Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

101–110 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#101
post #91
post #82

Earlier quoted context omitted.

what if the state actor who did this has nuclear weapons?

Who? I don’t think Russia is killing off senior citizens. North Korea? Nuke the shit out of them.

Crying for mass destruction is despicable.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#102
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

Also, stop using Windows in the healthcare system. Windows is a risk.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#103
post #77
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

Horrifying mindset that led to the disastrous war on terror in the aftermath of 9/11. Our foreign policy should not be based on an animalistic thirst for blood.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#104
post #83

Earlier quoted context omitted.

> health insurance is already a low margin business I’d like to know much, much more about this statement.

By the ACA law health insurance companies have to pay out at least 80% of premiums on claims. The cost of running the company and any profit has to come out of the other 20%. 5% of billions of dollars is huge in absolute figures but as a percentage falls in line with other industries.

This sounds like an incentive to increase costs (20% of 2X > 20% of X).

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#105
post #86

Earlier quoted context omitted.

treat them as terrorist, and eliminate some of the leaders until they get the message

I mean that sounds simple and all.. But historically that hasn't worked well for us long term.

It's true. Attacking random countries that follow the same religions as a particular bad guy is not a recipe for long term prosperity.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#106

Earlier quoted context omitted.

Do you blame the dev? Do you blame the HR system that hired them? How about the manager that pushed them too much? What about his manager? Is it the VP of IT's fault, even if he didn't know the technical specifics? Nothing is any one person's fault. Blame is a stupid waste of time.

At some point we will sit down and recognize that calling programmers "engineers" was a mistake. True engineers make guarantees within clearly specified limits and take on liability for those guarantees. Modern technology companies claim many things while owning little, if any, responsibility.

This is what I was thinking with my comment. I don't like the idea of being liable for software I make. I love that the MIT license has a clause saying whatever happens to your computer is not my fault. It's comforting when you're just trying to share something.

But.. there are certain classes of software that I think should be written differently.

I feel like we made a lot of bad decisions. There should be a completely separate stack for hospitals, power plants, etc., including a custom operating system. Why is Windows running on every machine? Isn't this a national security issue at this point?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#107
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

What about management? What about the sysadmins/developers that left a security hole somewhere? Are they held responsible in some way? It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?

My house would be trivially easy to break into but if someone did, I wouldn't be responsible.

Even if I leave the door unlocked, it's still a crime to break in and take my stuff.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#108
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

What about management? What about the sysadmins/developers that left a security hole somewhere? Are they held responsible in some way? It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?

Sometimes analogies can be misleading. It's a lot harder to design a secure hospital IT apparatus than a safe. Also, in the event of a safe getting cracked, you'd likely have no recourse against the safe vendor. Safes are designed to present a firewall against tampering, but with sufficient physical access, no safe will stand for long. So your analogy fails two ways: one is that it trivializes the difficulty of the problem you're analogizing, and the other is that even if it were a good analogy, it would cut against your argument.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#109
post #77
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

Attribution for cyberattacks is hard.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#110
post #77
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

The problem with this is that other bad players within US can "hack" this attempt to blame a state/group that had nothing to do with this. Has happened in the past.
Post reply on HN