Live data from Hacker News

2.7M medical calls breached in Sweden

twitter.com

91–100 of 116 posts

Re: 2.7M medical calls breached in Sweden

#91
post #18

Earlier quoted context omitted.

STDs in general are sensitive since people may want to hide them or hide the implications. Abortions are sensitive as well depending on the social group. If you're underage you may especially want to hide those two from your parents depending on the social group. If you're a woman you may also want those two hidden from your family depending on the social group. Sweden has a large refuge population from very conserva…

> and things like acid attacks against women are decently common. Wait, what? Where's your source on this. Via google I can find references to one case from 1997 and one from 2002, and that's it. The idea that this would in any way be "decently common" here is preposterous.

There are other, more recent cases of acid or threat of it, eg [1], though I'd say acid attacks are not particularly common in Sweden. Many more cases in UK, for instance. There are more actual cases of defenestration ("falling from the balcony") in Sweden.

In any case the leak of health information is nothing to laugh at e.g. for those who live under threat of "honor violence".

[1] https://www.na.se/artikel/hallefors/man-i-hallefors-anhallen...

Re: 2.7M medical calls breached in Sweden

#92
post #67

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Acid_throwing#United_Kingdom London Metropolitan Police showed a sharp rise in attacks, with 465 recorded in 2017 Particularly common in London, and amongst some immigrant communities. Other countries are not so far behind, and I gather it is quite common in some of the developing world, like India and Pakistan.

In the UK it seems it has mostly been a weapon among criminals more than a honor thing that is more common in the developing world.

This probably is due to incentives - carrying a knife may bring a long prison sentence, carrying a bottle of acid or lye as weapon did not. UK changed sentencing guidelines last year.

https://www.bbc.com/news/uk-43225911

Re: 2.7M medical calls breached in Sweden

#93

Earlier quoted context omitted.

Because Swedes are uniquely morally upstanding and non-judgemental?

No, we're highly judgemental, but an employer is not allowed to inquire or make hiring/firing decisions with regard to your health status. Likewise life insurance might have a higher premium if you regularly engage in extreme sports, but they can't deny you. Health care is ubiquitous regardless of your condition.

Sorry, but this sounds a little naive, in the Annie Lööf style: "In Sweden, it's forbidden to be a criminal".

Re: 2.7M medical calls breached in Sweden

#94
post #45

On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The…

why would you need a pair of only one hurts?

It's planned obsolescence. Soon the other one will fail too.

Re: 2.7M medical calls breached in Sweden

#95

On my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The…

The breach is still ongoing, according to statements on the dark web, 30 minutes ago (21:10 CET). "Tror ni inkompetensen är över? Nej. Man har inte dragit ut sladden. Kör wireshark och skicka skräppacket så ser ni att det enda som filtreras är syn-ack från servern.Slumpade seq-nr i respons bara någon timme och upprättade till slut en anslutning. Vad tror ni jag ser? Färska samtal från bara några sekunder sen i mappen…

Regardless if it is true, I unfortunately think Computer Sweden have been a bit naive here. They shouldn't be publish this specific information ~3 hours after the server was "locked down" (as they state in the article). This isn't a company like e.g. Google were correcting a mistake leaves them at "good security".

Re: 2.7M medical calls breached in Sweden

#96
post #90

Earlier quoted context omitted.

The breach is still ongoing, according to statements on the dark web, 30 minutes ago (21:10 CET). "Tror ni inkompetensen är över? Nej. Man har inte dragit ut sladden. Kör wireshark och skicka skräppacket så ser ni att det enda som filtreras är syn-ack från servern.Slumpade seq-nr i respons bara någon timme och upprättade till slut en anslutning. Vad tror ni jag ser? Färska samtal från bara några sekunder sen i mappen…

How can you make a connection by guessing seq nr ? What is the firewall rule that allow such an attack ?

My guess is that there were still some hosts allowed through the block (e.g. whatever is writing to that NAS), and that they were accessing the NAS with frequent new connections. The firewall only tracked transport layer state so the bad guy was able to hijack an existing session by sneaking in a correctly-numbered TCP segment inside an IP packet with his own IP address as the source.

Re: 2.7M medical calls breached in Sweden

#97
post #67

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Acid_throwing#United_Kingdom London Metropolitan Police showed a sharp rise in attacks, with 465 recorded in 2017 Particularly common in London, and amongst some immigrant communities. Other countries are not so far behind, and I gather it is quite common in some of the developing world, like India and Pakistan.

In the UK it seems it has mostly been a weapon among criminals more than a honor thing that is more common in the developing world.

Now, sure, especially in London. It's grown as a weapon of choice phenomenally quickly over the last 5 years, from almost nothing.

Seems like it may have been noticed being used for honour attacks in communities in London, Bradford, Leicester etc, and escalated from there. A particularly horrible form of attack.

Re: 2.7M medical calls breached in Sweden

#98

Earlier quoted context omitted.

The "funny" thing is, it wasnt using HTTPS, it was on the 443 port. But the data was sent unencrypted.

Still, sending the data unencrypted wasn't so much the issue here as the server was open to anyone.

Yes, although the transmission being in plaintext makes it even more vulnerable, because if you get to listen to the network where the call center nurses operate, no one needs to crack anything to find out the location of data, its structure and anything else you need to exploit it.

Re: 2.7M medical calls breached in Sweden

#99
post #74

Earlier quoted context omitted.

> My calls with personal identification number are absolutely in there Is this an assumption, or were you able to find a list of leaked calls somewhere?

If so, please provide details on how can verify if my details are in there as well. Slightly pissed of Swede who called 1177 just last week here. Still I'm glad this happened after GDPR, this means everyone who's personal details were compromise should have plenty of legal options right now.

Check what time of day your call happened. Daytime? Then its probably not stored.

Re: 2.7M medical calls breached in Sweden

#100
post #89
post #81

Earlier quoted context omitted.

But blaming politicians, the government and companies is the way to request responsibility, isn't it? Without the political pressure you can request whatever you like, but to a little effect. And as outsourcing work like this is totally illegal under GDPR, it's definitely up to the government to enforce it's laws on it's own contractors, and it's up to companies to suffer the consequences of not treating peoples priv…

I touched upon this in my other comment. I don't think it is wrong to criticize, but there can't be meaningful change unless you actually allow yourself to address the problem. It is a bit hard to explain if you haven't experienced Swedish politics lately. I'll just give you some examples: 1. The same county awarded contracts for building a hospital were the cost ended up quadrupling to $6 billion more than initially…

Hey, don’t forget some goodies:

1.1. The hospital is built and operated according to guidelines and specifications set by a consulting firm that had no previous experience building hospitals.

It’s been a cluster fcuk with things missing or completely out of place.

1.2: Appointed Head of operation was a previous employee of the aforementioned consulting firm. More than 80% of the billing from said firm lacked specification but was of course approved by... drumroll ...head of operation!

There other interesting bits as well, but these stood out to me at the time.

It’s all frankly a brilliant piece of right wing “entrepreneurship”.

Post reply on HN