Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

131–140 of 201 posts

Re: A billion medical images are exposed online

#131
post #7

% curl -L 'https://techcrunch.com/2020/01/10/medical-images-exposed-pacs/' curl: (7) Failed to connect to guce.advertising.com port 443: Connection refused WTF? I have a lying DNS server, and it's getting ridiculous. Here's the outline for people who care about privacy/tracking/GDPR, etc. https://outline.com/Ep5u4K

Exactly the same here. Wow.

Re: A billion medical images are exposed online

#133
post #67

Earlier quoted context omitted.

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

> I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Well... yeah. Nobody is sim swapping hospital staff. It’s not great, but this isn’t a real threat they’re facing.

There are clearly targeted phishing attempts, I wouldn’t rule it out.

Edit: I should add, I was very surprised when I got a phishing email sent by the obviously compromised email account of a colleague, and when I emailed them to say their email was hacked, the person who hacked them replied telling me everything was OK, and to open the attachment.

Re: A billion medical images are exposed online

#134
post #105

Earlier quoted context omitted.

> Except in one instance we had delays rolling out SSO not because the system was complicated to use, but because doctors complained that they didn't like the color of the SSO UI. They insisted it be blue rather than yellow and wanted to scrap the entire project because of it. That's the type of resistance I'm talking about. Is it really the hill you want to die on? Just change the damn widget color if it is so impor…

Ha, I agree! We were willing, able, (and did) change the color relatively easily. I'm just using it as an example of the type of pushback I've gotten. The doctors were the ones willing to die on that hill; they wanted to cancel the entire project and their reasoning was the color, and they didn't even care to hear that it could easily be changed. In that case it really did feel like resistance for resistance's sake.

Or they didn't really want the change. Or (devil advocate) maybe they had a very good reason you did not know. Like, they asked repetitively for that before. It takes a special straw to break a camel's back.

This reminds me of the M&Ms color in rock concerts artist room: a canary in the mine for the venue having ignored more important requests.

Re: A billion medical images are exposed online

#135

In 2009 I was building an enterprise medical imaging SaaS for hospitals, and we would constantly come across hospital IT admins who were adamantly against trusting a cloud vendor with their sensitive healthcare data - even one that's audited, security-checked and whose sole responsibility is to take care of these images. We always thought it was a joke that these guys questioned us, when we knew how bad their interna…

> In 2009 I was building an enterprise medical imaging SaaS for hospitals, and we would constantly come across hospital IT admins who were adamantly against trusting a cloud vendor with their sensitive healthcare data

This still rings very true in 2020.

Re: A billion medical images are exposed online

#136

In 2009 I was building an enterprise medical imaging SaaS for hospitals, and we would constantly come across hospital IT admins who were adamantly against trusting a cloud vendor with their sensitive healthcare data - even one that's audited, security-checked and whose sole responsibility is to take care of these images. We always thought it was a joke that these guys questioned us, when we knew how bad their interna…

Lots of open S3 buckets full of critical data not helping the counter argument. Security is hard, proving you’re secure to others more so. How do I know you’re not just storing my data in S3, abstracting away the mechanism, but your bucket policy or acls are garbage? I don’t. Cloud does not immediately mean more secure.

Re: A billion medical images are exposed online

#137

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

> I have never met a group of people more elitist and “too important to be bothered” by security than doctors.

In my opinion, they're the only bunch that gets it right.

Security should work correctly and not bother me. Period.

The fact that it doesn't is laziness on the part of the security vendors.

The bigger problem is that if security ever allows a user to make an incorrect security decision, it's probably worse than no security at all.

Re: A billion medical images are exposed online

#138
post #118
post #67

Earlier quoted context omitted.

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

Porn fiends? Doctors don't have the time. But you must admit that the profession brings out some very arrogant traits. They usually express the pointof view that they learned everything they needed to at med school and any new outside information is suspect and not important including IT security.

I'm not sure how to reply to your comment. I know a lot of doctors personally, and less than 1% are what I would describe as very arrogant. Some specialties probably enrich for arrogant people, particularly cardiothoracics, cardiology or neurosurgery at large prestigious institutions, and some countries have a system which tends to permit arrogance (eg the USA).

Re: A billion medical images are exposed online

#139
post #88

Earlier quoted context omitted.

Yes, I’m sure they have their reasons and their own priorities and constraints. Just like the doctors who decline to use basic authentication. See my point? Hospitals are notorious for passing the buck around. As it happens there is a single web property for accessing a remote desktop, not multiple systems, and the hospital down the road funded by the same entity has implemented TOTP authentication.

Curious, why would a doctor decline to use basic password auth?

What happens if they forget their password?

Re: A billion medical images are exposed online

#140
post #67

Earlier quoted context omitted.

It goes both ways. I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Anyway, ‘Doctors’ are a pretty diverse bunch, and most of them aren’t arrogant porn-fiends.

> I keep telling the IT people at my hospital to stop using SMS 2-factor and they blow me off and treat me like an idiot. Well... yeah. Nobody is sim swapping hospital staff. It’s not great, but this isn’t a real threat they’re facing.

You'd be surprised how much money flows through the medical system.

And how much of that flows through automated systems.

And how little of the total is actually audited on a detailed level.

Post reply on HN