[HN Gopher] The British Library URL has been offline due to cybe...
___________________________________________________________________
The British Library URL has been offline due to cyberattack for 10
days
Author : sph
Score : 164 points
Date : 2023-12-18 12:10 UTC (10 hours ago)
(HTM) web link (www.bl.uk)
(TXT) w3m dump (www.bl.uk)
| The-Old-Hacker wrote:
| Broken link. Should be https://www.bl.uk.
| sph wrote:
| Yeah the mod has edited the title and added another slash
| (https://www.bl.uk//) which now shows a blank page.
| willhackett wrote:
| Is there anything we can do to help?
| donbox wrote:
| Oh well, that is sad. Toronto Public Library's online services
| are still down since at least a month.
| pards wrote:
| The Toronto Public Library got hit with ransomware, but they
| obviously can't afford to pay.
|
| It's awful. TPL is one of the best library networks in North
| America, providing a vast array of valuable services to the
| people of Toronto.
|
| It should be considered an essential service given how many
| underprivileged people depend on its services.
| 5040 wrote:
| >vast array of valuable services
|
| I'd argue that this is how libraries get into this mess.
| Instead of specializing, they adopt a scattershot approach to
| services, many of which aren't even related to taking care of
| library materials. Flashy pet projects get prioritized while
| less interesting things like books or computer systems
| languish.
| that_guy_iain wrote:
| Looks like they got hacked and just shut down their web system
| while they rebuild a secure env/system.
| unwind wrote:
| Meta: the URL is not offline, the (web) service associated with
| it is. The title would be better with "URL" deleted, in my
| opinion.
|
| I hope they resolve the attack issues, that's of courses
| incredibly crappy and I feel sorry for them. :(
| wahnfrieden wrote:
| That's what a url being offline means and is understood to mean
|
| The store is closed vs that store location is closed. Same
| thing
| WendyTheWillow wrote:
| Colloquially perhaps, but it is wrong from a technological
| perspective, and IMO that matters.
| phyzome wrote:
| The URL https://www.bl.uk/ is working fine, but the site is
| busted.
| Retr0id wrote:
| It returns a resource but I wouldn't say it's working.
| netsharc wrote:
| Sounds like a middle manager adding technical terms to sound
| more... technical.
| xanderlewis wrote:
| It's wrong as interpreted literally, but I'm not sure of a
| better way to concisely express it. Deleting _URL_ seems to
| just make it more ambiguous.
| roelschroeven wrote:
| "The British Library website has been offline due to
| cyberattack for 10 days" feels more natural to me.
| jamesholden wrote:
| Man if only people had access to a large online free global
| library.
| throwup238 wrote:
| You could call it the "genesis library" or GenLib for short
| xnyan wrote:
| Wow, libraries general! We can call it libgen for short.
| reedjosh wrote:
| I love you guys!
| tivert wrote:
| Wouldn't help. You might as well say people could use
| Wikipedia and Wikibooks.
|
| A big reason people go to libraries like the British
| Library is for collections of rare books an manuscripts
| (https://www.publicbooks.org/how-to-lose-a-library/), which
| you're not going to find on some pirate site that scraped
| the (relatively) low-hanging fruit of digitally-distributed
| academic papers and ebooks.
|
| You might as well say "Man if only people would spend the
| billions of dollars to digitize every scrap of archival
| paper in the world, and put it online for free."
| pstuart wrote:
| TIL. Thank you!
| criddell wrote:
| An unfortunate number of people would only be able to access
| that global library using the computers at their local library.
| blexx wrote:
| The www.bl.uk website currently reads:
|
| > _Temporary holding page_
|
| > _Our website is currently unavailable_
|
| > _Last updated: 5pm on Friday, 8 December 2023._
|
| > _We 're experiencing a major technology outage following a
| cyber-attack affecting our website, online systems and services,
| and some onsite services. However, our buildings are still open
| as usual. We anticipate restoring more services in the next few
| weeks, but disruption to certain services is now expected to
| persist for several months._
|
| > _Last week the attackers released some of our data onto the
| dark web including some personal user information. We 've
| contacted our users to alert them to this incident and to offer
| advice from the National Cyber Security Centre (NCSC) on how to
| protect themselves, including updating their passwords on other
| systems._
|
| > _Because our systems are still unavailable, you can 't change
| the password for our services. However, if you use the same
| password for non-British Library services, we recommend that you
| change it as a precaution._
|
| > _NCSC provides guidance on staying secure online, including how
| to create a strong password, and specific guidance for
| individuals who may have been impacted by a data breach._
|
| > _Analysing the data is likely to take several months. Should we
| find specific information has been compromised, we will alert
| anyone affected as soon as we can. We are continuing to
| collaborate with the Metropolitan Police and professional
| cybersecurity advisors, and are receiving support from the NCSC._
|
| > _We 're really sorry for the ongoing disruption to our systems
| and services and we'll provide further updates when we can._
|
| > _What is currently available?_
|
| > _The Library 's buildings are open, but some services are
| limited, including access to collection items. We're regularly
| updating our blog with the latest information on what's currently
| available online and onsite so please check this before you
| visit._
|
| > _If you have purchased tickets for our exhibition, Fantasy:
| Realms of Imagination, you can still use them. Exhibition tickets
| can also be booked via See Tickets. Our free exhibition, Malorie
| Blackman: The Power of Stories, is open and no booking is
| required._
|
| > _All upcoming public events are going ahead as planned and you
| can find more information on our events blog update. We 're
| continuing to welcome schools and families too, as well as adult
| learners to our courses._
|
| > _Business & IP Centre (BIPC) in St Pancras is open to support
| businesses as usual but digital services onsite are unavailable.
| You can also join BIPC events and webinars and access one-to-one
| support. Read our BIPC blog update to find out what help and
| advice we can offer during this time._
|
| > _Contacting us_
|
| > _While our systems are offline, you can contact us by emailing
| customer@bl.uk We 'll do our best to answer your queries but
| please bear with us. This inbox is reviewed between 08.30 to
| 16.30 Monday to Friday. We're experiencing a high volume of
| enquiries so it may take us some time to respond. We'll get back
| to you as quickly as we can._
|
| > _Thank you for your patience and understanding._
| ta1243 wrote:
| Its been out since October
|
| https://www.theguardian.com/books/2023/oct/31/british-librar...
|
| And affecting far more than their public website - including
| everything from personnel records to payments to authors
|
| https://www.thetimes.co.uk/article/7f2b670a-f52a-4f88-b6d4-d...
| asicsp wrote:
| And multiple discussions here too (https://hn.algolia.com/?date
| Range=pastYear&page=0&prefix=fal...):
|
| * https://news.ycombinator.com/item?id=38356768
|
| * https://news.ycombinator.com/item?id=38430831
| wrycoder wrote:
| Extensive input from the BPL blog 15Dec:
|
| https://blogs.bl.uk/living-knowledge/2023/12/knowledge-under...
|
| Edit: They were legally forbidden to pay the PS600,000 ransom.
| 8372049 wrote:
| > They were legally forbidden to pay the PS600,000 ransom.
|
| That should have been the case for all ransoms everywhere.
| Obscurity4340 wrote:
| Y do you think thats NOT the case? Is it a Chernobyl type
| situation or is there something else I'm missing (lack of
| technical literacy or refusal to hire appropos consultantz
| in the public interest?)
| carstenhag wrote:
| Hospitals have been attacked and lives have been at risk
| (or people died, pretty sure there are articles on this)
| - paying a ransom could be okayish in this case.
| tensor wrote:
| The Toronto (Canada) public library has been out since October
| due to a cyberattack. Maybe they went on a library attack
| spree. Awful.
| btrettel wrote:
| Related:
|
| _How to Lose a Library_ -
| https://news.ycombinator.com/item?id=38657830 - Dec 2023 (21
| comments)
| maxehmookau wrote:
| The heritage, museum and library sectors in the UK are badly
| paid, even for technology and IT staff.
|
| Frankly, I suspect that the British Library is reaping the result
| of decades of underfunding and under-preparing for such an
| eventuality despite quite clearly being a target.
| flumpcakes wrote:
| IT workers had a PS4k uplift to every band compared to all
| other staff in the heritage sector from my experience, and that
| was specifically because you can get more money working
| elsewhere. They're paid "normal" salaries, if look at salary
| distributions of the UK as a whole.
|
| IT/technology is just abnormally overpaid as a whole. I'm not
| saying it shouldn't be, just that it is.
| maxehmookau wrote:
| I don't doubt you, but it clearly wasn't enough of an
| investment in cybersecurity for the UK's flagship, national
| library to be knocked offline for months with no end in
| sight.
|
| This is less about the pay of any individual working there,
| but a culture of underinvestment which the UK public sector
| has been undergoing for the past 15 years.
| zerkten wrote:
| >> culture of underinvestment which the UK public sector
| has been undergoing for the past 15 years.
|
| It's going on for much longer than that. It's hard to think
| of a time when there was investment. It's also hard to
| think of a time when the individuals and teams who could
| have prevented this would be given the respect that they
| deserve. This is a problem in the UK that extends beyond
| the UK public sector because a lot of the management in
| large organisations has some cultural similarities.
| okeuro49 wrote:
| > IT/technology is just abnormally overpaid as a whole.
|
| In the UK, IT/technology is arguably underpaid, compared to
| the value it generates. Just remember the TSB IT meltdown
| last year.
| (https://www.theguardian.com/business/2022/dec/20/tsb-bank-
| fi...)
|
| The average salary for a solicitor is ~PS70,000
|
| https://www.checkasalary.co.uk/salaries/solicitor
|
| The average salary for IT is ~PS50,000
|
| https://www.checkasalary.co.uk/salaries/information-
| technolo...
|
| For a software engineer ~PS60,000.
|
| https://www.checkasalary.co.uk/salaries/software-engineer
| Lio wrote:
| > _" abnormally"_
|
| There is no such thing as a _normal_ salary. People are paid
| what the market demands.
|
| We're not serfs. If one job offers more compensation than
| another everyone is entitled to leave and go elsewhere.
| bee_rider wrote:
| It looks like they defined what they meant by "normally"
| elsewhere in their comment. Why edit them down to one word?
| Seems like that is bound to lose important context.
| zerkten wrote:
| As a UK citizen living overseas, I would put problems like this
| down to more than just underfunding. One of these is the
| frequent challenge with "talkers" versus "doers" and the wrong
| people being promoted within the bureaucracy.
|
| This is especially the case in government orgs and those close
| to them which are old and extremely bureaucratic. There are
| many good people in these organisations who should be paid more
| in many cases, but they are severely limited by the system.
|
| I find it hard to see that this wasn't something expected by
| many in the know at multiple levels within the British Library.
| Now it's an even bigger mess that they are ill-equipped to
| respond to.
| mdcurran wrote:
| I visit the British Library often. It's a great place to work if
| no meetings are on your schedule that day. The library has been
| noticeably quieter the past few weeks. Perhaps it's the time of
| year, but many individuals use the library for researching family
| histories or accessing esoteric items in the catalogue. I hope
| this is resolved soon. Public libraries are a really wonderful
| utility.
| huytersd wrote:
| I love libraries. The only other quiet public place I can think
| of is churches and working your remote job from churches is
| frowned upon.
|
| Now that I mention it, churches should totally host remote
| working spots.
| Moru wrote:
| Speaking of Churches, the Swedish Church [1] is currently
| also down for similar reasons.
|
| [1] https://www.svt.se/nyheter/lokalt/dalarna/svenska-kyrkan-
| bek...
| donohoe wrote:
| The URL for this post is incorrect and has a double-slash.
|
| It should be:
|
| https://www.bl.uk/
|
| and not:
|
| https://www.bl.uk//
| seagullriffic wrote:
| Can anyone explain why this happens?
|
| Why would they pay ransomware hackers when they would obviously
| have backups. Sucks to have data compromised, but presumably it's
| not lost. And what part of the system was designed to bad
| practices that this was able to happen? Aren't there lots of UK
| white-hats who would freely lend their services to help improve
| the library's infrastructure?
|
| Presumably excluding attacks of this sort isn't arcane or
| impossible, because other major companies and orgs manage it. Is
| it secret knowledge, or something?
|
| Surely there's a SOP to just not have this happen.
| Pxtl wrote:
| I assume they lost something that's timely, like a
| transactional DB, where the "backup" would mean accepting the
| loss of some important transactions.
| amelius wrote:
| Maybe the attackers encrypted the data, and those encrypted
| files were backed up, maybe even overwriting older backups?
| gurchik wrote:
| > Why would they pay ransomware hackers when they would
| obviously have backups. Sucks to have data compromised, but
| presumably it's not lost.
|
| It's been more than a month. I think if it was this easy, they
| would be online by now. They said on their blog they will only
| begin to restore some functionality in January. A business
| could consider paying the random to avoid two months of
| downtime. Although in this case they didn't have the option to
| pay it.
| DharmaPolice wrote:
| I wouldn't necessarily assume they do have backups. At least,
| not recent backups of 100% of their content/systems.
| dazc wrote:
| They have back-ups but they are mostly not digital back-ups.
| krisoft wrote:
| > Aren't there lots of UK white-hats who would freely lend
| their services to help improve the library's infrastructure?
|
| You mean freely as in for no compensation? This is a massive
| public body. Do they pay the people who bolt together the
| shelves the books sit on? I believe they do. Then they should
| pay the people who audits their security posture too.
|
| > Is it secret knowledge, or something?
|
| Mismanagement and incompetence if you ask me.
| jen20 wrote:
| Indeed so - though not only of the library. Government in
| general is limited in pay bands that do not even begin to
| compare to private industry, so it relies on people who are
| altruistic if they're any good.
| toyg wrote:
| The amount of skilled altruistic It professionals is
| vanishingly tiny.
|
| The amount of not-very-good IT professionals, on the other
| hand...
| 15457345234 wrote:
| > The amount of skilled altruistic It professionals is
| vanishingly tiny.
|
| That's completely untrue. The IT industry is full of
| altruistic individuals, in fact almost the entire open
| source movement proves you wrong.
|
| What's relatively unusual is this new crop of 'all that
| matters is TC' types who view the industry as a means to
| get loaded and who do not, in any way shape or form,
| embody the hacker ethos and the mentality of putting
| something out there for the public good because that's
| just the type of person they are.
|
| The industry has been taken over by utterly despicable
| greedheads and that's why so much of it has become the
| way it is, unfortunately.
| crazygringo wrote:
| I know other institutions have paid ransoms rather than go to
| backups, because they had never planned for an org-wide restore
| which would take _months_ to execute.
|
| Turns out there's a huge difference between restoring the
| occasional system, and restoring _everything_.
|
| I'm not sure to what extent backup systems are being upgraded
| to work faster, how easy that even is, or whether it's more
| cost effective actually to pay the occasional ransom.
| adulau wrote:
| The ransomware group posted some evidences ->
| https://www.ransomlook.io/screenshots/rhysida/British%20Libr...
|
| and the ransomware group details ->
| https://www.ransomlook.io/group/rhysida
| rthkljlkrj wrote:
| Isn't it ironic that a _library_ of all places completely melts
| down when you damage their computers? It 's not like a hospital
| for example who could reasonably argue "of course if you manage
| my systems my business melts down, it's not like managing paper
| records is part of my core expertise, I'm busy with other
| things".
| dotnet00 wrote:
| The other way to look at it is that a library can afford the
| trouble, as no one is likely to be at immediate risk of death
| if their computers go down.
|
| A hospital has no choice but to be more resilient, since many
| other emergencies they would be most needed in (eg natural
| disasters) can also involve loss of access to computer systems.
| rthkljlkrj wrote:
| Of course, I wasn't making an argument that we should make
| hospitals more fragile...
| hardlianotion wrote:
| Meanwhile, the Ministry of Justice proposes a destructive
| digitisation of its archive of a couple of centuries worth of
| wills.
|
| https://twitter.com/MoJGovUK/status/1735642204809351595
| firtoz wrote:
| Decentralised storage could be pretty cool for this, no?
| Sirizarry wrote:
| Not if it's destructive. Not entirely sure what the procedure
| is to digitize them but if the original is lost in the
| process, no amount of digital decentralization will help that
| and there are plenty of good arguments against relying on
| digital storage solutions for long term data storage. They're
| just not long term enough (yet)
| space_fountain wrote:
| Idk, it's likely very expensive to maintain the physical
| copies. It's easy to say that the government should just do
| everything, but spending money to maintain an archive that
| probably is very rarely used isn't a good use of limited
| money. Digital copies aren't always infinitely durable, but
| they can be copied exactly which is something that can't be
| done with paper and honestly I'd guess more durable than a
| paper archive with a the same amount of money being spent
| jart wrote:
| In order to make digital data durable, you have to store
| it on cassette tape. This has the same issue as physical
| stuff in the sense that you have to wait for it to be
| recalled before you can access its data, which is why
| tape is normally only used for backup. So they'd have to
| have two digital copies, paying twice the price, one for
| prod and one for backup. At this point when it comes to
| managing that, we've already exceeded the ops
| competencies of most tech industry teams, let alone a
| homeless shelter. They're really much better off just
| leaving the wills as they are.
| cbsmith wrote:
| Yeah, but even three copies of stuff digitally is cheaper
| to maintain because we can back the data so much denser,
| and replicating it to newer media is so much faster.
| 15457345234 wrote:
| > Idk, it's likely very expensive to maintain the
| physical copies.
|
| Maintaining a large paper archive is almost free in the
| grand scheme of things. The UK (and pretty much every
| single other Western nation) has an absolute ton of
| abandoned bunkers, silos and mines that were intended for
| Cold War disaster management. Most of them were built to
| very high standards in locations that won't flood or
| degrade significantly even if left cold and dark.
|
| Using them for archive storage is trivial.
|
| This seems like a very poor decision. We're seeing
| vulnerability after vulnerability pour in this year in
| just about every single OS out there and yet they think
| something like this is a good idea?
|
| The UK government appears to be trying to shut the
| country down without anybody noticing until it's too
| late; it's very weird to watch.
| geraldwhen wrote:
| Paper will be destroyed, eventually, in the presence of
| incorrect humidity levels. It's just a matter of when.
| gorgoiler wrote:
| [delayed]
| ballooney wrote:
| no!
| timthorn wrote:
| So please respond to the consultation:
| https://www.gov.uk/government/consultations/storage-and-rete...
| crazygringo wrote:
| Can you clarify what is destructive?
|
| Is there a reason the originals need to be kept, like for some
| kind of chemical analysis?
|
| Or should descendants be allowed to claim them, and the rest
| auctioned off?
|
| Especially for something as generally mundane as wills, it's
| not obvious to me why high-resolution scans don't suffice for
| all future historical, legal, and archival purposes.
| hardlianotion wrote:
| From the site explaining what is to be done:
|
| "Currently about 110 million physical documents are stored
| costing taxpayers PS4.5 million per year. The consultation is
| seeking views on keeping hard copies for about 25 years, in
| recognition of their sentimental value to families, while
| saving them digitally longer term."
|
| https://www.gov.uk/government/news/easier-access-to-
| historic...
| lo_zamoyski wrote:
| Even in a restricted context (the apparent documented
| information), hard copies have advantages over digital copies
| under two considerations.
|
| First, they survive technological obsolescence. Consider how
| even reading a floppy disk is a huge pain in the ass for most
| people today. Now stretch the time frame.
|
| (Some might say that all you need to do is copy the contents
| to a new medium when upgrading. Sure, you can do that, but it
| has a migration cost, and perhaps some risk. It's not a
| freebie. Compare that to keeping around hard copies.)
|
| Second, they have historically been less ephemeral. Sure, we
| have durable, write-once media out there that manufacturers
| claim will last thousands of years (we'll see in...thousands
| of years), but that's rare.
|
| For important stuff, you should a) keep the hard copy, b)
| make a digital copy, and c) create backups. You have the
| option of migrating or reinjesting the original source
| material, at least.
| dogweather wrote:
| Are attacks like this--ransomware--always aimed at Windows-based
| systems? Is that the common denominator?
|
| I've noticed that most Internet attacks are Windows-based but
| somehow "Microsoft" or "Windows" never makes it into the news
| copy. I've wondered if MS has a massive marketing/legal outreach
| to make sure that doesn't happen. And to make it sound like "this
| can happen anywhere", and "no computer is 100% attack-proof".
| adolph wrote:
| Netcraft indicates Linux or unknown previous to the incident
| for www and bl.uk:
|
| https://sitereport.netcraft.com/?url=http://www.bl.uk
| Hosting History Netblock owner IP address OS Web
| server Last seen Microsoft Corporation One Microsoft Way
| Redmond WA US 98052 13.107.213.64 Linux unknown 26-Nov-2023
| Microsoft Corporation One Microsoft Way Redmond WA US 98052
| 13.107.246.64 Linux unknown 25-Nov-2023 British Library
| 194.66.233.215 Linux unknown 20-Jul-2023 British Library
| 194.66.233.215 Linux nginx 15-May-2019 British Library
| 194.66.233.215 unknown nginx 5-Jul-2016 British Library
| 194.66.233.215 Linux nginx 4-Jul-2016 British Library
| 194.66.233.215 unknown nginx 26-Jun-2016 British Library
| 194.66.233.215 Linux nginx 21-Jun-2016 British Library
| 194.66.233.215 unknown nginx 17-Jun-2016 British Library
| 194.66.233.215 Linux Apache 17-Jan-2016
| Moru wrote:
| Does not have to be what they are running their servers on.
| ahi wrote:
| This is bait, but I'll bite. From what I've seen, the common
| denominator is misconfiguration. We can all do it, but it seems
| especially concentrated in organizations with limited IT human
| resources largely dependent upon contracted service providers.
| Spend a butt load on systems and hope Bill in IT doesn't screw
| it up. A lot of that ecosystem happens to be Windows based.
| gosub100 wrote:
| This is a great observation. What if, back in the Ford Explorer
| Firestone tire explosion scandal, they said "SUVs are being
| recalled because tires are exploding". Makes the article much
| less informative.
| wongarsu wrote:
| To me the share of Windows as ransomware target seems
| proportional to Window's use in office computers in large and
| medium enterprises.
| emmender2 wrote:
| attack the incentives...
|
| have dedicated govt agencies going after the crypto money trail,
| and disrupt the theives. this happened in the pipeline hack.
|
| otherwise, the thieves will continue thieving with nothing to
| stop them.
|
| thats why we have the police and other such agencies in the real
| world.
|
| when thieves go after the commons (libraries/hospitals) - we the
| public taxpayers have every incentive to demand action of our
| govt as there is nobody else who can help here.
|
| why are the british taxpayers not demanding action ?
| toyg wrote:
| Demanding from whom? The current government could not cook an
| egg.
___________________________________________________________________
(page generated 2023-12-18 23:00 UTC)