Health-care cyberattack is worst in Canadian history, says expert
cbc.ca
cbc.ca
At least, for my systems, I found "Relax and Recover." As the project says, there is no excuse.
Elegant and simple, but definitely not workable for restoring a large network of ransomwared hospitals. Also, I doubt this would stand up well to ransomware either.. worms target shares and then what will you do? It's turtles all the way down! (Unless you use data diodes or write to tape or something.)
For now, we are immune.
This means we keep fewer, more important records on paper.
This requires rethinking management which, lets be honest, needs to happen anyway.
I was having asthma and went to the doctor in Cassis France. To get a ventolin inhaler and a round of prednisone only took two forms -- one at the doctor and the prescription -- and about $70 dollars.
I look at the reams of documents Kaiser generates anyway, virtual and real even though I'm "paperless" and I wonder how much of the expense of my health care goes into schlepping all these documents around.
There is a book by Derrida called Archive Fever that I read when I was a temp and I always think about the quote in it: "the archivist generates more archive, and so the archive is never closed"
Maybe we need that big hack to finally take away the bottle. We don't have to record everything forever, and digital technology is bad at it, anyway.
Every small little detail recorded by your doctor can be crucial to determine a timeline and help with treatment later. Or just to know your allergies and regular vital signs in case of a serious issue that requires emergency care, when you might not be able to give the information ( e.g. car crash, and you're allergic to penicillin or something in the usually used anesthetic or whatever). It can also be useful when you can just call a doctor to get a prescription, because they have your full medical records and know enough about you quickly.
Paper is extremely impractical.
My timeline is that it is too expensive and full of forms for me to go talk to my doctor. And I have to keep answering the same questions to my doctor about my allergies over and over and over anyway.
I think all this paper work helps a parasitic managerial class, but I've never seen it help me.
It's the physicians job to weigh the benefits against risk of a drug. And potential allergic reactions is a part of that. If a patient with a known history of severe allergic reactions gets another one from a prescribed drug, and the physician hasn't done their due diligence, then the physician could be at fault. I can only imagine that it's even more prudent for US-based physicians to ask that question due to lawsuits and or personal liability.
Also a patients medical status is never static. While unlikely a patient could have had a reaction since the last visit. I guess a more realistic example of something non static is pregnancy status which can be equally important when prescribing drugs etc.
I get it being a disruption, and loss of privacy for citizens. However why are they stopping appointments.
--The backups are not only not offsite; they are online and attackable.
--Backups are not done every day on every machine. The machines on which backups are done most rigorously are the gift shop cash registers and the machine that runs the janitorial scheduling spreadsheet. The blood test results pub/sub system was last backed up in 2019.
--The restore procedure is never tested. Not rarely, never. Because it would take machines out of service for an hour. Can't have that.
--Joe who runs department X drags his feet about upgrading his organization's computers and getting on the corporate backup rotation. And if department X gets taken out, the whole company shuts down.
--Bob in the basement is running a research network nobody knows about, and he puts it directly on the Internet so he can run his experiments from home. And of course it contains a bridge to the corporate intranet.
It's just a clusterfuck everywhere. Good people busy getting their jobs done who see security procedures as obstacles to work around. The bad guys completely understand this organizational dynamic and they exploit it for profit.
You restore from backups to alternate hardware, but your key software is license locked to hardware. It was always the documented recovery process to contact the vendor and request a new license. Their SLA is 30 days.
If you have an incremental backup that goes as far back as say 14 days for example. No separate archived snapshots, etc.
If you infiltrate the network and figure out this crucial bit of info - you just wait 14 days while you branch out and infect more PCs, more of the network.
Once 14 days goes by, it's guaranteed that any data the victim tries to restore from is corrupted or potentially encrypted with ransomware.
Question is, did they pay the ransom?
What’s CSEC up to?
Better would be constructing a system where government-paid appsec teams are granted access to cloud source control repos for all projects + ability to randomly pentest whatever they desire.
If a breach is found (in release candidate stage or prod), the offender's contract is reduced by the prize amount, and that amount goes into the appsec team's budget.
The only way to make people care about appsec is to (1) increase the likelihood and frequency of exploits & (2) ensure exploits have direct budgetary impact on the teams developing the software.
It's easy to say "Our systems are secure and follow all standards" when they aren't and they don't.
It's harder to explain why projects keep coming up with multiple successful pentests or security flags.
Increasing visibility of risk and aligning incentives, with a credible and independent validation party, is the solution.
The biggest gotcha: payment must be for a successful penetration, and must not be for some paperwork flagging of minutiae.
What's not so secret is that CSEC pays low and kills your career growth.
Are there any wider implications whete security doesn't get taken like we expect it to as a result?