Live data from Hacker News

Irish health service hit by cyber attack

bbc.co.uk

81–90 of 156 posts

Re: Irish health service hit by cyber attack

#81

I imagine, to use our vernacular, some chancing gobshite is talking his way our of responsibility for their shitty tender as we speak.

It's the HSE no one's going to be held accountable; in fact someone will probably get a nice bonus this year for 'managing' the situation

Re: Irish health service hit by cyber attack

#82
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

I typically work in situations where the entire data to be backed up (file storage, database) is on the order of 10-100Gb. The projects I’m working on don’t fit the high profile of a Colonial but I’d rather err on the side of safety.

Is there a service that could regularly fetch data from s3 or even connect to postgres, and regularly send a physical copy of the data by mail?

Does it make sense to offer airgapped backups as a service to smaller companies? Over mail?

Re: Irish health service hit by cyber attack

#83
post #80

Earlier quoted context omitted.

Complete, tested tape backups would cure many, many ills. They're out of fashion, but..

The bigger IMO problem with ransomware attacks isn't necessarily that they're holding your data hostage, it's that they can and will publish it. You might be able to tell them to kiss your ass because you have backups, but then they'll publish that information. It's a bit more of a rock-and-a-hard-place situation than most people realize.

Which if you pay the ransom, means also relying on the word of the people that are actively extorting you.

Scary, scary place to be. Especially for a health service.

Re: Irish health service hit by cyber attack

#84
One of the major issues I've seen while working with large organisation on software development is one of mindset. These are organisations who predominantly think: "We are an 'x' organisation that happens to develop software". The more productive and safer way of thinking is: "We are a software development organisation that is within 'x' market".

However, the latter requires a huge mindset and experience shift from the very top of the organisation. And groups and individuals of that organisation having strong interest in their survivability are, of course, not going to change that.

Re: Irish health service hit by cyber attack

#85

One of the major issues I've seen while working with large organisation on software development is one of mindset. These are organisations who predominantly think: "We are an 'x' organisation that happens to develop software". The more productive and safer way of thinking is: "We are a software development organisation that is within 'x' market". However, the latter requires a huge mindset and experience shift from t…

What if software development isn't the most technically challenging aspect of their operation? Say spaceX or a nuclear physics lab?

Re: Irish health service hit by cyber attack

#86
post #50
post #45

Earlier quoted context omitted.

1. It can only be an act of war if it was done by a nation state. Even though the US likes to declare war on abstract concepts like "drugs" and "crime", that is not how it works in international law. 2. Terrorism has similarly precise definitions, usually along the lines of "the act has to be in pursuit of political aims". Just because its a big and important target does not make it political, ransomware is an econom…

If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. Given the recent pipeline issue and its national security implications I am not going to be surprised at all if some hackers in Russia end up dead from 'accidents' that are so obviously not accidents that no one is fooled.

Here I was thinking about how wonderful it would be to live in a nation like Ireland, where hacks can happen without interested parties attempting in pathetic fashion to cover their asses by invoking the specter of RussiaRussiaRussia... I should have known someone would break the spell.

Re: Irish health service hit by cyber attack

#87
post #80

Earlier quoted context omitted.

Complete, tested tape backups would cure many, many ills. They're out of fashion, but..

The bigger IMO problem with ransomware attacks isn't necessarily that they're holding your data hostage, it's that they can and will publish it. You might be able to tell them to kiss your ass because you have backups, but then they'll publish that information. It's a bit more of a rock-and-a-hard-place situation than most people realize.

Eh. From my understanding the people that pay do fine. As sick as it is, these crews following through is good for business. These crews are making tons of cash. If word gets out they don't unencrypt and do publicly publish - people will just stop paying: period. Hell. Some of these crews have a help desk. [1]

https://www.macworld.co.uk/cmsdata/features/3659100/how_to_r...

Re: Irish health service hit by cyber attack

#88
post #64

I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…

I typically work in situations where the entire data to be backed up (file storage, database) is on the order of 10-100Gb. The projects I’m working on don’t fit the high profile of a Colonial but I’d rather err on the side of safety. Is there a service that could regularly fetch data from s3 or even connect to postgres, and regularly send a physical copy of the data by mail? Does it make sense to offer airgapped back…

If you use mail consider if your restore time will be less than your acceptable down time.

Re: Irish health service hit by cyber attack

#90

There's a trend of paying these ransomware attacks which are sometimes in the order of millions. Imagine if those millions were _proactively_ invested into the computer security of these systems?

I tried to imagine, but my mind told me that a couple of millions would not prevent these issues. Did I imagine it wrong? You would likely end up with better security. Would it be good enough to prevent breaches? Doubt it.

Most ransomware is pointless where regular reliable backups are in place. A situation like this where there are privacy and outage concerns is a bit different. We may eventually discover that the operators of the system discussed in TFA really were backing up that system, although probably for less than "a couple of millions". Still, ransomware payments are usually a penalty for not doing backups.
Post reply on HN