Live data from Hacker News

LifeLabs pays ransom after data breach affecting up to 15M Canadians

theglobeandmail.com

1–10 of 53 posts

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#2
If you don’t live in Canada, you might not know that LifeLabs has a virtual monopoly on the lab business. If your doctor wants you to take a blood test, you go to LifeLabs.

Whomever broke into their systems knows a great deal about the private health information of a large fraction of Canadians.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#3
One thing people propose is criminalizing paying ransoms. I feel like this is short minded in that it may prioritize hig value targets like hospitals. I don't have a good answer for how to avoid issues like criminals prioritizing health/ life companies. In general maybe raising the idea the targeting hospitals makes you less than human might help.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#4
Just a few months ago I had to take a series of tests with LifeLabs (blood, urine, physical, etc) to update my immigration papers. Did you know you cannot choose where to take these tests? You are more or less forced to use LifeLabs because the doctors designated by the IRCC (Immigration, Refugees and Citizenship Canada) only partner with LifeLabs to do these tests, it’s an ugly monopoly that is impossible to fight as an immigrant. I knew, from the moment I walked in the laboratory, all the information I was handing and the data they were going to find was going to be leaked sooner than later.

I have tried more than once to make secretaries, assistants and nurses to understand how bad most of their systems are and how easy it is to expose the information of all their patients to malicious actors, but arguing with them is pointless because they barely understand what I am talking about or do not have the power to change anything. And the worst thing is, I have to visit LifeLabs again next month for another physical checkup and to take some X-rays and these news will not change anything.

Side note…

I used to work as a malware researcher for a security information company in the US. One day I remembered the story of Sisyphus:

> In Greek mythology Sisyphus was the king of Ephyra (now known as Corinth). He was punished for his self-aggrandizing craftiness and deceitfulness by being forced to roll an immense boulder up a hill only for it to roll down when it nears the top, repeating this action for eternity — https://en.wikipedia.org/wiki/Sisyphus

I ended up quitting my job no long after reading this story because it made me realize I was fighting an endless fight.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#5
post #3

One thing people propose is criminalizing paying ransoms. I feel like this is short minded in that it may prioritize hig value targets like hospitals. I don't have a good answer for how to avoid issues like criminals prioritizing health/ life companies. In general maybe raising the idea the targeting hospitals makes you less than human might help.

Why would criminalizing paying ransoms cause attackers to target hospitals? I would think hospitals would have a fairly strict compliance effort, whereas Joe Schmoe probably never even heard that it's illegal to pay a ransom.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#7
“For customers who are concerned, LifeLabs has offered to cover one year of data protection that includes dark web monitoring as well as identity theft insurance.”

That’s it? If I was Canadian I’d want to see execs going to jail and or their contract yanked. If they switched over to using a webapp or chromeos on the desktop things would probably be much more secure.

But that’s not going to happen, cuz it’s owned by the pension system.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#8
post #2

If you don’t live in Canada, you might not know that LifeLabs has a virtual monopoly on the lab business. If your doctor wants you to take a blood test, you go to LifeLabs. Whomever broke into their systems knows a great deal about the private health information of a large fraction of Canadians.

Do they perform some back-office analysis function for Quebec's public health system, or is this get another way Quebec is different from the rest of Canada?

Here in Quebec we generally get our blood drawn for tests at a local public clinic called a CLSC, and can eventually view the results in a public government web system, but I'm not sure where the actual analysis happens.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#9

Just a few months ago I had to take a series of tests with LifeLabs (blood, urine, physical, etc) to update my immigration papers. Did you know you cannot choose where to take these tests? You are more or less forced to use LifeLabs because the doctors designated by the IRCC (Immigration, Refugees and Citizenship Canada) only partner with LifeLabs to do these tests, it’s an ugly monopoly that is impossible to fight a…

There's something in this story that doesn't ring true.

You knew from the moment you walked into the laboratory that their data handling practices were inadequate and prone to being hacked/leaked. How?

You tried to explain this to their secretaries and nurses. Why bother when it's obvious they can't/won't do anything about it? Why not contacting their management or IT?

Post reply on HN