Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

261–270 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#261

Earlier quoted context omitted.

I think the obvious solution would be to invest in a new open-source end-to-end infrastructure that could be thoroughly audited then implemented by hospitals everywhere. Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.

My armchair analysis of the obvious solution is to airgap all these systems. Perhaps this would require some new infrastructure in hospitals, but it would add a very difficult-to-penetrate layer.

Yes, but now consider how important remote doctor visits are right now... it's a really hard problem.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#262
post #226

Earlier quoted context omitted.

-

> the unlawful use of violence and intimidation, especially against civilians, in the pursuit of political aims. From Oxford dictionary. Terrorism absolute includes the political struggle. The point is that terrorism uses violence and intimidation to further its goals and that it has no legal base for it.

Ah, like the war in Iraq.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#263
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…

A lot of medical stuff seems to suffer from this problem of caution paralyzing the behavior of professionals, not just in IT.

That being said, most commercial software seems to be way worse. There was the article the other month of a windows 10 machine automatically updating while a patient was being operated on forcing them to be kept under for an extra few hours.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#264

Earlier quoted context omitted.

The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…

I think the obvious solution would be to invest in a new open-source end-to-end infrastructure that could be thoroughly audited then implemented by hospitals everywhere. Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.

I think people who don't work in healthcare don't realize the complexity of this proposal.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#266
post #141

Earlier quoted context omitted.

If you run your infrastructure on a “computer” directly connected to the Internet such that it puts hospitals and power grids in danger, then maybe you're in the wrong profession.

That’s a naive position to take. Hospitals employ actual people who need to access information from mobile devices, home, etc. They should, however, require those devices are locked down and connected via secure means.

If you're putting the words "secure" and "computer" in the same sentence, you've already lost. There is no such thing as computer security.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#268
US hospitals are ripe to attack. They make huge profits and use extremely outdated tech or use new (untested) software.

I take this opportunity to complain about regulatory capture and the medical cartels. Their constant irresponsibility (opioid epidemic, coronavirus response) affects everyone. Yet they still are paid more than any other industry.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#269

Earlier quoted context omitted.

My armchair analysis of the obvious solution is to airgap all these systems. Perhaps this would require some new infrastructure in hospitals, but it would add a very difficult-to-penetrate layer.

Yes, but now consider how important remote doctor visits are right now... it's a really hard problem.

Are remote doctor visits anything more than a video call? I'm not sure why that would make it difficult.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#270
post #99

It is happening: https://www.bloomberg.com/amp/news/articles/2020-10-28/u-s-h... Patients are being turned away: Wyckoff Hospital hit by computer virus https://www.reddit.com/r/nyc/comments/jju0rp/wyckoff_hospita...

non-amp

https://www.bloomberg.com/news/articles/2020-10-28/u-s-hospi...

Post reply on HN