Live data from Hacker News

Patient details of 'any Australian' for sale on darknet

theguardian.com

21–30 of 58 posts

Re: Patient details of 'any Australian' for sale on darknet

#21
post #5

Earlier quoted context omitted.

My guess, based on what's publicly available, is that this incident is quite possibly just a set of stolen or misused creds for a fairly widely available Medicare card lookup database used by doctors. In which case, this is less of a "cyber security" issue and more an issue with fundamental system design/requirements. But we'll see.

One way to avoid this would be to limit the access of a doctor to patient records. Unless you give permission at a doctor/hospital to have them access your record, they won't be able to do a lookup. Retract the permission automatically/renew it once every X months. This would make stolen/misused creds a much smaller risk.

This runs into problems when the patient can't give permission e.g. because they are unconscious.

Re: Patient details of 'any Australian' for sale on darknet

#22
post #5

Earlier quoted context omitted.

My guess, based on what's publicly available, is that this incident is quite possibly just a set of stolen or misused creds for a fairly widely available Medicare card lookup database used by doctors. In which case, this is less of a "cyber security" issue and more an issue with fundamental system design/requirements. But we'll see.

One way to avoid this would be to limit the access of a doctor to patient records. Unless you give permission at a doctor/hospital to have them access your record, they won't be able to do a lookup. Retract the permission automatically/renew it once every X months. This would make stolen/misused creds a much smaller risk.

So, this isn't access to patient records as such - it's merely access from a name to a Medicare number.

Additionally, how exactly are you going to get the patient to give permission beforehand? Patients will expect to walk into a medical clinic, hand over their card, and have it all just work.

Re: Patient details of 'any Australian' for sale on darknet

#23
Wait, this is 75 records? What kind of leak is that? Seems far more likely to be one user accessing data over an insecure network and having that session captured, or similar one-instance leak. But on the other hand...what are the odds this journalist was one of a random 75 records?

Re: Patient details of 'any Australian' for sale on darknet

#24
post #6
post #2

TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…

> We had the famous census night access issues due to a DDoS and I am just waiting for that data to leak That wasn't a DDoS, that was a few million Australians trying to use a poorly implemented system.

I thought they blamed a DDoS by unknown parties in addition to the unexpectedly high load of us all trying to access it?

Re: Patient details of 'any Australian' for sale on darknet

#25
post #9

Anyone have any feasible monetization schemes for personal healthcare data?

Identity theft. Medicare cards are used as a form of official identification by government here and it's photoless. Make a convincing fake with coherent details and I'm sure it'd be a handy stepping stone.

Granted, it's local to AU which makes it small fry on a worldwide data black market scale.

Re: Patient details of 'any Australian' for sale on darknet

#26
post #11

Earlier quoted context omitted.

The lesson there is that people have unrealistic budget and schedule expectations of large IT projects. Same with defense, medicare, etc.

I think it's just with everything. I saw a tweet once that was something like: "If you ask a programmer how long an hour will take they'll tell you 45 minutes"

That's because they only count the part that they're working on. The rest of the Hour project includes standups, testing, documentation, deployment, retrospectives and post-mortems, team happy hours, ...

Re: Patient details of 'any Australian' for sale on darknet

#28
post #24
post #6

Earlier quoted context omitted.

> We had the famous census night access issues due to a DDoS and I am just waiting for that data to leak That wasn't a DDoS, that was a few million Australians trying to use a poorly implemented system.

I thought they blamed a DDoS by unknown parties in addition to the unexpectedly high load of us all trying to access it?

They tried blaming it on that, but it was just incompetence. They didn't even buy DDoS protection services.

There's more details on the inside story of the Census here: https://risky.biz/censusfailupdate/

Re: Patient details of 'any Australian' for sale on darknet

#29
post #6
post #2

TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…

> We had the famous census night access issues due to a DDoS and I am just waiting for that data to leak That wasn't a DDoS, that was a few million Australians trying to use a poorly implemented system.

Risk Biz has more details [1].. Recommend the podcast!

* IBM and the ABS were offered DDoS prevention services from their upstream provider, NextGen Networks, and said they didn't need it.

* This plan was activated when there was a small-scale attack against the census website.

* Unfortunately another attack hit them from inside Australia. This was a straight up DNS reflection attack with a bit of ICMP thrown in for good measure. It filled up their firewall's state tables. Their solution was to reboot their firewall, which was operating in a pair.

* They hadn't synced the ruleset when they rebooted the firewall so the secondary was essentially operating as a very expensive paperweight. This resulted in a short outage.

[1] https://risky.biz/censusfailupdate/

Re: Patient details of 'any Australian' for sale on darknet

#30
post #20

Earlier quoted context omitted.

Is there at least ONE country where IT projects are successful and with a normal price tag?

Estonia[0]. [0] - https://e-estonia.com/

I actually own the e-residency card, but forgot about the country. :-D
Post reply on HN