Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

71–80 of 150 posts

Re: Update on IT Security Incident at UCSF

#72
post #35

Earlier quoted context omitted.

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

but they did get the benefit of cheaper IT workforce? What they did to their existing employees was certainly morally wrong but is outsourcing your IT support to cheaper third party seen as morally wrong too? Isn't that the idea of free captial market? Sure the state didn't get taxes from those employees but state owned university saved costs.

The H-1B program is not intended to give employers access to cheaper foreign labor. Its stated purpose is to allow people to immigrate when they can do jobs that US workers can't. When there are already US workers doing those jobs, that's clearly not the case. But that sort of abuse has been all too common.

The recent H-1B suspension probably goes too far the other way -- the program needs more safeguards against abuse rather than to be discontinued -- which requires a legislative solution (auctioning off the slots seems promising). But the legislators are apparently too busy flinging their own scat at each other right now because it's an election year. In the meantime it might not be such a bad thing to fail closed rather than fail open, given the effect of the lockdowns on the unemployment rate.

Re: Update on IT Security Incident at UCSF

#73
I recently listened to Mikko Hyppönen as the company I work for had invited him to give a talk. It was very interesting.

One thing I hadn't realized before was that ransomware criminals has developed their own backup strategy:

- in addition to encrypting the data they will also exfiltrate it and threaten to publish it ob the internet for everyone to see.

That way it doesn't necessarily help an organization just because they have multiple layers of offsite read-only backups.

Re: Update on IT Security Incident at UCSF

#74

Earlier quoted context omitted.

People who can properly secure a large enterprise are, actually, quite hard to find.

They're really, really not. You just have to pay an appropriate salary.

...and allow IT to control the security and access policies, rather than executive level users.

Re: Update on IT Security Incident at UCSF

#75

CISO: https://cio.ucop.edu/spotlight-patrick-phelan-once-a-ucla-br... I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes. Point in time recoveries for the entire account would be nice add too…

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system.

There is no excuse for not having backups.

Re: Update on IT Security Incident at UCSF

#77

Earlier quoted context omitted.

It's tiring to keep hearing these stories and tieing them to H1B. Satya Nadella also started on an H1B, Sundar Pichai did too and so did Andrew Ng. Just those 3 combined have created more jobs than were lost here. So please, stop spreading partial info that creates hate against a whole swathe of people who have come here legally, have contributed extremely productively to this nation in the form of taxes and labor, a…

This is a labour issue, not an issue of xenophobia. Though I'm sure these companies would love us to believe it's about xenophobia. The breakdown of western labour protections and the march towards near chinese levels of exploitation will likely be overseen by people who claim that western labour protections are racist.

"They are taking our jobs" is also overtly about labor but the jump to xenophobia happens pretty quickly.

Re: Update on IT Security Incident at UCSF

#78

Earlier quoted context omitted.

It's tiring to keep hearing these stories and tieing them to H1B. Satya Nadella also started on an H1B, Sundar Pichai did too and so did Andrew Ng. Just those 3 combined have created more jobs than were lost here. So please, stop spreading partial info that creates hate against a whole swathe of people who have come here legally, have contributed extremely productively to this nation in the form of taxes and labor, a…

I think most of the sentiments here are regarding the abuses of the H1-B program by the American companies and not targeted towards the recipients of the visas themselves. I don't think it's reasonable for people to draw the conclusion that the normal people that were awarded the visas should be to blame.

I do believe that you perhaps aren't tieing the program to the recipients. But I don't think the distinction between the program and the beneficiaries is clear to the average voter who likely hasn't ever met a person on an H1B. When they read these stories their instinctive reaction is jobs going to "other people" and then they vote for people who are against immigration, who are tacitly for xenophobia. You could have called me pessimistic, but we have clear examples now of how xenophobia can resonate and can be built on labor issues.

Re: Update on IT Security Incident at UCSF

#79

CISO: https://cio.ucop.edu/spotlight-patrick-phelan-once-a-ucla-br... I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes. Point in time recoveries for the entire account would be nice add too…

There are reasons not to use cloud services for backups, not trusting them with your data being a major one. But then you should still be using some kind of internal backup system. There is no excuse for not having backups.

If you don’t trust them with your data, you can encrypt it with your own keys.

Re: Update on IT Security Incident at UCSF

#80
What a cheesy attack. It only cost them $1.14M to get their data back. I can not tell if the attack hit something inconsequential, the criminals are stupid, or they just do not understand finances for them to ask for such a tiny sum.

UCSF received $1.43B in grants and contracts during 2017-2018 [1]. Assuming they are generating an equivalent amount of value in knowledge evenly distributed over time, the loss of one day of research would be ~$3.9M. So, if the the last whole organization backup was one day ago and the attackers were only able to stop access to the last day of work since they did not think to corrupt the backups before they went out, then the ROI of paying off the ransom would be ~3.43. If they were able to affect the entire organization for an entire week, then the cost would be ~$27.3M with an ransom ROI of ~24.

So, assuming they did any damage of consequence, asking for ~$1.14M seems like robbing a person at gunpoint for their pocket lint.

[1] https://www.ucsf.edu/news/2019/02/413396/ucsf-top-public-rec...

Post reply on HN