Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

251–260 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#251

Earlier quoted context omitted.

Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.

> It like an airplane running out of gas because the pilot forgot to fill up the tank That has happened in the past: https://en.wikipedia.org/wiki/Gimli_Glider It's easy to say "well they should've filled the tank" when you're comfortably sitting on the ground, but it's little consolation for the people 30,000 feet in the air, or for the patients in hospital waiting for time critical, life saving treatment.

Just to clarify, they did fuel up, but made a calculation error (metric to imperial if iirc) on the amount and is why they ran out early.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#252

Earlier quoted context omitted.

Well, a lot of the turmoil in the Middle East is at least partially (I'd argue mostly) to blame because of the US. Al Qaeda was trained by the CIA. I think it's relatively accepted that there were no WMDs in Iraq, so that entire invasion/war could be classified as terrorism. There are countless drone strikes with civilian casualties around the world. Whether or not you agree with why we did it, the CIA is credited wi…

A war that was started on incorrect pretenses is not the same thing as terrorism. Among other things, the US did not deliberately target the Iraqi civilian population, and made their best efforts to avoid civilians being harmed. The US provided substantial reconstruction aid to Iraq to help undo the damage of the war afterward - more than $60 billion. However, it's hard to avoid there being some undesired casualties…

They did their best to avoid civilian casualties by firing nearly a million Iraqi army men?

What could possibly go wrong.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#253

Earlier quoted context omitted.

It also means that the easiest way to earn more profit is for healthcare costs (the 80%) to be higher. Kind of a perverse incentive in the long run.

Only if the insurance companies form a cartel (in the economic sense). People will switch carriers to ones with lower premiums so the market forces direct costs down to parity. Most costs are outside of insurer's control anyway, regulations prevent insurance companies from telling providers how to offer care as long as the care is medically necessary and the standard of care.

If both the insurance and the hospital earns money by raising the price we will get what we have today where insurance covered procedures are more expensive than none covered procedures.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#254

Earlier quoted context omitted.

Well, a lot of the turmoil in the Middle East is at least partially (I'd argue mostly) to blame because of the US. Al Qaeda was trained by the CIA. I think it's relatively accepted that there were no WMDs in Iraq, so that entire invasion/war could be classified as terrorism. There are countless drone strikes with civilian casualties around the world. Whether or not you agree with why we did it, the CIA is credited wi…

A war that was started on incorrect pretenses is not the same thing as terrorism. Among other things, the US did not deliberately target the Iraqi civilian population, and made their best efforts to avoid civilians being harmed. The US provided substantial reconstruction aid to Iraq to help undo the damage of the war afterward - more than $60 billion. However, it's hard to avoid there being some undesired casualties…

> Among other things, the US did not deliberately target the Iraqi civilian population, and made their best efforts to avoid civilians being harmed.

Maybe for the second Iraq war, but for the first one that's bullshit – before the first Iraq war, Iraq was the richest third world country. The US bombed it back to the stone age, using more bombs than were dropped on Germany during WW2, hitting civilian infrastructure like water treatment plants, which then resulted in the following years in hundreds of thousands of dead children.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#255
post #194

Earlier quoted context omitted.

The original meaning of the word "terrorism" has long lost its course since the early 2000s.

Terrorist, too; it's a cheap and easy way to apparently get around those pesky human rights. Only caveat is that you can't use it against white people because those are on our side. (sarcasm / irony / etc)

You can use it against white people. You just have to dig though their social media until you find at least one of them saying something that can be construed as racist. Then the "domestic terrorist" label applies to the whole group.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#256

Earlier quoted context omitted.

I think you just accurately described most of North Korea's cyber attacks. Not to say that they are the culprit; just that state sponsored and and money driven aren't necessarily exclusive.

Cyber attacks are probably the least interesting enterprise that North Korea is involved in [1] They're also involved quite heavily in the illegal drug trade and bootlegging cigarettes and alcohol, using their embassies and diplomats as a distribution network, as well as counterfeiting currency and pharmaceuticals, running an international restaurant chain [2], building statues for tinpot dictators [3], shipping citi…

Yeah, fucking North Korean forced labor camps in Poland (!) in the middle of the European Union. It's mind-boggling !

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#257
post #55

Earlier quoted context omitted.

Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.

You certainly express an unpopular opinion, and at first glance you are right: secure backups should be a priority for any IT organization. However, not all backups are continuous and pervasive. There are often backup windows, gaps, and processes that halt with no one noticing. Ryuk also actively disables and deletes backups to maximize impact, while also seeking out mount points that might be backup targets - and en…

> Ransomware is akin to kidnapping

There is an expectation that information and services are to be secured with a certain level of care and standards. I don't see how that applies to people.

> Always blame the criminal, never the victim

This argument excludes the concept of negligence. If the victim was grossly negligent then they are also to blame.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#258

Earlier quoted context omitted.

Wasn't there a ransomware case in Germany recently where when they advised the hackers that they'd hit a hospital, the hackers immediately turned over the unlock keys, without a ransom? Not that that is any way a defense, and I'm sure there was as much a self-interested motivation of "We are going to be hit hard if we ransom a hospital _now_" as much as "doing the right thing"...

Self-interest; a financial crime is nowhere as high on the priority list as one causing injury and death. It crosses the line from fairly petty crime to getting an international warrant on your ass.

Exactly. That provincial government in who you're paying off may well turn your ass over if you kill people because protecting your industry is their cash cow and they don't wanna lose that because someone killed people.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#260
post #102

Earlier quoted context omitted.

Also, stop using Windows in the healthcare system. Windows is a risk.

Big claims need big proof. I would want to see how windows managed by a good IT team is significantly more of a threat than other OSes.

Software is easier to replicate than good education/training/know-how.
Post reply on HN