Fundamentally though, this is a failure of the tech community to engage policy makers and a failure of policy makers to engage / listen to the tech community. It took me (and others?) years to get self-driving car regulations enacted in Canada. And even there, we're just getting started with the basics. Not enough programmers are politically engaged and the field is moving so fast that it is tough for regulators to keep up. I'm not surprised that people are dying. Quite the opposite, really. I'm surprised so few have died given how horrible our security is for industrial systems and other fuddy-duddy sub-industries of software. Yes it's a lot better today than it was five or ten years ago, but the offensive tools are much better as well. It's literally an arms race and sometimes it looks like only one side recognizes it as such.
IMO you should not be running windows on hardware whose failure could cause deaths. Maybe windows could be secured to prevent this but that would require IT staff to keep things updated which does not always happen.
A much better solution is to run locked down Linux or BSD.
Additionally, you can often satisfy these things with policy statements rather than technological solutions. A weekly review of record access reports may satisfy in some cases, without needing to implement an ACL mechanism.
And after about 60 years of IT, I don't know that we ever will. Efforts to certify systems/processes are often bogus (participate in a CMMI appraisal for a good example of this). Legitimate efforts to certify them are drowned out by the charlatans. And very few in the IT industry would desire personal certifications along the lines of PEs. Either they don't want the legal and financial liability, or they truly believe there's no value in it.
However: Despite a law being in place since 2015 many hospitals are still underdeveloped when it comes to IT and IT security in particular.
If the brakes go out on your care, and you smash into a building, even though it was recently serviced to whatever 'standards' are you liable? Yes. And then it will be up to you to pursue the manufacturer of the car, who will claim they met all standards, so they're not liable. See how it works?
And that's important. You have to have some place to draw the line between "we did nothing and we're all out of ideas" and "what do you mean you didn't write your own operating system from scratch and hire fifteen security experts to continuously analyze it for un-patched zero-day exploits?"
That's where industry standard "best practices" come in. Once some sort of standard is issued (by regulation) or accepted (by industry), it becomes the thing that a Reasonable Person does. Meeting that standard is then usually sufficient to avoid charges of (or additional liability for) negligence.
> If the brakes go out on your car, and you smash into a building
In this case, you're liable because you carry strict liability for your actions as a driver. However, proof that you've kept the car in working order would be sufficient to escape any criminal charges (dangerous operation of a vehicle, for example)
Maybe comparing it to MilSpec makes it understandable to citizens of the USA: we want our hospitals IT infrastructure to be like the navy wants its warships: made out of steel, with redundant systems and sane compartmentalization so it can withstand most attacks. And we are willing to invest billions of tax money to get our existing hospitals up to these standards, because many are like viking longboats: they stay afloat and cure disease, but they are not protected against torpedoes. A hospital looses most of its infrastructure to a some ransomware? There is an investigation by the supervisory body into the technical and organizational details of the specific security incident and they really don't care about certifications printed by some private company that claims to have audited the hospital. The expected result is a "how this hospital intents to prevent this type of incident in the future" document. These standards are not about certifications of industry sector mediocrity waved around to shift blame and win liability cases in court. Also I don't think liability cases work that way over here, but i am not a lawyer.
What do you think?
I don't think there is a single hospital that completely fulfills those standards. The bar is very high and the umbrella organization of hospitals says there must be millions per hospital invested to reach the requirements.
In unrelated news: a new law was passed today, after years of preparation, that includes a 4.3 billion euro investment of tax money into hospital IT systems.
Wouldn't simply using a cloud-based B2B service with something like Chrome OS / Cloudready instead of Windows solve the entire problem?
If that wouldn't work for data privacy or network availability reasons, it could be an open-source self-hosted server application, accessible locally only through a REST API.
And the server security? Just use something like self-updating RHEL CoreOS with a bunch of isolated containers, which greatly limits the entire attack surface.
> I don't think there is a single hospital that completely fulfills those standards.
Why can't a single technical solution be designed and supported for all state-owned hospitals in Germany?
Are you aware that unlike Windows, Chromium OS has been designed from the ground up with security in mind[1]? And that it can run on almost any hardware[2]?
> All your mentioned alternatives could just as easily fail if not properly secured.
Software has to be designed and chosen with security in mind from the beginning.
If a hospital is running Windows Server instead of automatically-updating, minimal Container Linux[3], it has a much larger attack vector space.
These two factors alone (a proper client OS, and a proper server OS) can reduce the probability of a successful ransomware attack to almost zero.
[1] https://www.chromium.org/chromium-os/chromiumos-design-docs/...
I think you can’t tell the attack space from a glance like that. And there’s ways to properly lock down Windows installations too, patched or not. Careful systems design and planning is key, regardless of exact components.
That has been a solved problem, at least in Chromium OS[1]. Even hardware-based two-factor authentication can be required for all users by a click of a button.
> DDOS attacks?
If it's self-hosted by a hospital locally, most parts of the system should not be available on an open network. If it's not self-hosted locally, the largest European hosting provider, OVH, can survive a 1.1 Tbps DDoS attack[2].
> Careful systems design and planning is key, regardless of exact components.
If the solution is not designed around up-to-date technical components, it can fail regardless of careful planning.
[1] https://support.google.com/chrome/a/answer/1289314?hl=en
[2] https://arstechnica.com/information-technology/2016/09/botne...
In large organisations, the problems are always found in the organisation itself, seldom in whatever tech stack is used. That they used unpatched Windows installations is not the disease, it's a symptom of the disease.
You can enthusiastically treat the symptoms and improve the condition of the patient, but unless you go to the root causes, the patient will find new ways to be ill and you can 't be there to band-aid everything, all the time.
2: because Germany is federal-social-democratic, not stalinist.
Ah, "federal" is the right answer here. In many smaller EU countries, there is a single central social-democratic government, which can just fund an open-source solution for all regions to use.
> What do you think?
I don't understand why this apparently seems so obvious to you. I think I would need more information about the attack, the hospital's preparations for such an attack, and the legal and industry-standard security expectations for such a hospital.
The simple fact that an attack took down a hospital's computer systems is not sufficient to conclude that the hospital was negligent in its security. Surely a sufficiently sophisticated actor (e.g. a state) could take down the computers at most hospitals if they chose to.
I think you can follow all the laws and still get hacked, so I don't think the fact that they got hacked tells us much about whether they were following the rules
Software industry hates idea of regulation.
In that case, the active threat begins to look more like a random-chance natural disaster than the kind of event the human justice system can bring to heel. By all means use the justice system, but if the justice system is failing? Plan for fire.
(Seems like there's a lesson to be applied here to architecture in California, now that I think about it...)
Unfortunately, hospitals have a complex and expensive job ahead. I wonder if anyone has developed a blueprint for how to proceed?
https://reason.com/2020/08/22/do-threatened-businesses-and-i...
I see no real moral difference between arson and launching ransomware attacks.
1. Actions that are physically violent
2. Actions that cause physical harm, but the action itself is not physically violent
If 1 and 2 were the same, it would imply that voting for a politician that decides to kill people is just as bad as killing people yourself. The consequences of that wouldn't be good.
> You wouldn't say that someone firing a gun didn't commit a physically violent act just because all they did was pull a trigger.
If the gun is their property, it's their fault that their property is attacking someone. It's not pulling the trigger that's wrong, its that their property attacked someone else. Same idea applies to killer robots.
If the gun is not their property, then it's their fault that they used someone else's property.