7 ms·
2.7M Medical Calls Breached in Sweden
- HNLurker2 8y agohttps://news.ycombinator.com/item?id=19191241 https://news.ycombinator.com/item?id=19191241 It was discussed
- bjoli 8y agoOh, but it is the gift that keeps on giving. The sheer incompetence behind this is enormous.
- JoachimS 8y agoIndeed. The company has now gone to the police to report the newspaper and its journalist for hacking.
- chopin 8y agoThis surely will end well for the company.
- Strom 8y agoA classic move. Do you have any sources to link for this? I'm interested in reading more about them reporting the journalist.
- zyberzero 8y agoYou can read more here[0], unfortunately it is in Swedish, and not that much. More or less, the editor in chief of the journal denies to comment. The charges are suspected data breaches, suspected instigation of data breaches and unauthorized disclosure of personal data. [0] https://omni.se/medhelp-polisanmaler-tidning-efter-avslojande/a/8wy6GW https://omni.se/medhelp-polisanmaler-tidning-efter-avslojand...
- ambentzen 8y agoIt's good to see that we Danes have exported something to Sweden. The same thing happened after someone "hacked" some school webapp-thingy, I can't remember the exact details, by changing the URL to get access to another students data. He was promptly reported to the police for hacking after he reported it to the company.
- tokai 8y agoI just looked it up again, and he actually did hack them: "Forælderen, Henrik Høyer havde blandt andet opdaget, at den infoskærm, som hver enkelt børnehave havde i systemet, var befængt med et sikkerhedshul, der tillod cross-site scripting. Ganske enkelt blev de beskeder, som man skrev til den fælles infoskærm, ikke renset for tegn, der gør det muligt at indsende Javascript-kode. Det udnyttede Henrik Høyer til at skrive en simpel Javascript alertbox, der poppede frem med beskeden 'Ring til Infoba og sig at jeres nye intranet løsning er blevet hacket', hvorefter brugeren skulle trykke ‘OK’. Det var der flere af pædagogerne, som så, og som undrede sig over, ifølge Infobas produktchef. »Jeg skrev til Infoba og hørte aldrig fra dem. Så lavede jeg den her løsning, som måske var lige på grænsen for, hvad man må,« siger Henrik Høyer og fortsætter: »Jeg lavede et harmløst javascript, men kunne have gjort det meget værre.«"[0] (Sorry for the danish ya'll) [0] https://www.version2.dk/artikel/foraeldre-finder-banale-sikkerhedshuller-i-udbredt-it-system-til-boernehaver-247985 https://www.version2.dk/artikel/foraeldre-finder-banale-sikk...
- bjoli 8y agoMy porridge-language is limited, but if I understand correctly he used an XSS vulnerability to place an alert box on the page telling the users of the system they should contact the provider and tell them the system had been hacked. It could of course has been much worse. He was later found not guilty: https://www.version2.dk/artikel/derfor-blev-henrik-hoeyer-frifundet-1074649 https://www.version2.dk/artikel/derfor-blev-henrik-hoeyer-fr...
- tokai 8y agoYeah totally benign, the only ones guilty of anything is that awful contractor. I just wanted to point out that there was more to the story than a police report over emails.
- wil421 8y agoThe 10 talking points from the guy who spoke to the press are so terrible I burst out laughing. Government IT incompetence is so terrible all around I find it hard to imagine a way out. Either they do terrible things themselves or outsource it to the lowest bidder who might be slightly less clueless.
- mijamo 8y agoBy experience, and this is a good example, subcontractors are waaaaay more clueless than government employees. There are actually very competent tech peopme in government, although not at decision levels. For subcontractors you often have cheap labour with a high turnover and no worries about consequences of bad actions.
- Kiro 8y agoThey are even funnier in Swedish. Translated they sound much more reasonable but in Swedish it's complete mumbo-jumbo and have sprouted endless of memes in programming groups/forums.
- jacobush 8y agoYes! I can't put my finger on exactly why that is, but something about how it's said in Swedish makes the soundbites even more batshit insane. This is some new level, I've never seen this level of incompetence with these high level stakes.
- xorcist 8y agoLet me see if I got that right. When the government does something bad, it is (obviously) at fault. When a private company is hired instead, and fails spectacularly breaking along the way not just contract but both national and European law, then that is also sign of terrible government incompetence. There's just no winning for public officials, is there?
- tristor 8y agoMore like there's no winning for society when we put incompetent people in power. I don't have any crocodile tears for public officials, my concern is the long-term consequences of the actions of our government(s) and how that affects both us and future generations as societies and people.
- dkarl 8y agoWhat's sad is that the CEO seems to be doing his best to provide an accessible explanation to people who understand the technology even less than he does, as if those are the people he needs to answer to. It's a real "series of tubes" moment in that it feels unfair to nit-pick what he's saying on the level he's saying it, but it's obvious he doesn't understand it on any deeper level, and he doesn't understand that the issue needs to be in the hands of someone who does.
- Kiro 8y ago> “That someone probably, when updating at some point, seen that there was a free networking cable slot, and I guess they thought, some technician: ‘Aha, there should probably be a cable here, but it fell out [sic]’, and then they have connected a networking cable, so that it’s become connected to the Internet. That is just, like, how you do these things.” Yeah, no, that's not how you do these things...
- xorcist 8y agoNot only is this statement extremely funny in its own right, it completely ignores the fact that there was a public dns name too with a clear service name. Maybe that same poor technician also fell over the keyboard too. How extremely unfortunate!
- cle 8y ago> I sincerely hope that we fill see massive fines, people lose their jobs, and perhaps some more severe criminal charges brought against those whose negligence caused this. TBH I find this “off with their head” mentality to be counter productive. Sure, if someone broke the law then administer justice. But it’s not addressing the root cause. What systemic weaknesses led to this scenario, and what systemic changes can we make to prevent it from happening again? That’s a much more productive discussion to have, although doesn’t appeal to our baser instincts and so won’t score easy political points.
- aliswe 8y agoYes its kindof should we act or just react?
- jacobush 8y agoThere is such a thing as deterrent. But that only goes so far. I'd argue both are needed. But the deterrent mustn't hide the root cause.
- bjornroberg 8y agoYep. It is the Swedish government procurement process and lack of IT knowledge among the decision makers.
- oligopoly 8y agoGovernment and nobody is truly held accountable. Happens all the time to different extent. And still there are people wanting more government control. Mind boggling
- Gpetrium 8y agoI agree with your point. It is complicated since everytime humans become outraged about something, their emotional side tends to take over and they tend to look for someone(s) to blame and a head(s) to roll without taking all aspects into consideration, for example: * How to pin-point one or a group of individuals to blame within the company? What if it is someone that has long moved to another company? *Does finding a scapegoat and forcing someone out of their jobs resolve the matter? Whats the impact in that person's lives? Was it just for the masses to feel better? To be honest, I think society is rewarding the wrong attitude in some cases. Someone in the reporter's position should have raised the issue to the relevant authorities and after the issue was resolved (at least partially), he should have made a request to publish an article talking about what happened, how many people could have been impacted, the actions he took. The outcome could have been that the reporter receives an award for his work and appreciation from society for raising awareness in the area, the government talking about concrete actions they have/will take, other companies and society works towards improving said issue.
- jackconnor 8y ago"55 files have been downloaded from the drive, “many of them duplicates”" - I laughed pretty hard at "duplicates"
- tapland 8y agoMedhelp has filed a police report against the reporting paper ComputerSweden late last night: https://omni.se/medhelp-polisanmaler-tidning-efter-avslojande/a/8wy6GW https://omni.se/medhelp-polisanmaler-tidning-efter-avslojand...
- bjourne 8y agoThe crappy thing is that the psycho CEO that filed charges is 100% right. The journalist willfully and knowingly committed a data breach. There are no provisions in the law for "I did it for a good cause" or "I only demonstrated that it was possible." Of course if he hadn't, he wouldn't have been able to write a story about it and the security holes would not have become public knowledge. The laws in these areas are insanely antiquated and this is not the first time investigated people in power have tried to use them to silence or smear journalists. Freedom of speech is threatened.
- bjoli 8y agoOn the other hand, the journalist couldn't have known it was a data breach until he/she actually verified that it was classified healthcare data. The case should be dismissed.
- m-s 8y agoIf I understand correctly, the journalist did nothing more than accessing an entirely unsecured, public website.
- emerongi 8y agoI think in this case the argument actually applies. There is no action on the user's part that signifies bad intent. Maybe if they downloaded too many of the files, but otherwise I wouldn't expect the accusation to stick.
- xorcist 8y agoThere must have been some intent for it to be a crime. It is not illegal to click on a public link on the web. Accessing sensitive data is not a crime in itself. These accusations seem completely baseless. The data was public and could probably be found using one of several public search engines. Apart from that, the journalists could also claim they were given the link by someone, in which case it would even be illegal to investigate the source. This lawsuit was not filed to win.
- kmlx 8y agoon one hand, pretty terrible. on the other hand one could analyse all the calls and provide a helpful medical bot.
- ypolito 8y agoI had to call the emergency due to intense toothache in the middle of the night two years ago. Am I affected and was my call leaked?!
- IdontRememberIt 8y agoI was working on a project for a client in 2002. Our genius project leader, told us to set up a public ftp server... without password. We told him that it was a no solution and super dangerous. As junior devs, in a service company, we were told to simply shut our mouth and do what was ordered. The server was instantly found but they only started to use it during the week-end as a porn server. The hosting company was on fire. This leader is now a director. hehe