Data breach notification – 2-24-2017

All

Background – A “data breach notification” email went to customers today from a Security Analyst in the Information Security office.

A service called CloudFlare was impacted.

Per standard procedure, please call the customer first. If you don’t connect with them, leave a voicemail and send them the e-mail template.

Ticket update / e-mail template

That has been added to the ticket update templates under “Spam/phishing” called “Data breach 2-24-2017”

The contents of that e-mail template is below. A standard response for discussions with customers/e-mail template is below.

As expressed in the voice mail I left you, this is a legitimate concern. The message about “data breach” is legitimate.

A key common technology used by the list of websites you saw in the email was compromised. We recommend changing the passwords on those sites if you use *any* of them. Our previous message by no means implies you use all of those sites, you do probably use at least one of them.

If used the same password for any other account, including your Oregon State account, please change your password for those accounts as well.

Please give us a call if you have questions or need further information.

The master ticket is here:

https://oregonstate.teamdynamix.com/TDNext/Apps/425/Tickets/TicketDet?TicketID=b0mXxNhoCFg_

Please link tickets to it.

Langton New Core Move

Langton hall will be moving to the new core network this evening. This is a relatively small migration (around 40 hosts and three printers), covering Kidspirit and BPHS. After the move, hosts for either department should end up in the CN_IRS or CN_Printers container, in the “Small buildings” site (this “site” covers buildings not large enough to have their own switch). More details are available in the TD ticket, #2683198.

Changes to CN Request Forms

Please note that I have made the following changes to CN request forms:

  • Occasionally technicians ask customers to fill out a form and would like to be notified when this happens. To facilitate that, I have added a field called “Technician to notify” at the bottom of all of the Drupal forms. If you see a ticket come in with that field set, please set Responsible to the designated technician.
  • Some forms had instructions to technicians in the form output. As this ends up in the ticket description and is emailed to the customer, I decided it was a bit awkward to include there. I have removed these instructions for now.
  • With one exception, I have removed this text from the email as it is also visible to the customer (and confusing): “The results of this submission may be viewed at: [submission:url]”

 

 

Windows Imaging Server (ISCS-MDT) Updates

The Windows imaging server (ISCS-MDT) has been updated to include the Campus Labs Windows 7 image and all software included on that image. If lab computers come to the build bench for any reason and need to be re-imaged you can PXE boot to MDT as you normally would and select the Windows 7 master image under the Campus Labs section.

Task sequences are now associated with IP subnet. For example, if a computer PXE boots on the CN or ROOTS build bench you will see the task sequence selection screen. If a computer PXE boots in one of the computer labs MDT will perform what’s called a “zero-touch” installation and automatically re-image the computer. This assumes the IP range or individual workstations in Cyder are pointed at the OSU-MDT-PXE workgroup.

DocuSign is Live

DocuSign is now in production and being used by the Food Innovation Center. Other groups will be added gradually. The IS Service Desk will provide tier 1 support for DocuSign.

DocuSign Training: Please watch the videos on the DocuSign training page in the sections “Overview”, “Signing” and “Sending”. Total time to watch the videos is about 15 minutes. I also recommend glancing through the DocuSign User Guide.

For information on the implementation, see the DocuSign project page. For information about escalating DocuSign requests see the DocuSign InfoSheet in ITKnows.

 

If you have any questions about this new service, please contact Kirsten Petersen.