Live data from Hacker News

British Library cyber incident review [pdf]

bl.uk

21–30 of 70 posts

Re: British Library cyber incident review [pdf]

#21

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence.

The IT team most likely begged for years for funds to upgrade their infrastructure, but did not receive any of it. Public institutions are already short on money, but education has it even worse.

If anyone is to blame, it is the last British governments, who have focused their attention on Brexit and Ruanda crap instead of providing services for the citizens.

Re: British Library cyber incident review [pdf]

#22

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> everybody within their IT team should be fired immediately for gross negligence.

That may be true, but by that standard about 90% of every sysadmin, IT managers and even CISOs would be out of a job next week.

Most companies are just "getting by" and hoping it won't be them next.

We have a multi-national cybersecurity crisis due to decades of kicking the can down the road, excusing poor software engineering to allow unfettered commercial development, and destroying our education and training sectors.

Re: British Library cyber incident review [pdf]

#23

A lot of this sounds like they were under-resourced and the business increasingly adopted new technology with no ongoing support for their IT infrastructure. > These legacy systems will in many cases need to be migrated to new versions, substantially modified, or even rebuilt from the ground up, either because they are unsupported and therefore cannot be repurchased or restored, or because they simply will not operat…

The British Library is closer to academia than business. Their IT provider is a state-adjacent entity: https://en.wikipedia.org/wiki/Jisc .

Re: British Library cyber incident review [pdf]

#25
post #19

> When alerted by the Library following discovery of the attack, Jisc (who provide the Library’s internet access and monitor movement of data across their networks) identified that an unusually high volume of data traffic (440GB) had left the Library’s estate at 1.30am on 28 October. "Jisc is the UK digital, data and technology agency focused on tertiary education, research and innovation." State-owned quango asleep…

Could you elaborate why them being state owned was a contributing factor? We’ve seen countless similar incidents with private MSSPs as well.

Re: British Library cyber incident review [pdf]

#26

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> everybody within their IT team should be fired immediately for gross negligence. That may be true, but by that standard about 90% of every sysadmin, IT managers and even CISOs would be out of a job next week. Most companies are just "getting by" and hoping it won't be them next. We have a multi-national cybersecurity crisis due to decades of kicking the can down the road, excusing poor software engineering to allow…

Not keeping on top of basic IT security is the equivalent of driving drunk.

Re: British Library cyber incident review [pdf]

#27
post #19

> When alerted by the Library following discovery of the attack, Jisc (who provide the Library’s internet access and monitor movement of data across their networks) identified that an unusually high volume of data traffic (440GB) had left the Library’s estate at 1.30am on 28 October. "Jisc is the UK digital, data and technology agency focused on tertiary education, research and innovation." State-owned quango asleep…

> State-owned quango asleep at the qwheel. Unsurprising.

This used to be what we called JANET. Back in the day this was top banana and prestigious to work for like GCHQ etc.

I expect they've died from a thousand cuts under the Tories. Every university I've been in the past 10 years have their ICT run by Microsoft, and is absolute rubbish.

Re: British Library cyber incident review [pdf]

#28
> The increasing use of third-party providers within our network, some of which has been due to capacity and capability constraints within Technology and elsewhere in the Library, was noted by the Library’s Corporate Information Governance Group (CIGG) in late 2022, and the increasing complexity of managing their access was flagged as a risk. A review of security provisions relating to the management of third parties was planned for 2024; and the tightening of access provisions that would be enabled by improvements to underlying computer and storage infrastructure and the migration of storage to the cloud, which is currently being implemented. Unfortunately, the attack occurred before these necessary pre-requisites for this work were completed.

Price of everything and value of nothing. Outsource everything, underfund everything from systems renewal to staff salaries.

Re: British Library cyber incident review [pdf]

#29

A lot of this sounds like they were under-resourced and the business increasingly adopted new technology with no ongoing support for their IT infrastructure. > These legacy systems will in many cases need to be migrated to new versions, substantially modified, or even rebuilt from the ground up, either because they are unsupported and therefore cannot be repurchased or restored, or because they simply will not operat…

I've known people who have worked in IT in national museum settings, and from what I heard it sounded like a mix of traditional IT support—ensuring the lights stayed on, printers could print, emails and phones worked, and a very simple website stayed online.

Some aspects sounded quite interesting, but these weren't places pushing the envelope in any aspect of technology. I'm sure they were running outdated software and configurations on everything, but IT was closing their tickets and meeting their SLAs. And with no disrespect, these people weren't necessarily disruptors looking to shake up and modernize the museums' infrastructure and take it into the future either, they just did their job to the best of their ability and went home at the end of the day.

To generalize I find that this usually holds true in a lot of non-tech industries, and IT is generally seen as a burdensome cost as opposed to enabler of business.

Re: British Library cyber incident review [pdf]

#30
post #25
post #19

> When alerted by the Library following discovery of the attack, Jisc (who provide the Library’s internet access and monitor movement of data across their networks) identified that an unusually high volume of data traffic (440GB) had left the Library’s estate at 1.30am on 28 October. "Jisc is the UK digital, data and technology agency focused on tertiary education, research and innovation." State-owned quango asleep…

Could you elaborate why them being state owned was a contributing factor? We’ve seen countless similar incidents with private MSSPs as well.

Because the state (eh) of State-owned or state-adjacent anything, in modern Britain, is simply terrible. The dominant Thatcherite ideology ensures that state-provided services are almost invariably second-rate, thanks to systemic under-funding.

In this case, it looks like Jisc was basically turned into a charity in 2011, so technically they're not even state-owned anymore.

Post reply on HN