Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

301–310 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#301

Earlier quoted context omitted.

> Attacking a hospital is a war crime, Strictly speaking, if people we don't like attack a hospital it's a war crime; if we do it, it's an accident. > so how is it not terrorism? Murdering civilians during a war is a war crime; that doesn't mean murder automatically equals terrorism outside of war.

Come on. Blowing up a hospital is a crime, and arguably terrorism. Disabling the hospital and systematically preventing it from treating patients is a lesser thing. But still arguably terrorism if done intentionally. And yes, it matters if an enemy or friend does it. That's so obvious to not merit discussion.

How is it "arguably terrorism" and not extortion?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#302

Earlier quoted context omitted.

Come on. Blowing up a hospital is a crime, and arguably terrorism. Disabling the hospital and systematically preventing it from treating patients is a lesser thing. But still arguably terrorism if done intentionally. And yes, it matters if an enemy or friend does it. That's so obvious to not merit discussion.

How is it "arguably terrorism" and not extortion?

Because of the confusion, death and fear it creates. It's a hospital, remember?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#303

Earlier quoted context omitted.

In general, regulated entities are required to regularly prove that their change-management processes are sufficiently heavy as to make regular patching a non-starter.

This. A million times. Regulation isn't the solution to this industry's woes -- it's the cause.

HIPAA contains a security and privacy rule, but its original aim was to spur patient record portability between providers and insurers. That lineage of regulation, which also includes HITECH, ARRA, and provisions tied to Medicare expansion, established the carrots and sticks thought necessary to modernize the health industries records--to get them off paper and into bits. All this modernization eventually happened, but it's hard to say whether the regulation was the primary driver or if these companies would have done it anyway. Having worked in the industry, I lean toward the regulations being the primary driver. Low risk tolerance was already a characteristic of health organizations before HIPAA (and I think patient safety was the main reason). When HIPAA was signed in 1996, most US industries were heavily computerized, but health organizations lagged far behind. Lack of competition where most providers and insurers operated meant there was little commercial incentive for them to spend money to be able to exchange files with organizations in other states. Digitalization just wasn't coming together in health care as rapidly as in other industries, although I didn't work in health at the time so I don't feel like I personally know all the reasons.

It's been a long time since 1996, but most of the IT messes inside health organizations are self-inflicted. HIPAA and friends don't mandate which operating systems you use, specify approved encryption algorithms, or tell you when and how to update your computer systems. These are all choices left to the implementation teams, and they chose to work with vendors who aligned their solutions to information architectures that just don't change very fast. I think if you compared this IT situation to, say, large scale manufacturing in the US you'd find similar problems of outdated platforms supporting expensive and hard-to-change niche software. And it's probably market forces, not government regulation, that's responsible for this similarity.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#304
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

And if it’s from China? This is going to be a controversial suggestion, but I have a feeling that we might already be in an asymmetric world war and our leaders might quietly know it. This year has felt like checkmate.

Then we should not be so meek as to do nothing. During the Cold War, nations did not sit idly by as their adversaries developed nuclear capabilities which, make no mistake about it, targeted civilians and civilian infrastructure. Of course, we developed our own defensive capabilities but then, as now, we faced a type of threat which hugely favored the attacker. So we kept pace with the offensive capabilities of our adversaries. If China or Russia (the states themselves) is identified beyond doubt as the source of this attack, then our policy must be to retaliate in kind.

Mutually assured destruction for the cyber-age.

If it's organized criminal hackers we're dealing with, then we should treat them how we would treat any legitimate terroristic threat. I would want our intelligence agencies to reach out and touch them.

This may not be a popular point of view on Hacker News. I unfortunately cannot fathom an alternative solution.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#305

Earlier quoted context omitted.

How is it "arguably terrorism" and not extortion?

Because of the confusion, death and fear it creates. It's a hospital, remember?

Perhaps you should remember your own argument, or at least decide what it is, before continuing with the condescending attitude.

First it was terrorism because it's deliberate; now it's terrorism because it creates confusion, death and fear.

Here's just one example that checks all those boxes and is, of course, not terrorism:

https://en.wikipedia.org/wiki/Mercy_Hospital_shooting

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#306
post #247
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

So should Russia do the same? After all the US did officially declare a cyberwar against Russia. If this ends up being attributed to Russia they have a very real defence in pointing the finger at the US and saying "You started it!"

If the United States pre-emptively attacks a foreign country with a cyber attack resulting in the loss of human life, then yes, Russia or any state would be justified in retaliating. This is equally true for any such use of any weapon of mass destruction.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#308

Earlier quoted context omitted.

It is my experience that hospital(s) do not have the budget for Windows 10 across their entire network.

In that case, my proposal would be that hospital customers should be able to opt into a program that allows them to buy a thumb drive from the hospital that has their records in an encrypted file, with images exported into an open lossless standard such as PNG. What size thumb drive would most patients individual records fit onto?

I registered an account to comment because this made me laugh. One does not simply export images from medical systems. It takes a ton of effort and clicking to get patient images out of most PACS systems IF YOU ARE LUCKY. DICOM images are often high bit-depth JPEG2000 and are hard to get access to because of the way PACS systems and medical devices store data. Screen scraping DICOMs would take ages as each DICOM can have any number of slices. You don't want to lose the original bit-depth either as radiologists use contrast enhancement techniques which don't work with images encoded in 8-bits like screen scrapes. The PACS tech industry is simply painful to deal with.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#309
post #284

Earlier quoted context omitted.

The goal of terrorism is always political. Fear is the tool used by terrorism to reach the goal. Fear is a defining feature, but just means to an end. As others have noted: while this instance is unlikely to be terrorism, this is a tool that is useful in terrorism and has been used as such in the past.

Citing Wikipedia [1] > The use of violence or of the threat of violence in the pursuit of political, religious, ideological or social objectives One could argue these are all political. In the end, you can deduce anything to being political. Or this definition by Alex P. Schmid from 1988: > "Terrorism is an anxiety-inspiring method of repeated violent action, employed by (semi-)clandestine individual, group, or state…

I take issue with the first two: "idiosyncratic, criminal, or political reasons." Only political reasons is legitimately terrorism. Terrorism and provoking mere "terror" are not the same thing.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#310
post #288

Earlier quoted context omitted.

> This is what terrorism looks like in 2020. Given the (extra-)legal powers that are activated by that word, I'd be circumspect in using it. Many crimes are "horrifying, terrifying, [and] disgusting" without rising to the level of terrorism.

Attacking a hospital is a war crime, so how is it not terrorism?

Isn't terrorism trying to achieve a political goal through violence? Getting ransom money is just garden variety greed imo.
Post reply on HN