Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

91–100 of 150 posts

Re: Update on IT Security Incident at UCSF

#91
post #81

Earlier quoted context omitted.

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system. There is no excuse for not having backups.

“No, we can’t use leading cloud providers to store this data. What if someone unauthorised looks at it?” This attitude leaves the victim paying millions in ransom. Look, Microsoft and Amazon probably have a better handle on security than your IT dept which is two people who also have to fix any issues like the WiFi not working or software not updating.

There are stories of MSPs who got their offline backup from the same provider who they bought their cloud based RMM tool.

One day an account get's exploited and suddenly the backups are deleted and the systems are all encrypted remotely.

Cloud backups are not offline backups, if you want security use tapes or remote systems which turn on manually.

Re: Update on IT Security Incident at UCSF

#92
post #80

What a cheesy attack. It only cost them $1.14M to get their data back. I can not tell if the attack hit something inconsequential, the criminals are stupid, or they just do not understand finances for them to ask for such a tiny sum. UCSF received $1.43B in grants and contracts during 2017-2018 [1]. Assuming they are generating an equivalent amount of value in knowledge evenly distributed over time, the loss of one d…

You make the assumption here that this hack halted all research. It's unlikely to have even affected 10% of ongoing research. Plenty of things stored on cloud storage, in email, in personal computers, on computers not locked out, etc.

Re: Update on IT Security Incident at UCSF

#94
post #91
post #81

Earlier quoted context omitted.

“No, we can’t use leading cloud providers to store this data. What if someone unauthorised looks at it?” This attitude leaves the victim paying millions in ransom. Look, Microsoft and Amazon probably have a better handle on security than your IT dept which is two people who also have to fix any issues like the WiFi not working or software not updating.

There are stories of MSPs who got their offline backup from the same provider who they bought their cloud based RMM tool. One day an account get's exploited and suddenly the backups are deleted and the systems are all encrypted remotely. Cloud backups are not offline backups, if you want security use tapes or remote systems which turn on manually.

A backup that can be overwritten is not a backup.

It is possible to use a cloud provider and also write an immutable backup.

Re: Update on IT Security Incident at UCSF

#95
post #79

Earlier quoted context omitted.

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system. There is no excuse for not having backups.

If you don’t trust them with your data, you can encrypt it with your own keys.

But then you lose the main advantages of using them to begin with. It becomes harder to use, it may not be able to do efficient differential backups or snapshots anymore or require you to do some complicated thing to make it work because their interface isn't meant to be used that way etc. And if it's actually important for the data to remain private, you then have to get the cryptography right, not think that your backups are "encrypted" because you used TLS, or use some snake oil encryption software which is using export ciphers or bad random number generation or anything like that.

In-house backups aren't that hard. The hardest thing is to make sure everything is getting backed up that ought to be, and actually test that it is, which is no different with cloud backups.

Re: Update on IT Security Incident at UCSF

#96
post #81

Earlier quoted context omitted.

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system. There is no excuse for not having backups.

“No, we can’t use leading cloud providers to store this data. What if someone unauthorised looks at it?” This attitude leaves the victim paying millions in ransom. Look, Microsoft and Amazon probably have a better handle on security than your IT dept which is two people who also have to fix any issues like the WiFi not working or software not updating.

> This attitude leaves the victim paying millions in ransom.

Not if they still have backups that aren't cloud backups.

> Look, Microsoft and Amazon probably have a better handle on security than your IT dept which is two people who also have to fix any issues like the WiFi not working or software not updating.

And that's part of the problem, right? Your IT department isn't too bright, so they encrypt their cloud backups with a tool that does the encryption wrong, and the smarter engineers at the cloud provider know that it's vulnerable so now they can read your data when you thought they couldn't. Or you use a weak password for the cloud backup account and then some third party breaks in and gets them.

Not really a concern with a backup tape stored in a fire safe.

Re: Update on IT Security Incident at UCSF

#97
post #3

The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.

Optimistic counterpoint: a high-profile, (relatively) high-value ransom payout like USC's may incentivise other orgs vulnerable to this kind of attack to take steps to prevent this kind of issue. Anything from restricting program capabilities/permissions for external executables, to keeping "colder" backups of business-critical data, to monitoring and responding to software that looks like it's traversing the whole f…

  like USC's
UCSF is University of California, San Francisco. USC is University of Southern California, a private school.

Re: Update on IT Security Incident at UCSF

#98

Earlier quoted context omitted.

Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?

Most of the time, the insurance guys will just negotiate on your behalf (lowering costs) and handling purchasing of the crypto. They also won't tell you how much they paid out...

I'd expect that UCSF is self-insuring.

Re: Update on IT Security Incident at UCSF

#99
post #64

Earlier quoted context omitted.

but they did get the benefit of cheaper IT workforce? What they did to their existing employees was certainly morally wrong but is outsourcing your IT support to cheaper third party seen as morally wrong too? Isn't that the idea of free captial market? Sure the state didn't get taxes from those employees but state owned university saved costs.

They did benefit from the cheaper workforce, in fact they saved 1.14 million dollars! Wait Oh no...

You say that as though 1.14 million dollars is a lot.

Re: Update on IT Security Incident at UCSF

#100

What kind of data is worth at least a million dollars and isn't properly backed up? Unbelievable. Some heads should roll .

> academic work

I actually know a few people working on their PhD’s that have nothing backed up.

Their advisors buys servers, the university’s IT sets them up, they get access to it and work on it without backups, local copies or anything.

They have grants that they may have to provide results for.

As time passes, there are more people working in that lab that get access to the machines. Multiple projects being worked on for multiple grants.

I also know people running unsecured stuff on public ports for easier access.

Another thing, it could be that the data sets they where working on where given to them under a condition that they wouldn’t be shared, exposed or something.

I don’t know anyone in medicine or healthcare and no one at this university, but that’s what I’ve seen from people I’ve met throughout the year.

(I have also seems people loose their thesis because their laptops died on them and they didn’t have a backup or for their Word file getting corrupted.)

Post reply on HN