Earlier quoted context omitted.
Sure but if it become annoying then most people, including me will choose convinience over security every time. That's where I critize security professional. They often disregard this end user pain. You have to find frictionless solution and shouldn't impact their productivity.
As recently as maybe 20 years ago we learned a lot patient infection in hospital was caused by patient-to-doctor-to-patient transfer. Things like disposable gloves and hand cleaning stations at every bed were resisted by doctors initially as being over the top. Now they are ubiquitous once the benefits were proven. Maybe the same approach for IT as for germ security can be demonstrated, and that everyone needs to par…
A billion medical images are exposed online
181–190 of 201 posts
Re: A billion medical images are exposed online
#182Earlier quoted context omitted.
This is why in starting up my own little IT services company I'm planning on not serving medical clients. "HIPAA? I'm sure we're just fine, and no you can't take away my Windows 7 PCs."
I get the feeling big law is just as bad.
Re: A billion medical images are exposed online
#183Earlier quoted context omitted.
Yes, I’m sure they have their reasons and their own priorities and constraints. Just like the doctors who decline to use basic authentication. See my point? Hospitals are notorious for passing the buck around. As it happens there is a single web property for accessing a remote desktop, not multiple systems, and the hospital down the road funded by the same entity has implemented TOTP authentication.
Curious, why would a doctor decline to use basic password auth?
I'm not a (medical) doctor and I decline to use password authentication as well. Give me public key access or fuck off.
Re: A billion medical images are exposed online
#184Earlier quoted context omitted.
That is why plenty of medical systems have an override in place for emergency situations allowing you to bypass all but the most basic authentication and segmentation. You will usually need to explain your override afterwards.
I'm not talking about emergencies - I'm talking about situations where someone comes in for a "routine" blood test, but it shows they have cancer, and you as a doctor end up blaming yourself for not spending 10 minutes more to look at the test the day before, and the most obvious thing to blame for not having those 10 extra minutes is anything in IT that slows you down and takes those 10 minutes away. Even if it's ir…
The answer isn't "make the doctors change and accept the inconvenience". The answer is "find a solution that actually helps them rather than hindering".
Yes, there will always be recalcitrant users who stubbornly refuse to use systems irrespective of usability and/or utility. But I'd wager most aren't in this category. Most will be only too ready to use something that actually helps them.
If passwords are a barrier to use, find a better solution.
Re: A billion medical images are exposed online
#185An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…
Re: A billion medical images are exposed online
#186Earlier quoted context omitted.
I'm not talking about emergencies - I'm talking about situations where someone comes in for a "routine" blood test, but it shows they have cancer, and you as a doctor end up blaming yourself for not spending 10 minutes more to look at the test the day before, and the most obvious thing to blame for not having those 10 extra minutes is anything in IT that slows you down and takes those 10 minutes away. Even if it's ir…
This. I don't know enough about the econo-political situation gp mentions, but the idea that doctors are somehow irresponsible for not wanting to enter passwords is a perfect example of a usability fail. It's too easy to gloss over - "it's only a password". But think of your own situation: ever been a bit frustrated when your desktop/laptop times out and locks, just as you were about to start typing again? Objectivel…
Re: A billion medical images are exposed online
#187Earlier quoted context omitted.
The doctor is not the customer. The doctor and security personnel are coworkers in a business where the customer is the patient who is being treated and who's sensitive data is being stored. It is indeed the shared responsibility of the security team to keep in mind that the customer requires quality medical care, and security should not interfere with that. Similarly, it is also the shared responsibility of the doct…
So the doctor has to ensure security in addition of treating patient? Why do we need security professional then ?
Re: A billion medical images are exposed online
#188Re: A billion medical images are exposed online
#189Earlier quoted context omitted.
Just curious, but why are you using "-L"? Without it just doing -o to an .html opens fine in the browser for reading. I feel like I'm missing something here.
From the man page -L, --location (HTTP) If the server reports that the requested page has moved to a different location (indicated with a Location: header and a 3XX response code), this option will make curl redo the request on the new place. If used together with -i, --include or -I, --head, headers from all requested pages will be shown. When authentication is used, curl only sends its credentials to the initial ho…
Is the user only wanting to curl from the original page and any redirects are considered bad?, etc.
Re: A billion medical images are exposed online
#190To those making excuses for doctors, you should be ashamed of yourselves. There is enough blame for everyone in this case.