Shutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out?
I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?
Edit: There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place.
>There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place.
Take a look at that operating system and the UI from the article and tell me how that's unexpected.
Yes. NHS has a national level support agreement for XP.
There are a lot of legacy systems and it's not just the bother of replacing the system, there are a lot of front line staff who only know how to use specific applications and are not generally computer literate so moving them to new systems will slow everything down for weeks or months as they learn a new application.
And medical devices cannot just be modified after they are approved for medical use. Any changes must be introduced by the original vendor (or an approved 3rd party vendor) and put through a barrage of tests and certifications needed to release such a device for use on a human. Those include EMC/EMI testing, QC testing, safety testing, RF testing, clinical trials, regulatory compliance, etc.
When you buy a medical device running Windows 3.1, it will run that until it is thrown away or replaced.
It's hopefully not connected to the internet, but to the local network.
Many medical appliances in hospitals expose remote control over regular tcp/ip, Preferably running Windows XP or CE.
I wasn't seriously suggesting it was directly connected, but my understanding (and I am far from knowledgeable when it comes to security) is that mission-critical devices should be physically 'firewalled' from the Internet, and even any network.
If you do that, how do the images get from the x-ray machine to the radiologist for analysis? How do they end up as part of the electronic health record & accessible for future use? If you create an air gap and ask people to use USB sticks to move data from "mission-critical" systems to the main network, you only slightly reduce the risk of those systems becoming infected and you now have a situation that's much less convenient (time is money) and creates a new vector for leaking personal health information.
Caught wind of this earlier today with a European client. We were advised to not connect to their network via VPN. Looks like it's a large scale attack that's affecting more than just hospitals in England.
Shutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out?
I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?
There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place. Perhaps underinvestment in IT is to blame.
Or, indeed, over-investment in trash-tier IT services provided by blood-sucking IT consulting companies.
I've seen the insides of some UK Government IT systems (not the NHS), and it's astonishing how little functional software one can get in exchange for a few hundred million sterling.
That, and the bitrot of holding on to ancient, never-updated IT systems.
[Edit], back on topic, I sincerely hope whoever did this is burned alive for their crimes.
The whole EHR market is absolute crap in Canada too. You have around 10 competing standards with no interoperability, multiple data sources cobbled together through webpage links, and all running on a slow as fuck central server that you Citrix into.
Another research department I worked at was seriously underfunded, which resulted in questionable decisions, such as using round cube for email, and a central shared drive with a Microsoft access database containing patient data. Hospitals have terrible security.
It's a terrible UI for webmail, and our webmail was subject to a hack a few weeks ago, and they've since closed off WAN access. I'm pretty sure it was related to roundcube. Which is a bummer.
To be fair - healthcare IT infrastructure sucks everywhere, even in the country most well-known for remarkably expensive privatised healthcare. It's not really obvious at this point how to fix it. Have the Government Digital Service or similar work on it directly and ditch the contractors?
> Have the Government Digital Service or similar work on it directly and ditch the contractors?
Basically, yes. Bring it all in-house, ban the contractors/consultants/mercenaries/etc. Remove the profit motive and suddenly you don't have millions of dollars/pounds being siphoned off by vampiric consultancies and third-party vendors. Suddenly you can spend tax-payers money in a sane and rational way.
Hire a bunch of talented people who care about the wellbeing of their nation state, pay them well enough and task them with building the best systems possible in the most efficient way possible.
Without giving too much away, I've been involved in just such an initiative, and it was _awesome_.
However, in the context of an established organisation it's really hard to pull off, and so we eventually ran into serious pushback from other factions within the org, particularly the established IT Ops folk.
Still, it can be done, and it can be a raging success. Especially gratifying when you spend two days writing up a system in Python which replaces some 90's garbage that's costing the organisation 200k per year in licenses.
This. A million times this. I think at this point the tech community should be vocal about this issue.
Tech has improved ten-fold this last decade, and IT consulting services simply don't care because they profit hugely from it. What makes this issue even harder to solve is the fact that IT is so simple to hide because society does not understand it enough.
Similar to the Tech Pledge, we should stand and be very vocal about the fact that you CAN build strong, secure and relatively cheap systems. If we don't do this, who else will ?
We're stuck between a part of the industry which benefit from this (and especially the big bosses, they don't care about the developers either) and a society which doesn't see the value of homegrown (as in company/government-grown) tech talent and the tenfolds decreases in IT spending it could entail.
Can I ask, how did the employees fit in with the payment structure? My feeling has been that the NHS simply can't hire talented staff on the wages they expect because the pay grades don't go up that high. Hence hiring contractors.
This is what should have happened instead of the disastrous NPfIT. It took years and none of the big players (Accenture, BT, Fujitsu, CSC) could even agree what a fucking medical record should look like because nobody was willing/able to concede anything.
If it had been an in-house project with actual experts employed in building/deploying on a smallish scale (say, a town or county) and then rolling out it could have been a thing of beauty.
I agree with your solutiom, but there is far, far less blood sucking going on than you might imagine and far, far more organizational incompetence. That is, organizations hire contractors and then dont know how to tell them what they want, but simultaneously refuse to let the contractor have initiative because they dont know how to set up a pay structure for it. Businesses screw themselves.
Yeah but the truth isn't as exciting as thinking you can write DJango app to save the NHS. It's far more fun to think you can knock something up with your friends in a few months.
Then requirements start coming in, the stakeholders, the politics. The multi faceted organizations, the disparate teams with never ending edge cases.
3 years later when it's past phase 2 and creaking at the seams, along comes the next upstart... DJango! Which idiot picked that?!!! Me n my friends could....
> Hire a bunch of talented people who care about the wellbeing of their nation state, pay them well enough
This is impossible. Any large organization eventually resorts to using pay scales to combat corruption. When the right people will be 10+x more effective than the wrong people, pay scales are impossible.
Literally the entire reason why large organizations resort to hiring contractors is because they know it's impossible for them to hire good people directly.
How does it suck? Everywhere I look hospitals have dumb pc's connnected securely to cloud services for applications, primarily Citrix or web based portals hosted by a trusted contractor or the hospital themselves.
There's an awful lot of network-connected, really badly written, often unsupported software in healthcare, that uses proprietary formats. VDI doesn't save you if what's on the other end has to be Windows XP to run your shitty software that'd cost your IT department's entire budget for a year to replace and retrain users.
Or, indeed, over-investment in trash-tier IT services
Yeah, I think this is probably closer to what's happening.
I've worked with some of these Enterprise-level IT consultancies in the past. I do understand that it's quite a different market from the lean, tech-focused web development market, but some of the solutions I've seen implemented are shockingly* bad.
I wonder if it would be appropriate to "dramatically overreact" and send in the SAS or similar to send a polite message that mucking with the NHS is really not a good idea.
Maybe post offer a decent reward - say £10 million for information leading to the identification of the culprits.
Labour won't attack on this because they know it might have happened to them just as easily, whereas it fits the Tory narrative that "the NHS is useless and should be privatised" with almost no spin.
Most of my local Tories know that any kind of direct assault on the NHS would result in instant annihilation at the next election.
There are more subtle methods of course including outrageously broken internal market management restructures (Stafford Hospital Trust, 'fund holding GPs' in the time of Thatcher) and the like.
I suspect that if this does happen it will more likely be the French retaliating against the hacking of the election the French version of SAS/DELTA don't fuck about.
Everything is a "bug" according to most journalists. We'll probably get something a bit more coherent from Ars Technica or The Register.
WRT the failings: I've worked in IT in the UK for more than 25 years, and I have never (until now) worked in a place that took security seriously. That includes schools, a large accountancy firm, several well-known public sector establishments, a political campaign, etc. "Optimistic security" is the model here, and hospitals have huge rambling networks with many legacy systems and third-party solutions. I would be surprised if they don't have security issues. Where they are secure, it's probably down to some unsung hero(es) somewhere, who took it on themselves to push security. (I've done this myself and it's a thankless task; nobody notices or cares. Dogs not barking, etc.)
> Your experiences with UK IT make for depressing reading.
I am astonished that even skilled techies don't take security seriously, using passwords like their car registration or company name - I've seen that with a military contractor, ffs. People who had signed the Official Secrets Act and had network links into supposedly secure sites. It depresses me too.
People have this insane notion that one line of defense is enough or they have the equally insane notion that no wants to take something they have.
People have a really hard time evaluating simple risk/reward models. You have to make the reward of attacking you higher than any possible reward to have a reasonable chance at security. If anyone anywhere on the Internet can profit by your loss, eventually someone will try.
EDIT - To make life even more difficult sometimes the attack provides gains indirectly. Imagine one group of politicians attacking a service supported by another political faction, just that service going down profits the first group if it changes who voters vote for.
From my perspective its a fundamental problem with incentives. Good security costs time and money, never gets return gains, and no one will put money up that wont ever see a ROI. So incredibly short sighted, depressing indeed.
Is there some kind of saying: You can't secure a network that contains legacy systems?
Start from scratch, don't connect anything legacy. Assume the LAN is already penetrated and design for that. Store no data locally, client machines run something like ChromeOS by default. Timeout anything that's not used for 6 months. Don't use passwords, only SmartCards. Snapshot data for ease of restore.
Don't you think that, perhaps, replacing a dependency on a centralized infrastructure by replacing the entire system by centralized infrastructure, owned by a foreign company, might not be the smartest idea ?
Systems that can't depend on the outside, obviously, cannot use cloud services. That means no chromeOS, no active directory, nothing but the local network. This is beyond obvious, and yet, I actually believe we'll be stupid enough to do exactly the centralization thing.
Paying $300 to these crooks, incidentally, will be a LOT cheaper than whatever microsoft or any other company will ask for the centralized infrastructure. Not that I suggest doing that, but still.
$300 per machine. Issue is that ransomware also encrypts all files on shared drives.
But a problem with the approach of centralization taken by something like ChromeOS which uses Google accounts (or I guess Win10S which uses ms accounts) is that you're attempting to prevent one player from holding you hostage by giving yourself hostage to another. This is not going to work to prevent paying through the nose, although yes, your new hostage takers will probably realize that the NHS will be able to pay more when it actually takes care of patients. Not too well, of course, good enough to make sure it isn't replaced or repealed. Badly enough so that constant complaints ensure a fresh budget injection every quarter.
They're already being held hostage by 1000s of companies who won't update their crappy software so it runs properly, allowing them to install OS updates rapidly.
As I said, like ChromeOS, it's perfectly possible to run your own servers, don't need to pay Google or Microsoft.
> Start from scratch, don't connect anything legacy
The myth of the clean sweep. Personally, I've found such systems tend to be late, wrong and inevitably end up resembling what they replace, warts-and-all. This is because systems tend to mirror the organisational and political context they are in, and most programmers today are not significantly better than those who came before them. Quote me all the exceptions you like, this is my experience.
I've heard from some people in Portugal that MEO is affected, as well as the Spanish Vodafone. A friend working for the Portuguese Vodafone is saying that, so far, they're unaffected.
300$ ransom doesn't seem like they're being targetted. The virus just spreads very, very well through corporate (i.e. Windows) intranets, including when connecting through a VPN, using a remote code execution vulnerability (see my other comment here https://news.ycombinator.com/item?id=14324592).
Considering it's already hit some tech giants, it was just a matter of time until it spread through their VPNs to their workers, clients and beyond.
Note: I've zero idea if that screenshot is legit but it's posted on The Health Care Journal website so it likely is.
Edit:
- Earliest Google result for "WanaDecryptor" is from Aug 2015 (All other search results are from today):
> almost all of the files on the D drive is encrypted. C is not touched by the disc. file found is in the ProgramData folder, there is a hidden folder, the virus in it. When you delete a folder that is created again and the process starts again.
At a security seminar last year I got to hear an expert talk about tracking down ransomware over the course of a couple of years. He said, no matter what the value of bitcoin the price gets adjusted to be equivalent to $300. That is the presumed sweet spot where people realize it's worth the money to save their data.
A 'coordinated' attack apparently unless it is a very agile worm, lots of disparate unconnected levels being hit - such as GP surgeries (local clinics) to large hospitals A&E (ER). The common factor being the widescale abuse of @nhs.net as the email provider for all. Local GPs not meant to be using it at all.
Not necessarily a coordinated attack, it could be a technique which is exploiting some weakness in security practices and they happen to have hit on these systems.
What is the reason local GPs are not meant to use NHS.net email? I work in the sector and I thought it was policy to have them use it as the approved platform to securely communicate with secondary care.
GPs absolutely do use nhs.net; that's how they communicate. It's supposed to be secure enough to send medical records. If you go for a blood test or something, that's how the results come back.
It's apparently using the leaked NSA SMB exploits, so once it hits their internal networks any systems which aren't patched are probably going to get exploited pretty much instantly.
> A nominated Local Organisation Administrator (LOA). For primary care organisations, specifically GP practices, pharmacies, optometrists and dentists this is provided by NHS England Area Teams. Where appropriate, Department Administrators may be nominated.
'Cyberattack' seems to be the latest buzzword that tech journalists like to use. I'll agree that all the information I've seen points at this being a regular trojan rather than some targeted hacking. Will be interesting to see how it started.
From my knowledge of NHS IT, it is reasonably hard at the perimeter but with a very soft chewy unprotected centre. I am not surprised this went round like Billy-O once inside.
Telefonica (the largest telecom operator in Spain) is having the same issue. There are a few thousands of workers that are not working; it's a disaster!
I don't mean to be dramatic here folks, but multiple coordinated infrastructure attacks are a form of warfare. This is literally shaping the battle space. Correlation is not causation and all that, but while people are standing around comparing their knowledge of how to deploy zero-day exploits and which isms it would be satisfying to blame during some future retrospective, the systems we depend on are being actively compromised.
The NHS is notorious for using outdated software, so I'm surprised it's taken so long. We build websites for third-sector organisations who often deal with the NHS and we're only just now persuading them to drop support for Windows XP / IE8.
Yeah, I left the NHS in 2009 after much frustration in trying to implement modern(ish) replacements for various reporting systems. Every idea was discussed and watered down until what's left was neither use nor ornament.
There are many great and extremely dedicated employees but the vendor lock-in has painted them into many (disparate) corners.
NHS IT is, of course, vastly under-funded compared to even modest startups, and entangled in bureaucracy of upgrades. I used to work with someone who was one of two sysadmins for a hospital of several thousand staff.
This is partly a consequence of the NHS Connecting for Health debacle, which on an original budget of £2.3 billion managed to hit a projected cost of £12.4bn with almost nothing to show for it apart from a patchy implementation of Choose and Book.
NHS systems are remarkably un-integrated.
Communication, especially between trusts and external organisations like GPs, is often by email.
I'll be surprised if this isn't an email worm.
Best value for money health service in the world absolutely no contest. Free healthcare for all no questions asked. Sounds like some johnny foreigner to me. Probably a Trump supporter chiming in with his alternative facts. Even he can get treatment here. I'm not so sure about a cure.
Sadly, I think there are more people that would be in favour of a private system than we'd like to admit. A lot of people have bought into the Tory idea that the NHS is unsustainable, and that the reason we're all poor is because we're paying for what they see as sub-par care.
On one side, the NHS is arguably the greatest success story of the UK, and I think many people would riot if their free healthcare was taken away. On the other, people will happily vote against a party that is looking to increase its funding, and will happily vote for a party that has made significant moves to privatise our healthcare system, so logically there must be people that aren't in favour of the NHS.
Sadly what most of those people don't realise is that the majority of their private healthcare will take place thanks to the NHS. Going private gets you into the nicer wards at many of the same hospitals, to be treated by the same doctors and nurses, and without any significant delays.
It's all well and good getting your hernia sorted out faster than on the NHS, or getting knee ligaments rebuilt without a 12 month wait for an operation but there's almost no concept of a "private" Accident & Emergency department.
Yep, you're essentially paying for the administration costs by going private, but that's not what the Bupa adverts sell you, and it's not what people seem to assume when you say you've got private healthcare. They think you're in some kind of special institution where you're pampered 24/7 by medical professionals, when in reality you're in the same NHS bed as the person next to you with some minor benefits. Additionally, as you've rightly pointed out, your private insurance will only cover non-existing illnesses. A&E isn't covered, nor is anything that might've existed before you picked up your insurance, and they'll be sure to check up on that. Take away the NHS, and the infrastructure becomes fully private, and that's when the costs will go through the roof.
For the life of me, I don't know why this isn't what Labour are driving home to people. They should be telling people "Vote Labour, or kiss the NHS goodbye".
If the ransomware has no vulns itself, this is going to be a hit to economy, either by paying the ransom (it's already hit some major companies) or the losses produced by it.
I've rarely worked at a place that didn't shadow copy your user directory to a network location. The only thing that SHOULD be lost is whatever hadn't been saved when they were ransomwared.
The company should be able to pull a backups from the last file change prior to that event.
Has anyone paid this specific ransom and had their files decrypted? I've got a client who is infected.
A member of their staff has now left for a holiday, this is a nightmare. I'm loathed to have them pay the ransom, but restoring from the last backup will cost vastly more in work product and business impact than the cost of the ransom.
This is apparently part of coordinated ransomware campaign targeting large corporations in Europe, only a few of which are making the news at this time. Some other links:
the NHS is suffering from a human denial of service attack from old people, drunks, immigrants that haven't had immunisation, congenital diseases, fgm, etc.
What proportion of costs do you think "immigrants that haven't had immunization" and "fgm" represents in the NHS versus "old people"? Here's a hint: a rounding error.
According to Spain's CCN-CERT it's spreading through a remote code execution vulnerability in Windows' SMB Server, affecting pretty much all versions of Windows.
IIUC the security updates have been available since March. I can understand bureaucratic entities having shitty security policies, but Telefónica? It's just... wow.
SMB vulns courtesy of the NSA? As to shitty - how long do you think it takes reasonably to test these patches on thousands of servers? What no test on a critical health system?
It's literally as easy as installing a Windows update organization-wide. What is there to test? These aren't servers. These are workstations of common workers. Windows desktops mostly used for spreadsheets and playing solitaire.
I'd rather deploy a Windows update within 2 months of its release and be safe from a RCE vuln.
You have to test the patch against your images! You cannot simply roll out whatever shit Redmond send you down the pipe especially when they had to rush it out themselves due a tip off. That would be gross negligence what if there was some device attached to that workstation keeping someone's machine on? How would you know what that workstation is doing?
Funny you should say that regarding attitude, doctor. One networking guy who used to work in a big hospital told me he hated working at the hospital because of the attitude of doctors there. Doctors with attitude of 'I'm god' really turned him off from working in the hospital setting.
No one in this thread claimed to be God. It's worth remembering that the whole point of Hospital IT is to facilitate the doctors' and administrators' work.
When I worked night shift in emergency dispatch, our base network ops center pushed out an update that took our phone workstations offline. The phones that receive installation 911 calls and communiques from the command post. With no warning or notification of such an update.
Their reasoning? "We didn't think anyone would need it at 0300"
And hopefully they have well-designed and regularly audited firewalling and access control paradigms. There are good reliability reasons behind not just sucking down every patch, but it needs to be coupled with smart security work.
And in any case that doesn't seem to be the issue here, per reporting. It's not NHS's reliability-critical systems that are owned, it's all their PCs.
Which they use to communicate between staff. I was at a renal clinic this afternoon and the staff there couldn't check to see if my doctor wanted them to do some bloods - so I can go back onto the transplant list.
If I am unlucky this means I could miss out on a potential doner kidney due to the delay
Why the hell do they need thick Windows boxes to handle patient records, would a dumb terminal not do and be far more resistant to this kind of problem.
They don't need them, at all. Every business and organization that isn't using CAD or Photoshop or some other CPU / Memory intensive software could get by on thin clients alone. No problem.
Secondly, how the hell are these records being stored? These viruses usually search for pdf,jpeg,doc, and xls files. Is patient data in spreadsheets and word docs? I don't get it.
387 comments
[ 3.3 ms ] story [ 191 ms ] threadI'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?
Edit: There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place.
Take a look at that operating system and the UI from the article and tell me how that's unexpected.
A non-health example: http://www.effectivebits.net/2011/08/to-run-windows-or-not-t...
When you buy a medical device running Windows 3.1, it will run that until it is thrown away or replaced.
Except for budget and non-technical leadership in technical leadership roles
These could be a coincidence though.
Here is a source article talking about a Spanish TelCo: https://www.usnews.com/news/technology/articles/2017-05-12/s...
---------
Shutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out?
I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking?
There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place. Perhaps underinvestment in IT is to blame.
Or, indeed, over-investment in trash-tier IT services provided by blood-sucking IT consulting companies.
I've seen the insides of some UK Government IT systems (not the NHS), and it's astonishing how little functional software one can get in exchange for a few hundred million sterling.
That, and the bitrot of holding on to ancient, never-updated IT systems.
[Edit], back on topic, I sincerely hope whoever did this is burned alive for their crimes.
Another research department I worked at was seriously underfunded, which resulted in questionable decisions, such as using round cube for email, and a central shared drive with a Microsoft access database containing patient data. Hospitals have terrible security.
Basically, yes. Bring it all in-house, ban the contractors/consultants/mercenaries/etc. Remove the profit motive and suddenly you don't have millions of dollars/pounds being siphoned off by vampiric consultancies and third-party vendors. Suddenly you can spend tax-payers money in a sane and rational way.
Hire a bunch of talented people who care about the wellbeing of their nation state, pay them well enough and task them with building the best systems possible in the most efficient way possible.
However, in the context of an established organisation it's really hard to pull off, and so we eventually ran into serious pushback from other factions within the org, particularly the established IT Ops folk.
Still, it can be done, and it can be a raging success. Especially gratifying when you spend two days writing up a system in Python which replaces some 90's garbage that's costing the organisation 200k per year in licenses.
Killing Leeches is fun.
100 user system, Windows CALs and RDS licenses per user = a lot of money. Found only 40 users needed the CALs, rest were fine on Linux.
Took the devil of a job to persuade them this, as the Microsoft rep told them they couldn't.
Open sources equivalents are nowhere near as good.
> eventually ran into serious pushback from other factions within the org, particularly the established IT Ops folk
"Mordac, preventer of information services"
Thankyou very much for fixing this kind of thing, seriously.
Tech has improved ten-fold this last decade, and IT consulting services simply don't care because they profit hugely from it. What makes this issue even harder to solve is the fact that IT is so simple to hide because society does not understand it enough.
Similar to the Tech Pledge, we should stand and be very vocal about the fact that you CAN build strong, secure and relatively cheap systems. If we don't do this, who else will ?
We're stuck between a part of the industry which benefit from this (and especially the big bosses, they don't care about the developers either) and a society which doesn't see the value of homegrown (as in company/government-grown) tech talent and the tenfolds decreases in IT spending it could entail.
Please, Sam Altman ? Someone ? Please ?
edit: I should say some as to be fair, I'm not 100% sure of the extend of this.
[1] http://www.nhs.uk/
If it had been an in-house project with actual experts employed in building/deploying on a smallish scale (say, a town or county) and then rolling out it could have been a thing of beauty.
It should have been what AlphaGov became.
Then requirements start coming in, the stakeholders, the politics. The multi faceted organizations, the disparate teams with never ending edge cases.
3 years later when it's past phase 2 and creaking at the seams, along comes the next upstart... DJango! Which idiot picked that?!!! Me n my friends could....
This is impossible. Any large organization eventually resorts to using pay scales to combat corruption. When the right people will be 10+x more effective than the wrong people, pay scales are impossible.
Literally the entire reason why large organizations resort to hiring contractors is because they know it's impossible for them to hire good people directly.
Yeah, I think this is probably closer to what's happening.
I've worked with some of these Enterprise-level IT consultancies in the past. I do understand that it's quite a different market from the lean, tech-focused web development market, but some of the solutions I've seen implemented are shockingly* bad.
Maybe post offer a decent reward - say £10 million for information leading to the identification of the culprits.
This said, they're probably popping champagne at Tory HQ right about now.
There are more subtle methods of course including outrageously broken internal market management restructures (Stafford Hospital Trust, 'fund holding GPs' in the time of Thatcher) and the like.
And because departments are left to their own devices, they solve all their problems with shared drives and excel sheets.
Ransomware is the hero we didn't ask for.
WRT the failings: I've worked in IT in the UK for more than 25 years, and I have never (until now) worked in a place that took security seriously. That includes schools, a large accountancy firm, several well-known public sector establishments, a political campaign, etc. "Optimistic security" is the model here, and hospitals have huge rambling networks with many legacy systems and third-party solutions. I would be surprised if they don't have security issues. Where they are secure, it's probably down to some unsung hero(es) somewhere, who took it on themselves to push security. (I've done this myself and it's a thankless task; nobody notices or cares. Dogs not barking, etc.)
That's a good point, tech journalism is usually pretty poor.
https://twitter.com/ShaunLintern/status/863039464649744384 suggests it's significantly more boring than a zero-day (though still incredibly problematic).
Your experiences with UK IT make for depressing reading.
I am astonished that even skilled techies don't take security seriously, using passwords like their car registration or company name - I've seen that with a military contractor, ffs. People who had signed the Official Secrets Act and had network links into supposedly secure sites. It depresses me too.
People have a really hard time evaluating simple risk/reward models. You have to make the reward of attacking you higher than any possible reward to have a reasonable chance at security. If anyone anywhere on the Internet can profit by your loss, eventually someone will try.
EDIT - To make life even more difficult sometimes the attack provides gains indirectly. Imagine one group of politicians attacking a service supported by another political faction, just that service going down profits the first group if it changes who voters vote for.
Start from scratch, don't connect anything legacy. Assume the LAN is already penetrated and design for that. Store no data locally, client machines run something like ChromeOS by default. Timeout anything that's not used for 6 months. Don't use passwords, only SmartCards. Snapshot data for ease of restore.
Systems that can't depend on the outside, obviously, cannot use cloud services. That means no chromeOS, no active directory, nothing but the local network. This is beyond obvious, and yet, I actually believe we'll be stupid enough to do exactly the centralization thing.
Paying $300 to these crooks, incidentally, will be a LOT cheaper than whatever microsoft or any other company will ask for the centralized infrastructure. Not that I suggest doing that, but still.
All systems depend on the outside to some extent anyway.
Is it $300, or $300 per machine? Why can't the machines just be reimaged, what kind of giant corporation doesn't have that working automatically?
But a problem with the approach of centralization taken by something like ChromeOS which uses Google accounts (or I guess Win10S which uses ms accounts) is that you're attempting to prevent one player from holding you hostage by giving yourself hostage to another. This is not going to work to prevent paying through the nose, although yes, your new hostage takers will probably realize that the NHS will be able to pay more when it actually takes care of patients. Not too well, of course, good enough to make sure it isn't replaced or repealed. Badly enough so that constant complaints ensure a fresh budget injection every quarter.
As I said, like ChromeOS, it's perfectly possible to run your own servers, don't need to pay Google or Microsoft.
https://www.chromium.org/developers/how-tos/enterprise/runni...
The myth of the clean sweep. Personally, I've found such systems tend to be late, wrong and inevitably end up resembling what they replace, warts-and-all. This is because systems tend to mirror the organisational and political context they are in, and most programmers today are not significantly better than those who came before them. Quote me all the exceptions you like, this is my experience.
https://en.wikipedia.org/wiki/Conway's_law
https://arstechnica.com/information-technology/2017/05/nhs-r...
Seems serious.
This seems to be quite serious.
Considering it's already hit some tech giants, it was just a matter of time until it spread through their VPNs to their workers, clients and beyond.
This is gonna be fun to watch from the sidelines.
Note: I've zero idea if that screenshot is legit but it's posted on The Health Care Journal website so it likely is.
Edit:
- Earliest Google result for "WanaDecryptor" is from Aug 2015 (All other search results are from today):
> almost all of the files on the D drive is encrypted. C is not touched by the disc. file found is in the ProgramData folder, there is a hidden folder, the virus in it. When you delete a folder that is created again and the process starts again.
http://www.cyberforum.ru/viruses/thread1979411.html
http://www.cyberforum.ru/viruses/thread1979358.html
- Discussion from today mentioning it infecting Spanish Telecoms: http://gta-trinity.ru/forum/index.php?/topic/57671-novejshij....
All of NHS PCs and hospital systems have gone down from a ransomware trojan!
I have a full clinic this afternoon, and no way to look at my patients' histories, or meds. It's a damned disgrace.
The Trojan is demanding some bitcoins be paid, else they'll lose the boxen.
The entire NHS is penetrated.
I can't vouch for "the entire NHS is penetrated"
https://s3-eu-west-1.amazonaws.com/comms-mat/Comms-Archive/J...
> A nominated Local Organisation Administrator (LOA). For primary care organisations, specifically GP practices, pharmacies, optometrists and dentists this is provided by NHS England Area Teams. Where appropriate, Department Administrators may be nominated.
Maybe targeted emails with attachments?
https://www.publico.pt/2017/05/12/tecnologia/noticia/ataque-...
There are many great and extremely dedicated employees but the vendor lock-in has painted them into many (disparate) corners.
https://en.wikipedia.org/wiki/NHS_Connecting_for_Health#Cost...
http://www.bbc.co.uk/news/technology-37979456
https://www.gov.uk/government/publications/guidance-on-overs...
On one side, the NHS is arguably the greatest success story of the UK, and I think many people would riot if their free healthcare was taken away. On the other, people will happily vote against a party that is looking to increase its funding, and will happily vote for a party that has made significant moves to privatise our healthcare system, so logically there must be people that aren't in favour of the NHS.
It's all well and good getting your hernia sorted out faster than on the NHS, or getting knee ligaments rebuilt without a 12 month wait for an operation but there's almost no concept of a "private" Accident & Emergency department.
For the life of me, I don't know why this isn't what Labour are driving home to people. They should be telling people "Vote Labour, or kiss the NHS goodbye".
If the ransomware has no vulns itself, this is going to be a hit to economy, either by paying the ransom (it's already hit some major companies) or the losses produced by it.
I can't even fathom how many spreadsheets with no backup have been lost today.
WRT backups... :^)
The company should be able to pull a backups from the last file change prior to that event.
A member of their staff has now left for a holiday, this is a nightmare. I'm loathed to have them pay the ransom, but restoring from the last backup will cost vastly more in work product and business impact than the cost of the ransom.
http://sicnoticias.sapo.pt/pais/2017-05-12-PT-Vodafone-EDP-e... (Portuguese)
The worrying part is distribution and essencial companies and services
https://www.ft.com/content/74c666ec-8dc7-3b20-b573-245bc0e9d...
http://www.impala.pt/noticias/pt-alvo-ataque-informatico/ [PT]
https://news.ycombinator.com/newsguidelines.html
https://www.ccn-cert.cni.es/seguridad-al-dia/comunicados-ccn...
https://technet.microsoft.com/en-us/library/security/ms17-01...
IIUC the security updates have been available since March. I can understand bureaucratic entities having shitty security policies, but Telefónica? It's just... wow.
I'd rather deploy a Windows update within 2 months of its release and be safe from a RCE vuln.
Also... images? :^) I think you're giving too much credit to the sysadmins in these organizations (and I talk from experience, can't say more).
Then it shouldn't be connected to a non-secure network / the internet in the first place.
As a physician and researcher, this attitude from IT people is why you find physicians who don't like you.
Such hubris.
When I worked night shift in emergency dispatch, our base network ops center pushed out an update that took our phone workstations offline. The phones that receive installation 911 calls and communiques from the command post. With no warning or notification of such an update.
Their reasoning? "We didn't think anyone would need it at 0300"
And in any case that doesn't seem to be the issue here, per reporting. It's not NHS's reliability-critical systems that are owned, it's all their PCs.
If I am unlucky this means I could miss out on a potential doner kidney due to the delay
Secondly, how the hell are these records being stored? These viruses usually search for pdf,jpeg,doc, and xls files. Is patient data in spreadsheets and word docs? I don't get it.
https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX...
https://blockchain.info/address/1QAc9S5EmycqjzzWDc1yiWzr9jJL...
https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N...
1: https://twitter.com/BBCBreaking/status/863046075002884097
2: https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N...