Jump to content

Hackers post Hereford schoolchildren's data records on dark web


Recommended Posts

Posted

 

Not really... the report says that the school used remote access (probably RDP) and most likely a local MIS Sims database that was simple to leak once RDP had been compromised and credentials escalated.

 

We've moved away from both towards the cloud solutions for exactly this reason.

 

So, while I am vigilant and constantly look at this as well as our disaster and ransomware reaction plans, I'm not scared because as a school we've been prepared and taken action.

 

I urge every single school to ditch Sims and RDP.

Posted (edited)
Not really... the report says that the school used remote access (probably RDP) and most likely a local MIS Sims database that was simple to leak once RDP had been compromised and credentials escalated.

 

We've moved away from both towards the cloud solutions for exactly this reason.

 

So, while I am vigilant and constantly look at this as well as our disaster and ransomware reaction plans, I'm not scared because as a school we've been prepared and taken action.

 

I urge every single school to ditch Sims and RDP.

 

You’re making some assumption there.

 

Moving to the cloud means the risk is moved, not removed.

Edited by FN-GM
  • Thanks 1
Posted
You’re making some assumption there.

 

Moving to the cloud means the risk is moved, not removed.

 

Well yes... but the article does clearly say they had remote access open. It's been the same story in nearly all the school ransomware breaches I've looked into. RDP is the source.

 

It's a huge weak point, brought on by Sims not being cloud and people needing to open up their networks with RDP for teacher access.

 

Of course, Cloud doesn't solve the issues in that sense, but it does make it much harder.

 

As an example, I wouldn't even know how to grab our MIS database now without spending 3 months writing custom PowerBi reports haha. And thats if the hacker could get round modern Office 365 authentication and perhaps MFA as well.

 

Having the MIS local means copying perhaps a 4gb file in minutes using the credentials you already grabbed while hacking RDP.

Posted

I agree, moving to cloud MIS is the way. No need to worry about your SIMS server / clients anymore.

 

Here are some other benefits:

1. Save money on SIMS cloud backup service, if your school is using one.

2. Cheaper servers renewal - SIMS really likes that RAM / CPU.

3. No more SOLUS 3 DNS / updates issues or installing random SIMS patches outside of working hours.

4. No extra costs for Remote Desktop licenses.

5. No need for VPN / RDP.

6. For school using Google, cloud MIS is a perfect getaway to get rid of Windows computers and move fully to Chromebooks.

7. Extra security - 2 step verification to login to Cloud MIS.

8. Easy access to Cloud MIS for staff.

 

There are many more benefits, for IT it's mainly security and less maintenance.

  • Thanks 1
Posted (edited)
Always worth remembering one of your biggest vulnerabilities is people:

 

https://www.edugeek.net/showthread.php?t=219912

 

and your second biggest is resource constraints (staffing, funding, time).

 

My query would be "knowing the RDS box is compromised and would have been used as a beachhead to compromise the rest of the network, why did you leave a potentially compromised network connected to the Internet?"

 

Plug the router into a spare isolated PoE switch, offer basic WiFi for priority people and get SLT to deal with any whining.

 

(I mean I know the answer is likely 'due to whining by staff/SLT when that was proposed', but FFS)

Edited by pete
  • Thanks 2
Posted (edited)
I would try to choose my words carefully here but I take issue with the "The school has also appointed a specialist data protection officer." How about you employ a cyber security expert and not muddy the water on what that role needs to be focused on I think we have a long running post about devaluing IT... I too hope that this is not sat with what I bet is an over stretched and probably under funded and valued IT department and the head holds his hands up for his part to play in the whole situation over there. Edited by HPlum78
  • Thanks 1
Posted
You can secure RDP behind MFA for £0, if you've not, do it today

Sorry for possibly going off-topic, but how? Everyone i have spoken to says it requires extra licensing or 3rd party software?

Posted
I think focusing on "Cloud MIS" is the wrong thing to focus on here. You can have a cloud MIS and still get owned if it's not secured properly.

I've had blazing arguments with our council before when they threw the "But it's on the cloud, the government trust gsuite" line at me when I told them how they had its setup was completely insecure (Basically anyone with a google account could add anyone to their "Secure" storage & they wanted shared usernames/passwords (!!!!))

 

The line of thinking "It's on the cloud, so it's secure" is a dangerous mindset to get people into.

 

Strong authentication (eg MFA), strong ACLs, robust auditing/auditing, automatic lockouts & not exposing your core infrastructure straight to the web is key here.

 

I'd agree with this. I always advocate hugely for moving to cloud services but it isn't a magic "secure all the things" switch. It's perfectly possible to have a secure on-prem RDS farm and a leaky as heck modern cloud implementation depending on how well they're implemented.

 

Security starts with an honest appreciation of your org's exposure to risks and the cost of a risk being exposed, leading to properly designed security policies that are applied at all levels of your org, and technology being deployed according to well-planned and robust policies to adhere to those policies is only a small part of what needs to be done.

  • Thanks 3
Posted

We use RDP with MFA and also account locking after three bad tries. I don't want to use RDP but we have to until we make a decision on MIS within the 3 years we have on the ESS SIMS contract.

 

Teachers only grizzle about the account locking, but I won't be moved on it.

Posted (edited)
I could not agree more with @Roberto, hell just the other week MS themselves found out that a poorly configured storage account in Azure can expose your data/ your customers data! The cloud is as challenging and comes with a whole different set of challenges for security and I reiterate what others have said its not a silver bullet (or fire and forget) when it comes to security in someone else's data centre (The Cloud) you still have the same due diligence to ensuring you are secure. Edited by HPlum78
Posted
Could you elaborate, please?

 

Two methods

 

1) - You install the web client and hide it behind an Azure App proxy https://learn.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-integrate-with-remote-desktop-services

 

2) - You install the RD Gateway role and point it at an NPS server with the Azure AD MFA addon installed - Then users get a push notification when connecting. https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension

 

We do both - The azure app proxy for regular staff & then the RDGateway/Azure MFA method for those that need direct connection to their computers (Really just us, as in IT)

 

Before the official MS method came about, we used Ericom accessnow with a custom coded Azure MFA integration added.

  • Thanks 1
Posted
I'd agree with this. I always advocate hugely for moving to cloud services but it isn't a magic "secure all the things" switch. It's perfectly possible to have a secure on-prem RDS farm and a leaky as heck modern cloud implementation depending on how well they're implemented.

 

Security starts with an honest appreciation of your org's exposure to risks and the cost of a risk being exposed, leading to properly designed security policies that are applied at all levels of your org, and technology being deployed according to well-planned and robust policies to adhere to those policies is only a small part of what needs to be done.

 

Yup. You have to fight back at those that see moving stuff to the cloud as the solution for every IT problem ever - It isn't, it's just removing some problems but creating others.

The "cloud" is worthless unless someone sets it up properly. Partly why I didn't understand why so many techs worried it would cause them to lose their jobs, because the skillsets around managing services are still required, just different.

  • Thanks 1
Posted
Yup. You have to fight back at those that see moving stuff to the cloud as the solution for every IT problem ever - It isn't, it's just removing some problems but creating others.

The "cloud" is worthless unless someone sets it up properly. Partly why I didn't understand why so many techs worried it would cause them to lose their jobs, because the skillsets around managing services are still required, just different.

 

An example is the Frontier software data breach. 80,000 South Australian government workers had their data stolen. Plus many other organisations.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...