Live data from Hacker News

British Library cyber incident review [pdf]

bl.uk

61–70 of 70 posts

Re: British Library cyber incident review [pdf]

#61

> This paper provides an overview of the cyber-attack on the British Library that took place in October 2023 and examines its implications for the Library’s operations, future infrastructure, risk assessment and lessons learned. For a report from British--and a library, no less--the lack of Oxford comma cocnerns me.

Despite its name, use of the Oxford comma is more frequently promoted in the USA than it is in Britain. As a British person myself, I generally avoid it. N=1, but I wouldn't expect the London-based British Library to use a construction named after an Oxford University Press style guide.

Re: British Library cyber incident review [pdf]

#62

A few naive questions: I see a few comments indicating that connecting Microsoft (? not mentioned anywhere in the report??) t Terminal Services to the internet was a wholly bad idea. Aside: is the report using "Terminal Services" generically, or do they mean that the server hasn't been updated since before 2009 (? when it seems Terminal Services became Remote Desktop Services (RDS))? Is there something inherently ins…

The term has become a bit generic these days and people will use it in place of a range of things. Citrix or vmware are often just called "terminal server" by aome people.

There is a huge difference between a port forward on port 3389, and publishing the gateway behind azure app proxy - the latter supporting mfa, account lockouts, and not actually requiring any open port to the internet. Much of the discussion online treats these as equal.

Re: British Library cyber incident review [pdf]

#63

Earlier quoted context omitted.

> everybody within their IT team should be fired immediately for gross negligence. That may be true, but by that standard about 90% of every sysadmin, IT managers and even CISOs would be out of a job next week. Most companies are just "getting by" and hoping it won't be them next. We have a multi-national cybersecurity crisis due to decades of kicking the can down the road, excusing poor software engineering to allow…

Not keeping on top of basic IT security is the equivalent of driving drunk.

Coming from these sort of businesses, I usually read these sort of comments as "they should be fired because when they recommended mfa they management said no".
Post reply on HN