Earlier quoted context omitted.
My guess, based on what's publicly available, is that this incident is quite possibly just a set of stolen or misused creds for a fairly widely available Medicare card lookup database used by doctors. In which case, this is less of a "cyber security" issue and more an issue with fundamental system design/requirements. But we'll see.
One way to avoid this would be to limit the access of a doctor to patient records. Unless you give permission at a doctor/hospital to have them access your record, they won't be able to do a lookup. Retract the permission automatically/renew it once every X months. This would make stolen/misused creds a much smaller risk.
Patient details of 'any Australian' for sale on darknet
21–30 of 58 posts
Re: Patient details of 'any Australian' for sale on darknet
#22Earlier quoted context omitted.
My guess, based on what's publicly available, is that this incident is quite possibly just a set of stolen or misused creds for a fairly widely available Medicare card lookup database used by doctors. In which case, this is less of a "cyber security" issue and more an issue with fundamental system design/requirements. But we'll see.
One way to avoid this would be to limit the access of a doctor to patient records. Unless you give permission at a doctor/hospital to have them access your record, they won't be able to do a lookup. Retract the permission automatically/renew it once every X months. This would make stolen/misused creds a much smaller risk.
Additionally, how exactly are you going to get the patient to give permission beforehand? Patients will expect to walk into a medical clinic, hand over their card, and have it all just work.
Re: Patient details of 'any Australian' for sale on darknet
#23Re: Patient details of 'any Australian' for sale on darknet
#24TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…
> We had the famous census night access issues due to a DDoS and I am just waiting for that data to leak That wasn't a DDoS, that was a few million Australians trying to use a poorly implemented system.
Re: Patient details of 'any Australian' for sale on darknet
#25Anyone have any feasible monetization schemes for personal healthcare data?
Granted, it's local to AU which makes it small fry on a worldwide data black market scale.
Re: Patient details of 'any Australian' for sale on darknet
#26Earlier quoted context omitted.
The lesson there is that people have unrealistic budget and schedule expectations of large IT projects. Same with defense, medicare, etc.
I think it's just with everything. I saw a tweet once that was something like: "If you ask a programmer how long an hour will take they'll tell you 45 minutes"
Re: Patient details of 'any Australian' for sale on darknet
#27Re: Patient details of 'any Australian' for sale on darknet
#28Earlier quoted context omitted.
> We had the famous census night access issues due to a DDoS and I am just waiting for that data to leak That wasn't a DDoS, that was a few million Australians trying to use a poorly implemented system.
I thought they blamed a DDoS by unknown parties in addition to the unexpectedly high load of us all trying to access it?
There's more details on the inside story of the Census here: https://risky.biz/censusfailupdate/
Re: Patient details of 'any Australian' for sale on darknet
#29TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…
> We had the famous census night access issues due to a DDoS and I am just waiting for that data to leak That wasn't a DDoS, that was a few million Australians trying to use a poorly implemented system.
* IBM and the ABS were offered DDoS prevention services from their upstream provider, NextGen Networks, and said they didn't need it.
* This plan was activated when there was a small-scale attack against the census website.
* Unfortunately another attack hit them from inside Australia. This was a straight up DNS reflection attack with a bit of ICMP thrown in for good measure. It filled up their firewall's state tables. Their solution was to reboot their firewall, which was operating in a pair.
* They hadn't synced the ruleset when they rebooted the firewall so the secondary was essentially operating as a very expensive paperweight. This resulted in a short outage.