Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

51–60 of 150 posts

Re: Update on IT Security Incident at UCSF

#51
The article is inconsistent about the severity, which lowers its trustworthiness. It states that everything is under control, a top super leading security guru expert is on top of it, no important data was stolen or exposed, everything will be fine soon. And... oh yeah, BTW, we'll be paying an astronomic sum of money to the criminals to get our data back.

Re: Update on IT Security Incident at UCSF

#52

Earlier quoted context omitted.

Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?

I'll venture a guess that UCSF was nominally in compliance with some relevant bureaucratic regime (ISO 27001, SOC 2, etc), and that was good enough for a stodgy insurance company that's not very sophisticated about "cyber risk" (in case use of the term "cyber" isn't a giveaway...)

The CISO’s top 5 “security tips” PR piece didn’t mention off-system backups. Policy voided.

Re: Update on IT Security Incident at UCSF

#53
post #45
post #35

Earlier quoted context omitted.

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

using H1B for 4 months stint is very strange. It is too valuable a visa slot (significantly oversubscribed lottery usually, at least in the recent years) to be wasted that way. Usually it is done using something like B1 for such a short trips, especially if it is training, etc. I wonder whether the journalists and others did mistake one visa for another, especially given that they naturally wouldn't be privy to such…

I looked a little more and found this subsequent article talking about it:

https://www.latimes.com/business/hiltzik/la-fi-hiltzik-uc-vi...

Re: Update on IT Security Incident at UCSF

#54
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

It's tiring to keep hearing these stories and tieing them to H1B. Satya Nadella also started on an H1B, Sundar Pichai did too and so did Andrew Ng. Just those 3 combined have created more jobs than were lost here. So please, stop spreading partial info that creates hate against a whole swathe of people who have come here legally, have contributed extremely productively to this nation in the form of taxes and labor, and would like to be treated with atleast the same level of dignity as any European low skilled person who just got off a boat at Ellis Island.

Re: Update on IT Security Incident at UCSF

#55
post #45
post #35

Earlier quoted context omitted.

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

using H1B for 4 months stint is very strange. It is too valuable a visa slot (significantly oversubscribed lottery usually, at least in the recent years) to be wasted that way. Usually it is done using something like B1 for such a short trips, especially if it is training, etc. I wonder whether the journalists and others did mistake one visa for another, especially given that they naturally wouldn't be privy to such…

My understanding is that H1-B's for some educational institutions (and certain affiliated non-profits) are cap exempt.

Re: Update on IT Security Incident at UCSF

#56

What kind of data is worth at least a million dollars and isn't properly backed up? Unbelievable. Some heads should roll .

It's a university, university IT is often ultra political and those who win the various battles make the rules, regardless of competence... and often without IT's sign off.

Some universities generally have done better about such things and are making progress... but generally there is a push and pull for IT dollars by unversity departments who want to spend that money as they wish for their given programs and then that money comes FROM IT ... who down the road are then tasked with the costs related to maintaining it and the terrible decisions a department made in the meantime... or in the worst of cases tasked with securing that data and / or making it work at all.

It's the same story for IT in the private sector to some extent, but it is way worse at many universities. Imagine if your HR director got to pick the PCs to support, networking equipment, software, backup methods (if any) all on their own and wanted zero input. That's kinda how it is at many universities.

I spent months helping a large university dig out from a program where they hooked up some super special microscopes worth millions of dollars ... to low grade network switches and storage. I got to try to explain why you can't put 10,000 pounds of data into a borderline consumer grade network ... in all of a couple milliseconds.

Re: Update on IT Security Incident at UCSF

#57
post #10
post #3

The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.

If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!

    ... "lock" data in place rather than sell it to the highest bidder.
Why not both? And once the rightful owner of the data has paid a fat ransom, surely that's got to provide some kind of proof of its market value. The University did say that

    The attackers obtained some data as proof of their action
so unless they're logging their outbound traffic, who's to say they didn't exfiltrate all of it? It's the kind of thing that the University would remain tight-lipped about unless they were either sure that it hadn't happened (doubtful, seeing as they aren't running a tight ship) or had some kind of mandatory reporting obligation for the data.

Re: Update on IT Security Incident at UCSF

#58
post #10
post #3

The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.

If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!

Absolute nonsense.

First of all, they are increasingly selling the data. They exfil first, lock second.

Second of all, these wonderful criminals are targeting all manners of institutions, not just large universities.

Proper data hygiene at large enterprise levels is, in fact, exceedingly difficult.

Re: Update on IT Security Incident at UCSF

#59
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

It's tiring to keep hearing these stories and tieing them to H1B. Satya Nadella also started on an H1B, Sundar Pichai did too and so did Andrew Ng. Just those 3 combined have created more jobs than were lost here. So please, stop spreading partial info that creates hate against a whole swathe of people who have come here legally, have contributed extremely productively to this nation in the form of taxes and labor, a…

I think most of the sentiments here are regarding the abuses of the H1-B program by the American companies and not targeted towards the recipients of the visas themselves. I don't think it's reasonable for people to draw the conclusion that the normal people that were awarded the visas should be to blame.

Re: Update on IT Security Incident at UCSF

#60
post #10

Earlier quoted context omitted.

If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!

I know how much IT personnel at UCSF make -- you get what you pay for. If you want expertise, it's not hard to find.

People who can properly secure a large enterprise are, actually, quite hard to find.
Post reply on HN