Live data from Hacker News

Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

csoonline.com

31–40 of 50 posts

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#31

The internet of things... what could possibly go wrong?

Very good point. It reminds me a comment from the Usenet, a long ago: "if your VCR is still blinking 12:00 then Linux is not for you". Most people playing with technology don't know what they're doing. Giving them more power means giving them more danger.

Basically every piece of hardware with a clock in my house is blinking, yet I'm fine with Linux. The problem isn't that it's too hard to set, but usually they will get unplugged at some point, and you have to set the clocks again. It gets boring very fast.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#32

Very interesting article about the subject from November 2015: It’s Way Too Easy to Hack the Hospital, http://www.bloomberg.com/features/2015-hospital-hack/

Having worked in hospitals doing network security: They are terribly insecure. They really are a prime example of bad bureaucracy and proprietary software making everything horrible, despite the best of intentions. YMMV of course.

This goes beyond network security. Most hospital systems, including hardware and software, are insecure. One of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology. One hospital we used to work with had removed passwords on their EMR software for all users because the chief of surgery always forgot his. Their reasoning was that inability to remember passwords slowed people down, and the EMR software was "internal anyway" so what could be the worst case scenario of not having passwords?

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#33

Doesn't sound like a major hospital. The major hospital in Hollywood is Cedars-Sinai, IIRC.

Hollywood Presbyterian Medical Center has 434 beds and around 1500 employees. That's pretty decent.

Cedars-Sinai is indeed about twice the size, but that's mostly because Cedars-Sinai is extraordinarily large.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#34
post #16

Earlier quoted context omitted.

Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow. Another standard may be needed for the larger businesses.

Totally agree, but in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery. Regularly operate in each datacenter and you have Sustained Resiliency. A small business probably won't have staff to maintain such a solution but surely this is a space for a nice niche startup?

That won't work you'd need the whole datacwnter to comply with the security restriction you can't just have the data in a place where you don't know whom can access

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#36
post #8

This was quite low, even for a ransomware attack. What's next, daycare centers?

How do you figure? If I'm targeting digital data for ransom, I'm going after the easiest targets. I don't care if it's hospital records, online obituary guestbook, daycare records, a memorial Facebook account - anything that gives me what I'm looking for. This goes doubly so for how notoriously insecure (relatively speaking) hospitals are.

Even criminals tend to have some moral standards. They are not all complete sociopaths. For instance, go to jail for murdering an adult male and you will be accepted and perhaps even respected by other prisoners. Go to jail for murdering a child and you will be despised and quite possibly abused by the other prisoners.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#38
not sure if they are being specifically targeted, or hospital networks are easy targets, but i work with a vendor who supports this hospital.

this is the 3rd major healthcare org hit with this in like past 3 weeks. last one just got hit last week.

RIS/HIS/PACS/EHR/any systems all hit, with like 80-90% of network equipment compromised

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#39

Very interesting article about the subject from November 2015: It’s Way Too Easy to Hack the Hospital, http://www.bloomberg.com/features/2015-hospital-hack/

Hospital equipment is a sector where we need to push strongly for open solutions. Besides their own security, they are putting people's life in danger. An informed citizen should have a way to check the running software and that the equipment is working properly. An example is X-ray equipment. In some cases, patients have been exposed to strong doses of radiations because of malfunctioning equipment for more than 1O…

Hospital equipment is a sector where we need to push strongly for open solutions. Besides their own security, they are putting people's life in danger.

It's a sector where there needs to be a push for software/hardware quality, period! One of my former coworkers from years ago used to write software for medical equipment. The software ran on the cheapest Windows boards the company could find. There was no standardization apart from window dressing. Attitude of management was to just get it out the door, and it would be fine.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#40

Earlier quoted context omitted.

Having worked in hospitals doing network security: They are terribly insecure. They really are a prime example of bad bureaucracy and proprietary software making everything horrible, despite the best of intentions. YMMV of course.

This goes beyond network security. Most hospital systems, including hardware and software, are insecure. One of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology. One hospital we used to work with had removed passwords on their EMR software for all users because the chief of surgery always forgot his. Their reasoning was that inability to remember…

One of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology.

I remember that med students were early adopters of ePocrates in the Palm PDA era. I think it's more that they are atrociously bad at technology, unless it's particularly useful to them.

inability to remember passwords slowed people down

It would slow people down a lot. Someone needs to sell some sort of zero effort authentication technology for hospitals. (One where a supervising nurse could quickly auth the chief of surgery, because that sort of guy is going to forget his token/device.)

Post reply on HN