The FBI sleeps when libraries burn
This person could be damaging corporate infrastructure but he goes after internet archive
I mean this person seems to be not doing it maliciously. As they say, if it wasn’t them, it would be someone else. Pushing archive to improve their security is great for everyone. As long as this person doesn’t do anything actually malicious, they’re in the clear as far as I’m concerned.
This guy is outing the archive for terrible security posture by bringing attention to it because they received disclosures and did not fix them.
Don’t get shit twisted - he’s the hero here. IA fucked up and has been vulnerable to manipulation by any number of corporate or national actors this entire time.
If they were really “the hero”, they’d follow the bare minimum of responsible disclosure best practices, and allow 90 days between privately alerting them of the issue and going public with it. Two weeks is absurd.
You don’t leak a passwords database publicly on the Internet in good faith.