Live data from Hacker News

Irish health service hit by cyber attack

bbc.co.uk

131–140 of 156 posts

Re: Irish health service hit by cyber attack

#131
post #72
post #50

Earlier quoted context omitted.

If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. Given the recent pipeline issue and its national security implications I am not going to be surprised at all if some hackers in Russia end up dead from 'accidents' that are so obviously not accidents that no one is fooled.

> If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. You could but you probably would lose that bet. This has been done for decades now, especially between friendly countries (see https://www.independent.co.uk/news/uk/politics/eu-mi6-brexit... ) without any sort of repercussion. Diplomati…

> literally no government actually wants to go to war over a hack.

well, this is not just an "hack" this blocks the entire national healthcare IT, it could cost lives.

Re: Irish health service hit by cyber attack

#132
post #50

Earlier quoted context omitted.

If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. Given the recent pipeline issue and its national security implications I am not going to be surprised at all if some hackers in Russia end up dead from 'accidents' that are so obviously not accidents that no one is fooled.

Here I was thinking about how wonderful it would be to live in a nation like Ireland, where hacks can happen without interested parties attempting in pathetic fashion to cover their asses by invoking the specter of RussiaRussiaRussia... I should have known someone would break the spell.

Not talking about the Irish attack, but rather the Colonial Pipeline one. The ransomware group in that case are a well-known Russian gang who ended up putting out a press release apologizing for the inconvenience to everyone and that they just wanted money. Sometimes that specter isn't a phantom but actually exists; the only spell to be broken here was your own delusion.

Re: Irish health service hit by cyber attack

#133
post #72
post #50

Earlier quoted context omitted.

If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. Given the recent pipeline issue and its national security implications I am not going to be surprised at all if some hackers in Russia end up dead from 'accidents' that are so obviously not accidents that no one is fooled.

> If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. You could but you probably would lose that bet. This has been done for decades now, especially between friendly countries (see https://www.independent.co.uk/news/uk/politics/eu-mi6-brexit... ) without any sort of repercussion. Diplomati…

> no government actually wants to go to war over a hack

The war started more than a decade ago. Like the Cold War that preceded it, there is little value in pretending the conflict does not exist nor that escalation is impossible.

Re: Irish health service hit by cyber attack

#134

Earlier quoted context omitted.

Not all cryptocurrencies but it's true for something like Bitcoin. The problem is you can trace the transaction to the attackers wallet, but where does it go from there? It might sit there, they might throw the money in a tumbler, maybe they sell it for cash... If or when it shows up in a KYC-compliant exchange it could have changed hands many times already and it might not be possible to say anything about the actua…

So it's up to the individual to make sure they're not accepting dirty money. Shouldn't be hard to write software to accomplish that. The exchanges can do it --- flag incoming dirty money. Average users don't accept btc from strangers as a payment for goods or services anyway.

Yes, but for example when you use a tumbler (mixer) the whole idea is to receive random coins back. Also you can not rely on everyone to know and care about this. And not all dirty money is publicly known anyway. So there will always be ways to get rid of dirty BTC.

The non-fungibility of bitcoins can be seen as an advantage or one of its largest flaws, depending on how you look at it. Either way it's the reason quite a few people have switched to Monero and other completely fungible coins.

>Shouldn't be hard to write software to accomplish that

There are startups offering exactly this as a service already.

Re: Irish health service hit by cyber attack

#135

Earlier quoted context omitted.

I believe that if all health records leaked tomorrow, the world would end up a better place. Sure, someone might get more expensive insurance quotes or made fun of for having ADHD, HIV or acne treatment... But I think that would be outweighed by health benefits by combing the data for correlations and causations that have been unidentified in the past. Being able to shut down things that are poisoning millions of peo…

> I believe that if all health records leaked tomorrow, the world would end up a better place Let's say I'm a Saudi National, who worked in the United States. While there I disclosed to a doctor that I'm gay. I return to Saudi Arabia. This document gets leaked. How exactly does this make the world a better place? Summary of possible outcomes: https://en.wikipedia.org/wiki/LGBT_rights_in_Saudi_Arabia#Su... Notice the…

How does this refute OP's point? He proposed that the benefits outweighed the downsides, not that there weren't any downsides. Your point is that there are ultra-low frequency, high salience risks. This doesn't speak to the argument at all.

Re: Irish health service hit by cyber attack

#136

Earlier quoted context omitted.

> I believe that if all health records leaked tomorrow, the world would end up a better place Let's say I'm a Saudi National, who worked in the United States. While there I disclosed to a doctor that I'm gay. I return to Saudi Arabia. This document gets leaked. How exactly does this make the world a better place? Summary of possible outcomes: https://en.wikipedia.org/wiki/LGBT_rights_in_Saudi_Arabia#Su... Notice the…

How does this refute OP's point? He proposed that the benefits outweighed the downsides, not that there weren't any downsides. Your point is that there are ultra-low frequency, high salience risks. This doesn't speak to the argument at all.

> He proposed that the benefits outweighed the downsides

I thought it was self-evident. Killing someone innocent for the good of others is never acceptable; people are ends in themselves. This is a general precept in most ethical systems with the notable exception of Millian Utilitarianism. To be clear, I am not making an argument against justifiable self-defense, as that is almost always accepted as a different kind of situation.

Example: we allow people to be killed for the good of others as long as their death allows the survival of more people. This is the poster's argument distilled. As such, it would be morally justifiable to kill random people for their organs, as one person contains enough organs to keep dozens of people from dying. If you need a liver, and your neighbor needs a spleen, then there would be nothing wrong about abducting the first person you see, butchering them, and taking what you need.

This argument is essentially that we should allow people to be killed, harmed, maimed because the number of people it help would outnumber the number of people harmed. They are the same argument. They both treat people as means rather than ends.

There are many nations in the world where you can be brutally killed for being gay, or any number of other things which shows up in medical records. If we include imprisonment, the number rises. The cost isn't just "some people might get embarrassed". It's a lot more like "hundreds of thousands of people will be brutally murdered by others or their state".

Re: Irish health service hit by cyber attack

#137
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

Complete, tested tape backups would cure many, many ills. They're out of fashion, but..

I would be amazed if the Irish health service had advanced beyond tape storage. I mean primary storage. (I'm Irish btw)

Re: Irish health service hit by cyber attack

#139
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

You are both correct and incorrect. By following simple procedures you can likely stop the majority of ransomware attacks that have occurred recently, but that is because most of the ransomware attacks were likely done with a budget on the order of $1k-$10k since that is all you need to get a $1M payout from these organizations. No point in running a mission impossible style attack when walking in the front door works just as well.

The problem is that they are getting $1M payouts on a $10k budget. That is a staggering ROI of 100! If you could magically improve the security of every system on the market by 1000% you would wipe out the current forms of attack, but it would still be insanely profitable to run $100k attacks to get $1M payouts. To actually stop attacks from continuing to escalate exponentially at their recent pace of >100% per year that any VC darling would be proud to achieve, you need to make it cost more on average to attack than they can get.

We are literally orders of magnitude away from that in the average case at current returns. And even worse returns per attack keep escalating. Just 4 years ago during WannaCry the ask was $300 per computer which can be a painful chunk of change for an individual which is who most ransomware attacks were targeting before, but nothing for any company. They were attacking companies for ~$10k payout and still making enough money to expand their operations doing it.

As the focus has moved to industry the payouts have increased exponentially since there are many companies whose operations are so valuable that they are willing to pay millions or tens of millions or even hundreds of millions per day. At those payouts there are 0 commercial IT systems that can make attacks unprofitable. So, when those attacks become the ones with the best risk-adjusted ROI you better believe they will occur. And when the attackers have a $10M budget simple defenses and techniques that worked on $10k attacks will not work because the attackers will have literally 100,000% more resources at their disposal in much the same way that defenses that work against a rock thrown at 10 m/s do not work against a ICBM traveling 1000x faster at mach 30.

So yes, simple mitigations would stop the simple successful attacks now, but do not solve the actual problem that it would still be profitable to attack even if they were all implemented everywhere since payouts are so much higher than cost.

Re: Irish health service hit by cyber attack

#140

Earlier quoted context omitted.

How does this refute OP's point? He proposed that the benefits outweighed the downsides, not that there weren't any downsides. Your point is that there are ultra-low frequency, high salience risks. This doesn't speak to the argument at all.

> He proposed that the benefits outweighed the downsides I thought it was self-evident. Killing someone innocent for the good of others is never acceptable; people are ends in themselves. This is a general precept in most ethical systems with the notable exception of Millian Utilitarianism. To be clear, I am not making an argument against justifiable self-defense, as that is almost always accepted as a different kind…

The argument is that it saves more lives than it kills.

>Killing someone innocent for the good of others is never acceptable

You make this trade off all the time by e.g. not giving all your money to charity.

Post reply on HN