Live data from Hacker News

Irish health service hit by cyber attack

bbc.co.uk

61–70 of 156 posts

Re: Irish health service hit by cyber attack

#62

For those concerned about privacy violations, this should be rammed home as an argument against centralized collection of medical health data.

I believe that if all health records leaked tomorrow, the world would end up a better place.

Sure, someone might get more expensive insurance quotes or made fun of for having ADHD, HIV or acne treatment...

But I think that would be outweighed by health benefits by combing the data for correlations and causations that have been unidentified in the past. Being able to shut down things that are poisoning millions of people, but to such a minor extent it isn't immediately obvious, would have a big benefit for society.

Re: Irish health service hit by cyber attack

#64
I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years.

* Keep all systems up to date with the latest patches.

* Have a DR plan and test it regularly.

* Make frequent backups, verify them, and keep them offline.

Historically organizations have been so bad at backups that the advice has been to automate them as much as possible, to try to ensure that a recent backup at least exists. But I am increasingly of the opinion that the next level of backup maturity is to dial back on the automation and invest manual effort in airgapping the backups.

Fully automated backups are necessarily part of the software attack surface.

If you have to hire more ops people to rotate tapes by hand every day, that will have to be a cost of doing business safely.

Re: Irish health service hit by cyber attack

#65
post #45

wouldn't disrupting healthcare services be an act or terrorism or even war?

1. It can only be an act of war if it was done by a nation state. Even though the US likes to declare war on abstract concepts like "drugs" and "crime", that is not how it works in international law. 2. Terrorism has similarly precise definitions, usually along the lines of "the act has to be in pursuit of political aims". Just because its a big and important target does not make it political, ransomware is an econom…

> It can only be an act of war if it was done by a nation state

This is not true. For example major countries like the United States and the United Kingdom are not nation states but can still commit acts of war under international law.

Re: Irish health service hit by cyber attack

#66
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

Complete, tested tape backups would cure many, many ills. They're out of fashion, but..

Re: Irish health service hit by cyber attack

#67
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

Complete, tested tape backups would cure many, many ills. They're out of fashion, but..

Tape backups are ok but still mean significant operational downtime because recovery from tape is slow. This is better for long term data storage than rapid recovery.

For recovery, you need more accessible backups. And to test your backup plan.

Re: Irish health service hit by cyber attack

#68

For those concerned about privacy violations, this should be rammed home as an argument against centralized collection of medical health data.

I believe that if all health records leaked tomorrow, the world would end up a better place. Sure, someone might get more expensive insurance quotes or made fun of for having ADHD, HIV or acne treatment... But I think that would be outweighed by health benefits by combing the data for correlations and causations that have been unidentified in the past. Being able to shut down things that are poisoning millions of peo…

The upsides may come. The downsides will come.

I am pessimistic on this one.

Re: Irish health service hit by cyber attack

#69

There's a trend of paying these ransomware attacks which are sometimes in the order of millions. Imagine if those millions were _proactively_ invested into the computer security of these systems?

I tried to imagine, but my mind told me that a couple of millions would not prevent these issues. Did I imagine it wrong? You would likely end up with better security. Would it be good enough to prevent breaches? Doubt it.

I think preventing breaches is a losing battle. There will always be new vulnerabilities.

You can practice things that make recovery fast and reduce the impact of breaches though. Isolate data, encrypt it, only grant necessary access, have robust backups and test recovery regularly. These things take time and money though, and most companies are unwilling to do them sufficiently.

Re: Irish health service hit by cyber attack

#70

wouldn't disrupting healthcare services be an act or terrorism or even war?

You’d think these attacks would be worth some tit for tat. If people and companies were physically raided by groups, the govt would likely take action. I’m not sure what the difference is. (And to those saying it’s not international law, that’s just made up anyways so I’m not sure why that’d matter now).
Post reply on HN