Live data from Hacker News

British Library cyber incident review [pdf]

bl.uk

51–60 of 70 posts

Re: British Library cyber incident review [pdf]

#51

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

> everybody within their IT team should be fired immediately for gross negligence. That may be true, but by that standard about 90% of every sysadmin, IT managers and even CISOs would be out of a job next week. Most companies are just "getting by" and hoping it won't be them next. We have a multi-national cybersecurity crisis due to decades of kicking the can down the road, excusing poor software engineering to allow…

If 90% of them qualify as grossly negligent, then they should be fired. That is kind of what grossly negligent means.

You do not really worry about what would happen if all the grossly negligent doctors get fired. Who will do those procedures with a total disregard for safety, said no one ever.

Re: British Library cyber incident review [pdf]

#52
> This paper provides an overview of the cyber-attack on the British Library that took place in October 2023 and examines its implications for the Library’s operations, future infrastructure, risk assessment and lessons learned.

For a report from British--and a library, no less--the lack of Oxford comma cocnerns me.

Re: British Library cyber incident review [pdf]

#53
post #19

> When alerted by the Library following discovery of the attack, Jisc (who provide the Library’s internet access and monitor movement of data across their networks) identified that an unusually high volume of data traffic (440GB) had left the Library’s estate at 1.30am on 28 October. "Jisc is the UK digital, data and technology agency focused on tertiary education, research and innovation." State-owned quango asleep…

The library's ISP said "yes, our monitoring shows you shifted an unusual amount of traffic" at that time.

My ISP could do the same thing. How is that being asleep at the wheel?

Re: British Library cyber incident review [pdf]

#54
post #51

Earlier quoted context omitted.

> everybody within their IT team should be fired immediately for gross negligence. That may be true, but by that standard about 90% of every sysadmin, IT managers and even CISOs would be out of a job next week. Most companies are just "getting by" and hoping it won't be them next. We have a multi-national cybersecurity crisis due to decades of kicking the can down the road, excusing poor software engineering to allow…

If 90% of them qualify as grossly negligent, then they should be fired. That is kind of what grossly negligent means. You do not really worry about what would happen if all the grossly negligent doctors get fired. Who will do those procedures with a total disregard for safety, said no one ever.

> You do not really worry about what would happen if all the grossly negligent...

But I do. I care about them as people. People who have families and need a job. I'd rather help them to not be grossly negligent than see them fired (and probably worse idiots take their place since we are in a major skills crisis right now).

The world is getting complex faster than anyone can track. Tomorrow it could be you, or I who is getting called on gross negligence because we can't follow it. So I choose to be a teacher even though telling people the truth is getting REALLY F**ING HARD these days - cos no one wants to hear it.

Re: British Library cyber incident review [pdf]

#55
post #51

Earlier quoted context omitted.

If 90% of them qualify as grossly negligent, then they should be fired. That is kind of what grossly negligent means. You do not really worry about what would happen if all the grossly negligent doctors get fired. Who will do those procedures with a total disregard for safety, said no one ever.

> You do not really worry about what would happen if all the grossly negligent... But I do. I care about them as people. People who have families and need a job. I'd rather help them to not be grossly negligent than see them fired (and probably worse idiots take their place since we are in a major skills crisis right now). The world is getting complex faster than anyone can track. Tomorrow it could be you, or I who i…

No, they should not continue to be in a position where they can continue committing grossly negligent actions and harm others.

You can train them once they are removed and reinstate them when they can do the job right, but supporting their continued harm of others so they can “support themselves” is detrimental, counterproductive, misguided, and extremely selfish.

You are literally better off paying them to do nothing. Please at least do that instead of paying for harm.

Re: British Library cyber incident review [pdf]

#56
post #55

Earlier quoted context omitted.

> You do not really worry about what would happen if all the grossly negligent... But I do. I care about them as people. People who have families and need a job. I'd rather help them to not be grossly negligent than see them fired (and probably worse idiots take their place since we are in a major skills crisis right now). The world is getting complex faster than anyone can track. Tomorrow it could be you, or I who i…

No, they should not continue to be in a position where they can continue committing grossly negligent actions and harm others. You can train them once they are removed and reinstate them when they can do the job right, but supporting their continued harm of others so they can “support themselves” is detrimental, counterproductive, misguided, and extremely selfish. You are literally better off paying them to do nothin…

> they should not continue to be in a position

"should" is doing a lot of work there. Im so many ways we're in agreement. But I do this in the real world, and experience has shown me we must deal with the world as it is and not merely as we wish it to be.

Re: British Library cyber incident review [pdf]

#57

This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…

@everfrustrated: There is nothing in your piece that can be refuted. Therefore it must be modded into invisibility.

> This report is a joke.

> No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence.

> They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical.

> Their ability to rebuild in a timely manner was hampered by not having any spare servers and presumably because all their server hardware was compromised and couldnt be used for restore.

Re: British Library cyber incident review [pdf]

#59
post #42

Earlier quoted context omitted.

I would be fully supportive of the GDS ( https://www.gov.uk/government/organisations/government-digit... ) taking on additional responsibilities and providing support and assistance to other government agencies. gov.uk is almost universally praised by the general public and tech people.

Agree, but they can't really do very much about the massive number of legacy systems in departments that can't or won't spend money to modernise. My favourite example to hate is the Driver and Vehicle Licensing Agency which tracks different things in multiple systems, and still requires snail mail interactions (!!!) for some services, such as reclaiming a license after a medical suspension (personal experience). To D…

Having experienced both the DVLA and (California) DMV, the DVLA feels miles ahead, like it's living in the future.

Things like finding out the status of a renewal involved finding a fax machine, everything but the most trivial renewal (say, renewing if you're on a work visa) seems to be done in person with handwritten paperwork, and the amount of busywork that seems to be done by hand by the DMV agent is quite easy to blame for the impressive wait times, multiple hours even if you have an appointment.

My DVLA renewal was trivial comparatively, they could even use my passport for an updated ID photo. But maybe if you're not a UK citizen they also make you jump through weird hoops?

I'm not saying that the DVLA is good, just that it could be even worse.

Re: British Library cyber incident review [pdf]

#60
post #59

Earlier quoted context omitted.

Agree, but they can't really do very much about the massive number of legacy systems in departments that can't or won't spend money to modernise. My favourite example to hate is the Driver and Vehicle Licensing Agency which tracks different things in multiple systems, and still requires snail mail interactions (!!!) for some services, such as reclaiming a license after a medical suspension (personal experience). To D…

Having experienced both the DVLA and (California) DMV, the DVLA feels miles ahead, like it's living in the future. Things like finding out the status of a renewal involved finding a fax machine , everything but the most trivial renewal (say, renewing if you're on a work visa) seems to be done in person with handwritten paperwork, and the amount of busywork that seems to be done by hand by the DMV agent is quite easy…

> I'm not saying that the DVLA is good, just that it could be even worse

Some things they do reasonably well, yes. But edge cases like mine are the pits. To get a licence back after a medical suspension involves DVLA and the NHS posting physical letters to each other! It took 5 months for this purely admin process to complete, after I was medically fit. Grrrr. That is a long time to be denied the right to drive.

Post reply on HN