Live data from Hacker News

Irish health service hit by cyber attack

bbc.co.uk

121–130 of 156 posts

Re: Irish health service hit by cyber attack

#121
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

To be honest, it seems like a lot of part-time hobby projects created by single engineers have better security practices than whole government agencies.

Can't speak to the HSE specifically but when I see government jobs come up the pay is vastly lower than private sector.

Re: Irish health service hit by cyber attack

#122

Earlier quoted context omitted.

That's not really a reduction... more of a random association to a generality you feel strongly about. You "reduced" difficult to trace digital currencies to " any kind of positive development in personal sovereignty. " No need to keep defending a mistake. Just reread your own comment and the OP's. Respond to the comment itself, not other discussions you've had on the topic. If you think the argument implies somethin…

I genuinely appreciate your comment and the direction it provides - it's rare to see this when people disagree. When re-reading the OP's comment just now, I just can't interpret it any other way other than "see! crypto bad". Maybe I'm missing something. I'd accept that my responding, effectively in-kind ("see! your position bad"), isn't particularly useful other than potentially alerting them to the fact (my intentio…

Cheers mate.

The original comment linked ransomware to crypto, which isn't too controversial. There are good things about crypto, which may outweigh that... certainly discussable.

Personally, I don't see either point as representing the most substantial positive or negative of crypto... so I don't really have a dog in this one.

No need do indemnify or vilify anyone. It's perfectly ok to hold any of these views. It's also fine to make an unconvincing argument... it just may not be convincing.

Re: Irish health service hit by cyber attack

#125

For those concerned about privacy violations, this should be rammed home as an argument against centralized collection of medical health data.

I believe that if all health records leaked tomorrow, the world would end up a better place. Sure, someone might get more expensive insurance quotes or made fun of for having ADHD, HIV or acne treatment... But I think that would be outweighed by health benefits by combing the data for correlations and causations that have been unidentified in the past. Being able to shut down things that are poisoning millions of peo…

> I believe that if all health records leaked tomorrow, the world would end up a better place

Let's say I'm a Saudi National, who worked in the United States. While there I disclosed to a doctor that I'm gay. I return to Saudi Arabia. This document gets leaked. How exactly does this make the world a better place?

Summary of possible outcomes:

https://en.wikipedia.org/wiki/LGBT_rights_in_Saudi_Arabia#Su...

Notice the first line:

Same-sex sexual activity: Fines, prison time up to life, and capital punishment.

Re: Irish health service hit by cyber attack

#126

For those concerned about privacy violations, this should be rammed home as an argument against centralized collection of medical health data.

I believe that if all health records leaked tomorrow, the world would end up a better place. Sure, someone might get more expensive insurance quotes or made fun of for having ADHD, HIV or acne treatment... But I think that would be outweighed by health benefits by combing the data for correlations and causations that have been unidentified in the past. Being able to shut down things that are poisoning millions of peo…

In other words, you can't imagine this disclosure of data being useful for research, if it is done in such a way that individual identities cannot be recovered to it for the purposes of discrimination?

Re: Irish health service hit by cyber attack

#127
post #80

Earlier quoted context omitted.

The bigger IMO problem with ransomware attacks isn't necessarily that they're holding your data hostage, it's that they can and will publish it. You might be able to tell them to kiss your ass because you have backups, but then they'll publish that information. It's a bit more of a rock-and-a-hard-place situation than most people realize.

Which if you pay the ransom, means also relying on the word of the people that are actively extorting you. Scary, scary place to be. Especially for a health service.

> Which if you pay the ransom, means also relying on the word of the people that are actively extorting you.

As weird as it sounds, reputation matters for these guys. If you have a track record of taking the money and publishing data anyway, no one is ever gonna bother paying you in the first place. Why would they? Your data is gonna get published no matter what, may as well save the ransom money.

Re: Irish health service hit by cyber attack

#128
post #31

Earlier quoted context omitted.

apparently the traceability of digital currencies is proving effective in tracking down criminals that might otherwise operate in just cash.

Cryptocurrencies are what allows criminals to scale these attacks. They also significantly decrease the risk of getting caught, compared to accepting cash in a briefcase. I’m not sure what point you are trying to make.

im saying the traceability/digitalization is a double-edged sword.

Re: Irish health service hit by cyber attack

#129

Earlier quoted context omitted.

I have always understood that all payments were traceable with digital currencies. Am I wrong?

Not all cryptocurrencies but it's true for something like Bitcoin. The problem is you can trace the transaction to the attackers wallet, but where does it go from there? It might sit there, they might throw the money in a tumbler, maybe they sell it for cash... If or when it shows up in a KYC-compliant exchange it could have changed hands many times already and it might not be possible to say anything about the actua…

So it's up to the individual to make sure they're not accepting dirty money. Shouldn't be hard to write software to accomplish that. The exchanges can do it --- flag incoming dirty money. Average users don't accept btc from strangers as a payment for goods or services anyway.

Re: Irish health service hit by cyber attack

#130

wouldn't disrupting healthcare services be an act or terrorism or even war?

You’d think these attacks would be worth some tit for tat. If people and companies were physically raided by groups, the govt would likely take action. I’m not sure what the difference is. (And to those saying it’s not international law, that’s just made up anyways so I’m not sure why that’d matter now).

disrupting healthcare systems is likely to provoke physical damage to patients. To me this is even worse than a physical attack to a company because it affects those who deserve it the least. It's morally disgusting and would deserve serious counter measures. If backed by a state it is worth some serious sanctions or worse.
Post reply on HN