387 comments

[ 3.3 ms ] story [ 191 ms ] thread
Shutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out?

I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?

Edit: There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place.

>There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place.

Take a look at that operating system and the UI from the article and tell me how that's unexpected.

That will be stock photography, rather than taken today.
It is still accurate. We still have XP machines floating around our campus. They are running EMR software.
Are they paying Microsoft for extended support?
What does this cover provide? Any ideas? I assume every customer is different?
Yes. NHS has a national level support agreement for XP. There are a lot of legacy systems and it's not just the bother of replacing the system, there are a lot of front line staff who only know how to use specific applications and are not generally computer literate so moving them to new systems will slow everything down for weeks or months as they learn a new application.
Christ. There is no excuse for that whatsoever. A live machine?
If the software doesn't run on versions higher than XP, then there's no alternative. There's a lot of expensive equipment which is stuck on XP.
Virtual machines are a thing.
How does that help? We're talking about devices that need, for whatever driver-related reason, to run on the bare metal.

A non-health example: http://www.effectivebits.net/2011/08/to-run-windows-or-not-t...

And medical devices cannot just be modified after they are approved for medical use. Any changes must be introduced by the original vendor (or an approved 3rd party vendor) and put through a barrage of tests and certifications needed to release such a device for use on a human. Those include EMC/EMI testing, QC testing, safety testing, RF testing, clinical trials, regulatory compliance, etc.

When you buy a medical device running Windows 3.1, it will run that until it is thrown away or replaced.

>There is no excuse for that whatsoever.

Except for budget and non-technical leadership in technical leadership roles

I'm not sure which article you were referencing, but the pictures in the Guardian piece clearly show Windows 7.
How on earth could an X-ray machine be affected? Why the hell does the NHS have an X-ray connected to the Internet?
It's hopefully not connected to the internet, but to the local network. Many medical appliances in hospitals expose remote control over regular tcp/ip, Preferably running Windows XP or CE.
I wasn't seriously suggesting it was directly connected, but my understanding (and I am far from knowledgeable when it comes to security) is that mission-critical devices should be physically 'firewalled' from the Internet, and even any network.
They should be; but security in government organisations is pretty bad. They are heavy on security on it, but in completely ineffectual areas.
If you do that, how do the images get from the x-ray machine to the radiologist for analysis? How do they end up as part of the electronic health record & accessible for future use? If you create an air gap and ask people to use USB sticks to move data from "mission-critical" systems to the main network, you only slightly reduce the risk of those systems becoming infected and you now have a situation that's much less convenient (time is money) and creates a new vector for leaking personal health information.
If it's hitting everything it seems like it's just forking everywhere. For it to do that there must be some _really_ bad security practices
Caught wind of this earlier today with a European client. We were advised to not connect to their network via VPN. Looks like it's a large scale attack that's affecting more than just hospitals in England.

These could be a coincidence though.

Here is a source article talking about a Spanish TelCo: https://www.usnews.com/news/technology/articles/2017-05-12/s...

It is large scale all across Europe. NHS is only one among many (we are smack in the middle of it)
Like the NHS didn't have enough problems with unhappy staff, unfilled positions and Brexit looming... very uncool.
Existing discussion thread: https://news.ycombinator.com/item?id=14324129

---------

Shutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out?

I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?

There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place. Perhaps underinvestment in IT is to blame.

> Perhaps underinvestment in IT is to blame.

Or, indeed, over-investment in trash-tier IT services provided by blood-sucking IT consulting companies.

I've seen the insides of some UK Government IT systems (not the NHS), and it's astonishing how little functional software one can get in exchange for a few hundred million sterling.

That, and the bitrot of holding on to ancient, never-updated IT systems.

[Edit], back on topic, I sincerely hope whoever did this is burned alive for their crimes.

The whole EHR market is absolute crap in Canada too. You have around 10 competing standards with no interoperability, multiple data sources cobbled together through webpage links, and all running on a slow as fuck central server that you Citrix into.

Another research department I worked at was seriously underfunded, which resulted in questionable decisions, such as using round cube for email, and a central shared drive with a Microsoft access database containing patient data. Hospitals have terrible security.

What is the issue or alternative to Roundcube? I thought they were pretty good.
It's a terrible UI for webmail, and our webmail was subject to a hack a few weeks ago, and they've since closed off WAN access. I'm pretty sure it was related to roundcube. Which is a bummer.
To be fair - healthcare IT infrastructure sucks everywhere, even in the country most well-known for remarkably expensive privatised healthcare. It's not really obvious at this point how to fix it. Have the Government Digital Service or similar work on it directly and ditch the contractors?
> Have the Government Digital Service or similar work on it directly and ditch the contractors?

Basically, yes. Bring it all in-house, ban the contractors/consultants/mercenaries/etc. Remove the profit motive and suddenly you don't have millions of dollars/pounds being siphoned off by vampiric consultancies and third-party vendors. Suddenly you can spend tax-payers money in a sane and rational way.

Hire a bunch of talented people who care about the wellbeing of their nation state, pay them well enough and task them with building the best systems possible in the most efficient way possible.

This is a great idea, but since it's practically to the left of Corbyn I can't see any chance of it being enacted.
Without giving too much away, I've been involved in just such an initiative, and it was _awesome_.

However, in the context of an established organisation it's really hard to pull off, and so we eventually ran into serious pushback from other factions within the org, particularly the established IT Ops folk.

Still, it can be done, and it can be a raging success. Especially gratifying when you spend two days writing up a system in Python which replaces some 90's garbage that's costing the organisation 200k per year in licenses.

Killing Leeches is fun.

Had exactly the same.

100 user system, Windows CALs and RDS licenses per user = a lot of money. Found only 40 users needed the CALs, rest were fine on Linux.

Took the devil of a job to persuade them this, as the Microsoft rep told them they couldn't.

In organisation like the NHS something like active directory becomes almost mandatory.

Open sources equivalents are nowhere near as good.

Not the same thing I'm on about. Can't say too much, but was on a system where for majority of users they didn't even touch a Windows server or AD.
Was that related to one of the NHS hack days?

> eventually ran into serious pushback from other factions within the org, particularly the established IT Ops folk

"Mordac, preventer of information services"

Thankyou very much for fixing this kind of thing, seriously.

This. A million times this. I think at this point the tech community should be vocal about this issue.

Tech has improved ten-fold this last decade, and IT consulting services simply don't care because they profit hugely from it. What makes this issue even harder to solve is the fact that IT is so simple to hide because society does not understand it enough.

Similar to the Tech Pledge, we should stand and be very vocal about the fact that you CAN build strong, secure and relatively cheap systems. If we don't do this, who else will ?

We're stuck between a part of the industry which benefit from this (and especially the big bosses, they don't care about the developers either) and a society which doesn't see the value of homegrown (as in company/government-grown) tech talent and the tenfolds decreases in IT spending it could entail.

Please, Sam Altman ? Someone ? Please ?

Can I ask, how did the employees fit in with the payment structure? My feeling has been that the NHS simply can't hire talented staff on the wages they expect because the pay grades don't go up that high. Hence hiring contractors.
It is my understanding that the DWP has brought a lot of its IT back in house.

edit: I should say some as to be fair, I'm not 100% sure of the extend of this.

This is what should have happened instead of the disastrous NPfIT. It took years and none of the big players (Accenture, BT, Fujitsu, CSC) could even agree what a fucking medical record should look like because nobody was willing/able to concede anything.

If it had been an in-house project with actual experts employed in building/deploying on a smallish scale (say, a town or county) and then rolling out it could have been a thing of beauty.

It should have been what AlphaGov became.

(comment deleted)
I agree with your solutiom, but there is far, far less blood sucking going on than you might imagine and far, far more organizational incompetence. That is, organizations hire contractors and then dont know how to tell them what they want, but simultaneously refuse to let the contractor have initiative because they dont know how to set up a pay structure for it. Businesses screw themselves.
Yeah but the truth isn't as exciting as thinking you can write DJango app to save the NHS. It's far more fun to think you can knock something up with your friends in a few months.

Then requirements start coming in, the stakeholders, the politics. The multi faceted organizations, the disparate teams with never ending edge cases.

3 years later when it's past phase 2 and creaking at the seams, along comes the next upstart... DJango! Which idiot picked that?!!! Me n my friends could....

> Hire a bunch of talented people who care about the wellbeing of their nation state, pay them well enough

This is impossible. Any large organization eventually resorts to using pay scales to combat corruption. When the right people will be 10+x more effective than the wrong people, pay scales are impossible.

Literally the entire reason why large organizations resort to hiring contractors is because they know it's impossible for them to hire good people directly.

How does it suck? Everywhere I look hospitals have dumb pc's connnected securely to cloud services for applications, primarily Citrix or web based portals hosted by a trusted contractor or the hospital themselves.
There's an awful lot of network-connected, really badly written, often unsupported software in healthcare, that uses proprietary formats. VDI doesn't save you if what's on the other end has to be Windows XP to run your shitty software that'd cost your IT department's entire budget for a year to replace and retrain users.
Or, indeed, over-investment in trash-tier IT services

Yeah, I think this is probably closer to what's happening.

I've worked with some of these Enterprise-level IT consultancies in the past. I do understand that it's quite a different market from the lean, tech-focused web development market, but some of the solutions I've seen implemented are shockingly* bad.

I wonder if it would be appropriate to "dramatically overreact" and send in the SAS or similar to send a polite message that mucking with the NHS is really not a good idea.

Maybe post offer a decent reward - say £10 million for information leading to the identification of the culprits.

If this trend of targeting large institutions continues, yeah, I can see someone eventually "overreacting" with black ops.

This said, they're probably popping champagne at Tory HQ right about now.

wouldn't they be popping corks at Labour HQ? I mean, this isn't really "strong and stable"...
Labour won't attack on this because they know it might have happened to them just as easily, whereas it fits the Tory narrative that "the NHS is useless and should be privatised" with almost no spin.
The NHS is fundamentally a socialist endeavour - any failings in it are obviously the fault of socialism!
Most of my local Tories know that any kind of direct assault on the NHS would result in instant annihilation at the next election.

There are more subtle methods of course including outrageously broken internal market management restructures (Stafford Hospital Trust, 'fund holding GPs' in the time of Thatcher) and the like.

I suspect that if this does happen it will more likely be the French retaliating against the hacking of the election the French version of SAS/DELTA don't fuck about.
Exactly this. When ever anything comes to tender, out of the usual three on the table, the cheapest will always be chosen.

And because departments are left to their own devices, they solve all their problems with shared drives and excel sheets.

Ransomware is the hero we didn't ask for.

Everything is a "bug" according to most journalists. We'll probably get something a bit more coherent from Ars Technica or The Register.

WRT the failings: I've worked in IT in the UK for more than 25 years, and I have never (until now) worked in a place that took security seriously. That includes schools, a large accountancy firm, several well-known public sector establishments, a political campaign, etc. "Optimistic security" is the model here, and hospitals have huge rambling networks with many legacy systems and third-party solutions. I would be surprised if they don't have security issues. Where they are secure, it's probably down to some unsung hero(es) somewhere, who took it on themselves to push security. (I've done this myself and it's a thankless task; nobody notices or cares. Dogs not barking, etc.)

> Everything is a "bug" according to most journalists. We'll probably get something a bit more coherent from Ars Technica or The Register.

That's a good point, tech journalism is usually pretty poor.

https://twitter.com/ShaunLintern/status/863039464649744384 suggests it's significantly more boring than a zero-day (though still incredibly problematic).

Your experiences with UK IT make for depressing reading.

> Your experiences with UK IT make for depressing reading.

I am astonished that even skilled techies don't take security seriously, using passwords like their car registration or company name - I've seen that with a military contractor, ffs. People who had signed the Official Secrets Act and had network links into supposedly secure sites. It depresses me too.

People have this insane notion that one line of defense is enough or they have the equally insane notion that no wants to take something they have.

People have a really hard time evaluating simple risk/reward models. You have to make the reward of attacking you higher than any possible reward to have a reasonable chance at security. If anyone anywhere on the Internet can profit by your loss, eventually someone will try.

EDIT - To make life even more difficult sometimes the attack provides gains indirectly. Imagine one group of politicians attacking a service supported by another political faction, just that service going down profits the first group if it changes who voters vote for.

From my perspective its a fundamental problem with incentives. Good security costs time and money, never gets return gains, and no one will put money up that wont ever see a ROI. So incredibly short sighted, depressing indeed.
Is there some kind of saying: You can't secure a network that contains legacy systems?

Start from scratch, don't connect anything legacy. Assume the LAN is already penetrated and design for that. Store no data locally, client machines run something like ChromeOS by default. Timeout anything that's not used for 6 months. Don't use passwords, only SmartCards. Snapshot data for ease of restore.

Don't you think that, perhaps, replacing a dependency on a centralized infrastructure by replacing the entire system by centralized infrastructure, owned by a foreign company, might not be the smartest idea ?

Systems that can't depend on the outside, obviously, cannot use cloud services. That means no chromeOS, no active directory, nothing but the local network. This is beyond obvious, and yet, I actually believe we'll be stupid enough to do exactly the centralization thing.

Paying $300 to these crooks, incidentally, will be a LOT cheaper than whatever microsoft or any other company will ask for the centralized infrastructure. Not that I suggest doing that, but still.

I did say something like, just take ChromiumOS and your run own servers.

All systems depend on the outside to some extent anyway.

Is it $300, or $300 per machine? Why can't the machines just be reimaged, what kind of giant corporation doesn't have that working automatically?

$300 per machine. Issue is that ransomware also encrypts all files on shared drives.

But a problem with the approach of centralization taken by something like ChromeOS which uses Google accounts (or I guess Win10S which uses ms accounts) is that you're attempting to prevent one player from holding you hostage by giving yourself hostage to another. This is not going to work to prevent paying through the nose, although yes, your new hostage takers will probably realize that the NHS will be able to pay more when it actually takes care of patients. Not too well, of course, good enough to make sure it isn't replaced or repealed. Badly enough so that constant complaints ensure a fresh budget injection every quarter.

They're already being held hostage by 1000s of companies who won't update their crappy software so it runs properly, allowing them to install OS updates rapidly.

As I said, like ChromeOS, it's perfectly possible to run your own servers, don't need to pay Google or Microsoft.

https://www.chromium.org/developers/how-tos/enterprise/runni...

> Start from scratch, don't connect anything legacy

The myth of the clean sweep. Personally, I've found such systems tend to be late, wrong and inevitably end up resembling what they replace, warts-and-all. This is because systems tend to mirror the organisational and political context they are in, and most programmers today are not significantly better than those who came before them. Quote me all the exceptions you like, this is my experience.

https://en.wikipedia.org/wiki/Conway's_law

Investment Banks take it seriously. So seriously some clown in IT Sec cut off the links to 3rd party libraries from the internal Nexus.
Voip phones run on windows servers! Thanks Cisco.
Spanish big companies like Telefonica, Inditex, Iberdrola, Endesa... are being attacked too.

Seems serious.

Some portuguese too: EDP, PT and NOS...
I've heard from some people in Portugal that MEO is affected, as well as the Spanish Vodafone. A friend working for the Portuguese Vodafone is saying that, so far, they're unaffected.

This seems to be quite serious.

300$ ransom doesn't seem like they're being targetted. The virus just spreads very, very well through corporate (i.e. Windows) intranets, including when connecting through a VPN, using a remote code execution vulnerability (see my other comment here https://news.ycombinator.com/item?id=14324592).

Considering it's already hit some tech giants, it was just a matter of time until it spread through their VPNs to their workers, clients and beyond.

This is gonna be fun to watch from the sidelines.

Seems like non-targeted ransomware - https://twitter.com/ShaunLintern/status/863032223469056004 - based on the modest $300 request.

Note: I've zero idea if that screenshot is legit but it's posted on The Health Care Journal website so it likely is.

Edit:

- Earliest Google result for "WanaDecryptor" is from Aug 2015 (All other search results are from today):

> almost all of the files on the D drive is encrypted. C is not touched by the disc. file found is in the ProgramData folder, there is a hidden folder, the virus in it. When you delete a folder that is created again and the process starts again.

http://www.cyberforum.ru/viruses/thread1979411.html

http://www.cyberforum.ru/viruses/thread1979358.html

- Discussion from today mentioning it infecting Spanish Telecoms: http://gta-trinity.ru/forum/index.php?/topic/57671-novejshij....

At a security seminar last year I got to hear an expert talk about tracking down ransomware over the course of a couple of years. He said, no matter what the value of bitcoin the price gets adjusted to be equivalent to $300. That is the presumed sweet spot where people realize it's worth the money to save their data.
Friend of mine who works for the NHS sent me the following email:

All of NHS PCs and hospital systems have gone down from a ransomware trojan!

I have a full clinic this afternoon, and no way to look at my patients' histories, or meds. It's a damned disgrace.‎

The Trojan is demanding some bitcoins be paid, else they'll lose the boxen.

The entire NHS is penetrated.

I can't vouch for "the entire NHS is penetrated"

hmmm... that doesn't sound like a 'cyber attack' as much as it sounds like 'getting owned by a trojan'
A 'coordinated' attack apparently unless it is a very agile worm, lots of disparate unconnected levels being hit - such as GP surgeries (local clinics) to large hospitals A&E (ER). The common factor being the widescale abuse of @nhs.net as the email provider for all. Local GPs not meant to be using it at all.
Not necessarily a coordinated attack, it could be a technique which is exploiting some weakness in security practices and they happen to have hit on these systems.
What is the reason local GPs are not meant to use NHS.net email? I work in the sector and I thought it was policy to have them use it as the approved platform to securely communicate with secondary care.
GPs absolutely do use nhs.net; that's how they communicate. It's supposed to be secure enough to send medical records. If you go for a blood test or something, that's how the results come back.
It's apparently using the leaked NSA SMB exploits, so once it hits their internal networks any systems which aren't patched are probably going to get exploited pretty much instantly.
What makes you think GPs are not allowed to use nhs.net email?

https://s3-eu-west-1.amazonaws.com/comms-mat/Comms-Archive/J...

> A nominated Local Organisation Administrator (LOA). For primary care organisations, specifically GP practices, pharmacies, optometrists and dentists this is provided by NHS England Area Teams. Where appropriate, Department Administrators may be nominated.

'Cyberattack' seems to be the latest buzzword that tech journalists like to use. I'll agree that all the information I've seen points at this being a regular trojan rather than some targeted hacking. Will be interesting to see how it started.

Maybe targeted emails with attachments?

From my knowledge of NHS IT, it is reasonably hard at the perimeter but with a very soft chewy unprotected centre. I am not surprised this went round like Billy-O once inside.
Telefonica (the largest telecom operator in Spain) is having the same issue. There are a few thousands of workers that are not working; it's a disaster!
Same in Portugal (confirmed to be affecting PT, one of the biggest telecom companies, and EDP, the biggest electricity company)

https://www.publico.pt/2017/05/12/tecnologia/noticia/ataque-...

I don't mean to be dramatic here folks, but multiple coordinated infrastructure attacks are a form of warfare. This is literally shaping the battle space. Correlation is not causation and all that, but while people are standing around comparing their knowledge of how to deploy zero-day exploits and which isms it would be satisfying to blame during some future retrospective, the systems we depend on are being actively compromised.
(comment deleted)
(comment deleted)
Sometimes I wonder how much of the economic activity in bitcoin is generated by ransomware.
I'm pretty sure it is a really good chunk. Probably only trumped by drug deals.
(comment deleted)
The NHS is notorious for using outdated software, so I'm surprised it's taken so long. We build websites for third-sector organisations who often deal with the NHS and we're only just now persuading them to drop support for Windows XP / IE8.
Yeah, I left the NHS in 2009 after much frustration in trying to implement modern(ish) replacements for various reporting systems. Every idea was discussed and watered down until what's left was neither use nor ornament.

There are many great and extremely dedicated employees but the vendor lock-in has painted them into many (disparate) corners.

NHS IT is, of course, vastly under-funded compared to even modest startups, and entangled in bureaucracy of upgrades. I used to work with someone who was one of two sysadmins for a hospital of several thousand staff.
NHS systems are remarkably un-integrated. Communication, especially between trusts and external organisations like GPs, is often by email. I'll be surprised if this isn't an email worm.
look at what is happening in spain Telefonica giant
Oh the irony, the NHS has been holding the tax payers ransom since the '40s.
Here in the UK, that is an incredibly unpopular opinion. I've never met anyone who isn't in favour of the NHS.
Best value for money health service in the world absolutely no contest. Free healthcare for all no questions asked. Sounds like some johnny foreigner to me. Probably a Trump supporter chiming in with his alternative facts. Even he can get treatment here. I'm not so sure about a cure.
Sadly, I think there are more people that would be in favour of a private system than we'd like to admit. A lot of people have bought into the Tory idea that the NHS is unsustainable, and that the reason we're all poor is because we're paying for what they see as sub-par care.

On one side, the NHS is arguably the greatest success story of the UK, and I think many people would riot if their free healthcare was taken away. On the other, people will happily vote against a party that is looking to increase its funding, and will happily vote for a party that has made significant moves to privatise our healthcare system, so logically there must be people that aren't in favour of the NHS.

Sadly what most of those people don't realise is that the majority of their private healthcare will take place thanks to the NHS. Going private gets you into the nicer wards at many of the same hospitals, to be treated by the same doctors and nurses, and without any significant delays.

It's all well and good getting your hernia sorted out faster than on the NHS, or getting knee ligaments rebuilt without a 12 month wait for an operation but there's almost no concept of a "private" Accident & Emergency department.

(comment deleted)
Yep, you're essentially paying for the administration costs by going private, but that's not what the Bupa adverts sell you, and it's not what people seem to assume when you say you've got private healthcare. They think you're in some kind of special institution where you're pampered 24/7 by medical professionals, when in reality you're in the same NHS bed as the person next to you with some minor benefits. Additionally, as you've rightly pointed out, your private insurance will only cover non-existing illnesses. A&E isn't covered, nor is anything that might've existed before you picked up your insurance, and they'll be sure to check up on that. Take away the NHS, and the infrastructure becomes fully private, and that's when the costs will go through the roof.

For the life of me, I don't know why this isn't what Labour are driving home to people. They should be telling people "Vote Labour, or kiss the NHS goodbye".

You should get out more, I know loads of them.
On the other hand, $300 sounds like a bargain.
Per computer.

If the ransomware has no vulns itself, this is going to be a hit to economy, either by paying the ransom (it's already hit some major companies) or the losses produced by it.

I should hope that they can just reimage the workstations and if network drives were affected, just restore from shadow copy or backups.
You can reimage the workstations but how much work has been lost? Probably an awful lot.

I can't even fathom how many spreadsheets with no backup have been lost today.

WRT backups... :^)

I've rarely worked at a place that didn't shadow copy your user directory to a network location. The only thing that SHOULD be lost is whatever hadn't been saved when they were ransomwared.

The company should be able to pull a backups from the last file change prior to that event.

Has anyone paid this specific ransom and had their files decrypted? I've got a client who is infected.

A member of their staff has now left for a holiday, this is a nightmare. I'm loathed to have them pay the ransom, but restoring from the last backup will cost vastly more in work product and business impact than the cost of the ransom.

the NHS is suffering from a human denial of service attack from old people, drunks, immigrants that haven't had immunisation, congenital diseases, fgm, etc.
What proportion of costs do you think "immigrants that haven't had immunization" and "fgm" represents in the NHS versus "old people"? Here's a hint: a rounding error.
Yeah 'old' people because y'know you don't want to look after them do you?? Screw old people... and the sick.
According to Spain's CCN-CERT it's spreading through a remote code execution vulnerability in Windows' SMB Server, affecting pretty much all versions of Windows.

https://www.ccn-cert.cni.es/seguridad-al-dia/comunicados-ccn...

https://technet.microsoft.com/en-us/library/security/ms17-01...

IIUC the security updates have been available since March. I can understand bureaucratic entities having shitty security policies, but Telefónica? It's just... wow.

SMB vulns courtesy of the NSA? As to shitty - how long do you think it takes reasonably to test these patches on thousands of servers? What no test on a critical health system?
It's literally as easy as installing a Windows update organization-wide. What is there to test? These aren't servers. These are workstations of common workers. Windows desktops mostly used for spreadsheets and playing solitaire.

I'd rather deploy a Windows update within 2 months of its release and be safe from a RCE vuln.

You have to test the patch against your images! You cannot simply roll out whatever shit Redmond send you down the pipe especially when they had to rush it out themselves due a tip off. That would be gross negligence what if there was some device attached to that workstation keeping someone's machine on? How would you know what that workstation is doing?
And isn't 2 months enough for that?

Also... images? :^) I think you're giving too much credit to the sysadmins in these organizations (and I talk from experience, can't say more).

You should know, of course, because the system was designed and this documentation is easily available and up to date.
> what if there was some device attached to that workstation keeping someone's machine on?

Then it shouldn't be connected to a non-secure network / the internet in the first place.

> workstations of common workers. Windows desktops mostly used for spreadsheets and playing solitaire

As a physician and researcher, this attitude from IT people is why you find physicians who don't like you.

Funny you should say that regarding attitude, doctor. One networking guy who used to work in a big hospital told me he hated working at the hospital because of the attitude of doctors there. Doctors with attitude of 'I'm god' really turned him off from working in the hospital setting.
No one in this thread claimed to be God. It's worth remembering that the whole point of Hospital IT is to facilitate the doctors' and administrators' work.
I wasn't referring to physicians, the NHS wasn't patient zero.
> What is there to test? These aren't servers.

Such hubris.

When I worked night shift in emergency dispatch, our base network ops center pushed out an update that took our phone workstations offline. The phones that receive installation 911 calls and communiques from the command post. With no warning or notification of such an update.

Their reasoning? "We didn't think anyone would need it at 0300"

There are parts of the NHS who specifically do not patch.
And hopefully they have well-designed and regularly audited firewalling and access control paradigms. There are good reliability reasons behind not just sucking down every patch, but it needs to be coupled with smart security work.

And in any case that doesn't seem to be the issue here, per reporting. It's not NHS's reliability-critical systems that are owned, it's all their PCs.

I'd hope so, too, but in what i've seen it generally isn't the case.
Which they use to communicate between staff. I was at a renal clinic this afternoon and the staff there couldn't check to see if my doctor wanted them to do some bloods - so I can go back onto the transplant list.

If I am unlucky this means I could miss out on a potential doner kidney due to the delay

Don't forget to glue the USB ports; yes all of them. No, IT will need to setup a PXE server.
Software monoculture roosters are coming home...
Why the hell do they need thick Windows boxes to handle patient records, would a dumb terminal not do and be far more resistant to this kind of problem.
They don't need them, at all. Every business and organization that isn't using CAD or Photoshop or some other CPU / Memory intensive software could get by on thin clients alone. No problem.

Secondly, how the hell are these records being stored? These viruses usually search for pdf,jpeg,doc, and xls files. Is patient data in spreadsheets and word docs? I don't get it.

Windows + Web Browser is the "dumb terminal" of the 2010's.
I wonder how many of these systems have already been exploited (silently) in order to extract things like patient details? Scary.
For those wondering, while I'm writing this, these Bitcoin addresses store $7771.84 (according to XE).
(comment deleted)