The Internet Archive's Wayback Machine is back up after hack
The Internet Archive suffered both a data breach and a DDoS attack
Logo: Internet Archive
The Wayback Machine, a tool from the Internet Archive that allows users to visit archived versions of websites, is back online in read-only form after a hack last week. IA founder Brewster Kahle confirmed the news on Monday, posting on social media that users will not be able to save new pages for the time being. “Safe to resume but might need further maintenance, in which case it will be suspended again,” Kahle wrote, adding, “Please be gentle.”
News of the DDoS attack (which stands for “Distributed Denial of Service”) broke on October 9, when users attempting to access the Wayback Machine were met with a JavaScript alert that read: “Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!” The hacker reportedly shared the Internet Archive’s authentication database with Troy Hunt, creator of the site “Have I Been Pwned“; he confirmed to Bleeping Computer the breach “contains authentication information for registered members, including their email addresses, screen names, password change timestamps, Bcrypt-hashed passwords, and other internal data.” The timestamp of the breach, which included 31 million unique emails, reportedly occurred on September 18.
“What we know: DDOS attack–fended off for now; defacement of our website via JS library; breach of usernames/email/salted-encrypted passwords,” Kahle posted to Twitter/X on October 9. “What we’ve done: Disabled the JS library, scrubbing systems, upgrading security.” The following day, he posted that the “DDoS folks are back” and that IA “is being cautious and prioritizing keeping data safe at the expense of service availability.” He later stated that the Internet Archive’s “data has not been corrupted. Services are currently stopped to upgrade internal systems. We are working to restore services as quickly and safely as possible.”
Let me share more on the chronology of this: