139
Internet Archive Was Exposing User Email Addresses for Years Before Recent Breach
(theintercept.com)
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
Someone feel free to jump in and audit my take:
The Internet Archive is not a company, does not sell me anything, and is merely providing a public service.
The service has nothing to do with my health or wellbeing. It is not marketed as being privacy forward. Hell, the whole purpose of the project is to make data publically accessable.
Therefore, exposing email addresses... I kinda don't care?
Of course, it would be way better if they just used generic login numbers etc instead, but... I feel like this is the equivalent of my library card number getting leaked, and these headlines are treating it like Equifax just leaked my SSN again.
This article isnt about how emails associated with logins got released in a breach, but that documents that are uploaded to the archive are stamped with the email address of the account that uploaded it and that can be viewed by anyone who downloads the document.
So in standard, everyday use of the site, email addresses are being revealed and are associated with the actions of that person. Like if I upload a copy of the manual for my washing machine or something, which is a more benign example, my email is linked to that document now.
Then combine this with (1) the internet archive says in multiple spots that they dont reveal this info anywhere, and (2) the issue has been raised to the organization, and it becomes more of a specific negligence from them.