Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

171–180 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#171
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

Is this the hospitals fault, or as software engineers and tech entrepreneurs, our fault?

Really it's the regulatory environment. It treats any change as potentially life threatening. Imagine if you had to prove that none of your changes could possibly risk patient safety to people who think automated tests can't be trusted because they can be written to simply print "PASS" all the time.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#172
post #54

I don't see any specific details on this.

https://gist.github.com/aaronst/6aa7f61246f53a8dd4befea86e83...

That's got a list of some info, my understanding is that you can take information like that and look at other attack to start to see if there are elements in common to give you more overall information about the group possibly responsible, and how to detect the group again more quickly next time, to possibly jump in and deal with the problem before it leads to exfiltration or destruction or whatever bad thing you're trying to avoid. https://www.youtube.com/watch?v=BhjQ6zsCVSc talks a bit about how to detect UNC1878.

It sounds, specifically, like Hold Security is monitoring criminal communication and picked up a reference to this campaign ahead of the execution. Combined with the subsequent follow-through, it would be pretty straightforward to attribute the folks who said, "We're going to do this thing soon" as the folks who then ended up doing exactly that thing.

For what it's worth, I know nothing more about this than what was presented in the article.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#173

Earlier quoted context omitted.

Well, a lot of the turmoil in the Middle East is at least partially (I'd argue mostly) to blame because of the US. Al Qaeda was trained by the CIA. I think it's relatively accepted that there were no WMDs in Iraq, so that entire invasion/war could be classified as terrorism. There are countless drone strikes with civilian casualties around the world. Whether or not you agree with why we did it, the CIA is credited wi…

You should read your links and learn the differences between middle eastern extremists groups. The mujahideen are not Al Qaeda. Most people say the Taliban are trained by the CIA. But even that’s not technically correct. Taliban are also not Al Qaeda.

From one of the links you said they should read:

"Haqqani - one of bin Laden's closest associates in the 1980s - received direct cash payments from CIA agents, without the mediation of the ISI.

"This independent source of funding gave Haqqani disproportionate influence over the mujahideen."

"Haqqani and his network played an important role in the formation and growth of al Qaeda, with Jalalhuddin Haqqani allowing bin Laden to train mujahideen volunteers in Haqqani territory and build extensive infrastructure there."

From a more extensive page linked from there:

"Sheik Omar Abdel Rahman, an associate of Bin Laden's, was given visas to enter the US on four occasions by the CIA [...] Rahman was a co-plotter of the 1993 World Trade Center bombing."

"Afghan Arabs 'benefited indirectly from the CIA's funding, through the ISI and resistance organizations [...] at an estimated cost of $800 million in the years up to and including 1988'"

"The Guardian alleges that the CIA helped Osama bin Laden build an underground camp at Khost, which bin Laden used to train Mujahideen soldiers."

In a 2004 article entitled "Al-Qaeda's origins and links", the BBC wrote:

"During the anti-Soviet war Bin Laden and his fighters received American and Saudi funding. Some analysts believe Bin Laden himself had security training from the CIA."

"Two-time Prime Minister of Pakistan Benazir Bhutto said Osama bin Laden was initially pro-American [and] Robin Cook, Foreign Secretary in the UK from 1997–2001, wrote, 'Throughout the '80s [Bin Laden] was armed by the CIA and funded by the Saudis'.

And what do the Saudis have to say about it?

Prince Bandar bin Sultan of Saudi Arabia stated (in the wake of 9/11):

"He [Osama bin Laden] came to thank me for my efforts to bring the Americans, our friends, to help us against the atheists, he said the communists. Isn't it ironic?"

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#174

Earlier quoted context omitted.

Is this the hospitals fault, or as software engineers and tech entrepreneurs, our fault?

If there is one thing I’ve learned from HN commenters, it’s that software engineers are never, ever individually responsible for the ethical or moral consequences of the software they write. It’s one of the most consistently and quickly downvoted topics here. It’s always the company’s fault.

I wonder why? :)

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#175

Earlier quoted context omitted.

If we're honest, it's neither. It's 1000% profit-orientated.

I think you just accurately described most of North Korea's cyber attacks. Not to say that they are the culprit; just that state sponsored and and money driven aren't necessarily exclusive.

Cyber attacks are probably the least interesting enterprise that North Korea is involved in [1]

They're also involved quite heavily in the illegal drug trade and bootlegging cigarettes and alcohol, using their embassies and diplomats as a distribution network, as well as counterfeiting currency and pharmaceuticals, running an international restaurant chain [2], building statues for tinpot dictators [3], shipping citizens off to Russia as "contract workers", smuggling ivory, trafficking arms, and previously leased out embassy buildings in Berlin to a hostel [4]

[1] https://en.wikipedia.org/wiki/North_Korea%27s_illicit_activi...

[2] https://en.wikipedia.org/wiki/Pyongyang_(restaurant_chain)

[3] https://www.bbc.com/news/magazine-35569277

[4] https://en.wikipedia.org/wiki/Embassy_of_North_Korea,_Berlin

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#176
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

Usually the goal is political change through fear. Fear doesn't really make sense as an end in and of itself

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#177
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.

> It like an airplane running out of gas because the pilot forgot to fill up the tank

That has happened in the past: https://en.wikipedia.org/wiki/Gimli_Glider

It's easy to say "well they should've filled the tank" when you're comfortably sitting on the ground, but it's little consolation for the people 30,000 feet in the air, or for the patients in hospital waiting for time critical, life saving treatment.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#178
post #121

Earlier quoted context omitted.

Designed to destroy nuclear production facilities. Not terrorism.

What makes it not terrorism? Because the target was government-run facilities instead of civilians, or something else?

I think the argument would be because its a military target (equipment used to manufacture weapons).

Also probably a bit of, because we did it instead of it being done to us.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#179
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

Good God no! I get where you're coming from but you've clearly not worked in this field. Heath Care IT is a disaster that was CREATED by regulation written in a different era of computing. The whole industry is terrified of making changes because of the multi-year hoops they're forced to jump through to release them; you don't flog a horse for stopping when you pull on the reins.

The correct solution is to change the flawed thinking in our regulations that treats all changes as equally hazardous to patent safety. The government should be encouraging (the right) changes to be released more quickly -- punishing companies for following the rules won't fix anything.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#180
post #150

Earlier quoted context omitted.

What makes it not terrorism? Because the target was government-run facilities instead of civilians, or something else?

Yes. It's cyber warfare. No civilians harmed, UF4 centrifuges disabled. I guess you can call it a surgical strike only without air to ground missiles?

It also acted as a starting gun for every other country on earth to create and/or massively expand their cyber warfare capabilities. Sparking a new arms race for the 21st century, normalizing acts of (cyber) aggression against foreign infrastructure during peacetime.

Pandora's box

Post reply on HN