Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

281–290 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#281
post #102

Earlier quoted context omitted.

Also, stop using Windows in the healthcare system. Windows is a risk.

Big claims need big proof. I would want to see how windows managed by a good IT team is significantly more of a threat than other OSes.

As hospitals around the country race to the bottom, I'm not sure where a qualified IT team to manage these systems is going to come from. I don't think hospitals can afford them anymore.

I worked in hospital IT and it was a tough environment: it seemed like we had at least one big system rollout (EMR, radiology, lab, etc.) every year. It was difficult to manage when the hospital was paying a little below median for the area, now they are way below that where I live (western MA).

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#282
post #194

Earlier quoted context omitted.

The original meaning of the word "terrorism" has long lost its course since the early 2000s.

Terrorist, too; it's a cheap and easy way to apparently get around those pesky human rights. Only caveat is that you can't use it against white people because those are on our side. (sarcasm / irony / etc)

[deleted]

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#283

Do all these hospitals have backups that ransomware and automation can not tamper with? Is anti-tampering a requirement in their audits, or just detection? Have any hospitals started implementing secured workstations in kiosk mode? i.e. Windows 10 LTSC with all the hardening options enabled and AD permissions locked down and treating workstations as ephemeral devices.

It is my experience that hospital(s) do not have the budget for Windows 10 across their entire network.

In that case, my proposal would be that hospital customers should be able to opt into a program that allows them to buy a thumb drive from the hospital that has their records in an encrypted file, with images exported into an open lossless standard such as PNG. What size thumb drive would most patients individual records fit onto?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#284

Earlier quoted context omitted.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

The goal of terrorism is always political. Fear is the tool used by terrorism to reach the goal. Fear is a defining feature, but just means to an end. As others have noted: while this instance is unlikely to be terrorism, this is a tool that is useful in terrorism and has been used as such in the past.

Citing Wikipedia [1]

> The use of violence or of the threat of violence in the pursuit of political, religious, ideological or social objectives

One could argue these are all political. In the end, you can deduce anything to being political.

Or this definition by Alex P. Schmid from 1988:

> "Terrorism is an anxiety-inspiring method of repeated violent action, employed by (semi-)clandestine individual, group, or state actors, for idiosyncratic, criminal, or political reasons, whereby—in contrast to assassination—the direct targets of violence are not the main targets. The immediate human victims of violence are generally chosen randomly (targets of opportunity) or selectively (representative or symbolic targets) from a target population, and serve as message generators. Threat- and violence-based communication processes between terrorist (organization), (imperiled) victims, and main targets are used to manipulate the main target (audience(s), turning it into a target of terror, a target of demands, or a target of attention, depending on whether intimidation, coercion, or propaganda is primarily sought".

Source and more scholar definitions see [2].

For in-depth criteria I can recommend Alex P. Schmid's "Revised Academic Consensus Definition of Terrorism" from 2011 [3] as it is what scholars at Leiden University use.

Regarding the criterium is it always political, see #9:

> 9. While showing similarities with methods employed by organized crime as well as those found in war crimes, terrorist violence is predominantly political – usually in its motivation but nearly always in its societal repercussions;

(Its too large to quote all 12 criteria; again, please see [3] (no HTTPS))

Sometimes, the goal of ransomware is political, but its disguised as if goal is financial. This provides cover for e.g. a state actor.

[1] https://en.wikipedia.org/wiki/Definition_of_terrorism

[2] https://en.wikipedia.org/wiki/Definition_of_terrorism#Schola...

[3] http://www.terrorismanalysts.com/pt/index.php/pot/article/vi...

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#285
post #38

Earlier quoted context omitted.

Doesn’t matter if their Epic servers are up to date if the attacker got a domain admin account somewhere else and can just log in normally to run the ransomware.

Yup just spearfish one of the employees with a password reset email. People including educated developers and MDs are in general very lax about security. But also you have windows 7 legacy systems running specialized equipment that has been validated for that OS and software version number. There is really no way around this, if a country wants to kill Americans right now IMO it is most effective to disable EPIC serv…

The windows kernel is pretty good. However the rest of the windows ecosystem is a problem.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#286

Earlier quoted context omitted.

The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the nu…

I think the obvious solution would be to invest in a new open-source end-to-end infrastructure that could be thoroughly audited then implemented by hospitals everywhere. Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.

Yea so that won't happen. Hospitals don't audit anything for real. The hospital admin just hires their buddy to rubber stamp junk and gets a kickback. The actual software and hardware solutions too are based on who gives the best kickbacks to hospital admins and doctors.

Thats it. That's the American healthcare field and why its a complete shitshow. IT staff is made to deal with decisions they have no say or power in and turnover is quite high.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#287

Earlier quoted context omitted.

By the ACA law health insurance companies have to pay out at least 80% of premiums on claims. The cost of running the company and any profit has to come out of the other 20%. 5% of billions of dollars is huge in absolute figures but as a percentage falls in line with other industries.

To fix medical service affordability we need to bring down the cost of the services instead of expecting significantly more efficient insurance plans. We can’t insure away high costs. They just pass through the costs via premium and deductible increases. Even if health insurers were nonprofits that would only directly save us 5%. High deductibles encouraging shopping around but price discovery is very limited as even…

Step 1. Ban private equity and investment firms from owning healthcare providers.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#288
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

> This is what terrorism looks like in 2020. Given the (extra-)legal powers that are activated by that word, I'd be circumspect in using it. Many crimes are "horrifying, terrifying, [and] disgusting" without rising to the level of terrorism.

Attacking a hospital is a war crime, so how is it not terrorism?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#290
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

The hospital chain I work for was hit with ransomware last month. Door locks, time clocks, and photocopy machines still worked, but all computers were down. We use paper records, but it was frustrating and inconvenient. We're not allowed to pay due to laws. Corporate started slowly building us a brand new, but terrible, network 5 weeks after the old one went down. Definitely caused a little staff burnout, but not more than corporate's relentless attempts to extract additional profit from us at the expense of our patients and our wellbeing.
Post reply on HN