Live data from Hacker News

Patient details of 'any Australian' for sale on darknet

theguardian.com

31–40 of 58 posts

Re: Patient details of 'any Australian' for sale on darknet

#31

Original article written by the reporter who actually did the original research: https://www.theguardian.com/australia-news/2017/jul/04/the-m...

Ok, we'll change to that from http://www.news.com.au/technology/online/security/hackers-ar....

Re: Patient details of 'any Australian' for sale on darknet

#32

Wait, this is 75 records ? What kind of leak is that? Seems far more likely to be one user accessing data over an insecure network and having that session captured, or similar one-instance leak. But on the other hand...what are the odds this journalist was one of a random 75 records?

Given certain details they were performing lookups on demand for a price. This does not suggest server ingress, it implies lack of bulk exfil. Access to a logged-in authenticated session. Nothing like Google/Royal Free Hospital heist.

Re: Patient details of 'any Australian' for sale on darknet

#33
post #2

TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…

This is just as likely to be a rogue employee/sysadmin as it is a actual hack. I wouldn't start placing blame until it's determined what the actual cause is.

If it is an employee or sysadmin, they are an idiot.

Its $30 a pop for small volume and large risk. If you have a job with access to this data you should be charging a hell of a lot more. But its enough to get someone in a poorer country with little at risk to create a fake gmail account and use it to bootstrap access to an online self service portal or whatever approach they are using.

Re: Patient details of 'any Australian' for sale on darknet

#34
http://pwoah7foa6au2pul.onion/listing.php?id=224554

The data seems to consist only of ID numbers and expiry dates, not sensitive medical records as the somewhat sensational headline suggests.

Edit:

According to the description, details on pension recipients is absent, which might be a clue to its provenance.

Re: Patient details of 'any Australian' for sale on darknet

#35
post #26

Earlier quoted context omitted.

I think it's just with everything. I saw a tweet once that was something like: "If you ask a programmer how long an hour will take they'll tell you 45 minutes"

That's because they only count the part that they're working on. The rest of the Hour project includes standups, testing, documentation, deployment, retrospectives and post-mortems, team happy hours, ...

You forgot browsing HN -)

Re: Patient details of 'any Australian' for sale on darknet

#36
post #9

Anyone have any feasible monetization schemes for personal healthcare data?

Tabloid press looking for juicy info on those they want to monster could also be used to check celebs relatives for anything juicy.

One of the uk tabloids paid a lot for access to the medical records of Ian Brady (a notorious child serial killer)

Re: Patient details of 'any Australian' for sale on darknet

#37
post #33

Earlier quoted context omitted.

This is just as likely to be a rogue employee/sysadmin as it is a actual hack. I wouldn't start placing blame until it's determined what the actual cause is.

If it is an employee or sysadmin, they are an idiot. Its $30 a pop for small volume and large risk. If you have a job with access to this data you should be charging a hell of a lot more. But its enough to get someone in a poorer country with little at risk to create a fake gmail account and use it to bootstrap access to an online self service portal or whatever approach they are using.

Indeed. Assuming they have some kind of logs for legitimate use in place (X was logged in and requested X), how hard would it be to add a bogus record, request it and see who looks it up. If it's accessed and the logs are avoided, there's probably something leaky.

Assumption is a dangerous thing, however...

Re: Patient details of 'any Australian' for sale on darknet

#38
post #2

TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…

Privacy has never been a priority for the Australian government - its citizens simply don't have the right.

So there really shouldn't be much surprise over this. More importantly is that this story should educate Australians as to just how much their government values their privacy - sure, this will be hailed as a reason for even more political oversight over technological processes, but only for as long as there isn't a "legitimate corporate customer" for the Australian government, itself, to negotiate with, over ownership and control of this data.

Re: Patient details of 'any Australian' for sale on darknet

#39
post #2

TWO file photos of shady hooded figures with obscured faces and glitch art effects or other digital overlays put over the pic! Truly, this is a very comprehensive report about hacking indeed. On a serious note, I'm not at all surprised that my government's screwed up some sort of online database of private information. We had the famous census night access issues due to a DDoS and I am just waiting for that data to l…

EDIT: Nevermind, the URL was changed my mod.

---

> TWO file photos of shady hooded figures with obscured faces..

Where are these photos? I see only one of a medicare card, and another of the 'auction'.

Re: Patient details of 'any Australian' for sale on darknet

#40
post #24

Earlier quoted context omitted.

I thought they blamed a DDoS by unknown parties in addition to the unexpectedly high load of us all trying to access it?

They tried blaming it on that, but it was just incompetence. They didn't even buy DDoS protection services. There's more details on the inside story of the Census here: https://risky.biz/censusfailupdate/

"DDoS protection services" are a racket. Build the thing right and you don't want or need them.
Post reply on HN