Update on IT Security Incident at UCSF
ucsf.edu
ucsf.edu
I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes.
Point in time recoveries for the entire account would be nice add too but not having to fork over a million dollars in exchange for a few clicks sounds like a bargain. Hell we were setting up write-only S3 buckets for critical data stores 5+ years ago.
Gross incompetence, I'd fire everyone. A district-wide outage for a week, fine. A 1.4 million dollar check to get data that should have been archived somewhere GTFO.
There is no excuse for not having backups.
Nothing new, in a way: cut the spending on IT, lower quality, get incidents.
Meh.
In-house backups aren't that hard. The hardest thing is to make sure everything is getting backed up that ought to be, and actually test that it is, which is no different with cloud backups.
Poppycock. There's plenty of software that can do encrypted incrementals / differentials: Commvault, NetBackup, Veeam, tarsnap, Duplicity, ZFS snapshot send-recv,
They all require you to have a level of technical competence equivalent to what would be needed to implement the backups yourself.
And if you want 'consumer software' that offers cloud / offsite encrypted back, then Backblaze offers it in a very clicky-clicky fashion that most folks can handle with a bit of hand-holding:
* https://help.backblaze.com/hc/en-us/articles/217664688-Can-y...
As does Arq, with a documented file format:
* https://www.arqbackup.com/arq_data_format.txt
Every cloud-capable backup system (for consumers and enterprises) does encryption nowadays, so talking about 'data access' in the cloud is a straw man.
Assuming it's for an actual enterprise or at least large dept.
Source: Used to be a NetBackup engineer on enterprise accounts :)
How much productivity was lost from many dozens of people not being able to work because of lack of access, the IT resources that had to be extended to investigate the various options, and then the US$ 1M ransom eventually paid out.
For Want of a Nail:
This attitude leaves the victim paying millions in ransom. Look, Microsoft and Amazon probably have a better handle on security than your IT dept which is two people who also have to fix any issues like the WiFi not working or software not updating.
One day an account get's exploited and suddenly the backups are deleted and the systems are all encrypted remotely.
Cloud backups are not offline backups, if you want security use tapes or remote systems which turn on manually.
It is possible to use a cloud provider and also write an immutable backup.
Not if they still have backups that aren't cloud backups.
> Look, Microsoft and Amazon probably have a better handle on security than your IT dept which is two people who also have to fix any issues like the WiFi not working or software not updating.
And that's part of the problem, right? Your IT department isn't too bright, so they encrypt their cloud backups with a tool that does the encryption wrong, and the smarter engineers at the cloud provider know that it's vulnerable so now they can read your data when you thought they couldn't. Or you use a weak password for the cloud backup account and then some third party breaks in and gets them.
Not really a concern with a backup tape stored in a fire safe.
Just because the cloud provider is a big company doesn't mean the security is better. At the end of the day, they are a team of software engineers with all the usual people and org problems and can have usual human mistakes.
But cloud solutions are better in practice due to totally non-technical reasons. Here's how -
If UCSF can afford to pay millions in ransom, they can definitely afford to hire the right experts to do their IT systems properly.
It is likely that they hire the right people, but then the most commonly recommended security policies were considered but not implemented due to resistence from powerful non-security team members inside the organization. (Usually, the highly paid CISO is playing politics with peers to keep the job by ignoring those security experts).
If it also possible that the IT+security team is incompetent and is only good for deploying expensive but useless vendor solutions that do a lot of security theater but do very little to improve actual security. Also possible that the vendor solutions are susceptible to be misconfigured easily to become insecure.
Public cloud solutions can help overcome these above shortcomings of in-house security+IT teams in a org politics friendly manner.
The problem there being that the choice of "public cloud" is subject to all the same forces, so then the vendor with the best corporate marketing team gets the business even if their security is crap.
Which is why you encrypt the data before sending it over the wire. Just like how you'd use encryption on LTO tapes before sending them offsite.
Or just use a non-Windows file server that supports snapshots: NetApp, Isilon, FreeNAS, etc.
If an end-user devices gets infected, and then encrypts mapped drives under the credentials of the user in question, that won't do anything to the read-only data.
Snapshots are not backups, but for a lot of the most common situations, they offer a convenient, quick win so people can move on with their day (often in a self-service fashion by just going into a .snapshot/ directory).
Researchers may be generating or churning through countless TB of intermediary data, scratch files, etc. Often, the people who actually run the it infrastructure for researchers are... grad students. Sometimes they have grants for hardware and tight budgets, and paying anything for backups isn't part of it. Sometimes, if you're lucky, the it department will be aware of the work and allowed to help.
Now maybe that's not the case here, and there really is one department responsible, and that department decided against spending money on backups. Well maybe they were told by the provost or the dean of whoever that they couldn't afford to back up everything, so they should just stick to file servers. Maybe the boxes compromised here are compute only, and all code and valuable artifacts are expected to be stored safely somewhere else. And maybe the researchers heard this and understood it when they agreed to use the system. But maybe the new grad student didn't get the memo and developed his model in vim on the compute node.
The point is, academic computing is kind of the wild west. Weird fiefdoms and weird restrictions, budgetary and otherwise. It's tough to guess which of these scenarios played out from the outside and we really can't know whether the CISO or CTO, or even anybody working for them, dropped the ball.
And no, snapshots weren't an option on a legacy clustered filesystem that they wouldn't migrate from.
Was trying to think through scenario's like that as well, but they don't really make sense.
If various staff members created a few weeks (or even months) worth of work on storage that isn't backed up, then the response from mgmt would generally be "Bad luck, you'll need to redo it".
But mgmt decided that work was worth paying US$1.1M+ for, and copping the reputation damage.
So, it's a weird mix of potential scenarios to actually get that happening. ;)
Maybe someone internal was actually responsible for that malware and is going for some kind of weird payday?
Thinking of them as "staff" is the thing. If the random grad student is doing the work the pi really needs done, and deadlines are approaching, then other people's reputations are suddenly on the line. And maybe there's a deadline for a grant that would bring in millions that couldn't be met without that data. Would you pay a million now for much more grant funding?
And maybe that ransom money simply comes out of a different financial pot, but the purse strings are loosened for an important faculty member. Maybe the faculty member is hugely important but runs their own shop for vanity reasons, (which the it department really hates, by the way), but when the faculty member gets in trouble he can pull rank and raid the it department budget for the ransom.
The incentives and power structures in these organizations are complex. And the egos are huge.
https://sanfrancisco.cbslocal.com/2017/02/28/ucsf-tech-worke...
Fire the leadership from the top down. Every one approved outsourcing the IT staff.
> This move will save UCSF $30 million over the next 5 years.
So they're ahead?
I'm being slightly snarky here, but also earnest. If they save 30 but lose 1.14 isn't it worth it?
The 1.14M is just the ransom, doesn't account for how much money was wasted on other aspects of recovery and total downtime...
Are you asserting that the breach would not have happened if the IT operations were in-house? Could you also clarify why did you feel it necessary to qualify the location of outsourcing? If the project was outsourced to any other country besides India, this would not have happened?
I think the emphasis is on the fact it was outsourced to another country; you can't generally check the credentials of someone on the other side of the world very easily. The University of Delhi probably has good IT staff, but “Delhi International Computer Help”? Probably not.
If that were true, we would not have any trust in global trade. There are plenty of IT companies that have all American IT workforce and still have suffered data breaches. The issue at hand is not checking someone's credentials here. The issue is the political undertone that OP has taken.
Anything from restricting program capabilities/permissions for external executables, to keeping "colder" backups of business-critical data, to monitoring and responding to software that looks like it's traversing the whole filesystem, could reduce the harm ransomware causes.
EDIT: I should mention that I've managed IT services for a major private university earlier in my career, and I am now a software security consultant. When I say it is not possible, I mean that pragmatically. A FAANG company can control their IT well enough to make sure this doesn't happen to them, but a hospital or university relies on computer systems running software way outside of their control. That MRI machine? Its controller is probably running some ancient version of Windows Server 2003 with proprietary drivers. That university registration app? Custom coded by generations of CS student interns running on a shared system whose operating constraints are set by the Novell GroupWise instance that is co-hosted on it.
As a practical matter, one of these organizations simply cannot reduce their risk to zero or near zero. There's too many attack vectors they don't have control over. The IT departments can't mandate proper security because they don't have the budget to enforce.
And honestly, having even week-old cold backups makes this kind of attack _considerably_ less scary and cheaper, and it enables you to skip the payout (and I'm on the same page as you on that — if there's no money to be made, ransomware attacks will drop off).
like USC's
UCSF is University of California, San Francisco. USC is University of Southern California, a private school.Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!
... "lock" data in place rather than sell it to the highest bidder.
Why not both? And once the rightful owner of the data has paid a fat ransom, surely that's got to provide some kind of proof of its market value. The University did say that The attackers obtained some data as proof of their action
so unless they're logging their outbound traffic, who's to say they didn't exfiltrate all of it? It's the kind of thing that the University would remain tight-lipped about unless they were either sure that it hadn't happened (doubtful, seeing as they aren't running a tight ship) or had some kind of mandatory reporting obligation for the data.First of all, they are increasingly selling the data. They exfil first, lock second.
Second of all, these wonderful criminals are targeting all manners of institutions, not just large universities.
Proper data hygiene at large enterprise levels is, in fact, exceedingly difficult.
Proper data hygiene at large enterprise levels is, in fact, exceedingly difficult.
Creating a hermetically sealed IT environment where only way to exfiltrate data that remains is the employees eyeballs is definitely possible and is increasingly done well by a lot of large organizations.Defending against insider threat (malicious employees) is still a challenge for most civilian (non-military) organizations.
(also, this should reduce the amount that actually goes to the bad guys, since the amount of ransom would have greater downward pressure, i.e. if they'd probably not be able to collect more than $0.57M because that would cost UCSF $1.14M)
Also, it may not make the costs to them more. Remember the amount of ransom is based on what the ransomers think the ransomees are willing to pay. Today, the reason it was 1.4 million instead of 2.8 million, is that they didn't think UCSF would pay the latter amount. So if they knew UCSF would have to pay double the amount of the ransom, they'd have to only ask for half as much.
This would serve three purposes: help fund those things that are costly, deter the bad guys (since they can't ask for as much money if paying a ransom is going to be twice as costly to their victims), as well as to add additional incentivize people to secure their systems.
I don't know what you mean by ""catching bad guys" is just a pretense". Pretense for what? By who? That sounds very conspiracy minded.
Pay a fine to whom? UCSF is a state institution.
Many of the other recent examples are cities, counties, and so on.
Some universities generally have done better about such things and are making progress... but generally there is a push and pull for IT dollars by unversity departments who want to spend that money as they wish for their given programs and then that money comes FROM IT ... who down the road are then tasked with the costs related to maintaining it and the terrible decisions a department made in the meantime... or in the worst of cases tasked with securing that data and / or making it work at all.
It's the same story for IT in the private sector to some extent, but it is way worse at many universities. Imagine if your HR director got to pick the PCs to support, networking equipment, software, backup methods (if any) all on their own and wanted zero input. That's kinda how it is at many universities.
I spent months helping a large university dig out from a program where they hooked up some super special microscopes worth millions of dollars ... to low grade network switches and storage. I got to try to explain why you can't put 10,000 pounds of data into a borderline consumer grade network ... in all of a couple milliseconds.
While you're not necessarily wrong, another option is budget.
If this is academic- / research-generated data, then it could have been paid for by grant money, and most of the cash goes to paying grad students and perhaps some computer equipment.
IT may have chargebacks (they have bills / cost centres to pay too after all), and no one wants to "waste" grant money. Often these things are 'shadow IT' run in an ad hoc fashion by just throwing together some PCs.
If the group's expertise is in medicine / biology, how many members want to give up their day-light research hours to run the computer infrastructure?
I've spent about half my IT career in the academic sphere, and cheap solutions can be a fight to implement even if they solve the problem; even free (open source) ones can be an effort if they take time or slow down the workflow.
And these people aren't stupid: they 'know' they should do some of these things. But people 'know' they should get exercise, and how many folks do that?
I actually know a few people working on their PhD’s that have nothing backed up.
Their advisors buys servers, the university’s IT sets them up, they get access to it and work on it without backups, local copies or anything.
They have grants that they may have to provide results for.
As time passes, there are more people working in that lab that get access to the machines. Multiple projects being worked on for multiple grants.
I also know people running unsecured stuff on public ports for easier access.
Another thing, it could be that the data sets they where working on where given to them under a condition that they wouldn’t be shared, exposed or something.
I don’t know anyone in medicine or healthcare and no one at this university, but that’s what I’ve seen from people I’ve met throughout the year.
(I have also seems people loose their thesis because their laptops died on them and they didn’t have a backup or for their Word file getting corrupted.)
Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?
If news gets out that even if you pay the ransom you won’t get the decryption tools then no one would pay the ransom and the hackers get no money at all.
Friend of a friend said it was probably the most "customer" focused organization they've ever fought against
Once you’ve paid the Danegeld, you’ll never get rid of the Dane.
One thing I hadn't realized before was that ransomware criminals has developed their own backup strategy:
- in addition to encrypting the data they will also exfiltrate it and threaten to publish it ob the internet for everyone to see.
That way it doesn't necessarily help an organization just because they have multiple layers of offsite read-only backups.
https://www.trialsitenews.com/hacking-group-launches-success...
UCSF received $1.43B in grants and contracts during 2017-2018 [1]. Assuming they are generating an equivalent amount of value in knowledge evenly distributed over time, the loss of one day of research would be ~$3.9M. So, if the the last whole organization backup was one day ago and the attackers were only able to stop access to the last day of work since they did not think to corrupt the backups before they went out, then the ROI of paying off the ransom would be ~3.43. If they were able to affect the entire organization for an entire week, then the cost would be ~$27.3M with an ransom ROI of ~24.
So, assuming they did any damage of consequence, asking for ~$1.14M seems like robbing a person at gunpoint for their pocket lint.
[1] https://www.ucsf.edu/news/2019/02/413396/ucsf-top-public-rec...
The encryption is done on the user's machine using their processing power, and there's virtually no downside for you (either they pay and you decrypt or they don't and you just dissapear).
Ransomware will be an issue for years to come.
I am saying that that the ransom is hilariously small compared to what they would probably be able to get. So, when they realize they can actually ask for a number that is not a rounding error they will probably increase the number/outcome of attacks. They are criminals robbing people at gunpoint and only asking for their pocket lint. Once they all realize they can ask for a wallet and get it, I think the number is going to go way up.
If they keep asking for $1M from organizations that will pay because that’s pocket change, the more organizations they can attack.
If they start asking for too much, they’ll see they won’t pay as quickly, other people will start selling services to protect against you that seem more attractive, etc.
At a guess, they could probably have put in a some fairly high quality storage + backups for that price, and still had money left over for all expenses paid staff vacations. :)
You could have some sort of alert in place, but if the malware doesn't write fast enough to trigger it, you'd still miss the problem.
Generally, the approach places take is having backups (eg to tape, off site, etc), and/or having storage that makes a snapshot every few hours and retains them for days/weeks/months.
Snapshotx are generally very low cost and easy these days, as it's just a pointer manipulation thing on (say) ZFS rather than a complete copy of the entire data set.
It would still be nice to restrict encryption on a system that you control. I suspect, but don't know, that encryption has a particular pattern of memory and CPU activity that could be recognised. Or if there are a few commonly used libraries you could do it that way, although an attacker could roll their own encryption.
Seems like business is blooming.
https://www.reuters.com/article/us-cybercrime-netherlands-un...
At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered.
But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?
Perhaps the health of some businesses is so important that they should be protected by, ahem, state-backed insurance paid for by the taxpayer?
They also won't tell you how much they paid out...
Anyway, I wonder how this payment was made...
This is a very selfish thing to do, as you encourage the authors of such attacks.
I assume you read that though before you replied, right?
They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete.
https://sanfrancisco.cbslocal.com/2017/02/28/ucsf-tech-worke...
If that were me, I'd organize and have everyone quit; let them figure things out. Screw the pittance of a severance.
Sometimes this is hidden under the guise of big IT modernization projects. The company transitions or consolidates towards ERP platform X. It is a huge operation that touches almost every part of the business. Armies of analysts are brought in to map the AS-IS business operations, the system is developed, once stable enough, the other shoe drops and the whole IT department is now moved off- or near shore to the company that transitioned the system while other 'non-strategic' parts of the business are 'streamlined' into managed service contracts with other parties in the project consortium.
Be careful here... due to "freedom to choose" legislation targeting unions, it may be illegal for you to "organize labor" in your state...
https://www.latimes.com/business/hiltzik/la-fi-hiltzik-uc-vi...
Wait
Oh no...
The recent H-1B suspension probably goes too far the other way -- the program needs more safeguards against abuse rather than to be discontinued -- which requires a legislative solution (auctioning off the slots seems promising). But the legislators are apparently too busy flinging their own scat at each other right now because it's an election year. In the meantime it might not be such a bad thing to fail closed rather than fail open, given the effect of the lockdowns on the unemployment rate.
A large percentage of H1Bs go to "bodyshops", which import workers from abroad to temporarily work at companies that are offshoring their employees. Yes, it's perverse; they are in effect being used to replace American workers, but not explicitly.
Based on the specifics of my comment and the context of the article at hand, I don't understand how your point ties to my comment and do not appreciate the insinuation it brings.
1. H1B ties employees to a specific employer. This bonded labor prevents free labor movement. This allows the employer to exert tremendous control over the employee. Free labor movement is important to discourage employers from depressing wages for American workers.
2. H1B is allowed to participate in the EVC model. This would be fine if the H1B was not tied to the employer and instead it belonged to the employee. In absence of this, it explicitly allows exploitation of H1B workers hurting American employees.
3. H1B is dual-intent non-immigrant visa and is the first step to permanent residence. The employer dangles this carrot and exerts further control over employees. The long wait times (on the order of a decade or longer) due to the greencard backlog for certain countries (primarily India, China, etc.) make it worse. More importantly, the employer can rescind the application throughout this process and completely destroy the employee's professional and personal life.
4. Outsourcing companies will not start the greencard process for H1B employees until they're in the 5th year of H1B. Combine this with the 10+ years wait for certain employees, ties the employee to the employer for at least 15 years.
5. Until recently, employers could've rescinded the H1B any time and the employee had to exit the country immediately (no grace period). It was only recently that the US government gave a 60 day grace period for H1B visa holders. Imagine how a human being would feel if they have lived in the country for a decade, making their lives here, having to wind up and leave within a few days or even 60 days. Its simply inhuman. However, this is where we are right now.
This issue is more nuanced than it looks like but the underlying problem is due to the fact that the H1B visas and permanent residence process is tied to employers. If we look at visa programs in pretty much any other country, visas belong to employees, their PR process is between the government and the individual applying for the PR. The employer has very little control over the employees. This is why such large scale exploitation doesn't exist in other parts of the world.
There have been attempts over the years to fix this issue. The infamous Neufeld memo tried to eliminate the EVC model. Unfortunately, that did not fly and was eventually rescinded. Honestly, a tiny percentage of H1Bs are used by tech companies that genuinely treat their employees well. If you eliminate the bottom 80% of the H1B employees, EVC companies will shut shop and you'll also hurt foreign new grads.