Live data from Hacker News

British Library cyber incident review [pdf]

bl.uk

31–40 of 70 posts

Re: British Library cyber incident review [pdf]

#31

A lot of this sounds like they were under-resourced and the business increasingly adopted new technology with no ongoing support for their IT infrastructure. > These legacy systems will in many cases need to be migrated to new versions, substantially modified, or even rebuilt from the ground up, either because they are unsupported and therefore cannot be repurchased or restored, or because they simply will not operat…

> However, the first detected unauthorised access to our network was identified at the Terminal Services server. This terminal server had been installed in February 2020 to facilitate efficient access for trusted external partners and internal IT administrators, as a replacement for the previous remote access system, which had been assessed as being insufficiently secure. Remote usage expanded during the subsequent Covid-19 pandemic because of the greatly increased requirement for remote working and the range of IT projects being undertaken with third party support.

While I'm certain they are underfunded and overworked, this sounds like they had an internet accessible terminal server. I'd like to imagine IT screaming this is a bad idea but a suit somewhere saying they needed easy access for partners. I can only imagine how insecure the solution they replaced with this one was.

Re: British Library cyber incident review [pdf]

#32

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. The IT team most likely begged for years for funds to upgrade their infrastructure, but did not receive any of it. Public institutions are already short on money, but education has it even worse. If anyon…

It's a government with huge civil service infrastructure. The people involved with Brexit and Rwanda miles away from this stuff. Willing to bet that in your counterfactual world lacking Brexit and Rwanda (and let's throw in, say, a Labour government), this would still not have been financed.

Re: British Library cyber incident review [pdf]

#33

Earlier quoted context omitted.

> everybody within their IT team should be fired immediately for gross negligence. That may be true, but by that standard about 90% of every sysadmin, IT managers and even CISOs would be out of a job next week. Most companies are just "getting by" and hoping it won't be them next. We have a multi-national cybersecurity crisis due to decades of kicking the can down the road, excusing poor software engineering to allow…

Not keeping on top of basic IT security is the equivalent of driving drunk.

Good analogy. It is. People's livelihoods and even people's lives are at risk.

But we've utterly normalised digital ignorance and built what Edward Snowden very rightly calls an "Insecurity Industry".

I'd go further, we've turned a celebration of ignorance around cybersecurity and dismissive attitudes into virtuous slogans.

   "Don't make me think" - Krug

   "Move fast and break things" - Mark Zuckerberg

   "If you've nothing to hide you've nothing to fear" - J Random Idiot
And those who are charged with advising and protecting are deeply conflicted - because they want backdoor access or at least insecure products.

What it boils down to is that presently there's more money and power in insecurity than there is in security. Our industry has multiple principal agent, Shirky Principle and Pournelle's Law problems, see [0].

We allow ransomware and stalkerware companies, and outfits like NSO (which I only mention because they are most well recognised) to operate as legitimate.

We flood markets with defective IoT crap and reduce consumers expectations to the level of accepting vendor malware and backdoors installed out of the box.

And then we turn around and complain that "stuff ain't secure".

This whole ship is DUI.

[0] https://cybershow.uk/blog/posts/love/

Re: British Library cyber incident review [pdf]

#34
So Tom, Dick and Harry all have Terminal rdp access into the core infrastructure and they slept well knowing that they had - what was it? Ah, yes, - prevented clipboard copying as a hardening measure. That'll stop them pirates in their tracks. Nicely written post mortem. Though I can't help but notice the amount of committees and acronyms. Is it a British thing?

Re: British Library cyber incident review [pdf]

#35
post #3

"The Library utilises numerous trusted partners for software development, IT maintenance, and other forms of consultancy" ... "this terminal server was protected by firewalls and virus software, but access was not subject to Multi-Factor Authentication (MFA)" ¯\_(ツ)_/¯

There are many attack vectors to bypass MFA, especially sms based MFA

True, but if you don't have it enabled / required then you're giving off signals of negligence which may extend into other vulnerabilities.

Re: British Library cyber incident review [pdf]

#36

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> because they refuse to pay the ransom

They were following explicit government guidance, as promulgated by the National Cyber Security Centre (NCSC), which is the civvie offshoot of GCHQ.

Re: British Library cyber incident review [pdf]

#37

A lot of this sounds like they were under-resourced and the business increasingly adopted new technology with no ongoing support for their IT infrastructure. > These legacy systems will in many cases need to be migrated to new versions, substantially modified, or even rebuilt from the ground up, either because they are unsupported and therefore cannot be repurchased or restored, or because they simply will not operat…

I think it's part of a general trend where UK govt institutions have notoriously poor IT, usually consisting of semi-obsolete infrastructure, multiple legacy systems, sticking-plaster upgrades, one or two new state-of-the-art bits where budget is available, etc. Consider the NHS, the MOD, DVLA, etc.

Re: British Library cyber incident review [pdf]

#38

So Tom, Dick and Harry all have Terminal rdp access into the core infrastructure and they slept well knowing that they had - what was it? Ah, yes, - prevented clipboard copying as a hardening measure. That'll stop them pirates in their tracks. Nicely written post mortem. Though I can't help but notice the amount of committees and acronyms. Is it a British thing?

> the amount of committees and acronyms. Is it a British thing?

Take a look at the US DoD, NASA, etc. They love acronyms, complicated internal organisation structures, just as much as the Brits do.

Re: British Library cyber incident review [pdf]

#39
"Our major software systems cannot be brought back in their pre-attack form, either because they are no longer supported by the vendor or because they will not function on the new secure infrastructure that is currently being rolled out."

Ouch.

Re: British Library cyber incident review [pdf]

#40
post #29

A lot of this sounds like they were under-resourced and the business increasingly adopted new technology with no ongoing support for their IT infrastructure. > These legacy systems will in many cases need to be migrated to new versions, substantially modified, or even rebuilt from the ground up, either because they are unsupported and therefore cannot be repurchased or restored, or because they simply will not operat…

I've known people who have worked in IT in national museum settings, and from what I heard it sounded like a mix of traditional IT support—ensuring the lights stayed on, printers could print, emails and phones worked, and a very simple website stayed online. Some aspects sounded quite interesting, but these weren't places pushing the envelope in any aspect of technology. I'm sure they were running outdated software a…

The British library has pretty complex systems because of the vast size of teh collection. Some pretty interesting stuff:

https://www.youtube.com/watch?v=ZNVuIU6UUiM

Post reply on HN