2,000 NHS Security Vulnerabilities Disclosed
shkspr.mobi
shkspr.mobi
Patient data is typically held in secure systems like emis etc. run by one of a few large firms which have contracts with the NHS, so not on this sort of informational website.
I'm not sure that surgeries would ever be able to adequately protect patient data on their own sites, so they mostly use externally purchased systems and the NHS provided IT for handling that (from what I know second hand from people in the NHS, I don't work there) - those are separate systems from their brochure websites, which are typically bought from and hosted at some low-budget shop which churns out WP/drupal/PHP sites for £100 a pop and would hopefully have the sense to advise surgeries never to collect private patient data on their website.
The biggest problem here is that these sites have no business being subdomains of nhs.uk, and should be on something else like gp.uk or whatever, and the NHS should make it crystal clear that no patient data touches an informational site (to patients and GPs). It's either that or they need to set up a secure CMS which all GPs/Hospitals can use for their brochure sites, but that's likely to be a big budget project and is of questionable value.
You could say the same of most hospital websites - they will not be secure as they are fire-walled from the actual patient data, and thus it is less of a priority to keep them secure. Sure it's not nice if they are hacked, but it is not as important as what happens to patient data.
I think it's the "making crystal clear to patients" part that is important here, because if GPs don't have sufficient security and their sites are compromised, what they were supposed to do with those sites no longer matters.
The idea that there can be privileged domains like nhs.uk where unmaintained and potentially insecure sites are hosted and no-one even knows who's responsible for them is genuinely quite shocking. What next, file your tax return with izurrevenewzuncustomz.gov.uk (t/a HMRC Ltd)?
http://www.gosh.nhs.uk/ http://www.cam.ac.uk/ http://nyp.org/ http://www.highlands.state.nj.us/
It would not surprise me to find similar vulnerabilities in all of those picked at random, given the budget they are typically run on.
I agree it's far from ideal and a situation they should sort out given these are hosted on .nhs.uk, particularly as we move more and more of our lives online, there need to be clear rules about which sites are secured and safer and which are less important.
However, these sites do not host patient data.
The question is, do patients realise that, or will they tend to assume that because a site is part of the privileged .nhs.uk hierarchy, it is properly run by the NHS?
The real problem here is about trust, specifically about what should or should not appear trustworthy to patients because it is or isn't really. Given the increasing moves to do things like making appointments on-line, the much-reported efforts to share sensitive health data more widely, and the ever-changing sources of information and ways to contact the NHS, it seems to me that it is long past time these issues were resolved. IMHO it has to be done properly and from the top to have sufficient credibility and enforcement.
I do agree with most of what you're saying though, and this is far from an ideal situation. Probably a central system makes most sense long term but gov seems unable (or more recently unwilling) to deliver.
http://yourgpwebsite.nhs.uk/some-vulnerable-page?xss=...
And my XSS replaces the page with something that looks like an appointments system, the average person has no way of knowing that they shouldn't trust this. There's certainly none of the usual indicators.
Regarding hesitation of posting the information in the blog post; the author appears to have losely followed responsible disclosure methods attempting remediation with the NHS directly before publishing the findings.
NHS, HMRC etc the information security of these organizations is lax at best, and down right horrifying, without full disclosure forcing their hand I don't see any change.
This is why full disclosure / responsible disclosure formed in the first place.
I spent the last two months trying to contact the people responsible. When I finally did, they said they wouldn't / couldn't do anything :-/
If it be feared that this Discourse may unhappily advantage others in such unlawful Courses; ’tis considerable, that it does not only teach how to deceive, but consequently also how to discover Delusions.
but even then he knew there were liability risks that go along with information security research:
...the chiefe experiments are of such nature, that they cannot be frequently practised, without just cause of suspicion, when it is in the Magistrates power to prevent them.
Information like this demonstrating ways to discover exploits should be more common knowledge. I feel currently attackers have the advantage over developers. More posts like this where security is an open topic can only lead to more secure websites going forward.
Personally, what I'd do in such a situation is to contact a well-renowned hacker organization with experience in these matters (as for instance the CCC here in Germany) and ask for their assistance.
Alternatively, a tech publishing company could also be the right choice, preferably one with a legal department and experience in these things. He mentions that you should buy the issue of "Computer Active" that contains this article, so he probably took this route.
I also gave the DoH ample opportunity to fix the sites or shut them down.
I agree that there is a (minor) risk - but offset against hundreds of high profile sites being exploited, I think it's worthwhile.
We spoke to the overall owner of the sites and they did not object to myself or the magazine publishing this information.
That's...astonishing.
Sadly, it didn't transform into action.
I congratulate you for talking to the owners before publication, however.
What do you mean by this?
In the article you state:
> in many cases there is simply no way to contact the website owners
Do you simply refer to the owner of the parent domain name?
With some, we were able to contact the developers behind the sites. Others just didn't respond.
Basically - no one in the NHS or DoH knows who manages the thousands of .nhs.uk websites. We did our best to contact individual site owners and, where that was impossible, alerted the government directly.
Hope that clears it up.
From what I know vulnerability scanning (which is essentially what wpscan does) is a bit of a grey area under UK law.
It's been likened to someone "rattling the windows" of a house. They may be doing it with the intention of notifying the owner that he's left his house unlocked, or they may be doing it to attempt to gain unauthorised access..
The analogy isn't perfect but it's one I'd step carefully on.
And horrendous scope for phishing. Who's going to think twice about entering potentially sensitive information into their GP's web site accessed via a .nhs.uk address? Not most people, I suspect.
Like the NHS, American doctors usually don't store actual patient data on the generic CMS they use for hosting the website. If they have an online "patient portal" or "billing portal" it's usually a hosted solution that goes offsite, via a third-party company that provides such services. But it's nonetheless a huge phishing opportunity. Besides a fake contact form, you could also clone the portals, replacing the links from the main site, which are supposed to go off to places like medfusion.net or eclinicalweb.com, with ones that go off to medfusion.yourdomain.net or whatever, and most people will not think twice as long as your cloned site looks vaguely similar. I mean the genuine domains sound halfway like the domains of phishing sites to begin with...
Which of the following cars have you NOT owned?
- 1999 Ford Explorer
- 2001 Toyota Tercel
- 2008 Audi
- 1996 Hyundai
Along with a few more questions like that one, it's a dead give-away that my doctor's office is connected to a credit reporting agency. I have seen this happening in other places as well; evidently credit reporting agencies recently got into the business of on-line identification and authentication (I&A).