Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

181–190 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#181
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…

I don’t think hospital regulations are uniquely good or bad. It’s like a typical can’t live with them / can’t live without them dynamic.

Or to put it another way, the worst thing possible short of no regulation at all.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#182
post #77
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

And how many innocent civilians will die in the process, assuming they can even identify the group responsible?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#183
post #77
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

What if the responsible is the government?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#184
post #84

Earlier quoted context omitted.

Do you actually think that this comment adds to the conversation at hand or are you just using this as an opportunity to wedge in the 'but America does it too!' trope?

I think it's an interesting comment and see no reason America deserves some special shield from criticism, trope or not. It should be responded to on its own merit, just like anyone sharing any other opinion on HN.

It seems pretty irrelavent to me. Nobody was talking about specific state actors, claiming that X is evil while America is a saint, etc. The comment feels like a response to an argument that nobody made.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#185
post #126

Earlier quoted context omitted.

> But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? Absence of evidence is not evidence of absence.

Of course. It absolutely may have happened, and if or when it has, I want those instances known. But if someone were to have been arrested wrongly, or some government blamed wrongly, this would be a huge deal, and I'd expect there to be a lot of public controversy and discussion about it. Everyone should be subject to due process. If some organized crime ring in Ukraine is blamed for some particular ransomware attack…

I envy your optimistic view on this. When I look back at recent wars (including affairs with countries that are "just bombed", without military personnel on the ground), I'm not sure I can see through the same rose colored glasses.

The government alleges something that sounds terrible that would justify an invasion, both parties play along, media is pushing pro war propaganda, allies abroad go along as well. Twenty years later, still no consequences, no apologies from our politicians, and any time someone seriously considers pulling out the troops, mysteriously some dubious war story comes up that is supposed to distract us or justify the war.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#186

Earlier quoted context omitted.

True. The United States is the largest state sponsor of terrorism in the world (School of the Americas, Bay of Pigs, Iranian-Contra, Operation AJAX, COINTELPRO, Operation Mockingbird, United Fruit...)

Takes a goofy definition of terrorism to get Bay of Pigs to fit. A military attempt to overthrow a violent leader of another country doesn’t really land in the same category of shutting down hospitals and killing sick people with no political power.

Using violence to attempt to cause a regime change without formally declaring war, sounds much more like the traditional definition of terrorism to me [although maybe not the perfect fit], then randsomware which sounds like organized crime to me.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#187
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

Good God no! I get where you're coming from but you've clearly not worked in this field. Heath Care IT is a disaster that was CREATED by regulation written in a different era of computing. The whole industry is terrified of making changes because of the multi-year hoops they're forced to jump through to release them; you don't flog a horse for stopping when you pull on the reins. The correct solution is to change the…

That doesn't justify someone abusing flawed systems to threaten people's lives.

"Oh we brought it upon ourselves by making it easy to break in so we should fix that instead of going after the thieves?"

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#188
post #112

Earlier quoted context omitted.

And how are you going to identify the state/group that did this? Believing "experts"? Oh, that worked just fine previously https://en.wikipedia.org/wiki/United_Nations_Security_Counci...

Whatever makes us feel better, right? Reality is essentially unverifiable at this point, so ... nuke Russia? It's not that that's what I want, I just can't find a way to know what's real.

This is honestly the scariest part of living in 2020

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#189
post #127

Earlier quoted context omitted.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

There have been ransomware attacks that are covers for outright attacks, iirc some where the payment and decryption mechanism didn't even function. On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare

The best example of this is probably the 2017 Russian attacks on Ukraine, which used Petya disguised as ransomware.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#190
post #162

Earlier quoted context omitted.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

We can easily reconcile the two by recognizing that profit doesn't have to be money and that terrorists definitely profit from fear (otherwise they wouldn't do it). Everything we do is for profit, even if that profit isn't measured exclusively in dollars. We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losi…

I'm not following. Are they asking for ransom or not? If yes, then they are getting actual monetary profit, we don't need to think about "profit [that] isn't measured exclusively in dollars". If no, then it's not ransomware.

>We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losing their computer systems.

You might be partially right. But I see it more of them trying to convince you to take a deal. They're trying to sell you something: your data. They want you to have as little fear as possible that you can get your data back. They want you to be 100% confident in the payment process. Yes there's fear of what would happen if you don't pay. But that's a path they want you to avoid. You could almost categorize any negotiation this way. The person you're negotiating with will try to convince you how good it is to take the deal and how bad it is to not take the deal.

The other difference between this and regular terrorism is that regular terrorism wants the general population to be scared. In ransomware, they have no goal at all of making the general population scared. In fact making the general population scared would be counterproductive, because it could lead to people patching their computers making future profits harder.

Post reply on HN