TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Heartbleed Flaw Said Used in Hospital Hacking

43 pointsby rbcalmost 11 years ago

4 comments

mholtalmost 11 years ago
I thought Heartbleed attacks were difficult to detect. How did they determine they used the Heartbleed vulnerability, especially since the attack happened only a week after Heartbleed was revealed?<p>&gt; &quot;Community Health ... disclosed yesterday that Chinese hackers stole patients’ Social Security numbers, names and addresses, without revealing how the hackers got in.&quot;<p>And then...<p>&gt; “We never had any tangible proof of an attack until now,” said David Kennedy, founder of TrustedSec LLC, a security consulting company based in Cleveland, Ohio, who first reported Heartbleed was used to attack Community Health on his company’s website.<p>Here&#x27;s the report: <a href="https://www.trustedsec.com/august-2014/chs-hacked-heartbleed-exclusive-trustedsec/" rel="nofollow">https:&#x2F;&#x2F;www.trustedsec.com&#x2F;august-2014&#x2F;chs-hacked-heartbleed...</a> -- but I still wonder how it was detected.
评论 #8201383 未加载
hnnewguyalmost 11 years ago
&gt;<i>&quot;The Chinese embassy in Washington said it wasn’t aware of the attack.&quot;</i><p>It is utterly amazing to me how we view the Chinese people as such an evil &quot;other&quot;.<p>I&#x27;d love to know how they determined that this was Chinese hackers, which doesn&#x27;t appear in the Trusted Sec report, and from my amateur eyes would seem near impossible to determine with certainty. But if it was the case, why the first thought is that it was an action on behalf of the government instead of a couple Chinese kids messing about. Count the &quot;Chinese hackers&quot; in the article.<p>If the vulnerability was public at the beginning of April, how were there attacks made in June?<p>Hard to believe they actually asked the embassy if they knew about the attack. The embassy&#x27;s reaction was understandable.
NamTafalmost 11 years ago
The scariest part of this is that even a week after Heartbleed went public, there are InfoSec professionals out there who still hadn&#x27;t patched&#x2F;brought down public-facing OpenSSL implementations.
评论 #8201158 未加载
apstlsalmost 11 years ago
This is what happens when we live in a world that gives OpenSSL $2,000 a year and Yo $1.5MM in funding...
评论 #8201347 未加载
评论 #8201939 未加载