Live data from Hacker News

2.7M medical calls breached in Sweden

twitter.com

101–110 of 116 posts

Re: 2.7M medical calls breached in Sweden

#101

Earlier quoted context omitted.

Because Swedes are uniquely morally upstanding and non-judgemental?

No, we're highly judgemental, but an employer is not allowed to inquire or make hiring/firing decisions with regard to your health status. Likewise life insurance might have a higher premium if you regularly engage in extreme sports, but they can't deny you. Health care is ubiquitous regardless of your condition.

And how would you know that an employer refused you a position because of your health record ?

These kinds of laws exists in most country, but if you cannot prove it, they are useless. So if a employer has a public access to your health record, what you prevent him from doing the above and tell you a random reason ?

There was a case in France were an Ikea director has access to private police record and was making hiring decision based on that. It's completely illegal but they did it for years before getting caught.

Re: 2.7M medical calls breached in Sweden

#102
post #57

Earlier quoted context omitted.

Plug: this is what we're trying to solve (amongst other things) at Patients Know Best. Giving the control back to the patient (you should always have full access to all data about yourself, and be able to control sharing of these records). We're mostly present in the UK at the moment.

The question is who stores the data. If you manage to let the patients keep it locally or in physical media it's insane. If you are keeping it for them it's the same worries as any other service. This was not journals though, but calls to nurses.

We store data for you in a way that's considerably more secure and paranoid than how other providers work -- quite similarly to CryptDB. We can access your data when serving it to you, but your medical data is never stored on disk with a key that we store (it's derived from your password, and we throw it away after serving you through HTTP).

Re: 2.7M medical calls breached in Sweden

#103

Earlier quoted context omitted.

This is a far more general problem of states in general. They always see themselves above the rules they apply to others and this is particularly problematic in the medical realm, but also affects criminal justice for example. Governments just don't follow their own rules. This means that medical files just aren't trustworthy anymore, in the sense that the patient has no control over who sees these and how far they a…

I don’t see this as a problem of ”not following rules” and for “government” as a concept to eat the blame. This stuff, along with many other things have been outsourced in Sweden to private contractors. In the end, government is made up of people, and these guys outsourcing and selling off everything are just the ones that would blame the governement. It’s facinating, and a self fulfilling prophecy! “Look the governm…

Outsourced is another word for "hiring external people to do this stuff in my service"

The government is still the employer, the person doing the changes and responsible.

And yes, the solution is mostly NOT DOING THIS AT ALL. Or at least, doing significantly less.

Re: 2.7M medical calls breached in Sweden

#104

Earlier quoted context omitted.

Still, sending the data unencrypted wasn't so much the issue here as the server was open to anyone.

Yes, although the transmission being in plaintext makes it even more vulnerable, because if you get to listen to the network where the call center nurses operate, no one needs to crack anything to find out the location of data, its structure and anything else you need to exploit it.

So your reasoning goes that if I leave the front door to my home open, it would still be more secure if it had steel bars on the windows?

Re: 2.7M medical calls breached in Sweden

#105

Earlier quoted context omitted.

Yes, although the transmission being in plaintext makes it even more vulnerable, because if you get to listen to the network where the call center nurses operate, no one needs to crack anything to find out the location of data, its structure and anything else you need to exploit it.

So your reasoning goes that if I leave the front door to my home open, it would still be more secure if it had steel bars on the windows?

No, it's more like that if I leave the front door open, it would still be more secure if the driveway was lighted up so that any inappropriate visitors would be visible.

[Analogies may be terrible, but lack of encryption is an additional factor making attacks even easier, particularly for the purpose of discovering the attack vectors.]

Re: 2.7M medical calls breached in Sweden

#106

Earlier quoted context omitted.

So your reasoning goes that if I leave the front door to my home open, it would still be more secure if it had steel bars on the windows?

No, it's more like that if I leave the front door open, it would still be more secure if the driveway was lighted up so that any inappropriate visitors would be visible. [Analogies may be terrible, but lack of encryption is an additional factor making attacks even easier, particularly for the purpose of discovering the attack vectors.]

I'll give you the benefit of a doubt that you are arguing the general case, but I'm talking about this case specifically. If all you need to do to access the data is to just browse to a specific address, it matters not whether you need to put http or https in front of that address. No need to set up any eavesdropping devices en route. Just point your browser to the address and download the data. Transport security will not protect your data if you have no access control.

Re: 2.7M medical calls breached in Sweden

#108

Earlier quoted context omitted.

No, it's more like that if I leave the front door open, it would still be more secure if the driveway was lighted up so that any inappropriate visitors would be visible. [Analogies may be terrible, but lack of encryption is an additional factor making attacks even easier, particularly for the purpose of discovering the attack vectors.]

I'll give you the benefit of a doubt that you are arguing the general case, but I'm talking about this case specifically. If all you need to do to access the data is to just browse to a specific address, it matters not whether you need to put http or https in front of that address. No need to set up any eavesdropping devices en route. Just point your browser to the address and download the data. Transport security wi…

I think his point is that if you are in a Starbucks and you figure out what's on the server, all the other people with hoodies in the Starbucks now know as well.

Re: 2.7M medical calls breached in Sweden

#110

Either me, my girlfriend or both of us are in those phone calls. I feel absolutely betrayed by the state. I always knew that Sweden's obsession with medical data collection would back-fire but audio recordings? That's just too much. I hope everyone involved gets sued into oblivion!

Apparently Computer Sweden, the newspaper reporting on this is getting sued by Medhelp now.
Post reply on HN