15 ms·
Irish health service hit by cyber attack
- kasperni 5y agoRansomware: Another great "feature" of difficult to trace digital currencies.
- amoshi 5y agoRansomware: Another great "feature" of non-backdoored encryption. See how silly you sound?
- 0xfaded 5y agoThis is what-about-ism. There are valid reasons for strong encryption, e.g. protecting the very data that has been compromised here.
- azangru 5y agoIt is not a whataboutism; it's a reductio ad absurdum.
- ChainOfFools 5y agothat's malware, not new. the ransom part, at the scale possible with cryptocurrency, is new. those who sound "silly" are the ones elaborately pretending that this formerly obscure class of electronic extortion didn't suddenly explode into an epidemic with the concomitant rise of cryptocurrency.
- grlass 5y agotrue, though arguably it's a good thing. In the sense that it moves more of the costs of malware to the organisations that are meant to be securing the data. Previously, these costs were more borne by customers/clients/etc, and thus not taken as seriously - abstract costs and externalities. Putting a clear number of the cost of poor cybersecurity should push more organisations to actually do something about it.
- ChainOfFools 5y agono. mugging is not "good" because it incentivizes people to take karate classes. what an inhumane and cynical take.
- grlass 5y agoTheft was happening anyway via malware, it's just fewer of the costs were being borne directly. And as data collection increases, those indirect costs are getting higher. Now the organisation has more at to lose at first pass, rather than just data subjects.
- argvargc 5y agoSaid the medieval King: Ransom: Another great "feature" of difficult-to-trace personal gold coinage What you're actually saying is: Bad thing: Another great "feature" of any kind of positive development in personal sovereignty Or Bad thing: Another great "feature" of any kind of progress --- Progress comes with pitfalls. Sharp knives prepare food and also kill people. You argument effectively reduces to: never innovate.
- dTal 5y agoYour argument reduces to: "progress" is always good, even if it's bad. I think we're perfectly allowed to discuss whether we think a particular kind of change is a good or bad thing.
- argvargc 5y agoI'm not making an argument "for progress" at all. I actually 100% agree that we are allowed to, and should, discuss the ramifications of any kind of change. My point is only that the original comment didn't attempt make any argument, other than the reduced one I outlined.
- dTal 5y agoBut they did. They said that digital currencies are difficult to trace and lead to an increase in ransomware. The closest thing to a response you made was "Progress comes with pitfalls".
- dalbasal 5y agoThat's not really a reduction... more of a random association to a generality you feel strongly about. You "reduced" difficult to trace digital currencies to "any kind of positive development in personal sovereignty." No need to keep defending a mistake. Just reread your own comment and the OP's. Respond to the comment itself, not other discussions you've had on the topic. If you think the argument implies something you disagree with, make the connection. Don't just assert that the argument reduces to this. Besides being mistake prone, it's unfriendly and unproductive. I've made plenty of comments myself that I don't/shouldn't stand behind, in short retrospect. I suspect this is one of yours. Minor foul. Happens. Shake hands and make good.
- Quarrelsome 5y agoapparently the traceability of digital currencies is proving effective in tracking down criminals that might otherwise operate in just cash.
- Jolter 5y agoCryptocurrencies are what allows criminals to scale these attacks. They also significantly decrease the risk of getting caught, compared to accepting cash in a briefcase. I’m not sure what point you are trying to make.
- Quarrelsome 5y agoim saying the traceability/digitalization is a double-edged sword.
- tgv 5y agoSo, did they get the people that r'wared the US pipeline then?
- sbarre 5y agoInfosec Twitter this morning seems to imply that perhaps they did. https://twitter.com/hashtag/REvil?src=hashtag_click&f=live https://twitter.com/hashtag/REvil?src=hashtag_click&f=live caveat that this world is full of rampant speculation and lies so take it with a grain of salt. ;-)
- Enginerrrd 5y agoIf they haven't yet, give it a little time. Fucking with US oil supplies is a really good way to get the opportunity to feel the full engine of US intelligence and military might.
- deleted 5y ago[deleted]
- dmos62 5y agoRansomware: another great feature of cryptography.
- GrumpyNl 5y agoI have always understood that all payments were traceable with digital currencies. Am I wrong?
- trompetenaccoun 5y agoNot all cryptocurrencies but it's true for something like Bitcoin. The problem is you can trace the transaction to the attackers wallet, but where does it go from there? It might sit there, they might throw the money in a tumbler, maybe they sell it for cash... If or when it shows up in a KYC-compliant exchange it could have changed hands many times already and it might not be possible to say anything about the actual criminal at that point.
- bagacrap 5y agoSo it's up to the individual to make sure they're not accepting dirty money. Shouldn't be hard to write software to accomplish that. The exchanges can do it --- flag incoming dirty money. Average users don't accept btc from strangers as a payment for goods or services anyway.
- trompetenaccoun 5y agoYes, but for example when you use a tumbler (mixer) the whole idea is to receive random coins back. Also you can not rely on everyone to know and care about this. And not all dirty money is publicly known anyway. So there will always be ways to get rid of dirty BTC. The non-fungibility of bitcoins can be seen as an advantage or one of its largest flaws, depending on how you look at it. Either way it's the reason quite a few people have switched to Monero and other completely fungible coins. >Shouldn't be hard to write software to accomplish that There are startups offering exactly this as a service already.
- gccs 5y agoThe crypto-revolution and its consequences were a disaster for the human race...
- andrewnicolalde 5y agoWhat specifically do you mean by the crypto-revolution?
- fuzzer37 5y agoIt's a reference to the Unabomber's Manifesto
- andrewnicolalde 5y agoChrist..
- swiley 5y agoThis was done before crypto currencies.
- rjmunro 5y agoBut it only became a serious problem because of them.
- Graffur 5y agoRansomware: Another great "feature" of computers.
- easytiger 5y agoI imagine, to use our vernacular, some chancing gobshite is talking his way our of responsibility for their shitty tender as we speak.
- 2kreative 5y agoIt's the HSE no one's going to be held accountable; in fact someone will probably get a nice bonus this year for 'managing' the situation
- valenterry 5y agoOn one hand I'm excited about all the good things that e-health can enable for us, but then again, I'm super scared to leave a trail of my health history in IT systems.
- bilekas 5y agoWhat kinda scummy scrote you have to be to attack health services during a pandemic. This is a new low.
- belatw 5y agoIt’s just business. Don’t hate the player, hate the game.
- Xplune13 5y agoand this is one of the most backwarded response one can give in my opinion. "Don't hate the player, hate the game" doesn't justify the player's actions. This is not a video game. I really hate the fact that people will do anything under the name of business. It's more like we're moving towards uncivilized in that regard.
- wilsonrocks 5y agoI don't think 'the game' refers to video games here.
- Xplune13 5y agoI know that. What I'm saying is not to take things lightly and for granted.
- htatche 5y agoClearly you aren't affected, else you'd refrain from such blunt capitalist saying.
- bilekas 5y agoIts not business, its ransom, and its a whole different level of ransom. Going after the extremely vulnerable, litterally putting at risk lives. Theres no 'okay' ransom, this is just another all time low.
- 5y ago
- padraic 5y agoNot really suprising given that during most of the pandemic, track and trace was done through pen and paper and not through the computer system.
- anonymousDan 5y agoFor those concerned about privacy violations, this should be rammed home as an argument against centralized collection of medical health data.
- o___ 5y agoNot to be confused with centralization of health services.
- dariosalvi78 5y agoit's actually an argument in favour of well-protected centralized collection. It's more probable that smaller entities arre less protected than bigger ones even if the data they can disclose is more limited.
- indymike 5y ago> It's more probable that smaller entities arre less protected than bigger ones Size of an organization is not a good proxy for quality of security. Evidence: Colonial Penn, the DC Metro Police Department, Experian, Target, etc...
- londons_explore 5y agoI believe that if all health records leaked tomorrow, the world would end up a better place. Sure, someone might get more expensive insurance quotes or made fun of for having ADHD, HIV or acne treatment... But I think that would be outweighed by health benefits by combing the data for correlations and causations that have been unidentified in the past. Being able to shut down things that are poisoning millions of people, but to such a minor extent it isn't immediately obvious, would have a big benefit for society.
- chopin 5y agoThe upsides may come. The downsides will come. I am pessimistic on this one.
- 5y ago
- anonymousDan 5y agoYou'd have to think that sooner or later they are going to get into one of the big cloud providers and cause havoc.
- bilekas 5y ago(Usually) - Those cloud providers know what they're doing though and de-couple things as much as possible, reducing and entire system compromise. It's their bread and butter, I would much prefer them managing the systems than the HSE.
- q3k 5y agoBut they still make mistakes (ask me how I got into Google /rpcz pages by shodan dorking and slightly mangling an HTTP header...). And just a few of these mistakes strewn together can have a massive blast radius if exploited by a motivated entity. That, and all the high security cloud hosting in the world will not help the most commonly exploited security issues: unpatched wordpress plugins, world readable storage buckets, poorly secured privileged accounts, ransomware, phishing... A shoddily managed on-prem enteprise IT infra moved into the cloud will be just this: a poorly managed AWS infra, just as exploitable as before, but now also 10x as expensive to run.
- anonymousDan 5y agoSure, I don't disagree. But in many cases the value of the data lost even over a short period can dwarf the size of a ransom, as can losses from downtime before getting operations up and running again. Can you imagine if they managed to take down e.g. S3, even for a day? The incentive to pay would be high, which in turn increases its attractiveness as a target. Not saying they would pay of course.
- scandox 5y agoA bit more detail in The Irish Independent. References the Conti ransomware. https://m.independent.ie/irish-news/serious-and-sophisticated-hse-confirms-ransomware-cyber-attack-has-hit-all-hospital-it-systems-40425737.html https://m.independent.ie/irish-news/serious-and-sophisticate...
- mdeck_ 5y agoEver-relevant XKCD: https://xkcd.com/2030/ https://xkcd.com/2030/
- hesk 5y agoOT: In my recollection that comic ends with the 'That's terrifying' panel. Does XKCD ever update comics or is that a new iteration?
- Anthony-G 5y agoI’m not aware of XKCD updating comics after they’ve been published. The HTTP response header for the PNG indicates that it hasn’t been modified since 2018 (which seems like original publication date): $ curl -sI https://imgs.xkcd.com/comics/voting_software.png | grep Modified Last-Modified: Wed, 08 Aug 2018 16:59:09 GMT
- new_here 5y agoA lot of these articles don't actually mention specifically how the systems were compromised. Was it a malicious email attachment that propagated through unsecured networks or outdated OS versions? And what data was encrypted? Are we talking regular excel files or actual databases? It would be interesting to have some more detail or case studies so others could know how to fortify infection points and limit the blast radius of their own systems.
- switch007 5y agoThe media are keen to cover the story ASAP. It can take some time to do an investigation.
- sbarre 5y agoMy guess is that it's not mentioned because they don't know (yet). A lot of places that get crippled by ransomware have outdated or underfunded IT departments (health care is particularly bad at this), so that kind of insight is barely on the table at the best of times. Even when a postmortem is eventually done, companies don't want to have to admit the attack could have been prevented, or at least minimized, with better investment in security.
- nikhizzle 5y agoSo I don't have details on this specific case, but I did work in cybersecurity and can comment on the vast majority of similar cases I saw, including some which made the front page. Every single one I remember came from unpatched OS vulnerabilities for which the patch was already available. Regular patching is necessary hygiene for corporate IT, but often the department is understaffed, or frankly told by management to prioritize shiny things instead.
- londons_explore 5y agoMost corporate machines aren't directly on the internet though... How do attackers get through corporate firewalls to access said unpatched machines? I would guess the easiest way is to phish a login to the corp VPN or to send an email with a malicious attachment to give the attacker something inside the corp firewall as a place to start their port scan of the internal network and begin their attacks.
- pjmlp 5y agoI love the increase in these kind of attacks, eventually there will be enough pressure for liability legislation for companies to take security seriously.
- indymike 5y agoThe first response will be to make laws to punish the perpetrators and to pass knee-jerk cybersecurity laws that create the illusion that something is being done. The entire technology industry is built on a foundation of limited liability and has a tradition of being ok with defects (eh, it's a small bug). When do we get hardware that is guaranteed to perform and be safe, operating systems, languages and compliers that are safe? It's going to be very difficult to deal with liability in a strict sense. Who's at fault? The OS that had a bug, the library that made the syscall, the code that called the library, the script that ran the program, the network router that allowed the egress, or the user that pushed the button? (edit: fixed typo)
- tim333 5y agoI have limited faith in our legislators to fix computer security.
- dariosalvi78 5y agowouldn't disrupting healthcare services be an act or terrorism or even war?
- WJW 5y ago1. It can only be an act of war if it was done by a nation state. Even though the US likes to declare war on abstract concepts like "drugs" and "crime", that is not how it works in international law. 2. Terrorism has similarly precise definitions, usually along the lines of "the act has to be in pursuit of political aims". Just because its a big and important target does not make it political, ransomware is an economic crime.
- evgen 5y agoIf the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. Given the recent pipeline issue and its national security implications I am not going to be surprised at all if some hackers in Russia end up dead from 'accidents' that are so obviously not accidents that no one is fooled.
- vntok 5y ago> If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. You could but you probably would lose that bet. This has been done for decades now, especially between friendly countries (see https://www.independent.co.uk/news/uk/politics/eu-mi6-brexit-spying-surveillance-miche-lbarnier-negotiations-deal-uk-a8494721.html https://www.independent.co.uk/news/uk/politics/eu-mi6-brexit...) without any sort of repercussion. Diplomatic posturing aside ("We will treat any intrusion attempt on our networks as an agression"), literally no government actually wants to go to war over a hack. > Given the recent pipeline issue and its national security implications I am not going to be surprised at all if some hackers in Russia end up dead from 'accidents' that are so obviously not accidents that no one is fooled. This is even more nonsensical. Certainly governments would benefit way more from hiring those hackers and/or buying vulns from them than killing them. Especially in less-friendly countries like Russia.
- adriancooney 5y agoThere's a trend of paying these ransomware attacks which are sometimes in the order of millions. Imagine if those millions were _proactively_ invested into the computer security of these systems?
- tuwtuwtuwtuw 5y agoI tried to imagine, but my mind told me that a couple of millions would not prevent these issues. Did I imagine it wrong? You would likely end up with better security. Would it be good enough to prevent breaches? Doubt it.
- grumple 5y agoI think preventing breaches is a losing battle. There will always be new vulnerabilities. You can practice things that make recovery fast and reduce the impact of breaches though. Isolate data, encrypt it, only grant necessary access, have robust backups and test recovery regularly. These things take time and money though, and most companies are unwilling to do them sufficiently.
- jessaustin 5y agoMost ransomware is pointless where regular reliable backups are in place. A situation like this where there are privacy and outage concerns is a bit different. We may eventually discover that the operators of the system discussed in TFA really were backing up that system, although probably for less than "a couple of millions". Still, ransomware payments are usually a penalty for not doing backups.
- dmos62 5y agoI hope this train of thought becomes more mainstream.
- jonplackett 5y agoPoliticians always seem to be scared to front-load costs. Happens with military/infrastructure spending all the time - get a cheap initial quote and then get screwed long-term. And with covid. Govs didn't have the courage to lock down early and fast / close borders and cost themselves a lot of money in the short term.
- jl6 5y agoI have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline. Historically organizations have been so bad at backups that the advice has been to automate them as much as possible, to try to ensure that a recent backup at least exists. But I am increasingly of the opinion that the next level of backup maturity is to dial back on the automation and invest manual effort in airgapping the backups. Fully automated backups are necessarily part of the software attack surface. If you have to hire more ops people to rotate tapes by hand every day, that will have to be a cost of doing business safely.
- ransom1538 5y agoI would like to also add: A system to lower privileges based on last use. Companies often have IAM/ssh/keys all over the place. If you centralize things to IAM you can lower permissions based on their last use. EG. A frontend dev needs access to GCP to configure things in firebase. This frontend developer hasn't used these IAM permissions in 3 months. This persons IAM permissions should automatically have these permissions removed. Probably one of the easiest yet most powerful thing to implement in cloud sec ops AND probably never done. https://cloud.google.com/iam/docs/recommender-managing https://cloud.google.com/iam/docs/recommender-managing Example script to automate it: https://github.com/james-ransom/auto-apply-gcp-iam-recommendations https://github.com/james-ransom/auto-apply-gcp-iam-recommend...
- xen2xen1 5y agoComplete, tested tape backups would cure many, many ills. They're out of fashion, but..
- grumple 5y agoTape backups are ok but still mean significant operational downtime because recovery from tape is slow. This is better for long term data storage than rapid recovery. For recovery, you need more accessible backups. And to test your backup plan.
- TheMightyLlama 5y agoOne of the major issues I've seen while working with large organisation on software development is one of mindset. These are organisations who predominantly think: "We are an 'x' organisation that happens to develop software". The more productive and safer way of thinking is: "We are a software development organisation that is within 'x' market". However, the latter requires a huge mindset and experience shift from the very top of the organisation. And groups and individuals of that organisation having strong interest in their survivability are, of course, not going to change that.
- galangalalgol 5y agoWhat if software development isn't the most technically challenging aspect of their operation? Say spaceX or a nuclear physics lab?
- cgrealy 5y agoOr healthcare?
- galangalalgol 5y agoThat too. Although if they are making medical equipment, software (if you include the algorithms, which you should) is probably their main challenge. Everyone is not a software development company, but I agree security is every developers responsibility.
- motohagiography 5y agoOdd effect of this is that it would be difficult to distinguish encrypted backups from ransomware encrypted files being backed up. Cloud documents like Word and Google docs seem less susceptible, as writing a content parser for each file format to encrypt it would be a higher bar. Or am I missing something there? It also suggests there could be a market for cryptocurrency futures as a form of insurance. This is one extreme situation where you are forced to buy a currecy at market prices, but I suspect it's the first of more.
- jupiter909 5y agoOne can do ZFS snapshots so one does not need do insanely huge backups all the time. Just transfer off the diffs as needed. If an attack happens it's pretty easy to roll-back to a known good state. It's also not that complex to set some process in place that does random checksum verification of some files to trigger an alarm that such an attack has taken place. It is really perplexing me that very large institutes don't do this
- ashleyn 5y agoSnapshots, RAID, etc are not substitutes for backups
- moshmosh 5y agoLarge institutions aren't solving their security problems by hiring a small clutch of FreeBSD elves. They're hiring consultants to confirm that they've met the requirements of some checklist, which requirements may include "have a plan to fix this obvious problem.... someday. You do? OK, then you're fine". That's much cheaper and is 100% management-class controlled.
- killjoywashere 5y agoThe NIST 800 series and the CNSSI 1253 series cover pretty much everything you need to worry about.
- agumonkey 5y agoThat's not the first attack on health.. in the context of a worldwide struggle I find the operation against medical institution utterly despicable. God.