Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

231–240 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#231
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

[deleted]

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#232

Earlier quoted context omitted.

Good God no! I get where you're coming from but you've clearly not worked in this field. Heath Care IT is a disaster that was CREATED by regulation written in a different era of computing. The whole industry is terrified of making changes because of the multi-year hoops they're forced to jump through to release them; you don't flog a horse for stopping when you pull on the reins. The correct solution is to change the…

That doesn't justify someone abusing flawed systems to threaten people's lives. "Oh we brought it upon ourselves by making it easy to break in so we should fix that instead of going after the thieves?"

If the bad actors are halfway around the globe where they have zero jurisdiction, what can you reasonably expect US law enforcement to do? It's a bit like getting mad at police for not investigating your car getting broken into, because you left the windows cracked open.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#233

Earlier quoted context omitted.

At some point we will sit down and recognize that calling programmers "engineers" was a mistake. True engineers make guarantees within clearly specified limits and take on liability for those guarantees. Modern technology companies claim many things while owning little, if any, responsibility.

This is what I was thinking with my comment. I don't like the idea of being liable for software I make. I love that the MIT license has a clause saying whatever happens to your computer is not my fault. It's comforting when you're just trying to share something. But.. there are certain classes of software that I think should be written differently. I feel like we made a lot of bad decisions. There should be a complet…

[deleted]

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#234

Earlier quoted context omitted.

No, those are fascists.

To make matters even more complicated, even the anti-fascists (aka "antifa") have become the enemy too.

IIRC antifa from the start is a violent group. Use whatever means necessary to stop fascism. What means are necessary and what is fascism is left as an exercise for a reader.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#235

Earlier quoted context omitted.

I thought it was interesting too. It didn’t seem inflammatory or political flamewar. Sometimes I miss the days when such conversation was permitted. I’d vouch it, but I like my vouch privileges too much to risk it.

It's not interesting. Every major thread on HN has at least one comment trying to force the America Bad angle into the conservation regardless of whether the discussion is about the US. If the primary conversation - derived from the linked article - is about the US and about a topic having to do with something negative about the US, then it's both interesting (as the root source) and makes reasonable sense that it sh…

> It's not interesting.

It's not interesting to you. Not every comment needs to be interesting to everyone.

> Every major thread on HN has at least one comment trying to force the America Bad angle into the conservation

This is an extreme exaggeration. Plenty of large threads don't discuss this. I'd wager the vast majority.

> If the primary conversation - derived from the linked article - is about the US and about a topic having to do with something negative about the US…

There are plenty of sub-conversations on every thread that aren't explicitly about the main topic. On this post alone, there are comments about the definition of terrorism, bitcoin, health insurance laws, American military action, etc. It seems like you're singling out "criticism of America" as the only taboo topic for no real reason.

> Imagine if every large thread had someone trying to force comments about all the bad things France or Britain have done.

Nobody is "forcing" comments. People are leaving comments. About all sorts of opinions, including those criticizing other countries. And absolutely none of this happens on "every large thread".

> someone being triggered and unable to control theirself

Didn't sound like the commenter was triggered at all.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#236
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

Wasn't there a ransomware case in Germany recently where when they advised the hackers that they'd hit a hospital, the hackers immediately turned over the unlock keys, without a ransom? Not that that is any way a defense, and I'm sure there was as much a self-interested motivation of "We are going to be hit hard if we ransom a hospital _now_" as much as "doing the right thing"...

I wouldn't dismiss doing the right thing. Attacking corporations is easier to rationalize with your conscience than attacking hospitals.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#237
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…

I think the obvious solution would be to invest in a new open-source end-to-end infrastructure that could be thoroughly audited then implemented by hospitals everywhere.

Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#238

Earlier quoted context omitted.

That doesn't justify someone abusing flawed systems to threaten people's lives. "Oh we brought it upon ourselves by making it easy to break in so we should fix that instead of going after the thieves?"

If the bad actors are halfway around the globe where they have zero jurisdiction, what can you reasonably expect US law enforcement to do? It's a bit like getting mad at police for not investigating your car getting broken into, because you left the windows cracked open.

I didn’t say law enforcement. Maybe the intelligence agencies can do something useful.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#239

Earlier quoted context omitted.

No, those are fascists.

To make matters even more complicated, even the anti-fascists (aka "antifa") have become the enemy too.

If only there were a word to describe the people who are anti-antifa.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#240
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

Maybe the US should also invest some of their military money to solve the situation of insecure hospital IT. You need defense, you won't win it with offense. There'll always be another bad actor out there.

Absolutely true as well.
Post reply on HN