Live data from Hacker News

Chaos Computer Club saves the German healthcare system 400M Euros

ccc.de

41–50 of 51 posts

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#41
To play devils advocate:

€400M sounds a lot but how many of these devices are there? If there's one in every medical practice that could be 100-200,000. [EDIT: this article https://www.healthcareitnews.com/news/emea/error-which-cause... suggests there are 130,000 clinics, that would be €3K per clinic]

Having a technician visit each and do a firmware update - could well cost over $5K or more, as long as introducing downtime at the surgery, the changes would need to be done by people who are trained and this is a device that is involved in personal medical data - they need to be managed and monitored.

Delivering a new piece of hardware with the new certificates that could be dropped in could well be cheaper (how ever bad for the environment) than updating them within the legal requirements that may be in place for tech that handles medical data.

There may be good technical and legal reasons why the certificates can't be updated remotely or are set to expire, but if I were the companies involved I would take in some devices, 'refurbish' them with new certificates and send them out to medical practices for drop in replacement, rather than sending out new devices.

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#42
post #17

For anyone who doesn't read German, here is a summary: The company in charge of the connectors for the health care system "Telematik" built devices with certificates that expire after 5 years. Instead of updating thousands of machines with new certificates, the company claims these need to be replaced for a total cost of 400M Euro. The CCC showed how the firmware can be changed to accept new certificates, making the…

I‘m assuming the German government wouldn’t be able to compel them to turn over their private key, but they could certainly make it very clear that they would jeopardise any future contracts if they refused to cooperate.

there is somebody in the chain of command who benefits of that deal and will do what she can to keep it as inefficient as it is.

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#43

To play devils advocate: €400M sounds a lot but how many of these devices are there? If there's one in every medical practice that could be 100-200,000. [EDIT: this article https://www.healthcareitnews.com/news/emea/error-which-cause... suggests there are 130,000 clinics, that would be €3K per clinic] Having a technician visit each and do a firmware update - could well cost over $5K or more, as long as introducing do…

>There may be good technical and legal reasons why the certificates can't be updated remotely or are set to expire, but if I were the companies involved I would take in some devices, 'refurbish' them with new certificates and send them out to medical practices for drop in replacement, rather than sending out new devices.

It's about that the Devices DON'T accept new certificates over a certain date, like when your iphone just accept certificates who are valid up to 2022, then you need a new iphone, that should be illegal, and the firm should have to pay the technician/fw-update.

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#44

When it comes to anything with computers it’s difficult to imagine ways to end up more incompetent than literally all German public (or pseudo-public, like here) agencies. You’d certainly get something more competent by collecting random strangers off the street. It’s virtually impossible to overstate how bad the situation in this area truly is in Germany.

This is nonsense. In Spain the FNMT issued certificates work fine and have simplified much daily business.

Germany not Spain....

>>difficult to imagine ways to end up more incompetent than literally all German public

I think that pretty much sums it up perfectly.

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#45
post #25

Earlier quoted context omitted.

I'm assuming you haven't heard about corr^w lobby.

What's corr^w?

Ctrl-W in certain contexts (especially shells) deletes the previous word. Shells vary in their behavior, but in this situation partOfAWor^w is essentially the same as using strike through. It implies the writer started writing a word and changed their mind on which word to use.

In this case, they're implying lobbying and corruption are one and the same, as far as I can tell.

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#46
post #27

The corruption in Germany is unbelievable. Given Schröder, Merkel, Dieselgate, this thing ... Germany os basically a rich Russia.

The difference is that in russia corruption is "in theory" illegal, in germany no one (if you are a politician) gets hurt.

You forgot the mask-scandal ;)

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#47
post #43

To play devils advocate: €400M sounds a lot but how many of these devices are there? If there's one in every medical practice that could be 100-200,000. [EDIT: this article https://www.healthcareitnews.com/news/emea/error-which-cause... suggests there are 130,000 clinics, that would be €3K per clinic] Having a technician visit each and do a firmware update - could well cost over $5K or more, as long as introducing do…

>There may be good technical and legal reasons why the certificates can't be updated remotely or are set to expire, but if I were the companies involved I would take in some devices, 'refurbish' them with new certificates and send them out to medical practices for drop in replacement, rather than sending out new devices. It's about that the Devices DON'T accept new certificates over a certain date, like when your iph…

Isn't that because the certificate the boxes to use to validate the remote certificates have an expiration date (as they probably should). An iPhone gets updated certificates every time iOS is updated.

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#48
post #45

Earlier quoted context omitted.

What's corr^w?

Ctrl-W in certain contexts (especially shells) deletes the previous word. Shells vary in their behavior, but in this situation partOfAWor^w is essentially the same as using strike through. It implies the writer started writing a word and changed their mind on which word to use. In this case, they're implying lobbying and corruption are one and the same, as far as I can tell.

[deleted]

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#49
post #43

Earlier quoted context omitted.

>There may be good technical and legal reasons why the certificates can't be updated remotely or are set to expire, but if I were the companies involved I would take in some devices, 'refurbish' them with new certificates and send them out to medical practices for drop in replacement, rather than sending out new devices. It's about that the Devices DON'T accept new certificates over a certain date, like when your iph…

Isn't that because the certificate the boxes to use to validate the remote certificates have an expiration date (as they probably should). An iPhone gets updated certificates every time iOS is updated.

> An iPhone gets updated certificates every time iOS is updated.

No you get updated certs from cert-authorities (the one's trusted by apple/google/mozilla etc), the ones who "signed" the received certs from website X. Otherwise you would have to download gigabytes of certificates.

https://www.youtube.com/watch?v=86cQJ0MMses

>>TLS Handshake Explained - Computerphile

Re: Chaos Computer Club saves the German healthcare system 400M Euros

#50
post #17

For anyone who doesn't read German, here is a summary: The company in charge of the connectors for the health care system "Telematik" built devices with certificates that expire after 5 years. Instead of updating thousands of machines with new certificates, the company claims these need to be replaced for a total cost of 400M Euro. The CCC showed how the firmware can be changed to accept new certificates, making the…

I‘m assuming the German government wouldn’t be able to compel them to turn over their private key, but they could certainly make it very clear that they would jeopardise any future contracts if they refused to cooperate.

It is a little more problematic than that:

The Gematik GmbH is in part managed (owned?) by the German ministry of health [0] and some health organizations like the Association of Statutory Health Insurance Agencies.

That says something about the 'risks' the Gematik takes (Hint: none).

Similar story: Earlier this year some health card readers, certified by the Gematik had a bug. They wouldn't read certain cards that supposedly were electrostatically charged. The solution was a grounding device connected to the USB port of the card reader. [1] This thingy cost the doctor's practices another 100 bucks even though this clearly is a design flaw by the manufacturer.

They can do pretty much what they want at this point and the physicians and hospitals just have to cough up the dough.

[0] https://de.m.wikipedia.org/wiki/Gematik

[1] https://www.borncity.com/blog/2022/01/16/problem-mit-statisc...

Post reply on HN