Live data from Hacker News

Irish health service hit by cyber attack

bbc.co.uk

141–150 of 156 posts

Re: Irish health service hit by cyber attack

#141
post #89
post #18

Ever-relevant XKCD: https://xkcd.com/2030/

OT: In my recollection that comic ends with the 'That's terrifying' panel. Does XKCD ever update comics or is that a new iteration?

I’m not aware of XKCD updating comics after they’ve been published. The HTTP response header for the PNG indicates that it hasn’t been modified since 2018 (which seems like original publication date):

    $ curl -sI https://imgs.xkcd.com/comics/voting_software.png | grep Modified
    Last-Modified: Wed, 08 Aug 2018 16:59:09 GMT

Re: Irish health service hit by cyber attack

#142

Earlier quoted context omitted.

> He proposed that the benefits outweighed the downsides I thought it was self-evident. Killing someone innocent for the good of others is never acceptable; people are ends in themselves. This is a general precept in most ethical systems with the notable exception of Millian Utilitarianism. To be clear, I am not making an argument against justifiable self-defense, as that is almost always accepted as a different kind…

The argument is that it saves more lives than it kills. >Killing someone innocent for the good of others is never acceptable You make this trade off all the time by e.g. not giving all your money to charity.

>The argument is that it saves more lives than it kills

Which I've said is unacceptable. If anyone dies as a consequence of this, it's not acceptable. That's my response to that argument. Their position is "the good outweighs the bad" and mine is that "the bad is not the sort of bad that can be counter-balanced", or more clearly "no, it does not".

> You make this trade off all the time by e.g. not giving all your money to charity.

This is a completely nonsensical, borderline facetious argument. This is equivalent to saying that by sleeping at night rather than going out to help the homeless, I'm killing people. Or that standing still and not acting is killing people. To kill is a violation of an individual's inherent right to life. It is the result of an action of an agent. It is not, however, a violation to someone's inherent right to life not to prevent their death insofar as I have not caused their death. For instance, if I have a life preserver, I have not killed you by keeping it for myself, but should I have taken it away from you, then I have.

Clearly there's a difference here. The active action of releasing a medical document is the proximate cause of the harm, therefore not allowable. The first event is strictly necessary for the second.

Me not donating money to prevent someone's rights being stripped is not the proximate cause of the wrong doing, therefore not subject to ethical calculus. There is no strict necessity given this lack of causality. The action which is subject to ethical calculus is the proximal cause of the deprivation of the individual's rights. That which is strictly necessary for the consequence is all that can be reasoned about.

Re: Irish health service hit by cyber attack

#143
post #45

wouldn't disrupting healthcare services be an act or terrorism or even war?

1. It can only be an act of war if it was done by a nation state. Even though the US likes to declare war on abstract concepts like "drugs" and "crime", that is not how it works in international law. 2. Terrorism has similarly precise definitions, usually along the lines of "the act has to be in pursuit of political aims". Just because its a big and important target does not make it political, ransomware is an econom…

1 is not strictly true. A nation harbouring actors like this has a duty to intervene or they could be deemed responsible.

For anyone with time on their hands, the "Talinn Manual" has a lot of detail on this:

https://www.kobo.com/ie/en/ebook/tallinn-manual-2-0-on-the-i...

Re: Irish health service hit by cyber attack

#144

Earlier quoted context omitted.

The argument is that it saves more lives than it kills. >Killing someone innocent for the good of others is never acceptable You make this trade off all the time by e.g. not giving all your money to charity.

>The argument is that it saves more lives than it kills Which I've said is unacceptable. If anyone dies as a consequence of this, it's not acceptable. That's my response to that argument. Their position is "the good outweighs the bad" and mine is that "the bad is not the sort of bad that can be counter-balanced", or more clearly "no, it does not". > You make this trade off all the time by e.g. not giving all your mon…

>If anyone dies as a consequence of this, it's not acceptable

Right, then you are just down some bizarre philosophical rabbit hole if you truly believe that.

Under this logic policing is unacceptable, vaccine research is unacceptable, driving a car is unacceptable, etc.. They all make trade-offs between number of deaths caused vs. some benefit (sometimes lives saved).

Re: Irish health service hit by cyber attack

#145

Earlier quoted context omitted.

>The argument is that it saves more lives than it kills Which I've said is unacceptable. If anyone dies as a consequence of this, it's not acceptable. That's my response to that argument. Their position is "the good outweighs the bad" and mine is that "the bad is not the sort of bad that can be counter-balanced", or more clearly "no, it does not". > You make this trade off all the time by e.g. not giving all your mon…

>If anyone dies as a consequence of this, it's not acceptable Right, then you are just down some bizarre philosophical rabbit hole if you truly believe that. Under this logic policing is unacceptable, vaccine research is unacceptable, driving a car is unacceptable, etc.. They all make trade-offs between number of deaths caused vs. some benefit (sometimes lives saved).

> you are just down some bizarre philosophical rabbit hole if you truly believe that

What I've said isn't anything radical, and like I've mentioned above, this is a common tenant of pretty much every ethical system that life is an end in itself. This perspective is outlined in Nozick, Kant, Scanlon, Nagel, Rawls and countless others. Some of these authors have influenced the legal systems of entire nations. Rawls and Kant, for example, are considered "main stream" ethical theorists.

> Under this logic policing is unacceptable

No, because as I've already stated, justified self-defense is a different situation entirely. The situation of extrajudicial killings by police is, however, unacceptable.

> vaccine research is unacceptable, driving a car is unacceptable

This is a false equivalency. The key difference here is the informed consent that's associated with the actions. Nobody is consenting to having their confidential data released. In the above situations you listed, one of the stipulations of engaging in, say, a vaccine trial, is a clearly stated risk. A vaccine trial on someone unwilling is wrong. Someone who willingly agrees to 'open-source' their data and gets killed as a result is also in a different situation that the one we are discussing.

To pretend that someone who's willingly engaged in a dangerous activity and died has experienced the same sort of wrong as someone who'd date was leaked against their will, and as a consequence was murdered, is just nonsensical. Notice how I said "if anyone dies as a result of this" not "anyone dying makes any situation automatically wrong".

If I walk on a sidewalk and get hit by a car, I am the one who decided the sidewalk's risks were worth it. There was no gun to my head. As my life is mine, I can dispose of it and use it as I see fit. That's not something anyone else can do or decide for me.

Re: Irish health service hit by cyber attack

#146
post #132

Earlier quoted context omitted.

Here I was thinking about how wonderful it would be to live in a nation like Ireland, where hacks can happen without interested parties attempting in pathetic fashion to cover their asses by invoking the specter of RussiaRussiaRussia... I should have known someone would break the spell.

Not talking about the Irish attack, but rather the Colonial Pipeline one. The ransomware group in that case are a well-known Russian gang who ended up putting out a press release apologizing for the inconvenience to everyone and that they just wanted money. Sometimes that specter isn't a phantom but actually exists; the only spell to be broken here was your own delusion.

So, do you believe the press release? They clearly disavow connection to any of the dozens of national governments on earth who are subject to USA sanctions: "We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined goverment and look for other our motives." Do you only believe part of that press release? How did you decide which part to believe? Maybe just the parts that threaten to cause global thermonuclear war?

Of course I knew what you were talking about; the war media has been beating this drum for at least a week even though it was obvious from the start that Colonial do shit work and grasp at any straw to excuse that. Anyone who wants to see more of that CYA bullshit can find plenty to see, so your jingoistic and warmongering comment has no place in this thread. Foment war among nuclear powers elsewhere.

Re: Irish health service hit by cyber attack

#147
post #45

Earlier quoted context omitted.

1. It can only be an act of war if it was done by a nation state. Even though the US likes to declare war on abstract concepts like "drugs" and "crime", that is not how it works in international law. 2. Terrorism has similarly precise definitions, usually along the lines of "the act has to be in pursuit of political aims". Just because its a big and important target does not make it political, ransomware is an econom…

1 is not strictly true. A nation harbouring actors like this has a duty to intervene or they could be deemed responsible. For anyone with time on their hands, the "Talinn Manual" has a lot of detail on this: https://www.kobo.com/ie/en/ebook/tallinn-manual-2-0-on-the-i...

Kinda fair, but "duty to intervene" is heckin' vague. A nation can easily claim to have tried but failed. In any case, with all due respect to the Irish military I don't think they are quite up to invading any of the usual suspects when it comes to harboring extensive cyber operations.

Re: Irish health service hit by cyber attack

#148
post #127

Earlier quoted context omitted.

Which if you pay the ransom, means also relying on the word of the people that are actively extorting you. Scary, scary place to be. Especially for a health service.

> Which if you pay the ransom, means also relying on the word of the people that are actively extorting you. As weird as it sounds, reputation matters for these guys. If you have a track record of taking the money and publishing data anyway, no one is ever gonna bother paying you in the first place. Why would they? Your data is gonna get published no matter what, may as well save the ransom money.

You can flip it around (if you're a pessimist):

  1. If you *don't* pay, then you know bad things will happen.

  2. So you might as well pay, regardless of their reputation, because your chances are strictly better even if they are nearly nothing.

  3. Knowing that, there is no incentive for them to maintain a reputation by honoring the ransoms.
This seems like a stable equilibrium.

Re: Irish health service hit by cyber attack

#149

For those concerned about privacy violations, this should be rammed home as an argument against centralized collection of medical health data.

I believe that if all health records leaked tomorrow, the world would end up a better place. Sure, someone might get more expensive insurance quotes or made fun of for having ADHD, HIV or acne treatment... But I think that would be outweighed by health benefits by combing the data for correlations and causations that have been unidentified in the past. Being able to shut down things that are poisoning millions of peo…

You are inadvertently trivializing the consequences.

If someone has to pay a bit more for insurance or whatever, that may not sound like a big deal and also morally justifiable if you assume someone is always willing and able to evaluate risk accurately.

However, some diagnoses are treated as "unknown unknowns" rather than quantifiable risks. In that case, it's likely that there will simply be nobody to accept them at all.

The discrepancy between this treatment of a risk as effectively infinite, because nobody will take it on, versus the fact that it is really finite, constitutes economic destruction that would be caused by the disclosure of the diagnosis.

Right now there are restricted circumstances where things have to be disclosed. But it's relatively tolerable because it's limited. For instance, you might not be able to get life insurance, but at least you can hold a job, have health insurance, live where you like, etc.

Taking all that away from millions of people seems not a lot kinder than just liquidating them.

Re: Irish health service hit by cyber attack

#150
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

I typically work in situations where the entire data to be backed up (file storage, database) is on the order of 10-100Gb. The projects I’m working on don’t fit the high profile of a Colonial but I’d rather err on the side of safety. Is there a service that could regularly fetch data from s3 or even connect to postgres, and regularly send a physical copy of the data by mail? Does it make sense to offer airgapped back…

Why not just buy a tape drive and a few tapes? They are offline and air gapped the moment they are out of the machine and, if you have a small company, they can be stored in the owners house.

That gives you quick retrieval of of-site backups.

The only reason I haven't done something like that for all my personal data is that tape machines are terribly expensive. Tape drives are pretty cheap.

Post reply on HN