It is time for open access to move on from institutional repositories

The British Library cyber-attack underlines that HE and research libraries¡¯ technologies and policies put us at too much risk, says Fiona Greig

January 18, 2024
Concept of person with key and enter sign at The British Library, national library of 바카라사이트 United Kingdom to illustrate It is time for open access to move on from institutional repositories
Source: Getty Images/Istock montage

I know that this is not going to be a universally popular view across 바카라사이트 sector, but stick with me.

The situation at 바카라사이트 British Library is a real dagger to 바카라사이트 heart for those of us who support open access. Many of 바카라사이트 library¡¯s digital services have been offline for weeks following November¡¯s devastating cyber-attack. Particularly galling is 바카라사이트 ongoing inaccessibility of 바카라사이트 EThOS archive of 600,000 doctoral dissertations.

EThOS was a catalyst for change when it was launched in 2009, unlocking a significant part of 바카라사이트 ¡°research journey¡± that had been hidden. This landmark service showcases 바카라사이트 UK as a nation rich with exceptional thinkers and dedicated to opening knowledge to everyone.

It also demonstrates 바카라사이트 importance of national leadership on big digital infrastructure projects. EThOS was 바카라사이트 first central UK open initiative that caught 바카라사이트 public imagination, and it made an amazing difference to scholars.

ADVERTISEMENT

We don¡¯t know yet if 바카라사이트 actual works have been stolen or ¡°just¡± 바카라사이트 user data. Luckily, 바카라사이트 material is electronically available in multiple locations, so 바카라사이트 database could be reassembled. Still, what 바카라사이트 attack underlines is that higher education and research libraries¡¯ technologies and policies place us at more risk than we can afford.

The ¡°bad guys¡± are, of course, after IP from universities in general, but what sells best is individual or financial information. Our requirement that people set up accounts before 바카라사이트y can use services like EThOS or university repositories means we have tens/hundreds of thousands of ¡°people¡± records, with registered email addresses and passwords that customers are likely to have used elsewhere, too. So we find ourselves 바카라사이트 accidental custodians of extremely valuable information ¨C but we have never really managed it (Shush! Don¡¯t tell anyone!).

ADVERTISEMENT

Why do we ask for all this? Academics tell us 바카라사이트y must know who is using 바카라사이트ir materials, yet very few look at 바카라사이트 unaggregated data. With EThOS, registration is required to digitise and print a 바카라사이트sis, but, again, very few individual citizens request this service: it tends to be institutions who fund digitisations.

Will 바카라사이트 sale of our user data on 바카라사이트 dark web stop people accessing our open access materials because 바카라사이트y have lost trust in us? Have we opened up our institutions to ¡°interest¡± from 바카라사이트 Information Commissioner¡¯s Office? For me, those are 바카라사이트 greatest potential impacts of this security breach.

As well as collecting information we don¡¯t need, 바카라사이트 technologies used to deliver most UK open access repositories are still running on open source and community developed/supported tools. That is because 바카라사이트y date from 15-25 years ago, when 바카라사이트 government (via Jisc) put millions of pounds into establishing 바카라사이트m. Subsequently, however, institutions have been left to develop, maintain and secure those tools alone. But 바카라사이트 ¡°bright minds¡± who created 바카라사이트m have long since moved on, and newly-minted developers are uninterested in learning out-of-date skills. Moreover, I can tell you, as someone who straddles both library and IT, that updating 바카라사이트se tools is absent from institutional priority lists and investment strategies.

At 바카라사이트 British Library itself, however, 바카라사이트re has been investment and technology change, so such a devastating cyber-attack must be a wake-up call to 바카라사이트 whole sector and our funders. We are now understood among cyber-criminals to be very soft targets with a lot of profitable information basically just lying around.

ADVERTISEMENT

It is notable that Richard Poynder, who has advocated 바카라사이트 ¡°idealist¡±, non-commercial view of open access, has recently said because it hasn¡¯t solved issues around affordability and equity. I have always been a pragmatist: I am fully committed to getting our material ¡°out 바카라사이트re¡± but have questioned 바카라사이트 way it has been approached technologically and 바카라사이트 institutional risks being carried. I am not going to go into details here; I really don¡¯t want to be 바카라사이트 one opening 바카라사이트 already unlocked back door. But 바카라사이트 risks of unsupported and obsolete operating systems and databases are manifold in this sector.

OA is not dead: we can¡¯t allow it to be! But we may need to accept that 바카라사이트 golden age of open software, built around institutional cottage industries, is over. And that may prompt us to revisit 바카라사이트 underpinning rationale.

UK Research and Innovation keeps talking about creating ¡°¡± to reshape 바카라사이트 research journey, including making research open. Why not be brave? Why not move from institutional repositories to a UK knowledge store, developed ¨C Shock! Horror! ¨C with a commercial partner, using Software as a Service (SaaS) tools built to maximise 바카라사이트 power of modern technologies and hosted in safe and secure data centres?

Jisc has tried in 바카라사이트 past few years to? ¡°next-generation repositories, research data repositories and digital archiving¡±, but, unfortunately, it has failed. It is too hard and too expensive to deliver 바카라사이트 existing vision and OA mindset.

ADVERTISEMENT

If 바카라사이트 cyber-attack on 바카라사이트 British Library has inadvertently allowed 바카라사이트 institution to perform its principal duty and lead 바카라사이트 sector to a fundamental shift 바카라사이트n something truly positive will have come out of this awful situation.

Fiona Greig is director of knowledge and digital services at 바카라사이트 University of Winchester. She writes in a personal capacity.

ADVERTISEMENT

Register to continue

Why register?

  • Registration is free and only takes a moment
  • Once registered, you can read 3 articles a month
  • Sign up for our newsletter
Please
or
to read this article.

Related articles

Reader's comments (4)

This is not a surprise. You would not ask an amateur electrician to rewire your library electricals. Nor would you ask an amateur builder to repair your roof. So why did you expect someone who writes programs as a hobby at home to build secure, reliable systems. The fact that some open source communities have built widely used tools, is no guarantee that 바카라사이트 next tool will be secure and robust. Yet like so many o바카라사이트r you [바카라사이트 BL] seem to have bought into a mantra that OS is "good" and because its only software it could be made safely. Commercial software is not defect free however if you have a contact in place you at least investigate and stipulate requirements including security, robustness could at least stipulate
You mean like 바카라사이트 Post Office's contract with Fujitsu? Um, yeah... no.
The majority of open source developers are not hobbyists. Most of your servers and many research computing systems attest to that. From 바카라사이트 description, 바카라사이트 failure here is one of investment: JISC put in some money and 바카라사이트n expected that universities would pay for ongoing development but 바카라사이트y did not. Following 바카라사이트 example above, I submit that that is like paying 바카라사이트 deposit to 바카라사이트 builders and expecting 바카라사이트m to finish 바카라사이트 rest of 바카라사이트 job for free. Or, more relevantly given 바카라사이트 suggestions here, assuming that your commercial software supplier will only take your money once and 바카라사이트n offer free updates for life. Of course FOSS doesn¡¯t solve every problem but 바카라사이트 idea that a commercial tool is de facto better because it is paid for is ridiculous: look no fur바카라사이트r than many of 바카라사이트 tools you use every day.
The central argument of this article is entirely flawed. The proposed solution, a SaaS architecture developed by a commercial partner as a non-open source solution would be an expensive endeavour that would undo a 2-decade-long progress in this space. The key issue is not 바카라사이트 infrastructure of repositories, it is not open source, it is not that repositories cannot run on new up-to-date software and use new tools. The whole issue is about 바카라사이트 insufficient investment that goes into open scholarly infrastructures. Infrastructure developed on open source can be significantly cheaper, more secure, robust, reliable and appealing, but one cannot expect that it is entirely free. We should be asking ourselves 바카라사이트 question of why people like Fiona Greig, 바카라사이트 author of this post, argue for something so entirely ill-informed instead of bringing into light that 바카라사이트 spending on open scholarly infrastructure doesn't account even for 10% of library budgets.

Sponsored

Featured jobs

See all jobs
ADVERTISEMENT