Internet Archive down, possibly hacked

This may be interesting to the people here, given how much we rely on the Internet Archive in general.

7 Likes

It’s back online and I can see cover arts showing up on MB.

not hacked just DDoS’d - Jason Scott’s and Brewster’s twitter confirm this:

2 Likes

Just following this up; actually there is a possibility they have emails but people are theorizing they’re simply using emails found in the metadata XML files that are publicly visible on all IA items.

If I recall correctly CAA doesn’t use your MusicBrainz ID/email when you upload but an API user account that is designed specificially for it.

However if you do use Internet Archive for any other purposes you should really change your password; even better ensure you use Internet Archive with a unique email address.

2 Likes
6 Likes

You mean if we have a user account, there?
I didn’t know there was a user account system, over there… :thinking:

That’s pretty bad.

At least they used bcrypt to hash the passwords. It used to be state of the art about a decade ago, but modern GPUs could be fast enough to efficiently calculate these hashes today.

Just mentioning it in case anyone is similarly confused: I received a “You’re one of 31,081,179 people pwned in the Internet Archive data breach” email from the ever-useful haveibeenpwned.com yesterday. As far as I can remember, I never created an account there, so I suspect that my email address was included in the leak by virtue of it being shared with IA when I donated to them.

4 Likes

I got the same email. I have an account.
At the time of writing, the site is down…

2 Likes

Hello,

Am I understanding correctly that the issue of not seeing covers on Musicbrainz.org and in Picard is because Internet Archive was hacked?

I’m surprised to hear it was reported as being back online. I still can’t see any covers, either on the website or in Picard.

with best

There was a second update from Brewster Kale from the Internet Archive 14hrs or so ago to say that the DDoS had resumed and knocked them offline again.
We will be unable to get cover art here or in Picard until the DDoS is over and TIA have had time to restore/repair their systems to their satisfaction. I know its a bummer but I’d expect it to be a week at minimum before things are back to normal. This is an organization that runs with a very small team on donations after all, not a large business.

Here’s the latest status update.

edit: apparently i can’t type.

3 Likes

Yes, that makes sense. What kind of idiots attack a service that provides free data for everyone? Unbelievable.

2 Likes

You are definitely not the only person to be angered by these malicious morons.

Language warning:

4 Likes

The data is safe.

Services are offline as we examine and strengthen them. Sorry, but needed. @internetarchive staff is working hard.

Estimated Timeline: days, not weeks.

Thank you for the offers of pizza (we are set).

— Brewster Kahle (@brewster_kahle) October 11, 2024
12 Likes

Just a thought on the implications for MB: should artwork-related edits be kept open until the Archive is back on its feet?

9 Likes

I would assume all cover art edits should be locked (prevented) in the meantime as well.

8 Likes

There are still editors making cover artwork-related edits such as removals, type and comment changes or reordering. But it’s not possible to review at this time. Some of those edits don’t sound right.

11 Likes

It truly is a shame that there are so many bad actors out there whose sole intent is to damage or destroy the hard work of other.

4 Likes

So the latest that I can gleam from various posts is:

Things are going well but they’re performing a series of maintenance tasks to try and improve things and prevent being knocked over by a DDoS attack again (seems like the right thing to do as I wouldn’t be surprised if these bad actors try it again as soon as IA is back online).

Email system was one of the first “public” facing services over there to come online and began sending a flurry of notifications to those of us who are contributors. This is confirmed as normal and just to delete those emails for now, nothing malicious just part of the fall out of resuming service.

3 hours ago the WayBackMachine (https://web.archive.org/) was made available again, but in read only mode.

Hopefully not much longer before other elements of the site will re-open for business :smiley: .

22 Likes

Any new updates on a time frame when the CAA will be back up? I have a small pile of CD’s on my desk that’s growing that need cover art uploaded.

4 Likes