Update on IT Security Incident at UCSF
51–60 of 150 posts
Re: Update on IT Security Incident at UCSF
#52Earlier quoted context omitted.
Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?
I'll venture a guess that UCSF was nominally in compliance with some relevant bureaucratic regime (ISO 27001, SOC 2, etc), and that was good enough for a stodgy insurance company that's not very sophisticated about "cyber risk" (in case use of the term "cyber" isn't a giveaway...)
Re: Update on IT Security Incident at UCSF
#53Earlier quoted context omitted.
How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.
using H1B for 4 months stint is very strange. It is too valuable a visa slot (significantly oversubscribed lottery usually, at least in the recent years) to be wasted that way. Usually it is done using something like B1 for such a short trips, especially if it is training, etc. I wonder whether the journalists and others did mistake one visa for another, especially given that they naturally wouldn't be privy to such…
https://www.latimes.com/business/hiltzik/la-fi-hiltzik-uc-vi...
Re: Update on IT Security Incident at UCSF
#54As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
Re: Update on IT Security Incident at UCSF
#55Earlier quoted context omitted.
How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.
using H1B for 4 months stint is very strange. It is too valuable a visa slot (significantly oversubscribed lottery usually, at least in the recent years) to be wasted that way. Usually it is done using something like B1 for such a short trips, especially if it is training, etc. I wonder whether the journalists and others did mistake one visa for another, especially given that they naturally wouldn't be privy to such…
Re: Update on IT Security Incident at UCSF
#56What kind of data is worth at least a million dollars and isn't properly backed up? Unbelievable. Some heads should roll .
Some universities generally have done better about such things and are making progress... but generally there is a push and pull for IT dollars by unversity departments who want to spend that money as they wish for their given programs and then that money comes FROM IT ... who down the road are then tasked with the costs related to maintaining it and the terrible decisions a department made in the meantime... or in the worst of cases tasked with securing that data and / or making it work at all.
It's the same story for IT in the private sector to some extent, but it is way worse at many universities. Imagine if your HR director got to pick the PCs to support, networking equipment, software, backup methods (if any) all on their own and wanted zero input. That's kinda how it is at many universities.
I spent months helping a large university dig out from a program where they hooked up some super special microscopes worth millions of dollars ... to low grade network switches and storage. I got to try to explain why you can't put 10,000 pounds of data into a borderline consumer grade network ... in all of a couple milliseconds.
Re: Update on IT Security Incident at UCSF
#57The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.
If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!
... "lock" data in place rather than sell it to the highest bidder.
Why not both? And once the rightful owner of the data has paid a fat ransom, surely that's got to provide some kind of proof of its market value. The University did say that The attackers obtained some data as proof of their action
so unless they're logging their outbound traffic, who's to say they didn't exfiltrate all of it? It's the kind of thing that the University would remain tight-lipped about unless they were either sure that it hadn't happened (doubtful, seeing as they aren't running a tight ship) or had some kind of mandatory reporting obligation for the data.Re: Update on IT Security Incident at UCSF
#58The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.
If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!
First of all, they are increasingly selling the data. They exfil first, lock second.
Second of all, these wonderful criminals are targeting all manners of institutions, not just large universities.
Proper data hygiene at large enterprise levels is, in fact, exceedingly difficult.
Re: Update on IT Security Incident at UCSF
#59As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
It's tiring to keep hearing these stories and tieing them to H1B. Satya Nadella also started on an H1B, Sundar Pichai did too and so did Andrew Ng. Just those 3 combined have created more jobs than were lost here. So please, stop spreading partial info that creates hate against a whole swathe of people who have come here legally, have contributed extremely productively to this nation in the form of taxes and labor, a…
Re: Update on IT Security Incident at UCSF
#60Earlier quoted context omitted.
If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!
I know how much IT personnel at UCSF make -- you get what you pay for. If you want expertise, it's not hard to find.