[HN Gopher] The British Library URL has been offline due to cybe...
       ___________________________________________________________________
        
       The British Library URL has been offline due to cyberattack for 10
       days
        
       Author : sph
       Score  : 164 points
       Date   : 2023-12-18 12:10 UTC (10 hours ago)
        
 (HTM) web link (www.bl.uk)
 (TXT) w3m dump (www.bl.uk)
        
       | The-Old-Hacker wrote:
       | Broken link. Should be https://www.bl.uk.
        
         | sph wrote:
         | Yeah the mod has edited the title and added another slash
         | (https://www.bl.uk//) which now shows a blank page.
        
       | willhackett wrote:
       | Is there anything we can do to help?
        
       | donbox wrote:
       | Oh well, that is sad. Toronto Public Library's online services
       | are still down since at least a month.
        
         | pards wrote:
         | The Toronto Public Library got hit with ransomware, but they
         | obviously can't afford to pay.
         | 
         | It's awful. TPL is one of the best library networks in North
         | America, providing a vast array of valuable services to the
         | people of Toronto.
         | 
         | It should be considered an essential service given how many
         | underprivileged people depend on its services.
        
           | 5040 wrote:
           | >vast array of valuable services
           | 
           | I'd argue that this is how libraries get into this mess.
           | Instead of specializing, they adopt a scattershot approach to
           | services, many of which aren't even related to taking care of
           | library materials. Flashy pet projects get prioritized while
           | less interesting things like books or computer systems
           | languish.
        
       | that_guy_iain wrote:
       | Looks like they got hacked and just shut down their web system
       | while they rebuild a secure env/system.
        
       | unwind wrote:
       | Meta: the URL is not offline, the (web) service associated with
       | it is. The title would be better with "URL" deleted, in my
       | opinion.
       | 
       | I hope they resolve the attack issues, that's of courses
       | incredibly crappy and I feel sorry for them. :(
        
         | wahnfrieden wrote:
         | That's what a url being offline means and is understood to mean
         | 
         | The store is closed vs that store location is closed. Same
         | thing
        
           | WendyTheWillow wrote:
           | Colloquially perhaps, but it is wrong from a technological
           | perspective, and IMO that matters.
        
           | phyzome wrote:
           | The URL https://www.bl.uk/ is working fine, but the site is
           | busted.
        
             | Retr0id wrote:
             | It returns a resource but I wouldn't say it's working.
        
           | netsharc wrote:
           | Sounds like a middle manager adding technical terms to sound
           | more... technical.
        
         | xanderlewis wrote:
         | It's wrong as interpreted literally, but I'm not sure of a
         | better way to concisely express it. Deleting _URL_ seems to
         | just make it more ambiguous.
        
           | roelschroeven wrote:
           | "The British Library website has been offline due to
           | cyberattack for 10 days" feels more natural to me.
        
       | jamesholden wrote:
       | Man if only people had access to a large online free global
       | library.
        
         | throwup238 wrote:
         | You could call it the "genesis library" or GenLib for short
        
           | xnyan wrote:
           | Wow, libraries general! We can call it libgen for short.
        
             | reedjosh wrote:
             | I love you guys!
        
             | tivert wrote:
             | Wouldn't help. You might as well say people could use
             | Wikipedia and Wikibooks.
             | 
             | A big reason people go to libraries like the British
             | Library is for collections of rare books an manuscripts
             | (https://www.publicbooks.org/how-to-lose-a-library/), which
             | you're not going to find on some pirate site that scraped
             | the (relatively) low-hanging fruit of digitally-distributed
             | academic papers and ebooks.
             | 
             | You might as well say "Man if only people would spend the
             | billions of dollars to digitize every scrap of archival
             | paper in the world, and put it online for free."
        
           | pstuart wrote:
           | TIL. Thank you!
        
         | criddell wrote:
         | An unfortunate number of people would only be able to access
         | that global library using the computers at their local library.
        
       | blexx wrote:
       | The www.bl.uk website currently reads:
       | 
       | > _Temporary holding page_
       | 
       | > _Our website is currently unavailable_
       | 
       | > _Last updated: 5pm on Friday, 8 December 2023._
       | 
       | > _We 're experiencing a major technology outage following a
       | cyber-attack affecting our website, online systems and services,
       | and some onsite services. However, our buildings are still open
       | as usual. We anticipate restoring more services in the next few
       | weeks, but disruption to certain services is now expected to
       | persist for several months._
       | 
       | > _Last week the attackers released some of our data onto the
       | dark web including some personal user information. We 've
       | contacted our users to alert them to this incident and to offer
       | advice from the National Cyber Security Centre (NCSC) on how to
       | protect themselves, including updating their passwords on other
       | systems._
       | 
       | > _Because our systems are still unavailable, you can 't change
       | the password for our services. However, if you use the same
       | password for non-British Library services, we recommend that you
       | change it as a precaution._
       | 
       | > _NCSC provides guidance on staying secure online, including how
       | to create a strong password, and specific guidance for
       | individuals who may have been impacted by a data breach._
       | 
       | > _Analysing the data is likely to take several months. Should we
       | find specific information has been compromised, we will alert
       | anyone affected as soon as we can. We are continuing to
       | collaborate with the Metropolitan Police and professional
       | cybersecurity advisors, and are receiving support from the NCSC._
       | 
       | > _We 're really sorry for the ongoing disruption to our systems
       | and services and we'll provide further updates when we can._
       | 
       | > _What is currently available?_
       | 
       | > _The Library 's buildings are open, but some services are
       | limited, including access to collection items. We're regularly
       | updating our blog with the latest information on what's currently
       | available online and onsite so please check this before you
       | visit._
       | 
       | > _If you have purchased tickets for our exhibition, Fantasy:
       | Realms of Imagination, you can still use them. Exhibition tickets
       | can also be booked via See Tickets. Our free exhibition, Malorie
       | Blackman: The Power of Stories, is open and no booking is
       | required._
       | 
       | > _All upcoming public events are going ahead as planned and you
       | can find more information on our events blog update. We 're
       | continuing to welcome schools and families too, as well as adult
       | learners to our courses._
       | 
       | > _Business & IP Centre (BIPC) in St Pancras is open to support
       | businesses as usual but digital services onsite are unavailable.
       | You can also join BIPC events and webinars and access one-to-one
       | support. Read our BIPC blog update to find out what help and
       | advice we can offer during this time._
       | 
       | > _Contacting us_
       | 
       | > _While our systems are offline, you can contact us by emailing
       | customer@bl.uk We 'll do our best to answer your queries but
       | please bear with us. This inbox is reviewed between 08.30 to
       | 16.30 Monday to Friday. We're experiencing a high volume of
       | enquiries so it may take us some time to respond. We'll get back
       | to you as quickly as we can._
       | 
       | > _Thank you for your patience and understanding._
        
       | ta1243 wrote:
       | Its been out since October
       | 
       | https://www.theguardian.com/books/2023/oct/31/british-librar...
       | 
       | And affecting far more than their public website - including
       | everything from personnel records to payments to authors
       | 
       | https://www.thetimes.co.uk/article/7f2b670a-f52a-4f88-b6d4-d...
        
         | asicsp wrote:
         | And multiple discussions here too (https://hn.algolia.com/?date
         | Range=pastYear&page=0&prefix=fal...):
         | 
         | * https://news.ycombinator.com/item?id=38356768
         | 
         | * https://news.ycombinator.com/item?id=38430831
        
         | wrycoder wrote:
         | Extensive input from the BPL blog 15Dec:
         | 
         | https://blogs.bl.uk/living-knowledge/2023/12/knowledge-under...
         | 
         | Edit: They were legally forbidden to pay the PS600,000 ransom.
        
           | 8372049 wrote:
           | > They were legally forbidden to pay the PS600,000 ransom.
           | 
           | That should have been the case for all ransoms everywhere.
        
             | Obscurity4340 wrote:
             | Y do you think thats NOT the case? Is it a Chernobyl type
             | situation or is there something else I'm missing (lack of
             | technical literacy or refusal to hire appropos consultantz
             | in the public interest?)
        
               | carstenhag wrote:
               | Hospitals have been attacked and lives have been at risk
               | (or people died, pretty sure there are articles on this)
               | - paying a ransom could be okayish in this case.
        
         | tensor wrote:
         | The Toronto (Canada) public library has been out since October
         | due to a cyberattack. Maybe they went on a library attack
         | spree. Awful.
        
       | btrettel wrote:
       | Related:
       | 
       |  _How to Lose a Library_ -
       | https://news.ycombinator.com/item?id=38657830 - Dec 2023 (21
       | comments)
        
       | maxehmookau wrote:
       | The heritage, museum and library sectors in the UK are badly
       | paid, even for technology and IT staff.
       | 
       | Frankly, I suspect that the British Library is reaping the result
       | of decades of underfunding and under-preparing for such an
       | eventuality despite quite clearly being a target.
        
         | flumpcakes wrote:
         | IT workers had a PS4k uplift to every band compared to all
         | other staff in the heritage sector from my experience, and that
         | was specifically because you can get more money working
         | elsewhere. They're paid "normal" salaries, if look at salary
         | distributions of the UK as a whole.
         | 
         | IT/technology is just abnormally overpaid as a whole. I'm not
         | saying it shouldn't be, just that it is.
        
           | maxehmookau wrote:
           | I don't doubt you, but it clearly wasn't enough of an
           | investment in cybersecurity for the UK's flagship, national
           | library to be knocked offline for months with no end in
           | sight.
           | 
           | This is less about the pay of any individual working there,
           | but a culture of underinvestment which the UK public sector
           | has been undergoing for the past 15 years.
        
             | zerkten wrote:
             | >> culture of underinvestment which the UK public sector
             | has been undergoing for the past 15 years.
             | 
             | It's going on for much longer than that. It's hard to think
             | of a time when there was investment. It's also hard to
             | think of a time when the individuals and teams who could
             | have prevented this would be given the respect that they
             | deserve. This is a problem in the UK that extends beyond
             | the UK public sector because a lot of the management in
             | large organisations has some cultural similarities.
        
           | okeuro49 wrote:
           | > IT/technology is just abnormally overpaid as a whole.
           | 
           | In the UK, IT/technology is arguably underpaid, compared to
           | the value it generates. Just remember the TSB IT meltdown
           | last year.
           | (https://www.theguardian.com/business/2022/dec/20/tsb-bank-
           | fi...)
           | 
           | The average salary for a solicitor is ~PS70,000
           | 
           | https://www.checkasalary.co.uk/salaries/solicitor
           | 
           | The average salary for IT is ~PS50,000
           | 
           | https://www.checkasalary.co.uk/salaries/information-
           | technolo...
           | 
           | For a software engineer ~PS60,000.
           | 
           | https://www.checkasalary.co.uk/salaries/software-engineer
        
           | Lio wrote:
           | > _" abnormally"_
           | 
           | There is no such thing as a _normal_ salary. People are paid
           | what the market demands.
           | 
           | We're not serfs. If one job offers more compensation than
           | another everyone is entitled to leave and go elsewhere.
        
             | bee_rider wrote:
             | It looks like they defined what they meant by "normally"
             | elsewhere in their comment. Why edit them down to one word?
             | Seems like that is bound to lose important context.
        
         | zerkten wrote:
         | As a UK citizen living overseas, I would put problems like this
         | down to more than just underfunding. One of these is the
         | frequent challenge with "talkers" versus "doers" and the wrong
         | people being promoted within the bureaucracy.
         | 
         | This is especially the case in government orgs and those close
         | to them which are old and extremely bureaucratic. There are
         | many good people in these organisations who should be paid more
         | in many cases, but they are severely limited by the system.
         | 
         | I find it hard to see that this wasn't something expected by
         | many in the know at multiple levels within the British Library.
         | Now it's an even bigger mess that they are ill-equipped to
         | respond to.
        
       | mdcurran wrote:
       | I visit the British Library often. It's a great place to work if
       | no meetings are on your schedule that day. The library has been
       | noticeably quieter the past few weeks. Perhaps it's the time of
       | year, but many individuals use the library for researching family
       | histories or accessing esoteric items in the catalogue. I hope
       | this is resolved soon. Public libraries are a really wonderful
       | utility.
        
         | huytersd wrote:
         | I love libraries. The only other quiet public place I can think
         | of is churches and working your remote job from churches is
         | frowned upon.
         | 
         | Now that I mention it, churches should totally host remote
         | working spots.
        
           | Moru wrote:
           | Speaking of Churches, the Swedish Church [1] is currently
           | also down for similar reasons.
           | 
           | [1] https://www.svt.se/nyheter/lokalt/dalarna/svenska-kyrkan-
           | bek...
        
       | donohoe wrote:
       | The URL for this post is incorrect and has a double-slash.
       | 
       | It should be:
       | 
       | https://www.bl.uk/
       | 
       | and not:
       | 
       | https://www.bl.uk//
        
       | seagullriffic wrote:
       | Can anyone explain why this happens?
       | 
       | Why would they pay ransomware hackers when they would obviously
       | have backups. Sucks to have data compromised, but presumably it's
       | not lost. And what part of the system was designed to bad
       | practices that this was able to happen? Aren't there lots of UK
       | white-hats who would freely lend their services to help improve
       | the library's infrastructure?
       | 
       | Presumably excluding attacks of this sort isn't arcane or
       | impossible, because other major companies and orgs manage it. Is
       | it secret knowledge, or something?
       | 
       | Surely there's a SOP to just not have this happen.
        
         | Pxtl wrote:
         | I assume they lost something that's timely, like a
         | transactional DB, where the "backup" would mean accepting the
         | loss of some important transactions.
        
         | amelius wrote:
         | Maybe the attackers encrypted the data, and those encrypted
         | files were backed up, maybe even overwriting older backups?
        
         | gurchik wrote:
         | > Why would they pay ransomware hackers when they would
         | obviously have backups. Sucks to have data compromised, but
         | presumably it's not lost.
         | 
         | It's been more than a month. I think if it was this easy, they
         | would be online by now. They said on their blog they will only
         | begin to restore some functionality in January. A business
         | could consider paying the random to avoid two months of
         | downtime. Although in this case they didn't have the option to
         | pay it.
        
         | DharmaPolice wrote:
         | I wouldn't necessarily assume they do have backups. At least,
         | not recent backups of 100% of their content/systems.
        
           | dazc wrote:
           | They have back-ups but they are mostly not digital back-ups.
        
         | krisoft wrote:
         | > Aren't there lots of UK white-hats who would freely lend
         | their services to help improve the library's infrastructure?
         | 
         | You mean freely as in for no compensation? This is a massive
         | public body. Do they pay the people who bolt together the
         | shelves the books sit on? I believe they do. Then they should
         | pay the people who audits their security posture too.
         | 
         | > Is it secret knowledge, or something?
         | 
         | Mismanagement and incompetence if you ask me.
        
           | jen20 wrote:
           | Indeed so - though not only of the library. Government in
           | general is limited in pay bands that do not even begin to
           | compare to private industry, so it relies on people who are
           | altruistic if they're any good.
        
             | toyg wrote:
             | The amount of skilled altruistic It professionals is
             | vanishingly tiny.
             | 
             | The amount of not-very-good IT professionals, on the other
             | hand...
        
               | 15457345234 wrote:
               | > The amount of skilled altruistic It professionals is
               | vanishingly tiny.
               | 
               | That's completely untrue. The IT industry is full of
               | altruistic individuals, in fact almost the entire open
               | source movement proves you wrong.
               | 
               | What's relatively unusual is this new crop of 'all that
               | matters is TC' types who view the industry as a means to
               | get loaded and who do not, in any way shape or form,
               | embody the hacker ethos and the mentality of putting
               | something out there for the public good because that's
               | just the type of person they are.
               | 
               | The industry has been taken over by utterly despicable
               | greedheads and that's why so much of it has become the
               | way it is, unfortunately.
        
         | crazygringo wrote:
         | I know other institutions have paid ransoms rather than go to
         | backups, because they had never planned for an org-wide restore
         | which would take _months_ to execute.
         | 
         | Turns out there's a huge difference between restoring the
         | occasional system, and restoring _everything_.
         | 
         | I'm not sure to what extent backup systems are being upgraded
         | to work faster, how easy that even is, or whether it's more
         | cost effective actually to pay the occasional ransom.
        
       | adulau wrote:
       | The ransomware group posted some evidences ->
       | https://www.ransomlook.io/screenshots/rhysida/British%20Libr...
       | 
       | and the ransomware group details ->
       | https://www.ransomlook.io/group/rhysida
        
       | rthkljlkrj wrote:
       | Isn't it ironic that a _library_ of all places completely melts
       | down when you damage their computers? It 's not like a hospital
       | for example who could reasonably argue "of course if you manage
       | my systems my business melts down, it's not like managing paper
       | records is part of my core expertise, I'm busy with other
       | things".
        
         | dotnet00 wrote:
         | The other way to look at it is that a library can afford the
         | trouble, as no one is likely to be at immediate risk of death
         | if their computers go down.
         | 
         | A hospital has no choice but to be more resilient, since many
         | other emergencies they would be most needed in (eg natural
         | disasters) can also involve loss of access to computer systems.
        
           | rthkljlkrj wrote:
           | Of course, I wasn't making an argument that we should make
           | hospitals more fragile...
        
       | hardlianotion wrote:
       | Meanwhile, the Ministry of Justice proposes a destructive
       | digitisation of its archive of a couple of centuries worth of
       | wills.
       | 
       | https://twitter.com/MoJGovUK/status/1735642204809351595
        
         | firtoz wrote:
         | Decentralised storage could be pretty cool for this, no?
        
           | Sirizarry wrote:
           | Not if it's destructive. Not entirely sure what the procedure
           | is to digitize them but if the original is lost in the
           | process, no amount of digital decentralization will help that
           | and there are plenty of good arguments against relying on
           | digital storage solutions for long term data storage. They're
           | just not long term enough (yet)
        
             | space_fountain wrote:
             | Idk, it's likely very expensive to maintain the physical
             | copies. It's easy to say that the government should just do
             | everything, but spending money to maintain an archive that
             | probably is very rarely used isn't a good use of limited
             | money. Digital copies aren't always infinitely durable, but
             | they can be copied exactly which is something that can't be
             | done with paper and honestly I'd guess more durable than a
             | paper archive with a the same amount of money being spent
        
               | jart wrote:
               | In order to make digital data durable, you have to store
               | it on cassette tape. This has the same issue as physical
               | stuff in the sense that you have to wait for it to be
               | recalled before you can access its data, which is why
               | tape is normally only used for backup. So they'd have to
               | have two digital copies, paying twice the price, one for
               | prod and one for backup. At this point when it comes to
               | managing that, we've already exceeded the ops
               | competencies of most tech industry teams, let alone a
               | homeless shelter. They're really much better off just
               | leaving the wills as they are.
        
               | cbsmith wrote:
               | Yeah, but even three copies of stuff digitally is cheaper
               | to maintain because we can back the data so much denser,
               | and replicating it to newer media is so much faster.
        
               | 15457345234 wrote:
               | > Idk, it's likely very expensive to maintain the
               | physical copies.
               | 
               | Maintaining a large paper archive is almost free in the
               | grand scheme of things. The UK (and pretty much every
               | single other Western nation) has an absolute ton of
               | abandoned bunkers, silos and mines that were intended for
               | Cold War disaster management. Most of them were built to
               | very high standards in locations that won't flood or
               | degrade significantly even if left cold and dark.
               | 
               | Using them for archive storage is trivial.
               | 
               | This seems like a very poor decision. We're seeing
               | vulnerability after vulnerability pour in this year in
               | just about every single OS out there and yet they think
               | something like this is a good idea?
               | 
               | The UK government appears to be trying to shut the
               | country down without anybody noticing until it's too
               | late; it's very weird to watch.
        
               | geraldwhen wrote:
               | Paper will be destroyed, eventually, in the presence of
               | incorrect humidity levels. It's just a matter of when.
        
               | gorgoiler wrote:
               | [delayed]
        
           | ballooney wrote:
           | no!
        
         | timthorn wrote:
         | So please respond to the consultation:
         | https://www.gov.uk/government/consultations/storage-and-rete...
        
         | crazygringo wrote:
         | Can you clarify what is destructive?
         | 
         | Is there a reason the originals need to be kept, like for some
         | kind of chemical analysis?
         | 
         | Or should descendants be allowed to claim them, and the rest
         | auctioned off?
         | 
         | Especially for something as generally mundane as wills, it's
         | not obvious to me why high-resolution scans don't suffice for
         | all future historical, legal, and archival purposes.
        
           | hardlianotion wrote:
           | From the site explaining what is to be done:
           | 
           | "Currently about 110 million physical documents are stored
           | costing taxpayers PS4.5 million per year. The consultation is
           | seeking views on keeping hard copies for about 25 years, in
           | recognition of their sentimental value to families, while
           | saving them digitally longer term."
           | 
           | https://www.gov.uk/government/news/easier-access-to-
           | historic...
        
           | lo_zamoyski wrote:
           | Even in a restricted context (the apparent documented
           | information), hard copies have advantages over digital copies
           | under two considerations.
           | 
           | First, they survive technological obsolescence. Consider how
           | even reading a floppy disk is a huge pain in the ass for most
           | people today. Now stretch the time frame.
           | 
           | (Some might say that all you need to do is copy the contents
           | to a new medium when upgrading. Sure, you can do that, but it
           | has a migration cost, and perhaps some risk. It's not a
           | freebie. Compare that to keeping around hard copies.)
           | 
           | Second, they have historically been less ephemeral. Sure, we
           | have durable, write-once media out there that manufacturers
           | claim will last thousands of years (we'll see in...thousands
           | of years), but that's rare.
           | 
           | For important stuff, you should a) keep the hard copy, b)
           | make a digital copy, and c) create backups. You have the
           | option of migrating or reinjesting the original source
           | material, at least.
        
       | dogweather wrote:
       | Are attacks like this--ransomware--always aimed at Windows-based
       | systems? Is that the common denominator?
       | 
       | I've noticed that most Internet attacks are Windows-based but
       | somehow "Microsoft" or "Windows" never makes it into the news
       | copy. I've wondered if MS has a massive marketing/legal outreach
       | to make sure that doesn't happen. And to make it sound like "this
       | can happen anywhere", and "no computer is 100% attack-proof".
        
         | adolph wrote:
         | Netcraft indicates Linux or unknown previous to the incident
         | for www and bl.uk:
         | 
         | https://sitereport.netcraft.com/?url=http://www.bl.uk
         | Hosting History                Netblock owner IP address OS Web
         | server Last seen       Microsoft Corporation One Microsoft Way
         | Redmond WA US 98052 13.107.213.64 Linux unknown 26-Nov-2023
         | Microsoft Corporation One Microsoft Way Redmond WA US 98052
         | 13.107.246.64 Linux unknown 25-Nov-2023       British Library
         | 194.66.233.215 Linux unknown 20-Jul-2023       British Library
         | 194.66.233.215 Linux nginx 15-May-2019       British Library
         | 194.66.233.215 unknown nginx 5-Jul-2016       British Library
         | 194.66.233.215 Linux nginx 4-Jul-2016       British Library
         | 194.66.233.215 unknown nginx 26-Jun-2016       British Library
         | 194.66.233.215 Linux nginx 21-Jun-2016       British Library
         | 194.66.233.215 unknown nginx 17-Jun-2016       British Library
         | 194.66.233.215 Linux Apache 17-Jan-2016
        
           | Moru wrote:
           | Does not have to be what they are running their servers on.
        
         | ahi wrote:
         | This is bait, but I'll bite. From what I've seen, the common
         | denominator is misconfiguration. We can all do it, but it seems
         | especially concentrated in organizations with limited IT human
         | resources largely dependent upon contracted service providers.
         | Spend a butt load on systems and hope Bill in IT doesn't screw
         | it up. A lot of that ecosystem happens to be Windows based.
        
         | gosub100 wrote:
         | This is a great observation. What if, back in the Ford Explorer
         | Firestone tire explosion scandal, they said "SUVs are being
         | recalled because tires are exploding". Makes the article much
         | less informative.
        
         | wongarsu wrote:
         | To me the share of Windows as ransomware target seems
         | proportional to Window's use in office computers in large and
         | medium enterprises.
        
       | emmender2 wrote:
       | attack the incentives...
       | 
       | have dedicated govt agencies going after the crypto money trail,
       | and disrupt the theives. this happened in the pipeline hack.
       | 
       | otherwise, the thieves will continue thieving with nothing to
       | stop them.
       | 
       | thats why we have the police and other such agencies in the real
       | world.
       | 
       | when thieves go after the commons (libraries/hospitals) - we the
       | public taxpayers have every incentive to demand action of our
       | govt as there is nobody else who can help here.
       | 
       | why are the british taxpayers not demanding action ?
        
         | toyg wrote:
         | Demanding from whom? The current government could not cook an
         | egg.
        
       ___________________________________________________________________
       (page generated 2023-12-18 23:00 UTC)