Live data from Hacker News

2.7M medical calls breached in Sweden

twitter.com

71–80 of 116 posts

Re: 2.7M medical calls breached in Sweden

#71

Earlier quoted context omitted.

The "funny" thing is, it wasnt using HTTPS, it was on the 443 port. But the data was sent unencrypted.

These calls were answered by Swedish-speaking people in Thailand. Their business idea was to handle calls that were placed in inconvenient hours, relative to Swedish business hours. My best guess is that the Thai ISP this office used filtered all outgoing connections except port 80 and 443. And then someone decided that the way to implement this securely while still allowing this office to access the data was to put…

I would guess the server is run by the voip provider in Stockholm, which literally seems to be 1-3 contractors. Reading between the lines of the few articles published about the call center it seems like their business idea is to hire old nurses and not pay them very much.

https://www.voiceintegrate.com/se/support/vi-som-jobbar-h%C3...

Re: 2.7M medical calls breached in Sweden

#72
post #35

Earlier quoted context omitted.

Phone company? It's the comapny employing nurses receiving the calls.

Ah that's the reason you exert the maximum pain at a high enough level - then the phone companies will take security properly and enforce it on third parties.

If I record a phone call between you and me, then put said recording on pastebin or what not, can you honestly blame your phone company or mine?

Re: 2.7M medical calls breached in Sweden

#73

Why would you even record these calls indefinitely, without a deletion schedule? Were they recording all calls, not just a subset to be audited for customer service? Why not have an auditor listen to the call live and destroy the recording if everything is done by the book and evidence need not be retained?

Medical advice over the phone? What happens when someone dies, or gets worse? One of the first things you'll want to know is what advice was offered. I would imagine they had to record all, and keep for some preset period.

Oh yeah, I don't think it's weird that it's recorded, but having it delete after X days is so simple I'm shocked it wasn't implemented in a Nordic country w/ strong privacy laws.

On the upside, at least it's probably harder to sift through that data to find embarrassing and/or sensitive information than if it was textual.

(This is one reason that if I'm having a personal issue, I prefer to do a voice call with a friend rather than use IMs like many in my generation are so fond of)

Re: 2.7M medical calls breached in Sweden

#74
post #33

Yep. My calls with personal identification number are absolutely in there, with list of 10+ medications, and medical history including genetic disorders and other things. Imagine becoming a public person in the future with random russian mobs blackmailing me based on me and my family's medical history.

> My calls with personal identification number are absolutely in there Is this an assumption, or were you able to find a list of leaked calls somewhere?

If so, please provide details on how can verify if my details are in there as well.

Slightly pissed of Swede who called 1177 just last week here. Still I'm glad this happened after GDPR, this means everyone who's personal details were compromise should have plenty of legal options right now.

Re: 2.7M medical calls breached in Sweden

#75

On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The…

The breach is still ongoing, according to statements on the dark web, 30 minutes ago (21:10 CET).

"Tror ni inkompetensen är över? Nej. Man har inte dragit ut sladden. Kör wireshark och skicka skräppacket så ser ni att det enda som filtreras är syn-ack från servern.Slumpade seq-nr i respons bara någon timme och upprättade till slut en anslutning. Vad tror ni jag ser? Färska samtal från bara några sekunder sen i mappen /2019/."

Translates to: Do you think incompetence is over? No. They have not pulled out the cable. Run wireshark and send junk packets and you will see that the only thing that is filtered is syn-ack from the server. Sent random seq-no in response for an hour and finally made a connection. What do you think I see? Fresh calls from just a few seconds ago in the folder / 2019 /.

Re: 2.7M medical calls breached in Sweden

#76
post #47
post #33

Yep. My calls with personal identification number are absolutely in there, with list of 10+ medications, and medical history including genetic disorders and other things. Imagine becoming a public person in the future with random russian mobs blackmailing me based on me and my family's medical history.

> blackmailing me based on me and my family's medical history. like "we 'll tell everyone you re 1.5 times more likely to get ulcer?"

Maybe you were raped but don't want everyone to know, but you spoke to your doctor about psych referral for rape victims? Or you had a mental health crisis? Or you had/have sexually transmitted diseases/infections? Maybe you've been suicidal, and work will fire you if they find out? Perhaps you have cancer, a degenerative disease, but you don't want your family/employer/SO to know?

Seems like lots of possible blackmail opportunities.

But even something like having an ulcer could be used against you. I recall one national ruler using another's fear of dogs to humiliate them as part of a negotiation. Give someone food to inflame their ulcer prior to a business negotiation, use their discomfort to wrong-foot them ...

Re: 2.7M medical calls breached in Sweden

#77
post #34

Earlier quoted context omitted.

Stockholms landsting. The landsting are absolutely disgusting when it comes to handing out important tasks to private companys. I have _REALLY_ serious info in there, and so do members of my family, that can not get out. But it's effing public, and the CEO of the company responsible is handling it like an asshole and Stockholms Landsting will just add it to the pile of fuckups. It would literally take less than a min…

This is a far more general problem of states in general. They always see themselves above the rules they apply to others and this is particularly problematic in the medical realm, but also affects criminal justice for example. Governments just don't follow their own rules. This means that medical files just aren't trustworthy anymore, in the sense that the patient has no control over who sees these and how far they a…

I don’t see this as a problem of ”not following rules” and for “government” as a concept to eat the blame.

This stuff, along with many other things have been outsourced in Sweden to private contractors.

In the end, government is made up of people, and these guys outsourcing and selling off everything are just the ones that would blame the governement.

It’s facinating, and a self fulfilling prophecy!

“Look the government can’t do s*it, they should not be doing things at all. Let’s outsource some more.”

The next contractor hits the wall.

“Look, government can’t handle it. Let’s outsource”.

That is at least how I’ve seen play out here in Stockholm.

I’m hoping we can take the schools back at least... because outsourcing teaching has been a disaster imo.

Re: 2.7M medical calls breached in Sweden

#78
post #74

Earlier quoted context omitted.

> My calls with personal identification number are absolutely in there Is this an assumption, or were you able to find a list of leaked calls somewhere?

If so, please provide details on how can verify if my details are in there as well. Slightly pissed of Swede who called 1177 just last week here. Still I'm glad this happened after GDPR, this means everyone who's personal details were compromise should have plenty of legal options right now.

GDPR doesn't give you any legal option aside from asking your data protection authority.

Re: 2.7M medical calls breached in Sweden

#79
post #44
post #34

Earlier quoted context omitted.

Stockholms landsting. The landsting are absolutely disgusting when it comes to handing out important tasks to private companys. I have _REALLY_ serious info in there, and so do members of my family, that can not get out. But it's effing public, and the CEO of the company responsible is handling it like an asshole and Stockholms Landsting will just add it to the pile of fuckups. It would literally take less than a min…

You don't outsource, or 'privatize', because you want responsibility. In the pitch for the company in question they are stating how Stockholm has the lowest cost of all counties for this service [0]. Apparently that means outsourcing to a call center in Thailand [1]. Which in turn use some random provider [2]. It isn't really something hidden. In fact I would say that the whole idea is well supported by a significant…

I just wanted to add, if I came across as criticizing, that I do agree with you. I do think the county is at fault. I do think people should expect more. I am just not seeing people doing that.

Sweden was never perfect, but some of its reputation as a functional country is not unfounded. Today we have many systems we know aren't working, yet little is being done. I have even heard Swedish political analysts being dumbfounded that some political issues were there are obvious flaws, and should be something that matters to people, don't show in the polls. I guess it might have to do with the political landscape, were there are a large number of people that very likely are dissatisfied. It just doesn't, because of the polarized situation, result in change. Instead it results in whatever is less objectionable, which is mostly whatever made the situation bad in the first place.

Anyway. I hope this incident get some more attention in Swedish media.

Re: 2.7M medical calls breached in Sweden

#80

Earlier quoted context omitted.

Because Swedes are uniquely morally upstanding and non-judgemental?

No, we're highly judgemental, but an employer is not allowed to inquire or make hiring/firing decisions with regard to your health status. Likewise life insurance might have a higher premium if you regularly engage in extreme sports, but they can't deny you. Health care is ubiquitous regardless of your condition.

So do you then think it's legal in the U.S to possess stolen health data?
Post reply on HN