Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

81–90 of 150 posts

Re: Update on IT Security Incident at UCSF

#81

CISO: https://cio.ucop.edu/spotlight-patrick-phelan-once-a-ucla-br... I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes. Point in time recoveries for the entire account would be nice add too…

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system. There is no excuse for not having backups.

“No, we can’t use leading cloud providers to store this data. What if someone unauthorised looks at it?”

This attitude leaves the victim paying millions in ransom. Look, Microsoft and Amazon probably have a better handle on security than your IT dept which is two people who also have to fix any issues like the WiFi not working or software not updating.

Re: Update on IT Security Incident at UCSF

#83
post #80

What a cheesy attack. It only cost them $1.14M to get their data back. I can not tell if the attack hit something inconsequential, the criminals are stupid, or they just do not understand finances for them to ask for such a tiny sum. UCSF received $1.43B in grants and contracts during 2017-2018 [1]. Assuming they are generating an equivalent amount of value in knowledge evenly distributed over time, the loss of one d…

Doesn't matter, it's the perfect crime...

The encryption is done on the user's machine using their processing power, and there's virtually no downside for you (either they pay and you decrypt or they don't and you just dissapear).

Ransomware will be an issue for years to come.

Re: Update on IT Security Incident at UCSF

#84
post #18

What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?

The FBI's last attempts at breaking crypto rings found that these guys had 24/7 technical support and a phone number you could call that would actually have a person on the other side.

Friend of a friend said it was probably the most "customer" focused organization they've ever fought against

Re: Update on IT Security Incident at UCSF

#85
post #6

Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.

Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?

Most of the time, the insurance guys will just negotiate on your behalf (lowering costs) and handling purchasing of the crypto.

They also won't tell you how much they paid out...

Re: Update on IT Security Incident at UCSF

#86
post #21
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

What kind of monster of an employer makes their employees train the replacements they're getting fired for? If that were me, I'd organize and have everyone quit; let them figure things out. Screw the pittance of a severance.

> I'd organize and have everyone quit; let them figure things out.

Be careful here... due to "freedom to choose" legislation targeting unions, it may be illegal for you to "organize labor" in your state...

Re: Update on IT Security Incident at UCSF

#87
post #70

Earlier quoted context omitted.

It's pretty obvious that the answer is 'no backup'...

It’s not that obvious. It could be assurance that the data would be deleted and not sold/shared.

> We therefore made the difficult decision to pay some portion of the ransom, approximately $1.14 million, to the individuals behind the malware attack in exchange for a tool to unlock the encrypted data and the return of the data they obtained.

I assume you read that though before you replied, right?

Re: Update on IT Security Incident at UCSF

#88
This just illustrates how incredibly important solid backup strategies can be. A big university should be able to figure out how to make WORM (write once read many) backups of their data. A million bucks buys a shitload of cloud storage or physical airgapped tapes...

Re: Update on IT Security Incident at UCSF

#89
post #80

What a cheesy attack. It only cost them $1.14M to get their data back. I can not tell if the attack hit something inconsequential, the criminals are stupid, or they just do not understand finances for them to ask for such a tiny sum. UCSF received $1.43B in grants and contracts during 2017-2018 [1]. Assuming they are generating an equivalent amount of value in knowledge evenly distributed over time, the loss of one d…

Doesn't matter, it's the perfect crime... The encryption is done on the user's machine using their processing power, and there's virtually no downside for you (either they pay and you decrypt or they don't and you just dissapear). Ransomware will be an issue for years to come.

I am confused by your response since it seems to agree with my post but you used words that indicate you think that they do not agree. Did you mean to reply to someone else?

I am saying that that the ransom is hilariously small compared to what they would probably be able to get. So, when they realize they can actually ask for a number that is not a rounding error they will probably increase the number/outcome of attacks. They are criminals robbing people at gunpoint and only asking for their pocket lint. Once they all realize they can ask for a wallet and get it, I think the number is going to go way up.

Re: Update on IT Security Incident at UCSF

#90
post #79

Earlier quoted context omitted.

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system. There is no excuse for not having backups.

If you don’t trust them with your data, you can encrypt it with your own keys.

Really, someone just did that for them, for the bargain price of $1.4M. I'm guessing they saved at least that much by outsourcing their entire IT department a few years ago.
Post reply on HN