Live data from Hacker News

2.7M medical calls breached in Sweden

twitter.com

81–90 of 116 posts

Re: 2.7M medical calls breached in Sweden

#81
post #44
post #34

Earlier quoted context omitted.

Stockholms landsting. The landsting are absolutely disgusting when it comes to handing out important tasks to private companys. I have _REALLY_ serious info in there, and so do members of my family, that can not get out. But it's effing public, and the CEO of the company responsible is handling it like an asshole and Stockholms Landsting will just add it to the pile of fuckups. It would literally take less than a min…

You don't outsource, or 'privatize', because you want responsibility. In the pitch for the company in question they are stating how Stockholm has the lowest cost of all counties for this service [0]. Apparently that means outsourcing to a call center in Thailand [1]. Which in turn use some random provider [2]. It isn't really something hidden. In fact I would say that the whole idea is well supported by a significant…

But blaming politicians, the government and companies is the way to request responsibility, isn't it? Without the political pressure you can request whatever you like, but to a little effect. And as outsourcing work like this is totally illegal under GDPR, it's definitely up to the government to enforce it's laws on it's own contractors, and it's up to companies to suffer the consequences of not treating peoples privacy seriously. The blame here is 100% real.

Re: 2.7M medical calls breached in Sweden

#82

On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The…

Not HTTPS. Plain unencrypted HTTP on port 443.

No authentication for clients either.

Re: 2.7M medical calls breached in Sweden

#83
post #35

Earlier quoted context omitted.

Maybe the phone company responsible needs to have its licence revoked without compensation.

Phone company? It's the comapny employing nurses receiving the calls.

I guess "phone company" is used here loosely, to describe the provider of VoIP call center and recording service provider employed by the service (which is owned by the municipal/county co-operation organisation SKL, Sveriges Kommuner och Landsting).

Re: 2.7M medical calls breached in Sweden

#84
post #65

Earlier quoted context omitted.

Recording the calls could even be a requirement. You call in to get medical advice, then later decide the advice was wrong and sue them for malpractice. Recordings of the calls could be crucial to deciding the case later on.

That's Sweden, not the USA.

Such requirements do exist in Sweden, too.

Re: 2.7M medical calls breached in Sweden

#85

There are quite a few hosts responding on port 80 in the 188.92.248.0/21 subnet, including versions of httpd and php over a decade old. I wouldn't be surprised if there are more things unsecured. Yikes.

Not a good idea to show the ip addr in the screenshot.

Re: 2.7M medical calls breached in Sweden

#86
post #6

I'm not clear on why medical records are so sensitive. I can understand some people might want to hide HIV status - but is there anything else? In the US people have wanted to hide prior conditions from insurance companies, but I wouldn't expect this a problem in Sweden.

Thanks for the replies on this. I was really thinking of my friends and family, I think I know most of what people have had, including abortions, mental illness, cancer etc. I can now see how others can have serious problems with abuse, harassment or unwanted publicity of private issues.

Re: 2.7M medical calls breached in Sweden

#87
post #34

Earlier quoted context omitted.

Stockholms landsting. The landsting are absolutely disgusting when it comes to handing out important tasks to private companys. I have _REALLY_ serious info in there, and so do members of my family, that can not get out. But it's effing public, and the CEO of the company responsible is handling it like an asshole and Stockholms Landsting will just add it to the pile of fuckups. It would literally take less than a min…

This is a far more general problem of states in general. They always see themselves above the rules they apply to others and this is particularly problematic in the medical realm, but also affects criminal justice for example. Governments just don't follow their own rules. This means that medical files just aren't trustworthy anymore, in the sense that the patient has no control over who sees these and how far they a…

> At this point the only advice you can give is to please ask every doctor you ask to not make any notes or files on you at all, and just deal with that. "I travel a lot and this just causes trouble" is a useful phrase in that regard.

Does this work? From what I hear, beyond the obvious benefits of enabling continued care, notes have an extra important purpose: it helps doctors to protect themselves against bullshit lawsuits.

An medical student in my family told me a story once, about a doctor who told a patient to get some tests. The patient ignored the advice, and found themselves dead couple of years later, from illness that would be detected early on those tests. The patient's husband came to doctor's office, seeking to sue her for negligence, and what saved her was that she had notes from those years ago, that clearly stated she did in fact order the patient to get the relevant tests done.

Re: 2.7M medical calls breached in Sweden

#88
post #26

Seeing posts like this remind me of a nice quotation I saw somewhere, which is like "all data will eventually be either public or gone forever". Unfortunately my search skills are insufficient to find the exact wording or author.

I'm okay with that: when I'm dead, do with my data what you will (of course, so long as anyone implicated like chat partners in chat data, are also dead). But I guess the quote refers to shorter timespans than that.

Except with medical history, your data can impact your children and grandchildren (both positively and negatively, but also hopefully privately regardless).

Re: 2.7M medical calls breached in Sweden

#89
post #81
post #44

Earlier quoted context omitted.

You don't outsource, or 'privatize', because you want responsibility. In the pitch for the company in question they are stating how Stockholm has the lowest cost of all counties for this service [0]. Apparently that means outsourcing to a call center in Thailand [1]. Which in turn use some random provider [2]. It isn't really something hidden. In fact I would say that the whole idea is well supported by a significant…

But blaming politicians, the government and companies is the way to request responsibility, isn't it? Without the political pressure you can request whatever you like, but to a little effect. And as outsourcing work like this is totally illegal under GDPR, it's definitely up to the government to enforce it's laws on it's own contractors, and it's up to companies to suffer the consequences of not treating peoples priv…

I touched upon this in my other comment. I don't think it is wrong to criticize, but there can't be meaningful change unless you actually allow yourself to address the problem. It is a bit hard to explain if you haven't experienced Swedish politics lately. I'll just give you some examples:

1. The same county awarded contracts for building a hospital were the cost ended up quadrupling to $6 billion more than initially expected. (They got reelected). https://www.thelocal.se/20180207/finance-minister-calls-for-...

2. There was a well publicized scandal a little more than a year ago were aggressive outsourcing ended up potentially exposing classified data. (Some politicians did have to quit, but only for handling situation poorly after the fact). https://www.thelocal.se/20170721/it-workers-in-other-countri...

3. "Sweden has had a quicker liberalisation than any other advanced economy in the world, in terms of privatisation and deregulation" https://www.thelocal.se/20120324/39864

4. Yet, "They were shocked to find that there is very little evaluation of the effects of the privatisation on Swedish society" https://www.thelocal.se/20110907/36006

5. And maybe the most glaring example of dysfunction, the housing market. https://www.telegraph.co.uk/personal-banking/mortgages/swede... https://www.thelocal.se/20170518/housing-crisis-forces-recor... https://www.thelocal.se/20170828/the-story-of-swedens-housin...

There just isn't much of an expectation of control, or that issues will be dealt with, these days in Sweden. It is unlikely that there would be any meaningful change in this situation either. Any effective change will be off the table and they will continue to outsource without much oversight because that is the agenda. Which is largely what has happened in other areas.

Re: 2.7M medical calls breached in Sweden

#90

On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The…

The breach is still ongoing, according to statements on the dark web, 30 minutes ago (21:10 CET). "Tror ni inkompetensen är över? Nej. Man har inte dragit ut sladden. Kör wireshark och skicka skräppacket så ser ni att det enda som filtreras är syn-ack från servern.Slumpade seq-nr i respons bara någon timme och upprättade till slut en anslutning. Vad tror ni jag ser? Färska samtal från bara några sekunder sen i mappen…

How can you make a connection by guessing seq nr ? What is the firewall rule that allow such an attack ?
Post reply on HN