Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

141–150 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#141

Earlier quoted context omitted.

You are on a site where there are thousands of people who have personally encountered ransomware. Are we all neocons to you?

If you run your infrastructure on a “computer” directly connected to the Internet such that it puts hospitals and power grids in danger, then maybe you're in the wrong profession.

That’s a naive position to take. Hospitals employ actual people who need to access information from mobile devices, home, etc.

They should, however, require those devices are locked down and connected via secure means.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#142
post #102
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

Also, stop using Windows in the healthcare system. Windows is a risk.

Big claims need big proof. I would want to see how windows managed by a good IT team is significantly more of a threat than other OSes.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#143

Earlier quoted context omitted.

got anything from the past 50 years?

You gotta wait for it to be declassified. Syria was likely CIA funded. Same with Libya. Just wait a bit. It all comes out after everyone's stopped caring.

Are you speaking about Syria and Libya today that was a result of the Arab Spring in multiple Arab countries, which took everyone including CIA by surprise? Do you really believe the CIA is capable of something on that scale?

https://en.wikipedia.org/wiki/Arab_Spring

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#144

Is the US ransom-ware-ing Russia? Or anything similar?

Several years ago the Obama admin took down the entire financial and banking sector of Russia after the iirc early signs of election tampering were shown in 2016 But Ryuk is not the Russian government anyways

Fascinating .. do you have more info?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#145
post #49

Earlier quoted context omitted.

You could just have hospitals be required to meet FedRAMP compliance. It is kind of crazy that hipaa compliance isn’t encompassing enough

Likewise, I love FISMA, but I don't think hospitals would cease operations just because their systems couldn't get an ATO. What kind of accountability would motivate them to complete POAMs with any urgency? I don't think there is an effective way to incentivize a proactive approach - financial penalties would simply be indirectly paid for by customers.

I this case I think they could just have the proper regulations and use the "stick" portion of "carrot and stick" with fines.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#146

Earlier quoted context omitted.

The problem with this is that other bad players within US can "hack" this attempt to blame a state/group that had nothing to do with this. Has happened in the past.

Of course; it happens all the time. False flags (in the form of routed connections and much more) are extremely common in cyberwar and among cybercriminals, naturally. But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? It may have happened, and I wouldn't be shocked, but I haven't actually seen a publicized case…

> But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag"

SWATting via VoIP spoofing etc., could arguably fall entirely within the realm of this.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#147
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

Is this the hospitals fault, or as software engineers and tech entrepreneurs, our fault?

The technology is there to get rid of 99% of this therefore the ball is in the hospital's court

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#148

Earlier quoted context omitted.

By the ACA law health insurance companies have to pay out at least 80% of premiums on claims. The cost of running the company and any profit has to come out of the other 20%. 5% of billions of dollars is huge in absolute figures but as a percentage falls in line with other industries.

It also means that the easiest way to earn more profit is for healthcare costs (the 80%) to be higher. Kind of a perverse incentive in the long run.

Only if the insurance companies form a cartel (in the economic sense). People will switch carriers to ones with lower premiums so the market forces direct costs down to parity.

Most costs are outside of insurer's control anyway, regulations prevent insurance companies from telling providers how to offer care as long as the care is medically necessary and the standard of care.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#149

Seriously HR admins, if you care anything about your reputation, you should cease re-posting this kind of neocon disinformation.

You are on a site where there are thousands of people who have personally encountered ransomware. Are we all neocons to you?

>"You are on a site where there are thousands of people who have personally encountered ransomware."

Got any proof about those number in regards to HN users or it is just another "everybody knows"

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#150
post #121

Earlier quoted context omitted.

Designed to destroy nuclear production facilities. Not terrorism.

What makes it not terrorism? Because the target was government-run facilities instead of civilians, or something else?

Yes. It's cyber warfare. No civilians harmed, UF4 centrifuges disabled. I guess you can call it a surgical strike only without air to ground missiles?
Post reply on HN