Live data from Hacker News

Covid Test Data Breach: 1.3M Patient Records Exposed Online

vpnmentor.com

51–60 of 143 posts

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#51
post #32

Earlier quoted context omitted.

Why does it need to be logged and stored by a third party? I'd not have a problem with an employer offering daily on-site testing with no persistent logging for people who have to be on-site but for whatever reason can't be vaccinated, or if they're having outbreak problems in the area. If no one stored it, there would be nothing to get leaked when the eventuality of data breach happens. Storing it is not in the best…

The “instant” tests that can be done without a lab are not anywhere near as accurate as lab tests.

Right, but you can do them as you come into work, visit a customer site as a contractor, whatever. Were any places that required a test for entry really requiring a lab test? If so, were they isolating the people whose test results were not in? If not, what's the point of testing?

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#52
post #47

Earlier quoted context omitted.

Admittedly, the results of COVID instant tests were not necessarily recorded anywhere--at least unless you made an appointment with your doctor after a positive result. But I'm pretty sure that's not a reason to more or less uniquely exclude laboratory COVID tests from electronic record systems.

I was commenting w.r.t. employer-mandated tests of some/any sort. Things you might have to do as part of your going-to-work daily routine. During the pandemic, I had a few customers who would take temperature when you arrived on-site, and put it in the paper contractor/visitor log. If they'd wanted me to submit the data to some third party and actually associate it with my and/or my business's name, I'd have had a pr…

I think I only once had to take a test to attend an event--and the company that handled the process claimed that records weren't kept. Of course, I had to submit proof of vaccination on many occasions including to my company.

I assume required testing was much more common in domains like healthcare.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#53

During the height of COVID, I was exploring the API design of the top-selling COVID tests on Amazon. Several had wildly unsecured APIs—sequential patient IDs but the results endpoint assumed knowing the “secret” patient ID counted as auth. Or just completely open GraphQL implementations, no different than a password-less db… For anyone considering DIYing a diagnostics program, don’t. But I’m biased (I’m the founder o…

I was working for the NL government on COVID stuff and the only thing I can say is that it's a shame I'm under NDA. It changed my view of the tech industry and I feel silly for calling colleagues in the past out for what I consider inadequate practices. As all were far above the mean.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#54

Earlier quoted context omitted.

[flagged]

You'd prefer to just move on without mentioning or discussing the mass hysteria we all saw happen? People were literally locked in camps and we're supposed to just forget about it? I don't care if it takes 5, 10 or 20 years. Heads have to roll. We were lied to and ridiculed by the people that are supposed to protect us, and they're getting away with it. Your straw-man doesn't make it go away.

I focus on what I can control and use people in power as instruction manuals for alpha when things line up for me or my network

If I can scare the legislature to pass all my riders in a 1,000 page bill nobody read, I absolutely will. I probably won't care what the pretext was, just that consensus to get something passed is possible for once in a decade, after everything I wanted died in committee the last 5 sessions.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#55
post #4

[flagged]

So the company getting hacked isn't to blame? Thats like blaming your employer if the background check company gets hacked. Companies have standards, they use other companies to assess those standards, the blame is on those companies who were compromised. Unless your employer knew they were picking a known vulnerable vendor, you're just looking for outrage at covid testing.

Companies have little incentive to pick vendors that don't get other people's data stolen.

Imagine there are two vendors offering a service:

Vendor 1 costs $1 per unit of service, doesn't give a shit about security and will probably get hacked.

Vendor 2 costs $1.2 per unit of service because they care about security

Then if it's not your data that's about to be leaked, the "smart" (profitable) thing to do is to not look at the second part so you can pretend you didn't know, and pick vendor 1.

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#56

Earlier quoted context omitted.

[flagged]

1. Consider the pandemic response an international hysteria specifically engineered by the global elite to move as much real value up the socioeconomic ladder as possible. 2. Don’t consider the Dutch to be any different. 3. Bingo. The Dutch fit into the diatribe. I don’t understand why you think this would somehow be difficult to contend with.

difficult isn't the word as opposed to "hilarious", "waste of energy", "deaf ears", "lack of focus on what can be controlled"

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#57

During the height of COVID, I was exploring the API design of the top-selling COVID tests on Amazon. Several had wildly unsecured APIs—sequential patient IDs but the results endpoint assumed knowing the “secret” patient ID counted as auth. Or just completely open GraphQL implementations, no different than a password-less db… For anyone considering DIYing a diagnostics program, don’t. But I’m biased (I’m the founder o…

I was working for the NL government on COVID stuff and the only thing I can say is that it's a shame I'm under NDA. It changed my view of the tech industry and I feel silly for calling colleagues in the past out for what I consider inadequate practices. As all were far above the mean.

Weren’t CoronaCheck and CoronaMelder open source? I would have assumed plenty of people would audit them, but I don’t recall seeing any negative news (jokes on their availability aside)

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#58
post #47

Earlier quoted context omitted.

Admittedly, the results of COVID instant tests were not necessarily recorded anywhere--at least unless you made an appointment with your doctor after a positive result. But I'm pretty sure that's not a reason to more or less uniquely exclude laboratory COVID tests from electronic record systems.

I was commenting w.r.t. employer-mandated tests of some/any sort. Things you might have to do as part of your going-to-work daily routine. During the pandemic, I had a few customers who would take temperature when you arrived on-site, and put it in the paper contractor/visitor log. If they'd wanted me to submit the data to some third party and actually associate it with my and/or my business's name, I'd have had a pr…

How many temperature readers now log the information to the cloud?

Re: Covid Test Data Breach: 1.3M Patient Records Exposed Online

#60
post #39

Earlier quoted context omitted.

Where did I absolve the medical company of wrongdoing for not securing this data?

It is possible for people to train themselves to recognize dog whistles like yours.

What am I dog whistling exactly? Do tell.
Post reply on HN