Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

81–90 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#81

Earlier quoted context omitted.

True. The United States is the largest state sponsor of terrorism in the world (School of the Americas, Bay of Pigs, Iranian-Contra, Operation AJAX, COINTELPRO, Operation Mockingbird, United Fruit...)

got anything from the past 50 years?

stuxnet...

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#82
post #77
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

what if the state actor who did this has nuclear weapons?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#83

I'm not sure how, but somehow, I suspect that my health insurance premiums are about to increase.

Health insurance premiums are just total healthcare costs for the insured lives plus x% for operations of the health insurance company. If all hospitals have to raise prices to meet IT costs, then presumably the total cost of healthcare for the insured lives goes up, and hence the health insurance premium has to go up. So yes, typically if your vendor's suppliers increase price, then your vendor will increase their p…

> health insurance is already a low margin business

I’d like to know much, much more about this statement.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#84

Earlier quoted context omitted.

These are not mutually exclusive.

True. The United States is the largest state sponsor of terrorism in the world (School of the Americas, Bay of Pigs, Iranian-Contra, Operation AJAX, COINTELPRO, Operation Mockingbird, United Fruit...)

Do you actually think that this comment adds to the conversation at hand or are you just using this as an opportunity to wedge in the 'but America does it too!' trope?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#85

Earlier quoted context omitted.

I'm not experiencing any surprise that the hospitals are attacked, I know that happens, I am experiencing surprise at three government agencies hanging out in a chatroom where hackers are credibly discussing attacking a bunch of hospitals with ransomware. My understanding is that the ransomware operators just take a look at computers that are infected, and then negotiate based on who they appear to be.

I get the impression you're taking what you know of attacks against consumers, and just assuming that attacks against large organizations work the same way. They (generally) don't. With a consumer attack it's get execution on a computer, encrypt some files, and ransom them back. This might earn a few hundred dollars per computer, and isn't worth putting a whole lot of effort into any individual. At a corporate level…

Thanks that is insightful

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#86
post #82
post #77

Earlier quoted context omitted.

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

what if the state actor who did this has nuclear weapons?

treat them as terrorist, and eliminate some of the leaders until they get the message

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#87
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

What about management? What about the sysadmins/developers that left a security hole somewhere? Are they held responsible in some way? It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?

Do you blame the dev? Do you blame the HR system that hired them? How about the manager that pushed them too much? What about his manager? Is it the VP of IT's fault, even if he didn't know the technical specifics? Nothing is any one person's fault. Blame is a stupid waste of time.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#88

Earlier quoted context omitted.

What about management? What about the sysadmins/developers that left a security hole somewhere? Are they held responsible in some way? It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?

Do you blame the dev? Do you blame the HR system that hired them? How about the manager that pushed them too much? What about his manager? Is it the VP of IT's fault, even if he didn't know the technical specifics? Nothing is any one person's fault. Blame is a stupid waste of time.

At some point we will sit down and recognize that calling programmers "engineers" was a mistake. True engineers make guarantees within clearly specified limits and take on liability for those guarantees. Modern technology companies claim many things while owning little, if any, responsibility.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#89
post #83

Earlier quoted context omitted.

Health insurance premiums are just total healthcare costs for the insured lives plus x% for operations of the health insurance company. If all hospitals have to raise prices to meet IT costs, then presumably the total cost of healthcare for the insured lives goes up, and hence the health insurance premium has to go up. So yes, typically if your vendor's suppliers increase price, then your vendor will increase their p…

> health insurance is already a low margin business I’d like to know much, much more about this statement.

By the ACA law health insurance companies have to pay out at least 80% of premiums on claims. The cost of running the company and any profit has to come out of the other 20%. 5% of billions of dollars is huge in absolute figures but as a percentage falls in line with other industries.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#90
post #86
post #82

Earlier quoted context omitted.

what if the state actor who did this has nuclear weapons?

treat them as terrorist, and eliminate some of the leaders until they get the message

I mean that sounds simple and all.. But historically that hasn't worked well for us long term.
Post reply on HN