it sought. Our arguments against such backdoors predate both cases, when Apple spoke out on the issue in the wake of terrorist attacks in Paris more than a decade ago: "Apple is absolutely right to say that the moment you build in a backdoor for use by governments, it will only be a matter of time before hackers figure it out. You cannot have an encryption system which is only a little bit insecure any more than you can be a little bit pregnant. Encryption systems are either secure or they're not -- and if they're not then it's a question of when, rather than if, others are able to exploit the vulnerability." This latest case perfectly illustrates the point. The law required ISPs to create backdoors that could be used for wiretaps by US law enforcement, and hackers have now found and accessed them. Exactly the same would be true if Apple created backdoors into iPhones.

Read more of this story at Slashdot.

Categories: Computer, News

Rises In Life Expectancy Have Slowed Dramatically, Analysis Finds

Slashdot - Thu, 2024-10-10 09:00
The rapid increases in life expectancy seen in the 20th century have slowed significantly, according to a new analysis published in the journal Nature. The Guardian reports: According to the study, children born recently in regions with the oldest people are far from likely to become centenarians. At best, the researchers predict 15% of females and 5% of males in the oldest-living areas will reach 100 this century. "If you're planning for retirement, it's probably not a good idea to assume you're going to make it to 100," said Jay Olshansky, professor of epidemiology and biostatistics at the University of Illinois at Chicago. "You'd probably have to work for at least 10 years longer than you'd think. And you want to enjoy the last phase of your life, you don't necessarily want to spend it working to save for time you're not going to experience." Advances in public health and medicine sparked a longevity revolution in the 20th century. In the previous 2,000 years, life expectancy crept up, on average, one year every century or two. In the 20th century, average life expectancy rocketed, with people gaining an extra three years every decade. For the latest study, Olshansky delved into national statistics from the US and nine regions with the highest life expectancies, focusing on 1990 to 2019, before the Covid pandemic struck. The data from Hong Kong, Japan, South Korea, Australia, France, Italy, Switzerland, Sweden, and Spain showed that rises in life expectancy had slowed dramatically. In the US, life expectancy fell [T]he researchers describe how on average, life expectancy in the longest-living regions rose only 6.5 years between 1990 and 2019. They predict that girls born recently in the regions have only a 5.3% chance of reaching 100 years old, while boys have a 1.8% chance. "In the modern era we have, through public health and medicine, manufactured decades of life that otherwise would not exist," Olshansky said. "These gains must slow down. The longevity game we're playing today is different to the longevity game we played a century ago when we were saving infants and children and women of child-bearing age and the gains in life expectancy were large. Now the gains are small because we're saving people in their 60s, 70s, 80s, and 90s." Olshansky said it would take radical new treatments that slow ageing, the greatest risk factor for many diseases, to achieve another longevity revolution. Research in the field is afoot with a dozen or so drugs shown to increase the lifespan of mice.

Read more of this story at Slashdot.

Categories: Computer, News

Google Identifies Low Noise 'Phase Transition' In Its Quantum Processor

Slashdot - Thu, 2024-10-10 05:30
An anonymous reader quotes a report from Ars Technica: Back in 2019, Google made waves by claiming it had achieved what has been called "quantum supremacy" -- the ability of a quantum computer to perform operations that would take a wildly impractical amount of time to simulate on standard computing hardware. That claim proved to be controversial, in that the operations were little more than a benchmark that involved getting the quantum computer to behave like a quantum computer; separately, improved ideas about how to perform the simulation on a supercomputer cut the time required down significantly. But Google is back with a new exploration of the benchmark, described in a paper published in Nature on Wednesday. It uses the benchmark to identify what it calls a phase transition in the performance of its quantum processor and uses it to identify conditions where the processor can operate with low noise. Taking advantage of that, they again show that, even giving classical hardware every potential advantage, it would take a supercomputer a dozen years to simulate things.

Read more of this story at Slashdot.

Categories: Computer, News

DIY Photographer Builds Full-Frame Camera, Open-Sources the Project

Slashdot - Thu, 2024-10-10 04:10
Boston-based engineer and photographer Wenting Zhang built his own full-frame camera and open-sourced the project on GitLab for anyone else to build upon. The camera, named Sitina S1, features a 10MP CCD sensor, custom electronics, and a 3D-printed body. Digital Photography Review reports: Zhang says he started the project in 2017, and it's not finished yet. "Engineers are usually bad at estimating how long things will take. I am probably particularly bad at that. I expected this project to be challenging, so it would take a bit longer, like probably one year. Turned out my estimation was off," he says. He makes clear to point out that this is a hobby project, purely for fun, and that his camera isn't going to achieve the level of image quality found in commercially available products from established companies. Despite that, his project provides a fascinating look into what's involved in building a camera from the ground up. Although CMOS has become the dominant sensor technology in consumer cameras, owing to factors like speed, lower power consumption and cost, Zhang's camera is built around a 10MP Kodak KAI-11000CM CCD sensor with a global electronic shutter, which he selected for a rather pragmatic reason: it was easy to source. "Most manufacturers (like Sony) aren't going to just sell a sensor to a random hobbyist, so I have to buy whatever is available on eBay. This 10MP CCD turned out to be available," he explains. The choice of sensor has a useful benefit. As he explains in one of his videos, designing and building a mechanical shutter is complicated and beyond his area of expertise, so his DIY design is based on using an electronic shutter. For similar reasons, he chose to use an LCD screen as a viewfinder rather than a prism-based optical design, resulting in a mirrorless camera. Zhang wanted his design to be compatible with existing lenses. His mirrorless design, with a short flange distance, provided a great deal of flexibility to adapt different lenses to the camera, and he's currently using E-mount with active electrical contacts. And that's just the start. Zhang also needed to integrate a CCD signal processor with an ADC (analog to digital converter), a CPU, battery, an LCD screen and buttons. He also designed and built his own circuit board with a power-only USB port, flash sync terminal, power button and SD card slot, and create the software and user interface to tie it all together. Finally, everything fits inside a 3D-printed enclosure that, to my eye, looks rather attractive.

Read more of this story at Slashdot.

Categories: Computer, News

Kim Dotcom Fends Off Arrest Before Conspiracy Theories and Reality Collide

Slashdot - Thu, 2024-10-10 03:30
TorrentFreak's Andy Maxwell reports: In August, New Zealand's Justice Minister authorized Kim Dotcom's immediate arrest and extradition. Dotcom's response to his followers on X was simple: "I'm not leaving." Another post mid-September -- "we are very close to disaster" -- led to Dotcom disappearing for three weeks. On his return, Dotcom said X had suspended his account, based on an extremely serious allegation. After accusing Elon Musk of failing to help, yesterday Dotcom warned that a Trump loss would see Musk indicted and "fighting for his life." Dotcom has a plan to avoid extradition; chaos like this provides the fuel. The details of Dotcom's "plan" to stay in New Zealand are yet to be revealed. Given Dotcom's history, exhausting the judiciary with every possible avenue of appeal is pretty much guaranteed, no matter how unlikely the prospects of success. At the same time, it's likely that Dotcom will use social media to preach to the existing choir. He will also try to appeal to those who loathe him, and those who merely hate him, by focusing on a common grievance. "People keep suggesting that I should leave this corrupt US colony like a fugitive on the run. Hell no," he told 1.7 million X followers recently. "Corrupt US colony" and the interchangeable "obedient" variant are clearly derogatory, catering to theories of joint complicity and sniveling weakness. This rhetoric has been visible on Dotcom's social media accounts for some time, but the main theme is Dotcom's belligerent, out-of-the-blue support for Russia's invasion of Ukraine. [...] Some people believe that Dotcom genuinely supports Russia and, with his quotes regularly appearing on state-run news channels, arguing otherwise is a pretty tough ask. A different assessment starts with the things Dotcom values most -- his family, his wealth, and his freedom -- and applies that to a reputation of doing whatever it takes to protect and maintain those three, non-negotiable aspects of his life. Right now, his best chance is to tilt the chess board via a change at the White House, and then carefully exploit a change in policy. Dotcom's colleagues took a plea deal from the U.S. and New Zealand that Dotcom insists he would never accept; certainly not if Biden was in power. A Donald Trump win, on the other hand, would introduce an administration Dotcom could be seen to negotiate with, on previously unthinkable terms, without losing face. Previous reluctance to admit any wrongdoing could suddenly seem trivial after the prevention of World War 3. [Since 2022, Dotcom supported narratives more closely aligned with those of the Kremlin, in particular the claim that United States policy is the root cause of the current conflict. The amplification of anti-Ukraine rumors in the United States, strategically links alleged U.S. policy failures to billions of dollars in military aid, all at taxpayers' expense. This toxic mix, Dotcom insists, heralds the collapse of the dollar, the dismantling of the "US Empire," and ultimately a global human catastrophe; World War 3, no holds barred.]

Read more of this story at Slashdot.

Categories: Computer, News

Turkey Blocks Discord

Slashdot - Thu, 2024-10-10 02:50
Turkey has blocked access to Discord after the messaging platform refused to share potentially illegal information with authorities. Reuters reports: Justice minister Yilmaz Tunc said an Ankara court decided to block access to Discord from Turkey due to sufficient suspicion that crimes of "child sexual abuse and obscenity" had been committed by some using the platform. The block comes after public outrage in Turkey caused by the murder of two women by a 19-year-old man in Istanbul this month. Content on social media showed Discord users subsequently praising the killing. Transport and infrastructure minister Abdulkadir Uraloglu said the nature of the Discord platform made it difficult for authorities to monitor and intervene when illegal or criminal content is shared. "Security personnel cannot go through the content. We can only intervene when users complain to us about content shared there," he told reporters in parliament. "Since Discord refuses to share its own information, including IP addresses and content, with our security units, we were forced to block access." Russia also recently blocked Discord for violating Russian law, after previously fining the company for failing to remove banned content.

Read more of this story at Slashdot.

Categories: Computer, News

Open-Source AI Definition Finally Gets Its First Release Candidate

Slashdot - Thu, 2024-10-10 02:10
An anonymous reader quotes a report from ZDNet: Getting open-source and artificial intelligence (AI) on the same page isn't easy. Just ask the Open Source Initiative (OSI). The OSI, the open-source definition steward organization, has been working on creating an open-source artificial intelligence definition for two years now. The group has been making progress, though. Its Open Source AI Definition has now released its first release candidate, RC1. The latest definition aims to clarify the often contentious discussions surrounding open-source AI. It specifies four fundamental freedoms that an AI system must grant to be considered open source: the ability to use the system for any purpose without permission, to study how it works, to modify it for any purpose, and to share it with or without modifications. So far, so good. However, the OSI has opted for a compromise regarding training data. Recognizing it's not easy to share full datasets, the current definition requires "sufficiently detailed information about the data used to train the system" rather than the full dataset itself. This approach aims to balance transparency with practical and legal considerations. That last phrase is proving difficult for some people to swallow. From their perspective, if all the data isn't open, then AI large language models (LLM) based on such data can't be open-source. The OSI summarized these arguments as follows: "Some people believe that full, unfettered access to all training data (with no distinction of its kind) is paramount, arguing that anything less would compromise full reproducibility of AI systems, transparency, and security. This approach would relegate Open-Source AI to a niche of AI trainable only on open data." The OSI acknowledges that the definition of open-source AI isn't final and may need significant rewrites, but the focus is now on fixing bugs and improving documentation. The final version of the Open Source AI Definition is scheduled for release at the All Things Open conference on October 28, 2024.

Read more of this story at Slashdot.

Categories: Computer, News

OpenBSD 7.6 Released

Slashdot - Thu, 2024-10-10 01:30
Phoronix's Michael Larabel reports: OpenBSD 7.6 is out this evening as another major step forward for this BSD operating system with enhanced hardware support, security improvements, updating various user-space software, and enabling other kernel enhancements. There are a ton of changes to find with the just-released OpenBSD 7.6. Some of the new OpenBSD 7.6 features include: - OpenBSD 7.6 provides initial support for Qualcomm Snapdragon X1 Elite (X1E80100) SoCs. The 7.6 release also has initial Samsung Galaxy Book4 Edge boot support in ACPI mode with OpenBSD 7.6. - ARM64 has additional CPU security mitigations with Spectre-V4 now in place on ARM64 and adding Spectre-BHB for Cortex-A57 cores. - OpenBSD 7.6 on RISC-V now supports the Milk-V Pioneer board. - OpenBSD 7.6 on AMD64 has finally implemented support for AVX-512. - Various SMP kernel improvements. You can view the full list of features and download the OpenBSD 7.6 release via OpenBSD.org.

Read more of this story at Slashdot.

Categories: Computer, News

Internet Archive Suffers 'Catastrophic' Breach Impacting 31 Million Users

Slashdot - Thu, 2024-10-10 00:50
BleepingComputer's Lawrence Abrams: Internet Archive's "The Wayback Machine" has suffered a data breach after a threat actor compromised the website and stole a user authentication database containing 31 million unique records. News of the breach began circulating Wednesday afternoon after visitors to archive.org began seeing a JavaScript alert created by the hacker, stating that the Internet Archive was breached. "Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!," reads a JavaScript alert shown on the compromised archive.org site. The text "HIBP" refers to is the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service. Hunt told BleepingComputer that the threat actor shared the Internet Archive's authentication database nine days ago and it is a 6.4GB SQL file named "ia_users.sql." The database contains authentication information for registered members, including their email addresses, screen names, password change timestamps, Bcrypt-hashed passwords, and other internal data. Hunt says there are 31 million unique email addresses in the database, with many subscribed to the HIBP data breach notification service. The data will soon be added to HIBP, allowing users to enter their email and confirm if their data was exposed in this breach.

Read more of this story at Slashdot.

Categories: Computer, News

Pages