Reviews
I visit the…read morelibrary frequently, and have previously given them a good review for the service side of the house.
Today's review is regarding the IT side of the house, and inability/refusal to respond to security incidents*. On 2/16/23, while using library services it was discovered access to files from other users, files not from my session were available to me. Timestamps indicated they were from 2/13 & 2/14, a couple of days prior. Files included receipts from ride services, and tax data for at least one user. This was brought to the attention of the resident IT person "Andrew"(IT) and Reference Desk staff.
IT accepted the feedback on the discovered misconfiguration and made some dismissals regarding open support tickets with vendors. Those would not address the topic raised on 2/16.
IT was offered a temp fix to implement until such time as a more permanent solution could be designed and implemented for the library patrons Any solution would need to isolate user sessions TO THE USER, with zero ability for one user to access any other users data.
On 2/18/23 similar file/data leak behaviors were discovered, tested, and communicated to the reference desk personnel after the front desk refused to hear the reports. Reference Desk personnel attempted to dismiss these reports as insignificant due to "no one else saying anything", and "feeling that IT has kept the library 'safe'".
Additionally discovered on or about 2/18/23 was a local school student account being logged into windows mail since roughly 08/2022.
A request for a form to write up and report the findings to IT directly was not available, indicating reference desk would need to "email IT about the issue". It should be noted that if non-technical staff dismiss technical issues, the communication would not occur. If non-technical staff dismiss reported information Security Incidents, the report to IT would not occur. Additionally, filtering incidents like this through unqualified staff may reasonably result in further Information Security incidents and possibly lawsuits, should no corrective actions be taken and any exploitation were to occur.
An offer to write up the vulnerability report, and to perform a full vulnerability assessment were given to Reference Desk personnel, both were dismissed.
It was indicated that the person making the report is the problem, not any perceived or actual security incidents. It should be noted we learn to "see something, say something, do something" regarding work-related safety violations. We also learn "If you see something Say something"** regarding suspicious and/or criminal activities to local law enforcement. The Library report process seems to disregard best practices in favor of feelings. it was observed yelp, a public business/service review website, was blocked ON library computers. That block would not prevent a public review where a private report was handled inappropriately. Library personnel were informed of this report prior to posting, and scoffed at the notion.
*Information Security Incident reports are essential for receiving, processing, and resolving various technical issues as they are uncovered.
Misconfigurations and staff fatigue may be understandable. Refusal to take reports is not.
https://www.embroker.com/blog/top-10-cybersecurity-threats-2022/
**OSHA, DHS, and IT Security Compliance advocate reporting safety, security, suspicious activity concerns IMMEDIATELY/ASAP.
https://www.metacompliance.com/blog/cyber-security-awareness/incident-reporting-and-why-you-need-it