TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Irish health service hit by cyber attack

149 点作者 basisword大约 4 年前

19 条评论

jl6将近 4 年前
I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years.<p>* Keep all systems up to date with the latest patches.<p>* Have a DR plan and test it regularly.<p>* Make frequent backups, verify them, and keep them <i>offline</i>.<p>Historically organizations have been so bad at backups that the advice has been to automate them as much as possible, to try to ensure that a recent backup at least exists. But I am increasingly of the opinion that the next level of backup maturity is to dial back on the automation and invest <i>manual</i> effort in airgapping the backups.<p>Fully automated backups are necessarily part of the software attack surface.<p>If you have to hire more ops people to rotate tapes by hand every day, that will have to be a cost of doing business safely.
评论 #27153417 未加载
评论 #27153580 未加载
评论 #27154698 未加载
评论 #27158156 未加载
评论 #27154145 未加载
评论 #27154003 未加载
评论 #27154883 未加载
评论 #27153659 未加载
评论 #27154428 未加载
评论 #27153421 未加载
评论 #27153337 未加载
new_here将近 4 年前
A lot of these articles don&#x27;t actually mention specifically how the systems were compromised.<p>Was it a malicious email attachment that propagated through unsecured networks or outdated OS versions? And what data was encrypted? Are we talking regular excel files or actual databases?<p>It would be interesting to have some more detail or case studies so others could know how to fortify infection points and limit the blast radius of their own systems.
评论 #27153169 未加载
评论 #27153955 未加载
评论 #27153151 未加载
评论 #27153149 未加载
评论 #27154961 未加载
kasperni大约 4 年前
Ransomware: Another great &quot;feature&quot; of difficult to trace digital currencies.
评论 #27153157 未加载
评论 #27153306 未加载
评论 #27153273 未加载
评论 #27152909 未加载
评论 #27164395 未加载
评论 #27152867 未加载
评论 #27153459 未加载
评论 #27152824 未加载
anonymousDan将近 4 年前
For those concerned about privacy violations, this should be rammed home as an argument against centralized collection of medical health data.
评论 #27153290 未加载
评论 #27153003 未加载
评论 #27152918 未加载
jupiter909将近 4 年前
One can do ZFS snapshots so one does not need do insanely huge backups all the time. Just transfer off the diffs as needed. If an attack happens it&#x27;s pretty easy to roll-back to a known good state. It&#x27;s also not that complex to set some process in place that does random checksum verification of some files to trigger an alarm that such an attack has taken place. It is really perplexing me that very large institutes don&#x27;t do this
评论 #27154747 未加载
评论 #27154735 未加载
adriancooney将近 4 年前
There&#x27;s a trend of paying these ransomware attacks which are sometimes in the order of millions. Imagine if those millions were _proactively_ invested into the computer security of these systems?
评论 #27153114 未加载
评论 #27154484 未加载
评论 #27153165 未加载
scandox将近 4 年前
A bit more detail in The Irish Independent. References the Conti ransomware.<p><a href="https:&#x2F;&#x2F;m.independent.ie&#x2F;irish-news&#x2F;serious-and-sophisticated-hse-confirms-ransomware-cyber-attack-has-hit-all-hospital-it-systems-40425737.html" rel="nofollow">https:&#x2F;&#x2F;m.independent.ie&#x2F;irish-news&#x2F;serious-and-sophisticate...</a>
bilekas将近 4 年前
What kinda scummy scrote you have to be to attack health services during a pandemic. This is a new low.
评论 #27153906 未加载
评论 #27153038 未加载
评论 #27152825 未加载
评论 #27153057 未加载
anonymousDan将近 4 年前
You&#x27;d have to think that sooner or later they are going to get into one of the big cloud providers and cause havoc.
评论 #27152898 未加载
TheMightyLlama将近 4 年前
One of the major issues I&#x27;ve seen while working with large organisation on software development is one of mindset. These are organisations who predominantly think: &quot;We are an &#x27;x&#x27; organisation that happens to develop software&quot;. The more productive and safer way of thinking is: &quot;We are a software development organisation that is within &#x27;x&#x27; market&quot;.<p>However, the latter requires a huge mindset and experience shift from the very top of the organisation. And groups and individuals of that organisation having strong interest in their survivability are, of course, not going to change that.
评论 #27153741 未加载
motohagiography将近 4 年前
Odd effect of this is that it would be difficult to distinguish encrypted backups from ransomware encrypted files being backed up.<p>Cloud documents like Word and Google docs seem less susceptible, as writing a content parser for each file format to encrypt it would be a higher bar. Or am I missing something there?<p>It also suggests there could be a market for cryptocurrency futures as a form of insurance. This is one extreme situation where you are forced to buy a currecy at market prices, but I suspect it&#x27;s the first of more.
pjmlp将近 4 年前
I love the increase in these kind of attacks, eventually there will be enough pressure for liability legislation for companies to take security seriously.
评论 #27153027 未加载
评论 #27153082 未加载
valenterry将近 4 年前
On one hand I&#x27;m excited about all the good things that e-health can enable for us, but then again, I&#x27;m super scared to leave a trail of my health history in IT systems.
agumonkey将近 4 年前
That&#x27;s not the first attack on health.. in the context of a worldwide struggle I find the operation against medical institution utterly despicable. God.
padraic将近 4 年前
Not really suprising given that during most of the pandemic, track and trace was done through pen and paper and not through the computer system.
easytiger将近 4 年前
I imagine, to use our vernacular, some chancing gobshite is talking his way our of responsibility for their shitty tender as we speak.
评论 #27153642 未加载
killjoywashere将近 4 年前
The NIST 800 series and the CNSSI 1253 series cover pretty much everything you need to worry about.
mdeck_将近 4 年前
Ever-relevant XKCD: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;2030&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;2030&#x2F;</a>
评论 #27153821 未加载
dariosalvi78将近 4 年前
wouldn&#x27;t disrupting healthcare services be an act or terrorism or even war?
评论 #27153099 未加载
评论 #27153391 未加载