8 ms·
Ransomware, Data Breaches at Hospitals Tied to Uptick in Fatal Heart Attacks
- arcticbull 7y agoAnother win for cryptocurrency! Truly, it has changed the world. We couldn't have this kind of progress without it.
- an_ko 7y agoWhy do you think this is the fault of cryptocurrency?
- arcticbull 7y agoRansomware doesn't really work without it. In fact, they specifically call out WannaCry which demands ransom in BTC.
- nyolfen 7y agoit doesn’t work without the internet or strong open source cryptography either
- root_axis 7y agoDon't you see the obvious logical failure of that rebuttal?
- nyolfen 7y agois the failure "i don't see cryptographers as my ideological opponents"? ransomware existed before bitcoin; it used moneypak, western union and similar services as the payment vehicle.
- magduf 7y agoIt also doesn't work too well without Microsoft Windows.
- nyolfen 7y agoyou will be pleased to learn there are ransomware families that target macos and linux as well
- magduf 7y agoCitation needed for the Linux one. People have been telling me for decades now that "there's viruses for Linux too!" but I've never seen any actual malware that actually affects desktop Linux. It's like the Yeti.
- ceejayoz 7y agoRansomware relies on there being safe ways to collect the ransom. There were a few predecessors (https://en.wikipedia.org/wiki/PGPCoder https://en.wikipedia.org/wiki/PGPCoder) using stuff like Liberty Reserve (long since shut down by the Feds), but Bitcoin made it pretty easy. One tried "mail money to a PO box" back in the 80s. https://en.wikipedia.org/wiki/AIDS_(Trojan_horse) https://en.wikipedia.org/wiki/AIDS_(Trojan_horse) The downsides of that approach for a criminal should be fairly obvious.
- Scoundreller 7y agoDownside? Sounds like a great way to get anyone you want arrested by the FBI without them knowing who made this all happen.
- cartoonworld 7y agoOne of the useful features of cryptocurrency is regulatory arbitrage. Without this ability, ransom payments in cash, or electronic bank transfers would drastically reduce the feasibility of receiving the ransom payment without also revealing the identity of the payee. A side effect of the anonymity is that crypto provides the opsec cover for these undesirable operations.
- Acrobatic_Road 7y agoHe's a resident cryptocurrency hater, so he never misses the opportunity even though ransomware long predates cryptocurrency.
- arcticbull 7y agoI am :) but there's no doubt that cryptocurrency has made ransomware easier to write/execute, makes it harder to catch people responsible, and availability thereof has led to massive worldwide spike in ransomware. [1] Seriously, what options did you have to obtain the value before? A wire transfer? [1] https://phoenixnap.com/blog/ransomware-statistics-facts https://phoenixnap.com/blog/ransomware-statistics-facts
- Acrobatic_Road 7y agoThey used moneypak transfers, from what I remember. Personally, I would rather live in the world where we have financial privacy and financial freedom even if that means dealing with ransomware. (which is mitigable with proper planning). If a ransomware author doesn't have financial freedom or privacy then that means you don't either. Edward Snowden is being financially censored right now by US Government in a move to take away the proceeds of his book. It is no wonder then that Snowden is a fan of cryptocurrencies which have no such mechanism. Likewise, WikiLeaks was financially censored by PayPal, VISA and Mastercard under unofficial pressure from the US Gov. You don't even have to break any laws to be financially censored. PayPal regularly freezes people's balances for 180 days and does not even provide a reason. The sometimes do this at the behest of political activists looking to use financial pressure to censor their opponents. So, I will accept ransomware as an unavoidable consequence of the greater good - because if all of these people are censored then so am I.
- arcticbull 7y agoThe only place it has any advantage is crime. The problem is a social one: we need to lobby the government to ensure folks like Snowden are protected, and not allow the tyranny of the minority through spending money in a way that can't be traced or censored. We can all agree sending money to North Korea is bad. [1] Funding ISIS is bad. [2] Ransomware is bad. [3] Wikileaks and Snowden? There's a debate to be had. You're actively circumventing democracy by preventing us from having that debate and by refusing to abide by democracy's decisions. You're attacking symptoms, not problems, with tools that are just broadly worse. Social problems need social solutions, not anarchy and magic beans that live in your computer. Of course that's harder, but it is better, and there's no "number go up" to compensate you. [1] https://bitcoinist.com/un-north-korea-accumulating-cryptocurrency-for-weapons-programs/ https://bitcoinist.com/un-north-korea-accumulating-cryptocur... [2] https://www.nytimes.com/2019/08/18/technology/terrorists-bitcoin.html https://www.nytimes.com/2019/08/18/technology/terrorists-bit... [3] https://phoenixnap.com/blog/ransomware-statistics-facts https://phoenixnap.com/blog/ransomware-statistics-facts
- bequanna 7y agoI reluctantly agree with you. The main use case right now (and in the foreseeable future) for crypto is difficult-to-trace payments for illegal activities.
- magashna 7y agoYes, it's pushed companies to have real backups and security. Great! Before, data would just be covertly stolen and sold.
- arcticbull 7y agoThis, along with its absurd energy consumption "pushing people into renewable energy" is fascinating. Why don't we set fire to buildings downtown to motivate investment in fire departments? Why don't we steal things and smash things to motivate investment in police departments? How about dumping toxic chemicals into lakes to invest in the EPA and bolster environmentalism? Why don't we in general actively engage in the behavior we want to stop in an attempt to motivate different people to stop us? I think this is the main idea behind "The Purge," and if "The Purge: Survival" is any indication, it's unlikely to work ;)
- magashna 7y agoYour analogy makes no sense. Are there building fires we aren't aware of? Are there smash and grabs happening without police being notified? The last one actually does happen and it would be great to have a better way to know when and where by who.
- arcticbull 7y agoWhy on earth would you cheer on a company dumping toxic chemicals into the lake just because they raised awareness?! It's caused material harm. That's madness. You punish them for that, and anyone who enabled them.
- jturpin 7y agoIf buildings catching fires easily was a real problem, then yes one major event would be a wake-up call to everyone else to provide a real solution to the problem.
- arcticbull 7y ago
- Acrobatic_Road 7y agoYou clearly don't remember when they used to ask for moneypack transfers.
- vkou 7y agoIt's easier to tie them to the real-world identity of the criminal distributing the ransomware. It's not impossible to do it with BTC, but at the moment, law enforcement isn't doing much about BTC, unless it involves drugs or CP.
- Acrobatic_Road 7y agoAs far as I know, no, moneypak transfers cannot be traced.
- vkou 7y agoThey cannot be reverted once spent, they can absolutely be traced. Police can subpoena records from Moneypak, which is more than happy to comply. You also actually have to go out to a physical location, and swipe your Moneypak card, to buy something. That physical location will keep records, may have security footage, etc. If you're doing Moneypak fraud, and live in any country with a funcitonal rule of law, it's just a matter of time until you either find yourself booked for processing, or, alternatively, ziptied, and with a brown bag over your head, put on a flight to the US.
- Acrobatic_Road 7y agoThe Wikipedia article seems to suggest otherwise. Select quote: "In August 2012, the FBI also issued a warning that scammers were taking advantage of MoneyPak's untraceability to coerce unwitting victims into paying a "ransom" to unlock their computers infected with malware." https://en.wikipedia.org/wiki/Green_Dot_Corporation#MoneyPak_Security_Concerns https://en.wikipedia.org/wiki/Green_Dot_Corporation#MoneyPak...
- jacquesm 7y ago
- pjc50 7y agoOn the other hand, it's a world-readable leger. It would be easy enough for the government to permanently blacklist any downstream transactions from such coins as "proceeds of terrorism", and impose strict liability prison sentences on any regulated person (or exchange) found in posession of them...
- deleted 7y ago[deleted]
- chelmzy 7y agoThe FBI and private companies have tools to track Bitcoin transactions. The FBI brags about the capability often. I'm sure that in most cases it is hard to follow up on because the malicious actors are in other countries. https://www.chainalysis.com/ https://www.chainalysis.com/ https://www.elliptic.co/ https://www.elliptic.co/
- blotter_paper 7y agoThey can certainly legislate about that, and I suspect they will, but there are issues. The ledger doesn't have a concept of a specific unit of currency that changes hands. It has transactions, which have one or more inputs and outputs. Lets say Alice has 3 blacklisted bitcoins and Bob has 2 whitelisted coins. They both sign a transaction which takes all 5 of their coins as inputs, and gives 2 coins as an output to Carol and 2 coins as an output to Dan. The remaining coin is left as an implicit miner's fee. Who got Alice's 3 blacklisted coins? You can make up an arbitrary rule dictating who got which coin in a legal sense (based on order of inputs and outputs or something meaningless like that), or say that any coins output from a transaction with any blacklisted coins are themselves blacklisted, but you can't actually track individual coins. Applying such rules to Monero would make even less sense, as the coins essentially go through a mixer during each transaction. Back to Bitcoin, it's also not clear what it means to possess a coin. We can make fairly arbitrary (though Turing incomplete) scripts for the validation of ownership, a signature is just the most common. Next-most common is probably the m-of-n signature; if I possess 1 of 2 signatures that can spend a coins from an output, do I own those coins? What if I have 1 of 3 signatures, and at least 2 are needed to spend the coins? What if the coin is only spendable by solving a non-cryptographic math problem? If I know the answer to the math problem, do I own the coin? If I make a transaction with blacklisted funds that has outputs spendable by anybody who solves the script by putting in the answer to the problem 2+2, does everybody aware of that transaction now jointly own the coin? I'm not saying you can't legislate about this, I'm just saying it gets silly. Also, I doubt there is a single legislator in your entire government who understands the properties of a Bitcoin transaction that I just described. I bet that their first attempt at regulation will be totally ignorant of what it is that they're actually regulating, and it will be hilarious.
- kempbellt 7y agoCryptocurrency isn't going anywhere. It exists now, people value it. It will remain so. We need to focus on building systems that mitigate this as a potential attack vector
- arcticbull 7y agoIt’s a core feature.
- ganzuul 7y agoInteresting. So you can 'invest' in cryptocurrency and then release ransomware for your chosen scrip to boost your share. Wonder what sort of pen-and-paper white collar crime this would correspond to.
- arcticbull 7y agoSecurities fraud and something under the Computer Fraud and Abuse Act I'm sure ^_^ fun thought exercise.
- chapium 7y agoCryptocurrency is a tool used by bad actors long after they have compromised the system.
- dang 7y agoWould you please not post flamebait to HN? That's against the site guidelines: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html Long flamewars or long tit-for-tat arguments about a generic thing like cryptocurrency, which you unfortunately did a couple times in the last few days, are also against the site guidelines (see "generic tangents").
- Forge36 7y agoWithout any arguments it's just data. Is a lack of spending on key infrastructure, tied to poorer outcomes something we can discuss? I'm not sure this is the best article to discuss the causes/mitigations. There was one interesting data point, but no source of cause listed. >for care centers that experienced a breach, it took an additional 2.7 minutes for suspected heart attack patients to receive an electrocardiogram. Is this while they were prevented from performing care? Thankfully PBS's article goes into more details https://www.pbs.org/newshour/science/ransomware-and-other-data-breaches-linked-to-uptick-in-fatal-heart-attacks https://www.pbs.org/newshour/science/ransomware-and-other-da... >hospitals that experienced a data breach, the death rate among heart attack patients increased in the months and years afterward. This increased mortality doesn’t appear to be due to the perpetrators themselves — the hackers are not controlling the allocation of medications or doctors. Rather the issue may lie with how health care systems adjust their cybersecurity after an attack Which makes a much different argument: the hospital response to a Cybersecurity incident increases mortality (thus: can we expect a similar uptick in negative outcomes amongst healthcare organizations who implement similar security polices?) Research paper: https://onlinelibrary.wiley.com/doi/full/10.1111/1475-6773.13203 https://onlinelibrary.wiley.com/doi/full/10.1111/1475-6773.1... The PBS article points out that security practices applied to clinicians led to this problem. Do we have evidence that the hacking took advantage of the EMR's security issues? >Time from door to ECG significantly increased after a breach and the elevated time to ECG persisted at 4 years after the breach. Security typically adds inconvenience by design—making it more inconvenient for the adversary. For example, stricter authentication methods, such as passwords with two‐factor authentication, are additional steps that slow down workflow in exchange for added security. Lost passwords and account lockouts are nuisances that may disrupt workflow. The persistence in the longer time to ECG suggests a permanent increase in time requirement due to stronger security measures. So what compromise is possible to ensure fast login? Can two factor login be limited to new login devices? (Thus limiting impact to those working in new locations?) Login devices which aren't recognized? (Ie: external servers) Should EMR login be separated from local PC login within a hospital/emergency department? (Cold booting a PC and logging into windows would be the slowest response time). Can we tie logins to employee badges to skip all password entry? (Lost badges would thus warrant reporting loss.)
- 7y ago
- Scoundreller 7y agoThis study may be biased toward smaller/rural/poorer locales. In big-city Canada, patients with heart attack symptoms will usually have an ECG done by paramedics before arriving. In the US, this has quite survival advantage. https://heart.bmj.com/content/100/12/944 https://heart.bmj.com/content/100/12/944 I don’t know if it’s standard practice to do another upon arrival, but it is redundant and should probably take a back seat to activating other processes that need to happen. It also helps send them to the most appropriate facility.
- analog31 7y agoSo, don't ask me how I know this... If you are having chest pain, call 911. If you mention "chest pain" to them, you hear a beep in the background, and everything else is a machine. In my locale, the paramedics carry a portable EKG. If they decide to take you for a ride, they have an EKG machine in the ambulance that's networked to the hospital, and a cardiologist is now on your team. When you arrive, you get wheeled into a special room where an entire heart attack team is standing there, waiting for you. At that point they do another EKG, and as I understand it, their machine has a larger number of electrodes, so they can get more detailed information from it. The patient is never off an EKG at this point, and it's not a discrete step, but is a continuous monitor. A blood test will confirm the presence of an enzyme that's produced if the heart muscle is stressed. This is a rapid test, the lab is ready and waiting for the sample. So, the second EKG isn't really consuming time, since other stuff is happening concurrently, and they need the EKG running continuously to make minute by minute decisions. Regardless of what happens, you're on the EKG until you go home. I don't know if rural or poorer locations have less sophisticated processes. If you are having chest pain, call 911.
- netfl0 7y agoWow I had no idea they were linked in remotely. Thanks for sharing.
- ghostpepper 7y agoIs it possible that increased security after breaches is actually what's slowing down medical staff?
- chapium 7y agoI doubt it. Desktop pc's in hospitals are usually just thin clients. Ransomware targets the client pc and implementing security at this level is not cumbersome.
- itronitron 7y agofrom the article... “Breach remediation efforts were associated with deterioration in timeliness of care and patient outcomes,” the authors found. “Remediation activity may introduce changes that delay, complicate or disrupt health IT and patient care processes.”
- aaron695 7y agoThe actual moral is fuck the Ransomware. It's just a fancy name for a broken computer. How many people does a broken computer kill? How many people does a slow computer kill?
- CUNT_DESTROYER 7y agoFUCKING. WHATEVER. YOU PIECES OF SHIT JUST HAD TO SPIKE, MONKEY WRENCH AND POISON PEER-TO-PEER FILE SHARING, AND I HAVE NO FUCKING SYMPATHY FOR ANY OF THE SUBSEQUENT DESTRUCTION, HOWEVER RAMPANT THIS MAY BE. AND FUCK MICROSOFT WINDOWS, ESPECIALLY FOR IT'S PERPETUAL VULNERABILITY/EXPLOIT/PATCH/UPDATE HAMSTER WHEEL. WHAT A FUCKING JOKE. KILL YOURSELF IMMEDIATELY, BEFORE RANSOMWARE FILLS YOUR HARD DRIVE WITH ENCRYPTED CHILD PORNOGRAPHY NEXT TIME, INSTEAD OF JUST LOCKING YOUR FILES. NO LAW ENFORCEMENT ORGANIZATION OR GOVERNMENT AGENCY WILL REFRAIN FROM SACRIFICING YOU TO AN INMATE INFLICTED CHOMO DEATH SENTENCE, THE DAY YOUR IDIOTIC OPERATING SYSTEM IS USED TO FRAME YOU FOR A CRIME YOU DIDN'T COMMIT, ALL FOR THE GLORY OF A GEEK SQUAD'S $500 FBI INFORMANT MERIT BADGE. THIS IS THE FUTURE YOU DESERVE FOR LINING STEVE BALLMER'S POCKETS.