This is why you should not go to a therapist who uses electronic records. This will happen to you at some point.
The 'untouchable hacker god' behind Finland's biggest crime
81–90 of 183 posts
Re: The 'untouchable hacker god' behind Finland's biggest crime
#82I have seen therapists in the past, but never over video calls, and the notes have been kept on paper. Sometimes in person is much better. This rush to put everything online will destroy everyone's privacy even though privacy is the thing we all need.
This isn't a great solution, but it has helped me forgive myself, maybe it can be a trend in the future: You didn't pick your DNA, you didn't pick your environment. (Determinism in a nutshell) The bad things that happened to you, and the bad thing you did, should be seen as somewhat outside our control. I think of my worst google searches (nsfw stuff) and think: "Well, I'm just a chemical reaction." But then again, I…
Re: The 'untouchable hacker god' behind Finland's biggest crime
#83He’s done less than seven years of time, shows no remorse and even denies doing it in the first place. You dropped the ball on this Finland, don’t be surprised when he does it again. What a disgusting human being.
I'd bet good money that this dude has some sort of antisocial personality disorder, and really can't be "cured", so to speak. Something tells me he'll try to sneak out of Finland (which is easy due to Schengen), purchase a new passport, and leave Europe. I guess a silver lining here is the possibility that he'll commit crimes in countries with far harsher penalties than Finland. I've lived in Finland myself, and curr…
I'm happy to take you up on this, but I feel like the stakes will need to be pretty high to justify all the effort involved.
>Something tells me he'll try to sneak out of Finland (which is easy due to Schengen), purchase a new passport, and leave Europe.
Why would I do that? I hold a valid Finnish passport, haven't had any trouble entering or exciting Schengen zone lately.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#84This is why you should not go to a therapist who uses electronic records. This will happen to you at some point.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#85"the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it" There _should_ be a bunch of people in jail for that. Including, but not limited to the CEO. It should also include all the people on the org chart between whoever set that database up and the CEO.
Exactly, was it a burglary when your front door is open, lights on, spotlights on your wall safe, with the keys still inserted? The CEO should be in prison.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#86Earlier quoted context omitted.
Funny whenever people complain about the GDPR here they're thinking they would be slapped with a €20Mi fine and that EU team 6 is going to parachute in their office and arrest everyone So they're saying this is not the case?
Well, not for public bodies at least: “ Administrative fines cannot be imposed on public organisations, such as the government or state-owned companies, municipalities and parishes” [1] But luckily this sort of thing never happens in the public sector. Except for when it does: https://yle.fi/a/74-20094950 [1] https://tietosuoja.fi/en/corrective-powers
However I don't see any municipality in Finland getting fines
Re: The 'untouchable hacker god' behind Finland's biggest crime
#87Re: The 'untouchable hacker god' behind Finland's biggest crime
#88Earlier quoted context omitted.
According to this report [1] the appeal was about specific requirements like encryption, and he claimed he had delegated it. So it is clear that it is hard to actually hold people responsible. > The appellate court rejected the prosecution's argument and dismissed all charges. In its unanimous decision, the court stated that neither the GDPR nor the applicable Finnish healthcare legislation required encryption or pse…
No, it’s just that it’s crazy to hold the CEO liable for absolutely everything that can go wrong.
If that is not created -> CEO responsibility.
If that is not followed -> top level mgmt responsibility.
And so on, further down the chain.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#89Earlier quoted context omitted.
According to this report [1] the appeal was about specific requirements like encryption, and he claimed he had delegated it. So it is clear that it is hard to actually hold people responsible. > The appellate court rejected the prosecution's argument and dismissed all charges. In its unanimous decision, the court stated that neither the GDPR nor the applicable Finnish healthcare legislation required encryption or pse…
No, it’s just that it’s crazy to hold the CEO liable for absolutely everything that can go wrong.
It isn’t absolutely everything, it’s for negligence. If you don’t have basics in place, like independent pen-tests, ISO 27001 audits — or some equivalent — when you’re handling clinical data, then that’s negligence.
If a breach happens and you were seen to have followed best practice, you won’t be found criminally negligent.
That is part of being an executive. The buck stops with you — if you’re an executive, you’d better understand your obligations, you get the big bucks for a reason, it isn’t just a fancy job title.
Other people in the organisation can be held accountable for criminal acts, but when it comes to criminal negligence, it’s the executives that are liable, because it’s a systemic failure and you’re deemed to be in-charge of the system.