Live data from Hacker News

LifeLabs pays ransom after data breach affecting up to 15M Canadians

theglobeandmail.com

11–20 of 53 posts

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#11

Just a few months ago I had to take a series of tests with LifeLabs (blood, urine, physical, etc) to update my immigration papers. Did you know you cannot choose where to take these tests? You are more or less forced to use LifeLabs because the doctors designated by the IRCC (Immigration, Refugees and Citizenship Canada) only partner with LifeLabs to do these tests, it’s an ugly monopoly that is impossible to fight a…

There's something in this story that doesn't ring true. You knew from the moment you walked into the laboratory that their data handling practices were inadequate and prone to being hacked/leaked. How? You tried to explain this to their secretaries and nurses. Why bother when it's obvious they can't/won't do anything about it? Why not contacting their management or IT?

> You knew from the moment you walked into the laboratory that their data handling practices were inadequate and prone to being hacked/leaked. How?

The laboratory is divided into small rooms where the patient talks with the nurse and/or doctor, each room looks something like this [1] along with a computer that is connected to whatever system LifeLabs uses. When I arrived for my appointment the nurse left me alone in the room for approximately 15 minutes, the computer was on, and the user session (which I believe was created using the doctor’s credentials) was still alive, I could have done a lot with that computer while the nurse was outside checking the other patients.

Later, the doctor came to do the initial physical checkup and then left for another 10-15 minutes to talk with another nurse. This gave me more time to “snoop around” and in fact, I took the opportunity to take a picture of the computer screen [1]. Ironically, you can see in the picture that the doctor uses a Post-it Note to cover the webcam, which means they do care about their privacy but not the privacy of their patient’s.

You may think “this is not LifeLabs fault but the doctor’s fault” but this is how social engineering works and as people say “A chain is only as strong as its weakest link”.

> You tried to explain this to their secretaries and nurses.

> Why bother when it's obvious they can't/won't do anything about it?

> Why not contacting their management or IT?

Yes, good point, but this doesn’t disprove the rest of my anecdote.

[1] https://en.wikipedia.org/wiki/Doctor%27s_office

[2] https://i.imgur.com/c0tXTEK.png

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#12

“For customers who are concerned, LifeLabs has offered to cover one year of data protection that includes dark web monitoring as well as identity theft insurance.” That’s it? If I was Canadian I’d want to see execs going to jail and or their contract yanked. If they switched over to using a webapp or chromeos on the desktop things would probably be much more secure. But that’s not going to happen, cuz it’s owned by t…

Yeah, it's disgusting. I'm not sure how "1 year" of "fraud protection" coverage and the like became the defacto response of corporations who suffer breaches.

Also wonder how motivated they are to do security right if insurance covers it: In an interview, LifeLabs CEO Charles Brown said the company had purchased cyberinsurance, but did not provide details on the coverage.

It makes me sad to see Marriott, Equifax and others skipping along with stocks at near record highs and little long-term impact from their incidents.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#13
post #2

If you don’t live in Canada, you might not know that LifeLabs has a virtual monopoly on the lab business. If your doctor wants you to take a blood test, you go to LifeLabs. Whomever broke into their systems knows a great deal about the private health information of a large fraction of Canadians.

New title: All your medical lab results are belong to us

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#14
post #2

If you don’t live in Canada, you might not know that LifeLabs has a virtual monopoly on the lab business. If your doctor wants you to take a blood test, you go to LifeLabs. Whomever broke into their systems knows a great deal about the private health information of a large fraction of Canadians.

From their website, it looks like they only operate in Ontario and BC, perhaps Saskatchewan. I certainly haven't seen one here in Alberta, unless they operate under a different name.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#15

Just a few months ago I had to take a series of tests with LifeLabs (blood, urine, physical, etc) to update my immigration papers. Did you know you cannot choose where to take these tests? You are more or less forced to use LifeLabs because the doctors designated by the IRCC (Immigration, Refugees and Citizenship Canada) only partner with LifeLabs to do these tests, it’s an ugly monopoly that is impossible to fight a…

“One must imagine Sisyphus happy.” —Albert Camus, The Myth of Sisyphus

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#16

“For customers who are concerned, LifeLabs has offered to cover one year of data protection that includes dark web monitoring as well as identity theft insurance.” That’s it? If I was Canadian I’d want to see execs going to jail and or their contract yanked. If they switched over to using a webapp or chromeos on the desktop things would probably be much more secure. But that’s not going to happen, cuz it’s owned by t…

Does anyone know what “dark web monitoring” actually involves, and what sorts of firms provide this kind of service?

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#17
post #3

One thing people propose is criminalizing paying ransoms. I feel like this is short minded in that it may prioritize hig value targets like hospitals. I don't have a good answer for how to avoid issues like criminals prioritizing health/ life companies. In general maybe raising the idea the targeting hospitals makes you less than human might help.

we need instead to fix laws around sensible data handling and criminalise it/managers that skirt around them, current laws are too vague, outdated and don't provide enough reparations to get people whose data was compromised to actually litigate them

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#18

Just a few months ago I had to take a series of tests with LifeLabs (blood, urine, physical, etc) to update my immigration papers. Did you know you cannot choose where to take these tests? You are more or less forced to use LifeLabs because the doctors designated by the IRCC (Immigration, Refugees and Citizenship Canada) only partner with LifeLabs to do these tests, it’s an ugly monopoly that is impossible to fight a…

There's something in this story that doesn't ring true. You knew from the moment you walked into the laboratory that their data handling practices were inadequate and prone to being hacked/leaked. How? You tried to explain this to their secretaries and nurses. Why bother when it's obvious they can't/won't do anything about it? Why not contacting their management or IT?

To be fair to life labs, at least they don’t dox you aloud to an entire waiting room.

I witnessed that happen to a few prominent financiers in Toronto while I was getting some bloodwork done. It was terrifying within about 5 minutes I had all the personal information I’d need to do some seriously nefarious things.

This happens on most every occasion I visit a clinic in Canada. Nurses and secretaries do not care.

Re: LifeLabs pays ransom after data breach affecting up to 15M Canadians

#19
Reading the official news release [1], the cynic in me thinks the wording of just "password" indicates that these were plain text passwords. From my experience, when the passwords are hashed/salted, the companies make it a point to include that.

[1] https://www.lifelabs.com/lifelabs-releases-open-letter-to-cu...

Post reply on HN