Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

101–110 of 150 posts

Re: Update on IT Security Incident at UCSF

#101
post #89

Earlier quoted context omitted.

Doesn't matter, it's the perfect crime... The encryption is done on the user's machine using their processing power, and there's virtually no downside for you (either they pay and you decrypt or they don't and you just dissapear). Ransomware will be an issue for years to come.

I am confused by your response since it seems to agree with my post but you used words that indicate you think that they do not agree. Did you mean to reply to someone else? I am saying that that the ransom is hilariously small compared to what they would probably be able to get. So, when they realize they can actually ask for a number that is not a rounding error they will probably increase the number/outcome of att…

On the other hand, the more they ask for, the less likely they’re going to get paid for it.

If they keep asking for $1M from organizations that will pay because that’s pocket change, the more organizations they can attack.

If they start asking for too much, they’ll see they won’t pay as quickly, other people will start selling services to protect against you that seem more attractive, etc.

Re: Update on IT Security Incident at UCSF

#102
post #70

Earlier quoted context omitted.

It’s not that obvious. It could be assurance that the data would be deleted and not sold/shared.

> We therefore made the difficult decision to pay some portion of the ransom, approximately $1.14 million, to the individuals behind the malware attack in exchange for a tool to unlock the encrypted data and the return of the data they obtained. I assume you read that though before you replied, right?

> and the return of the data they obtained

Re: Update on IT Security Incident at UCSF

#103
post #47

Earlier quoted context omitted.

Someone's gotta be thinking about doing a ransomware operation that doesn't unlock the data in order to poison the well.

It's been done. There was one "ransomware" attack that just erased everything.

NotPetra

Re: Update on IT Security Incident at UCSF

#104
Is there a way to restrict encryption at a hardware level? The conditions where you would like to voluntarily encrypt data are usually quite rarefied. Allowing any sort of encryption activity on your system seems like a hazard these days.

Re: Update on IT Security Incident at UCSF

#105

CISO: https://cio.ucop.edu/spotlight-patrick-phelan-once-a-ucla-br... I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes. Point in time recoveries for the entire account would be nice add too…

> I can't think of any reason not to use a cloud hosted service for backup today.

Or just use a non-Windows file server that supports snapshots: NetApp, Isilon, FreeNAS, etc.

If an end-user devices gets infected, and then encrypts mapped drives under the credentials of the user in question, that won't do anything to the read-only data.

Snapshots are not backups, but for a lot of the most common situations, they offer a convenient, quick win so people can move on with their day (often in a self-service fashion by just going into a .snapshot/ directory).

Re: Update on IT Security Incident at UCSF

#106

CISO: https://cio.ucop.edu/spotlight-patrick-phelan-once-a-ucla-br... I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes. Point in time recoveries for the entire account would be nice add too…

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system. There is no excuse for not having backups.

> […] not trusting them with your data being a major one.

Which is why you encrypt the data before sending it over the wire. Just like how you'd use encryption on LTO tapes before sending them offsite.

Re: Update on IT Security Incident at UCSF

#107
post #79

Earlier quoted context omitted.

If you don’t trust them with your data, you can encrypt it with your own keys.

But then you lose the main advantages of using them to begin with. It becomes harder to use, it may not be able to do efficient differential backups or snapshots anymore or require you to do some complicated thing to make it work because their interface isn't meant to be used that way etc. And if it's actually important for the data to remain private, you then have to get the cryptography right, not think that your b…

> But then you lose the main advantages of using them to begin with.

Poppycock. There's plenty of software that can do encrypted incrementals / differentials: Commvault, NetBackup, Veeam, tarsnap, Duplicity, ZFS snapshot send-recv,

Re: Update on IT Security Incident at UCSF

#108
post #56

What kind of data is worth at least a million dollars and isn't properly backed up? Unbelievable. Some heads should roll .

It's a university, university IT is often ultra political and those who win the various battles make the rules, regardless of competence... and often without IT's sign off. Some universities generally have done better about such things and are making progress... but generally there is a push and pull for IT dollars by unversity departments who want to spend that money as they wish for their given programs and then th…

> It's a university, university IT is often ultra political […]

While you're not necessarily wrong, another option is budget.

If this is academic- / research-generated data, then it could have been paid for by grant money, and most of the cash goes to paying grad students and perhaps some computer equipment.

IT may have chargebacks (they have bills / cost centres to pay too after all), and no one wants to "waste" grant money. Often these things are 'shadow IT' run in an ad hoc fashion by just throwing together some PCs.

If the group's expertise is in medicine / biology, how many members want to give up their day-light research hours to run the computer infrastructure?

I've spent about half my IT career in the academic sphere, and cheap solutions can be a fight to implement even if they solve the problem; even free (open source) ones can be an effort if they take time or slow down the workflow.

And these people aren't stupid: they 'know' they should do some of these things. But people 'know' they should get exercise, and how many folks do that?

Re: Update on IT Security Incident at UCSF

#109

CISO: https://cio.ucop.edu/spotlight-patrick-phelan-once-a-ucla-br... I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes. Point in time recoveries for the entire account would be nice add too…

These sound like servers used by researchers. I've worked with higher education research computing and you might be surprised at what you would find.

Researchers may be generating or churning through countless TB of intermediary data, scratch files, etc. Often, the people who actually run the it infrastructure for researchers are... grad students. Sometimes they have grants for hardware and tight budgets, and paying anything for backups isn't part of it. Sometimes, if you're lucky, the it department will be aware of the work and allowed to help.

Now maybe that's not the case here, and there really is one department responsible, and that department decided against spending money on backups. Well maybe they were told by the provost or the dean of whoever that they couldn't afford to back up everything, so they should just stick to file servers. Maybe the boxes compromised here are compute only, and all code and valuable artifacts are expected to be stored safely somewhere else. And maybe the researchers heard this and understood it when they agreed to use the system. But maybe the new grad student didn't get the memo and developed his model in vim on the compute node.

The point is, academic computing is kind of the wild west. Weird fiefdoms and weird restrictions, budgetary and otherwise. It's tough to guess which of these scenarios played out from the outside and we really can't know whether the CISO or CTO, or even anybody working for them, dropped the ball.

Re: Update on IT Security Incident at UCSF

#110
post #35
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

Lots of people are brought from overseas on B1, J1, L1 whataver cheap visas and employed illegally. All these HCL-Wipro-Mahindra rent out whole apartment complexes in the areas where they have large customers; there these B1s are allowed/forced to live on cheap.
Post reply on HN