Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

311–320 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#311

That's messed up if true, but why would a ransomware operator target them? I mean like, they don't really target, they just wait for people to install something right?

Why hospitals? They have lots of money (same as any big organization) and a very good reason to pay up. It would be far from the first time a hospital was attacked. It wouldn't even by the first time it directly resulted in a death [0]. Unfortunately ransomware operators aren't very ethical. Considering the timing it could also be geopolitical unfortunately, people dying from a ransomware attack could substantially r…

> It would be far from the first time a hospital was attacked. It wouldn't even by the first time it directly resulted in a death [0]

Just pointing out that this is a little misleading. The link you're referencing refers to the first ever reported hospital death related to a hospital's ransomware attack, and this article was from just a month ago (I remember, I read it on Hacker News too). But the juxtaposition of these sentences might suggest that death-by-ransomware-in-hospitals has been a common occurrence for quite some time.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#312
post #308

Earlier quoted context omitted.

In that case, my proposal would be that hospital customers should be able to opt into a program that allows them to buy a thumb drive from the hospital that has their records in an encrypted file, with images exported into an open lossless standard such as PNG. What size thumb drive would most patients individual records fit onto?

I registered an account to comment because this made me laugh. One does not simply export images from medical systems. It takes a ton of effort and clicking to get patient images out of most PACS systems IF YOU ARE LUCKY. DICOM images are often high bit-depth JPEG2000 and are hard to get access to because of the way PACS systems and medical devices store data. Screen scraping DICOMs would take ages as each DICOM can…

That sounds challenging to deal with. What you are describing reminds me of proprietary backend banking, military systems and most internet-of-things that have custom firmware. Maybe I was hoping too much for hospitals to have pushed for more compatible standards. Do you have a theory as to why they have not evolved? Lack of vendor competition due to certification costs?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#313
post #162

Earlier quoted context omitted.

We can easily reconcile the two by recognizing that profit doesn't have to be money and that terrorists definitely profit from fear (otherwise they wouldn't do it). Everything we do is for profit, even if that profit isn't measured exclusively in dollars. We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losi…

I'm not following. Are they asking for ransom or not? If yes, then they are getting actual monetary profit, we don't need to think about "profit [that] isn't measured exclusively in dollars". If no, then it's not ransomware. >We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losing their computer systems. You…

[deleted]

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#314
post #288

Earlier quoted context omitted.

> This is what terrorism looks like in 2020. Given the (extra-)legal powers that are activated by that word, I'd be circumspect in using it. Many crimes are "horrifying, terrifying, [and] disgusting" without rising to the level of terrorism.

Attacking a hospital is a war crime, so how is it not terrorism?

One involves the violent deaths of hundreds or thousands of innocent civilians.

The other involves financial loss and probably a temporary shut-down of one or more hospitals.

Frankly, a cyberattack is the kind of thing a hospital can and should be hardened against. This is an administrative and regulatory failure being dressed up as "terrorism."

Criminals that use ransomware should be prosecuted and sent to prison, not disappeared to Guantanamo Bay and tortured.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#315

Earlier quoted context omitted.

If there is one thing I’ve learned from HN commenters, it’s that software engineers are never, ever individually responsible for the ethical or moral consequences of the software they write. It’s one of the most consistently and quickly downvoted topics here. It’s always the company’s fault.

I wonder why? :)

It's such a strange dichotomy. On one hand, software engineers command healthy salaries, have massive power to decide where they work, and are in high demand everywhere. They get perks up the wazoo. On the other hand, when it comes to agency over what they work on, all of a sudden they claim their power is totally gone. "Whelp, if the boss tells me to write malware or cheat at a benchmark, I guess I just have to put my head down and do it! Poor me, nothin' I can do about it. Don't blame me, not my fault, everyone!"

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#316
It's interesting that this topic was much talked about when I was working with hospitals 3-5 years ago. They've seen it coming, but have largely squandered the opportunity.

Most hospitals store their data and run systems on-prem and are hyper-allergic to anything cloud based. They often have sloppy if extant back-up policies, and I've never heard of a hospital practicing a restore from backups. They also all seem to have terrible policies around passwords that cause most of their staff to iterate passwords every few months by simply incrementing a number at the end. You're also quite likely to find passwords on post it notes under half the keyboards in a given facility.

Security certifications are kind of a joke and mostly conducted by lawyers and compliance officers who have no technical background, let-alone info sec training.

TL;DR this has been a ticking time bomb for a decade and everyone involved knew it.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#317
post #102
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

Also, stop using Windows in the healthcare system. Windows is a risk.

Ancient versions of Windows are used because they are a stable target for drivers.

Linux would end up the same way, some ancient kernel/distro because the closed source driver only works on that one ancient installation.

Post reply on HN