Live data from Hacker News

Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

csoonline.com

21–30 of 50 posts

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#22
post #18

Earlier quoted context omitted.

..rather than, say, not pay nurses their salaries for a while?

Heaven forbid that top executives ever have to take a pay hit.

I never understood this attitude.

Most executives are either life long doctors, or worked their way up the corporate ladder. I don't understand why people who work hard to get to these positions are suddenly vilified as being somehow overpaid?

Take for example the CEO at Cedars-Sinai Health System in LA. They guy has held his CEO position for 17 years and worked his way up thought the ranks. He also went to school and got an undergrad and masters degree. He started in 1979 as an assistant admin and took the top job in 1994. So after 15 years of working his way up to CEO, he's should somehow not be paid in accordance with what other Health Care CEO's are getting paid?

If you want a villain, look at the system that's broken, or the government regulations, but seriously, get off the executives back for fucks sake. They aren't "gifted" CEO spots, they had to work hard to get there, and most have done amazing things for the industry.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#23

Very interesting article about the subject from November 2015: It’s Way Too Easy to Hack the Hospital, http://www.bloomberg.com/features/2015-hospital-hack/

Having worked in hospitals doing network security: They are terribly insecure. They really are a prime example of bad bureaucracy and proprietary software making everything horrible, despite the best of intentions.

YMMV of course.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#24
post #21

So instead of targeting random people in opportunistic attacks, the malware writers had a very clear target here. It's like "spearansomware". I only wonder why it took them so long to get to this idea.

It didn't, they've been doing this to police departments for nearly a year at least.

http://www.darkreading.com/attacks-breaches/police-pay-off-r...

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#25
post #16

Earlier quoted context omitted.

Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow. Another standard may be needed for the larger businesses.

Totally agree, but in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery. Regularly operate in each datacenter and you have Sustained Resiliency. A small business probably won't have staff to maintain such a solution but surely this is a space for a nice niche startup?

> in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery

Things that look simple on the surface are often not easy to implement in practice - especially when you're not starting with a green field.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#26
post #18

Earlier quoted context omitted.

Heaven forbid that top executives ever have to take a pay hit.

I never understood this attitude. Most executives are either life long doctors, or worked their way up the corporate ladder. I don't understand why people who work hard to get to these positions are suddenly vilified as being somehow overpaid? Take for example the CEO at Cedars-Sinai Health System in LA. They guy has held his CEO position for 17 years and worked his way up thought the ranks. He also went to school an…

I think the idea is that they can afford to take a hit on their income. A nurse or patient doesn't have as much flexibility.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#27
post #8

This was quite low, even for a ransomware attack. What's next, daycare centers?

How do you figure? If I'm targeting digital data for ransom, I'm going after the easiest targets. I don't care if it's hospital records, online obituary guestbook, daycare records, a memorial Facebook account - anything that gives me what I'm looking for. This goes doubly so for how notoriously insecure (relatively speaking) hospitals are.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#28
post #12

Exactly what happened? Most hospitals use proprietary electronic medical record systems. These are layered constructs of different networks requiring different passwords and VPNs for their different functions. Is there an actual url that one can visit to verify this? Did the internet archive capture this in a snapshot I can see? Or is this smack that a neighboring hospital is pushing to capture market share in this e…

Probably locked down the physical machines at the hospital. >Most hospitals use proprietary electronic medical record systems. These are layered constructs of different networks requiring different passwords and VPNs for their different functions. That's idealistic. Usually they're giant pieces of shit.

So really the data is unaffected. Just the OS on the client machines is borked and throwing up a scare screen. If that is the case, they can 'just' reimage the machines from backups. I agree, the EMRs are repurposed shit , but honed to an incredibly complex and fine edge.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#30

Very interesting article about the subject from November 2015: It’s Way Too Easy to Hack the Hospital, http://www.bloomberg.com/features/2015-hospital-hack/

Hospital equipment is a sector where we need to push strongly for open solutions. Besides their own security, they are putting people's life in danger. An informed citizen should have a way to check the running software and that the equipment is working properly. An example is X-ray equipment. In some cases, patients have been exposed to strong doses of radiations because of malfunctioning equipment for more than 1O years. Nobody checked. And then you add the risk of hacking.
Post reply on HN