Live data from Hacker News

Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

csoonline.com

41–50 of 50 posts

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#41
post #36

Earlier quoted context omitted.

How do you figure? If I'm targeting digital data for ransom, I'm going after the easiest targets. I don't care if it's hospital records, online obituary guestbook, daycare records, a memorial Facebook account - anything that gives me what I'm looking for. This goes doubly so for how notoriously insecure (relatively speaking) hospitals are.

Even criminals tend to have some moral standards. They are not all complete sociopaths. For instance, go to jail for murdering an adult male and you will be accepted and perhaps even respected by other prisoners. Go to jail for murdering a child and you will be despised and quite possibly abused by the other prisoners.

Even criminals tend to have some moral standards. They are not all complete sociopaths.

I've met a lot of "techie-trash" who even outwardly portray themselves as sociopathic, as if that made them seem smart and cool. Hell, I've been meeting people like that since the 90's! (They are a very slim minority of the tech populace, but their lack of self-awareness makes them tend to be very visible.)

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#42
post #16
post #5

Earlier quoted context omitted.

Yes, I'd love for HIPAA to say: if we're talking about a medical centre, you've got to be able to snapshot and reimage within X hours with data loss of less than Y hours. One can dream...

Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow. Another standard may be needed for the larger businesses.

Part of the problem is that HIPAA must be easy for small private practices as well as massive hospitals to follow.

We're at the point where some company could sell a comprehensive software package for small practices that includes disaster recovery.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#44

Earlier quoted context omitted.

Very good point. It reminds me a comment from the Usenet, a long ago: "if your VCR is still blinking 12:00 then Linux is not for you". Most people playing with technology don't know what they're doing. Giving them more power means giving them more danger.

Basically every piece of hardware with a clock in my house is blinking, yet I'm fine with Linux. The problem isn't that it's too hard to set, but usually they will get unplugged at some point, and you have to set the clocks again. It gets boring very fast.

Somebody should make a simple alarm clock with wifi to sync time via NTP. I guess once you open that can of worms, most alarm clocks add other features, too.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#45

Earlier quoted context omitted.

Totally agree, but in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery. Regularly operate in each datacenter and you have Sustained Resiliency. A small business probably won't have staff to maintain such a solution but surely this is a space for a nice niche startup?

That won't work you'd need the whole datacwnter to comply with the security restriction you can't just have the data in a place where you don't know whom can access

That's not true actually. You can be HIPAA compliant while storing data on AWS. https://aws.amazon.com/compliance/hipaa-compliance/

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#46
post #44

Earlier quoted context omitted.

Basically every piece of hardware with a clock in my house is blinking, yet I'm fine with Linux. The problem isn't that it's too hard to set, but usually they will get unplugged at some point, and you have to set the clocks again. It gets boring very fast.

Somebody should make a simple alarm clock with wifi to sync time via NTP. I guess once you open that can of worms, most alarm clocks add other features, too.

You don't need NTP. There are lots of clocks which can synchronise to radio signal, which is much easier and doesn't require internet connection.

(https://en.wikipedia.org/wiki/Radio_clock)

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#47

Earlier quoted context omitted.

Totally agree, but in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery. Regularly operate in each datacenter and you have Sustained Resiliency. A small business probably won't have staff to maintain such a solution but surely this is a space for a nice niche startup?

> in 2016 that doesn't take much: spin up two instances in different AWS datacenters and fail between them and you have Disaster Recovery Things that look simple on the surface are often not easy to implement in practice - especially when you're not starting with a green field.

Why am I not starting with a greenfield? In my example I did mention a niche start up.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#48

Earlier quoted context omitted.

This goes beyond network security. Most hospital systems, including hardware and software, are insecure. One of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology. One hospital we used to work with had removed passwords on their EMR software for all users because the chief of surgery always forgot his. Their reasoning was that inability to remember…

One of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology. I remember that med students were early adopters of ePocrates in the Palm PDA era. I think it's more that they are atrociously bad at technology, unless it's particularly useful to them. inability to remember passwords slowed people down It would slow people down a lot. Someone needs to sel…

Speech recognition? It's hands free and harder to brute-force than a fingerprint.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#49
post #11

I'm sure they'll just pass the cost (either of the ransom, or of the missed profits) onto the patients.

It's Hollywood, option the movie rights.

Next summer we'll see how many explosions can be worked into a movie "based on a true story" about cybercrime.

Re: Ransomware takes Hollywood hospital offline, $3.6M demanded by attackers

#50

Earlier quoted context omitted.

Having worked in hospitals doing network security: They are terribly insecure. They really are a prime example of bad bureaucracy and proprietary software making everything horrible, despite the best of intentions. YMMV of course.

This goes beyond network security. Most hospital systems, including hardware and software, are insecure. One of the main reason for this is that hospital staff, especially doctors and nurses, tend to be atrociously bad at technology. One hospital we used to work with had removed passwords on their EMR software for all users because the chief of surgery always forgot his. Their reasoning was that inability to remember…

Well, there's too sides to this. You can say they're bad at technology, but why hasn't technology made it possible to sign in with voice recognition or some other speedy and foolproof method? I don't want a doctor switching her attention from diagnostic and treatment questions (which, let us not forget, are rather complicated and challenging in their own right, especially in an urgent care situation) in order to comply with some absent programmer's idea of how security ought to work. Why is typing in a password considered the only acceptable method of system access, given the fact of physical hospital security and so on? Why do technologists like yourself think everyone else should adapt to your standards rather than inventing something that meets the particular needs and circumstances of the clients?
Post reply on HN