Hospitals across England hit by large-scale cyber-attack
theguardian.com
theguardian.com
Honestly, I would be glad if a high impact issue like this, would change any of that for the better. I am unfortunately also a cynic (after 20 years in, well anywhere really) so I doubt it will. This means it will only negatively impact people who need the healthcare, and a bunch of consultants will make millions on sweeping up the mess, and creating the next failure-to-be.
I'm making popcorn.
Having said that, I feel bad, but I just don't see any other way.
Quite a moronic point of view when lives could be potentially put at risk.
However, think about a levee about which you know that it will not hold when a storm comes, but people don't believe you and are not even willing to listen to you. Would you think it's moronic to welcome a storm as a shot across the bows so people realized what you are talking about?
The constructive solution to this problem is to find a way to convey the message such that people are willing to listen. But that can be very difficult.
Have you ever considered the possibility that management deliberately selects for this kind of passivity and conflict aversion when staffing IT departments, hiring exactly the sort of people who might roll their eyes or grumble at things but will reliably do what they're told?
So for something like this to happen now is much better than it happening later, because people need events like this to wake up and motivate action.
Turn on your gas stove for a moment, but don't light it.
That smell you detect is a memorial to the 295 students and teachers of the New London School:
https://en.m.wikipedia.org/wiki/New_London_School_explosion
Early in 1937, the school board canceled their natural gas contract and had plumbers install a tap into Parade Gasoline Company's residue gas line to save money. This practice—while not explicitly authorized by local oil companies—was widespread in the area. The natural gas extracted with the oil was considered a waste product and was flared off. As there was no value to the natural gas, the oil companies turned a blind eye. This "raw" or "wet" gas varied in quality from day to day, even from hour to hour.
I understand that you've been trying to persuade people of the merits of openness, but as you have experienced it's very difficult for an individual to persuade people of things without being a politician or offering some commercial bargains. Managers keep making bad decisions because they can always find someone who will write the code instead, but for some reason developers are unwilling to act in concerted opposition to this and so find themselves endlessly ignored and overruled.
A labor union that protects you when you refuse to implement things that should not be implemented?
IMHO it is a difficult thing to manage and integrate into the tech culture.
Leaks? Maybe, we're seeing them.
While I'm not a big fan of unions or guilds - insofar as they rely on internal hierarchies that just reproduce existing and faulty control structures - those who resist or deny the possibility of organization among technologists are not necessarily disinterested in the outcome.
Just today I was helping somebody retrieve an export of older transactions from PayPal, and they were forced to go through a series of steps to sign up for "secure" access to a special account in order to download a "secure" zip file that PayPal had uploaded containing the transactions.
The password on the zip file? PayPal123.
Wouldn't that hold Microsoft liable then?
I'm 100% in favor of better systems/processes/technology to prevent exploits, but I'm also 100% in favor of blaming the perpetrators of the ransom also.
In the real world we don't accept the argument that the victim is primarily at fault.
* leaving your car unlocked doesn't mean that is OK for someone to steal it and demand a ransom for its return
* leaving your house/apartment unlocked doesn't mean that it is OK for someone to swap out the locks and demand ransom for the new keys
And it really isn't about being locked/unlocked. Doors and locks can generally be easily broken or bypassed, doesn't mean that everyone should have to purchase industrial strength doors and locking systems (and windows, and...).+2 for that ;)
But when financially lucrative attacks can be carried out with very little risk of being caught, and the results are so bad, organizations who don't take security very seriously are at fault for not recognizing the threat landscape, and government is at fault for not recognizing that the market isn't solving this problem, stepping in and requiring higher quality assurance or liability for software.
If you're worried about X, and Y promises to prevent X for a cost, you seek recourse against Y.
X: I can't miss this flight. Y: Pay this surcharge to reserve a seat. Overbooking ensues. I'm blaming Y and not the other passengers.
X: Really don't want this disease to kill me. Y: Take these pills to not die. Death ensues. I'm (well somebody else is) blaming Y and not the disease.
In life we can't always control the cause so we aim to minimize the effect. Thus, while the ransomers are culpable for the blast, IT security are accountable for the size of the blast radius.
Due to the nature of the web, unless you unplug from the Internet, the risk is persistent. So although a cybercrime-free world would be swell, until that day arrives we must control the effects.
I'm not convinced this isn't the answer. What are we gaining by putting hospital networks on the Internet? Are those gains worth the cost in increased vulnerability?
Which is to say, that public health countermeasures and similar modes of risk-mitigation apply.
Bad weather is indifferent to the shaking fists. It won't get worse or more frequent if people fail to shake their fist. But human behavior is very much responsive to feedback from other humans. I'm arguing that we should all be shaking our fists when we see extortionists at work as well as tracking them down and punishing them. And we should also take care to protect ourselves from them. It isn't a binary choice.
Nowhere id I assert that it's a binary choice, and that interpretation of ym words only make sense if you ignore chunks of what I'm saying. Over the near term, you're not going to eliminate crime by moral suasion so it's important to have a strategy to mitigate its predictable incidence while we also work on the problem of how to reduce crime through deterrence, reducing incentives, and so on.
That doesn't make you correct.
https://www.ncbi.nlm.nih.gov/pubmed/9532958
Crime is a public health issue. It shares common causes with ill health, particularly poverty, and fear of violent crime is itself a major cause of anxiety. Community development in pre-school education, parental education, and among ethnic minorities, both reduces crime and promotes better health, for example in reducing the effects of alcohol and illicit drugs. Health workers should contribute in full to community development.
I note that I'm standing with my earlier characterisation of a public health domain rather than weather, but both carry very strong similarities, including a risk / forecast / mitigations approach.
If you hire a bodyguard and still get shot while the bodyguard is on his phone both the perpetrator goes to jail and the bodyguard gets fired/pays restitution. Not that unheard of. It's not like one person gets all of the legal and ethical blame and everyone else is entirely absolved.
In your bodyguard example I don't think in that type of a situation that people fixate on the quality of the security detail. They rightly demand that the shooter be tracked down.
The civic justice system, on the other hand, is completely driven by public interest—nothing gets done to change things unless somebody (or some class) bothers to sue.
Well, for one thing, we could try to think of ways how to catch these criminals, how to help law enforcement.
We can blame the criminals, but we will always have criminals when the crime is easy.
Those who are really responsible here are the ones who allowed themselves to become dependent on an ancient and insecure operating system.
To me, the buck should stop with the head of the hospitals.
Any number of reasons all boiling down to the same reason: what does calling bad people bad accomplish? Best for people who want to be good to talk about how to be good.
The NSA?
Not saying that the NSA is innocent as a child, but please don't put all on them.
If I would have a zero-day I wouldn't go out and encrypt people computers.
But if you find a cooler with a vial of Ebola on the street, take it home instead of turning it in, then have it stolen and have that strain implicated in an outbreak?
Yeah... that's definitely at least partly on your hands.
The 'arms' in 'right to bear arms' is not clearly defined, and the founders would not have had any concept of software or weaponised software, but I can't think of an argument against people owning malicious software if the argument for owning firearms is also in play.
I would say this is closer to having your guns stolen from your home while you're asleep and then used in a crime.
It shouldn't be a surprise when someone else starts shooting off doorknobs.
https://mobile.nytimes.com/2017/05/12/world/europe/uk-nation...
No, it would make IT security about as expensive as good lawyers. Just to cover the losses. A method to reliably produce vulnerability-free software is not invented yet.
I beg to differ. We have formal methods, ranging from type systems to full blown verification. This isn't a technical problem, it's an economic one.
That's not the goal. Well it is, but it's unachievable. We need to get people to care about security beyond ensuring that teenagers can't trivially get in—the current state of affairs for enterprise IT.
A law would at least require companies to give a fuck beyond the "can the CEO's niece break in" level.
At a high level, the priority is simply to swallow up as many healthcare solutions as you can, to reduce cost and increase profit, and make healthcare process more seamless for the patients.
At a medium level, this means you have 50 different organizations connected to your network, and you may or may not have centralized control over any of them. You don't have the cash, time or resources to go in and overhaul all the networks. So you tell them all to connect through your central office and throw every single transparent filter or proxy at them to try to catch all the crap flying out the door (and there is a lot of it).
At a local level, doctors are already stymied by the complex process of providing care to patients. I've worked with them to try to find tailored solutions to speed up simple things like returning lab results. It's surprisingly difficult to improve on. Add new security procedures and their time shrinks even more, adding on top of all their existing procedure.
Healthcare is just always going to suck at security. The alternative is more costly and slower healthcare.
We wouldn't accept from a civil engineer that "the bridge might collapse" but that it's "no big deal, takes a moment to rebuild".
It was one thing when software was controlling some random machinery in a basement or fueling our BBSes, but nowadays large-scale software failure can end a lot of lives, nothing less. And yet, society is largely oblivious to how fragile it all is...
If a the bridge maintainer instructed you that a column needed replacing it would be replaced.
Everything constructed in reality requires maintenance in one way or another. Your house, your car, your bridge and yourself for example. To suggest that software should be different is an interesting point of view.
That's a laymans impression of what a bridge is. In reality bridges are in an extremely dynamic environment with loads changing magnitude and direction constantly, unpredictably. The fact that you think that a bridge is 'a largely static unmoving object' is a tribute to the engineers that designed it and the contractors that built it, it's whole function can be described as 'appear not to move'.
But if you looked at the bridge in a little bit more detail and you would see how the bridge copes with the load your estimate would change to 'a bridge is an extremely versatile structure that dynamically responds to a wide variety of loads by rejecting those loads onto the foundation and soil around it'.
I think most of society has experienced enough software crashes and had enough anti-virus warnings to realise computers are a wee bit unstable and insecure (as well as being well aware they can't judge secure software from insecure software). If anything, it's HN that's the outlier for faith in internet-connected software to do stuff like drive our cars safely.
The software that is run in the hospitals should also be over-engineered because when it doesn't work properly it could be a matter of life and death
When talking about bridges, roads, buildings, tunnels, power grids and sewage pipelines - just to name a few - there is one additional factor that we should always consider.
Once made available, all of these will see constant use and they become part of the fabric of society. Taking parts of core infrastructure out to fix then has severe repercussions. Total cost of invasive maintenance will be a lot higher than the fairly simply calculated cost of on-site fixes.
I will gladly accept overengineering and nearly ludicrous safety margins.
When an engineer gets a license from the state they stamp the drawings. If anything goes wrong, they go write back to the engineer who stamped it. When I was in civil engineering we were asked to redo another firms calculations when things didn't go well (mostly slope stability).
Though for software, I did work on mission critical systems (radar), and they did have a pretty good review/testing regimen. They tested a lot.
For smaller shops, there is pressure to get it done fast and ship yesterday, quality isn't the first consideration. I think liability for attacks from your boxes that have been hacked is low, so even then people aren't as vigilant. See IOT devices..
It seems to me that most software development is not engineering in this sense and I assume that we will get to that stage at some point, but right now things like public institutions being hacked, because their software security was not up to par, will happen.
I certainly don't blame you for making popcorn, but surely part of why poor operating practices and decisions get entrenched if that the people doing the work passively go along with whatever bad idea management is proposing while hoping that either inevitable failure or some higher level of management will intervene to vindicate the initial objections of the technical people and topple a few of the more inept managers from their perches. Because IT people tend not to be organized into a union or professional association, they have little to no political leverage of their own so any personal sense of organizational mission or ethical scruples don't count for much in the event of a conflict with the management people, who may sweep aside objections on the basis that the IT person 'doesn't understand the big picture' or somesuch.
I don't mean to suggest that you should be reiterating old faulty models of social organization like unions or guilds; if anything the lesson of technology is that we should be restructuring our pyramidal structures of control and authority (whether corporate, political or whatever) into more effective network paradigms. But I do think that if you just munch on popcorn and hope to see some bad managers ousted and some technical people finally lifted up to positions of seniority within the existing decision structure, then it will just be more of the same until the system is forced into a state of collapse.
Why leave everything to he management and consulting types 'sweeping up the mess, and creating the next failure-to-be' as you eloquently put it, when you have one of those rare opportunities to force change?
I remember spending more time pushing against the inertia and self-interest, than actually solving the problems. Solutions that, in a fairly straightforward and rather conservative fashion, stopped problems like these.
We are already seeing the uptake of the "rubber hose" in IT/IS oversight. Up to the Federal level, in the U.S.
It's not going to be a matter of who is responsible and who is technically capable. It's going to be the rubber hose and the lead pipe.
Whether that's a winning strategy...?
I guess that's why you're making popcorn.
https://www.ccn-cert.cni.es/seguridad-al-dia/comunicados-ccn...
https://technet.microsoft.com/en-us/library/security/ms17-01...
IIUC the security updates have been available since March. I can understand bureaucratic entities having shitty security policies, but Telefónica? It's just... wow.
I'd rather deploy a Windows update within 2 months of its release and be safe from a RCE vuln.
Also... images? :^) I think you're giving too much credit to the sysadmins in these organizations (and I talk from experience, can't say more).
Then it shouldn't be connected to a non-secure network / the internet in the first place.
As a physician and researcher, this attitude from IT people is why you find physicians who don't like you.
Such hubris.
When I worked night shift in emergency dispatch, our base network ops center pushed out an update that took our phone workstations offline. The phones that receive installation 911 calls and communiques from the command post. With no warning or notification of such an update.
Their reasoning? "We didn't think anyone would need it at 0300"
And in any case that doesn't seem to be the issue here, per reporting. It's not NHS's reliability-critical systems that are owned, it's all their PCs.
If I am unlucky this means I could miss out on a potential doner kidney due to the delay
Here's another screenshot, with a different address: https://img.jes.xxx/1472
Also appears to be paid: https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX...
Appears to be paid twice in fact, honestly I'd bet that it's people paying these as a joke rather than the NHS.
And multiple payments could occur if the software has a pre-populated list of addresses rather than generating a new one for each infected machine.
Of course, it could be the attacker sending money to himself to try to make victims think other people are paying.
I don't know what to do with it. I mean some stores support it, and I found you can buy Amazon gift cards.
It's not like you just "turn it into cash" and Xappo is not supported in the US. I realize there are alternatives.
I don't have much anyway, but it's crazy! Worth more than gold. I wonder about that 4K $ value that someone estimated.
I'm just buying for FOMO I guess.
By not developing an unlock in the first place they can get it out quicker and have less risk. Sure, the next hacker may not get paid because they aren't trusted but for the most part we're talking about individual operations.
Not at all. This is run-of-the-mill encryption. You pay the bitcoins, your computer receives the decryption key. There is no possible way to crack it, otherwise the entire internet would be broken. (i.e. TLS)
Similar to the entire internet, while the tools to securely encrypt things exist, incompetence can cause people to roll their own, or roll things out improperly.
Whereas throwing together a program that corrupts every file on the hard drive is not too difficult.
You were wrong.
> This is not really a mistake from the ransomware authors, as they properly use the Windows Crypto API. Indeed, for what I've tested, under Windows 10, CryptReleaseContext does cleanup the memory (and so this recovery technique won't work)
(From https://news.ycombinator.com/item?id=14377328)
So it's yet another security bug in Windows that lets people recover those keys.
If a sufficiently large proportion of cryptolocker malware didn't actually have an unlock mechanism, it would become apparent quite quickly. We'd see reports on places like HN and SO, ultimately trickling out into the popular press. Only the most naive victims would ever bother paying the ransom, because it would be common knowledge that it doesn't work.
In the long run, ransomware is only successful if paying the ransom usually works. There may be an element of collusion amongst organised criminals, or simply a sense of personal pride by the authors.
Everybody understands that it is in their future business interest to unlock.
[1]: https://www.bleepingcomputer.com/news/security/development-v...
Are there any examples where that's not the case? Where regardless of payment, you're still fucked (either by files not being decrypted or by them deleting regardless of payment?)
1. Anecdote about the "logical" argument you already described
2. Anecdote from an internet person about an unnamed professor
3. A call to selection bias, with no hard evidence
For a rather generous interpretation of "honest" :)
Other people are definitely paying. The scheme stops working as soon as word gets out that paying doesn't restore your files.
Edit. Corrected currency to the Pound.
(UPDATE: sounds like there are many more impacted parties since I first commented, so my comment is likely much less correct.)
Typically it's just hard-coded and then they ask you to just email them with which transaction is yours to unlock. So you could just wait for somebody else to pay and then quickly claim their transaction first..
Apart from that, I agree: I suspect it has a hardcoded list of addresses and it picks one at random.
All of NHS PCs and hospital systems have gone down from a ransomware trojan!
I have a full clinic this afternoon, and no way to look at my patients' histories, or meds. It's a damned disgrace.
The Trojan is demanding some bitcoins be paid, else they'll lose the boxen.
The entire NHS is penetrated.
I can't vouch for "the entire NHS is penetrated"
https://s3-eu-west-1.amazonaws.com/comms-mat/Comms-Archive/J...
> A nominated Local Organisation Administrator (LOA). For primary care organisations, specifically GP practices, pharmacies, optometrists and dentists this is provided by NHS England Area Teams. Where appropriate, Department Administrators may be nominated.
Maybe targeted emails with attachments?
https://www.publico.pt/2017/05/12/tecnologia/noticia/ataque-...
Note: I've zero idea if that screenshot is legit but it's posted on The Health Care Journal website so it likely is.
Edit:
- Earliest Google result for "WanaDecryptor" is from Aug 2015 (All other search results are from today):
> almost all of the files on the D drive is encrypted. C is not touched by the disc. file found is in the ProgramData folder, there is a hidden folder, the virus in it. When you delete a folder that is created again and the process starts again.
http://www.cyberforum.ru/viruses/thread1979411.html
http://www.cyberforum.ru/viruses/thread1979358.html
- Discussion from today mentioning it infecting Spanish Telecoms: http://gta-trinity.ru/forum/index.php?/topic/57671-novejshij....
---------
Shutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out?
I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?
There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place. Perhaps underinvestment in IT is to blame.
Or, indeed, over-investment in trash-tier IT services provided by blood-sucking IT consulting companies.
I've seen the insides of some UK Government IT systems (not the NHS), and it's astonishing how little functional software one can get in exchange for a few hundred million sterling.
That, and the bitrot of holding on to ancient, never-updated IT systems.
[Edit], back on topic, I sincerely hope whoever did this is burned alive for their crimes.
Another research department I worked at was seriously underfunded, which resulted in questionable decisions, such as using round cube for email, and a central shared drive with a Microsoft access database containing patient data. Hospitals have terrible security.
Basically, yes. Bring it all in-house, ban the contractors/consultants/mercenaries/etc. Remove the profit motive and suddenly you don't have millions of dollars/pounds being siphoned off by vampiric consultancies and third-party vendors. Suddenly you can spend tax-payers money in a sane and rational way.
Hire a bunch of talented people who care about the wellbeing of their nation state, pay them well enough and task them with building the best systems possible in the most efficient way possible.
However, in the context of an established organisation it's really hard to pull off, and so we eventually ran into serious pushback from other factions within the org, particularly the established IT Ops folk.
Still, it can be done, and it can be a raging success. Especially gratifying when you spend two days writing up a system in Python which replaces some 90's garbage that's costing the organisation 200k per year in licenses.
Killing Leeches is fun.
100 user system, Windows CALs and RDS licenses per user = a lot of money. Found only 40 users needed the CALs, rest were fine on Linux.
Took the devil of a job to persuade them this, as the Microsoft rep told them they couldn't.
Open sources equivalents are nowhere near as good.
> eventually ran into serious pushback from other factions within the org, particularly the established IT Ops folk
"Mordac, preventer of information services"
Thankyou very much for fixing this kind of thing, seriously.
Tech has improved ten-fold this last decade, and IT consulting services simply don't care because they profit hugely from it. What makes this issue even harder to solve is the fact that IT is so simple to hide because society does not understand it enough.
Similar to the Tech Pledge, we should stand and be very vocal about the fact that you CAN build strong, secure and relatively cheap systems. If we don't do this, who else will ?
We're stuck between a part of the industry which benefit from this (and especially the big bosses, they don't care about the developers either) and a society which doesn't see the value of homegrown (as in company/government-grown) tech talent and the tenfolds decreases in IT spending it could entail.
Please, Sam Altman ? Someone ? Please ?
edit: I should say some as to be fair, I'm not 100% sure of the extend of this.
If it had been an in-house project with actual experts employed in building/deploying on a smallish scale (say, a town or county) and then rolling out it could have been a thing of beauty.
It should have been what AlphaGov became.
Then requirements start coming in, the stakeholders, the politics. The multi faceted organizations, the disparate teams with never ending edge cases.
3 years later when it's past phase 2 and creaking at the seams, along comes the next upstart... DJango! Which idiot picked that?!!! Me n my friends could....
This is impossible. Any large organization eventually resorts to using pay scales to combat corruption. When the right people will be 10+x more effective than the wrong people, pay scales are impossible.
Literally the entire reason why large organizations resort to hiring contractors is because they know it's impossible for them to hire good people directly.
Yeah, I think this is probably closer to what's happening.
I've worked with some of these Enterprise-level IT consultancies in the past. I do understand that it's quite a different market from the lean, tech-focused web development market, but some of the solutions I've seen implemented are shockingly* bad.
Maybe post offer a decent reward - say £10 million for information leading to the identification of the culprits.
This said, they're probably popping champagne at Tory HQ right about now.
There are more subtle methods of course including outrageously broken internal market management restructures (Stafford Hospital Trust, 'fund holding GPs' in the time of Thatcher) and the like.
And because departments are left to their own devices, they solve all their problems with shared drives and excel sheets.
Ransomware is the hero we didn't ask for.
WRT the failings: I've worked in IT in the UK for more than 25 years, and I have never (until now) worked in a place that took security seriously. That includes schools, a large accountancy firm, several well-known public sector establishments, a political campaign, etc. "Optimistic security" is the model here, and hospitals have huge rambling networks with many legacy systems and third-party solutions. I would be surprised if they don't have security issues. Where they are secure, it's probably down to some unsung hero(es) somewhere, who took it on themselves to push security. (I've done this myself and it's a thankless task; nobody notices or cares. Dogs not barking, etc.)
That's a good point, tech journalism is usually pretty poor.
https://twitter.com/ShaunLintern/status/863039464649744384 suggests it's significantly more boring than a zero-day (though still incredibly problematic).
Your experiences with UK IT make for depressing reading.
I am astonished that even skilled techies don't take security seriously, using passwords like their car registration or company name - I've seen that with a military contractor, ffs. People who had signed the Official Secrets Act and had network links into supposedly secure sites. It depresses me too.
People have a really hard time evaluating simple risk/reward models. You have to make the reward of attacking you higher than any possible reward to have a reasonable chance at security. If anyone anywhere on the Internet can profit by your loss, eventually someone will try.
EDIT - To make life even more difficult sometimes the attack provides gains indirectly. Imagine one group of politicians attacking a service supported by another political faction, just that service going down profits the first group if it changes who voters vote for.
Start from scratch, don't connect anything legacy. Assume the LAN is already penetrated and design for that. Store no data locally, client machines run something like ChromeOS by default. Timeout anything that's not used for 6 months. Don't use passwords, only SmartCards. Snapshot data for ease of restore.
Systems that can't depend on the outside, obviously, cannot use cloud services. That means no chromeOS, no active directory, nothing but the local network. This is beyond obvious, and yet, I actually believe we'll be stupid enough to do exactly the centralization thing.
Paying $300 to these crooks, incidentally, will be a LOT cheaper than whatever microsoft or any other company will ask for the centralized infrastructure. Not that I suggest doing that, but still.
All systems depend on the outside to some extent anyway.
Is it $300, or $300 per machine? Why can't the machines just be reimaged, what kind of giant corporation doesn't have that working automatically?
But a problem with the approach of centralization taken by something like ChromeOS which uses Google accounts (or I guess Win10S which uses ms accounts) is that you're attempting to prevent one player from holding you hostage by giving yourself hostage to another. This is not going to work to prevent paying through the nose, although yes, your new hostage takers will probably realize that the NHS will be able to pay more when it actually takes care of patients. Not too well, of course, good enough to make sure it isn't replaced or repealed. Badly enough so that constant complaints ensure a fresh budget injection every quarter.
As I said, like ChromeOS, it's perfectly possible to run your own servers, don't need to pay Google or Microsoft.
https://www.chromium.org/developers/how-tos/enterprise/runni...
The myth of the clean sweep. Personally, I've found such systems tend to be late, wrong and inevitably end up resembling what they replace, warts-and-all. This is because systems tend to mirror the organisational and political context they are in, and most programmers today are not significantly better than those who came before them. Quote me all the exceptions you like, this is my experience.
https://www.ft.com/content/74c666ec-8dc7-3b20-b573-245bc0e9d...
http://www.impala.pt/noticias/pt-alvo-ataque-informatico/ [PT]
These could be a coincidence though.
Here is a source article talking about a Spanish TelCo: https://www.usnews.com/news/technology/articles/2017-05-12/s...
This one asking for $300 to the NHS and the other one asking for $600 000 to a phone provider.
Either the criminals have no idea what the NHS is or $300 is the limit of what middle managers can pay without much approval.
Unfortunately, the state of security right now is such that these wide-band transmissions can still pick up a lot of hits.
Same cost for Telefonica - just "per machine".
===begin quote===
A number of NHS organisations have reported to NHS Digital that they have been affected by a ransomware attack which is affecting a number of different organisations.
The investigation is at an early stage but we believe the malware variant is Wanna Decryptor.
At this stage we do not have any evidence that patient data has been accessed. We will continue to work with affected organisations to confirm this.
NHS Digital is working closely with the National Cyber Security Centre, the Department of Health and NHS England to support affected organisations and to recommend appropriate mitigations.
This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors.
Our focus is on supporting organisations to manage the incident swiftly and decisively, but we will continue to communicate with NHS colleagues and will share more information as it becomes available.
Notes to editors As at 15.30, 16 NHS organisations had reported that they were affected by this issue.
===end quote===
I'd be interested to know how many patients are under the care of those 16 organisations.
1: https://twitter.com/BBCBreaking/status/863046075002884097
2: https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N...
https://en.wikipedia.org/wiki/NHS_Connecting_for_Health#Cost...
Word I've heard is that working through the DC office liason is probably the more effective route.
Edit: Oh, it's indeed USD$300 in Bitcoin that is asked. Cheap!
Plus potentially hundreds of cancelled procedures, including all electives for the next two days, cancelled GP appointments, etc. etc. The lesson is going to cost a lot more than $300 per machine (and as it's per machine that could end up being $300k per hospital when you consider the number of machines they have).
In the NHS, GPs are usually the first point of contact for anything serious that doesn't result in an immediate trip to hospital, as well as for general medical advice or minor treatment, so the effects could be anything from disrupting someone's recovery from a sports injury to losing a referral to a specialist for something serious like cancer or a heart condition.
Obviously if this affects the systems used by the specialists who are actively treating serious conditions, the consequences could also be horrendous: lost records of appointments, medical histories, test results that can take weeks to obtain, etc.
There will, sadly, be nothing cheap about the lesson here. The cost will almost certainly be measured in human lives, and whoever did this should be charged with at least attempted murder.
There are many great and extremely dedicated employees but the vendor lock-in has painted them into many (disparate) corners.
http://sicnoticias.sapo.pt/pais/2017-05-12-PT-Vodafone-EDP-e... (Portuguese)
The worrying part is distribution and essencial companies and services
[1] http://nos.nl/artikel/2172840-waarschuwing-voor-grote-intern...
Unless it's like a local attack whether by a worker or something like found a thumb drive outside, plugged it into my work computer.
not my field
I get that this is probably social hacking/phishing, so not really analogous -- but I wonder if there's a way to apply that kind of mentality to good. I wonder if there's white hat phishing (though I guess that might be oxymoronic).
WannaCry ramsoware is the culprit.
I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?
Edit: There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place.
Take a look at that operating system and the UI from the article and tell me how that's unexpected.
A non-health example: http://www.effectivebits.net/2011/08/to-run-windows-or-not-t...
When you buy a medical device running Windows 3.1, it will run that until it is thrown away or replaced.
Except for budget and non-technical leadership in technical leadership roles
Greenway had backup procedures in place, but they were file-based - backing up databases, transaction logs, files, etc. and able to restore them onto a new server image as required. The problem arose when they had to do that for hundreds of customer servers at once.
One of my customers knew there was a big problem when she signed onto their server (Intergy On Demand, hosted by Greenway, accessed via RDP) and saw ransom icons on the server desktop.
There may be certain mission-critical, non-internet-connected machines for which it's still safer not to install updates, but for the average doctor's workstation it will probably become the norm to install Windows patches.
Where I live, doctors have more freedom in how they run their clinics and IT. That probably causes its own problems, but at least they're free to run a modern version of their OS and keep it patched. This kind of virus wouldn't affect us the same way since there's no top-down tech policy which prevents individual doctors from following good security practices; in fact, if you just follow all the recommended settings when installing Windows/macOS, you'll end up with automated patching by default.
So if you really want an epidemiological analogy, maybe the best one is a monoclonal, monoculture crop (e.g. the Gros Michel banana) being decimated by a pathogen which has just evolved the ability to infect it: take down one banana, and you take them all. Take down one English doctor's computer...
Um, doesn't "encrypted beyond your reach" fall somewhere under "compromised?"
This doesn't sound like a spread by phishing or attachment.
How could such an attach be co-ordinated?
I can think of two possibilities:
1) The attack has been spreading over days or weeks with a trigger date for activation. 2) The ransomware has been distributed through the desktop update system.
Any other ideas?
https://securelist.com/blog/incidents/78351/wannacry-ransomw...
Life support machines, x-ray machines, heart-rate monitoring machines, even voting machines. Nobody knows what's going on in there, and a software fault or hack could be the end of you. Like that Toyota "unintended acceleration" bug which would've been discovered a lot sooner had other people been looking at the code.
This is also coupled with the fact that these vendors, for reasons that challenge the absolute limits of my comprehension, insist on using old versions of Windows. I would not be surprised if equipment of that sort sold today still runs unpatched versions Windows XP.
ATMs and cash-registers are likewise a total farce. Some of them are packaged so poorly it should be criminal.
Who knows if an intern forgot to convert properly and the thing spews out a million times more radiation than intended.
Makes me wonder how many of those infected machines didn't have to be connected to the internet in the first place.
Each trust and hospital handle I.T their own way. Which is why some are affected and some are not.
So far it spread via file sharing and emails.
The main issue is they don't patch, and update their stuff!
https://twitter.com/AdamTheAnalyst/status/863040924783345665
Couldn't someone take the "already paid" bitchain address from someone else, put it in and click "paid" with that to unlock it?
Seems serious.
This seems to be quite serious.
Considering it's already hit some tech giants, it was just a matter of time until it spread through their VPNs to their workers, clients and beyond.
This is gonna be fun to watch from the sidelines.
If the ransomware has no vulns itself, this is going to be a hit to economy, either by paying the ransom (it's already hit some major companies) or the losses produced by it.
I can't even fathom how many spreadsheets with no backup have been lost today.
WRT backups... :^)
The company should be able to pull a backups from the last file change prior to that event.
A member of their staff has now left for a holiday, this is a nightmare. I'm loathed to have them pay the ransom, but restoring from the last backup will cost vastly more in work product and business impact than the cost of the ransom.
Secondly, how the hell are these records being stored? These viruses usually search for pdf,jpeg,doc, and xls files. Is patient data in spreadsheets and word docs? I don't get it.
http://blogs.cfr.org/cyber/2016/02/29/paying-ransom-on-ranso...
Excuse us but we just found out that you're NHS. Please make it $300,000 or else.
Asking for just a little is a pretty good tactic, used by these guys, patent trolls and the mafia for protection money.
There's a lot of focus on human factors in the NHS, and that tends to avoid things like blame.
It really should be the case that IT infrastructure is resistant to these problems.
That was the nastyness of the earlier announced zero day. All the attacker needed was to have the file on your system when Microsoft's malware scanner ran.
http://www.suspension-nhs.org/Resources/Safety%20-%20IDT%20(...
In that tree (which is about harm to patients) the path to "consider suspension" is "were the actions as intended?" and "were adverse consequences intended?" (Did you harm the patient, did you mean to harm the patient?)
You get referral to the regulatory body (which may lead to suspension or dismissal) if someone took an unacceptable risk and there are no mitigating circumstances.
The point of NHS.Net email is that it is secure. A staff member should be able to open email without causing havoc.