Live data from Hacker News

British Library cyber incident review [pdf]

bl.uk

11–20 of 70 posts

Re: British Library cyber incident review [pdf]

#11
post #9

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

>They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. That doesn't fit their claims on page 7 about reviewing the lost data and contacting affected users.

They reviewed what the criminals later dumped on the dark web. They have no way to determine if the criminals kept more for themselves.

Re: British Library cyber incident review [pdf]

#12
A lot of this sounds like they were under-resourced and the business increasingly adopted new technology with no ongoing support for their IT infrastructure.

> These legacy systems will in many cases need to be migrated to new versions, substantially modified, or even rebuilt from the ground up, either because they are unsupported and therefore cannot be repurchased or restored, or because they simply will not operate on modern servers or with modern security controls.

> There is a clear lesson in ensuring the attack vector is reduced as much as possible by keeping infrastructure and applications current, with increased levels of lifecycle investment in technology infrastructure and security.

> Our reliance on legacy infrastructure is the primary contributor to the length of time that the Library will require to recover from the attack.

A lot of lines like the following, also indicate to me IT was increasingly were involved in fighting fires and maintining operational systems ("keeping the lights on") rather than deploying new infrastructure and automation, updating software etc.

> Some of our older applications rely substantially on manual extract (...) which in a modern data management and reporting infrastructure would be encapsulated in secure, automated end-to end workflows.

Modern business is IT, I know that I am preaching to the chior but this sounds a lot like their IT was seen as a cost.

Re: British Library cyber incident review [pdf]

#13
post #3

"The Library utilises numerous trusted partners for software development, IT maintenance, and other forms of consultancy" ... "this terminal server was protected by firewalls and virus software, but access was not subject to Multi-Factor Authentication (MFA)" ¯\_(ツ)_/¯

There are many attack vectors to bypass MFA, especially sms based MFA

Re: British Library cyber incident review [pdf]

#14

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

I suspect they don't have the forensic evidence to determine the root cause. Chances are there are probably too many ways it could have happened, and the evidence was encrypted or simply wasn't being captured.

At least they seem to have a plan moving forward that seems considered, though I think a lot of what they want to do is easier said than done effectively. I wish them the best of luck.

Re: British Library cyber incident review [pdf]

#15

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> they refuse to pay the ransom and have no other way to tell what was stolen. Farcical.

It's bad that they don't know what was taken, but as for paying the ransom, I wouldn't do it either: first, because it's danegeld; second, because you're just exposing yourself to even further risk by accepting files from criminals; third, because as others said, it would be UK tax money.

Re: British Library cyber incident review [pdf]

#17

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> they refuse to pay the ransom

As an organisation forming part of the UK State, they're not allowed to. Rightly, in my opinion.

Re: British Library cyber incident review [pdf]

#18
post #14

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

I suspect they don't have the forensic evidence to determine the root cause. Chances are there are probably too many ways it could have happened, and the evidence was encrypted or simply wasn't being captured. At least they seem to have a plan moving forward that seems considered, though I think a lot of what they want to do is easier said than done effectively. I wish them the best of luck.

> I suspect they don't have the forensic evidence to determine the root cause.

It said that. The terminal server entry point was completely scorched in the attack. Offsite rlogd would have helped.

Re: British Library cyber incident review [pdf]

#19
> When alerted by the Library following discovery of the attack, Jisc (who provide the Library’s internet access and monitor movement of data across their networks) identified that an unusually high volume of data traffic (440GB) had left the Library’s estate at 1.30am on 28 October.

"Jisc is the UK digital, data and technology agency focused on tertiary education, research and innovation."

State-owned quango asleep at the wheel. Unsurprising.

Re: British Library cyber incident review [pdf]

#20

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> they refuse to pay the ransom As an organisation forming part of the UK State, they're not allowed to. Rightly, in my opinion.

If i was user/staff, I would sure prefer if they paid the ransom…

Since I dont trust the library to actually assess my impact, or track records of companies getting hacked often drag their feet making it up to victims. (equifax)

Post reply on HN