After 20 years in IT, listening to all the bullshit by "Management" about "Audits" and "accepting the risk", "lessons learned" and whatnot.
Honestly, I would be glad if a high impact issue like this, would change any of that for the better. I am unfortunately also a cynic (after 20 years in, well anywhere really) so I doubt it will. This means it will only negatively impact people who need the healthcare, and a bunch of consultants will make millions on sweeping up the mess, and creating the next failure-to-be.
Fault will be leveled against Bitcoin for facilitating the ransom, against Microsoft, against NHS budget underfunding... everywhere EXCEPT where the blame belongs. Products liability law applied to IT security would put a quick end to most vulnerabilities.
Seems strange to not mention the ransomers as having culpability.
I'm 100% in favor of better systems/processes/technology to prevent exploits, but I'm also 100% in favor of blaming the perpetrators of the ransom also.
In the real world we don't accept the argument that the victim is primarily at fault.
* leaving your car unlocked doesn't mean that is OK for someone to steal it and demand a ransom for its return
* leaving your house/apartment unlocked doesn't mean that it is OK for someone to swap out the locks and demand ransom for the new keys
And it really isn't about being locked/unlocked. Doors and locks can generally be easily broken or bypassed, doesn't mean that everyone should have to purchase industrial strength doors and locking systems (and windows, and...).
You're confusing ethics with legal liability. Nobody is saying IT is ethically responsible, they're saying they are legally responsible since the entire reason they get a paycheck is to prevent these sorts of things. Reduce it to a contractual matter if that assuages your conscience.
If you hire a bodyguard and still get shot while the bodyguard is on his phone both the perpetrator goes to jail and the bodyguard gets fired/pays restitution. Not that unheard of. It's not like one person gets all of the legal and ethical blame and everyone else is entirely absolved.
I'm not confusing things. I'm saying that public discussion seems to migrate towards prevention/mitigation and de-emphasizes the criminality. I'm arguing that we not forget that and pointing out that it was missing from the post I responded to.
In your bodyguard example I don't think in that type of a situation that people fixate on the quality of the security detail. They rightly demand that the shooter be tracked down.
People talk about it that way because locking your doors is more pragmatic than eliminating every criminal in the world for all time? Because the purpose of conversation about preventable injuries should be constructive, rather than idle? Because whether someone should do bad things should be a discussion between people who do bad things, but people who are victims should be discussing how not to be victims? Because when someone trusts you to protect something, there's 1) an assumption that that thing could be damaged, or else no reason to have hired you to protect it, and 2) a moral responsibility as the person entrusted with guarding it to do a good job, or else your taking money is wasteful and your promise made in order to get it is fraud?
Any number of reasons all boiling down to the same reason: what does calling bad people bad accomplish? Best for people who want to be good to talk about how to be good.
We have the same likelihood of bringing the criminals to justice as someone who left a laptop on a bench at an international airport for several days and then went back to look for it.
We can blame the criminals, but we will always have criminals when the crime is easy.
Those who are really responsible here are the ones who allowed themselves to become dependent on an ancient and insecure operating system.
To me, the buck should stop with the head of the hospitals.
What's the point of discussing criminality? The criminal justice system is centralized and functions independent of public interest in getting results from it. (And, in fact, functions better when the public is mostly unaware of crime, re: jury selection.)
The civic justice system, on the other hand, is completely driven by public interest—nothing gets done to change things unless somebody (or some class) bothers to sue.
Exactly, and if you had someone's important confidential information sitting on the seat (or even on an un-encrypted laptop), you would be liable for that loss.
Of course the ransomware authors/controllers should be (and are) culpable.
But when financially lucrative attacks can be carried out with very little risk of being caught, and the results are so bad, organizations who don't take security very seriously are at fault for not recognizing the threat landscape, and government is at fault for not recognizing that the market isn't solving this problem, stepping in and requiring higher quality assurance or liability for software.
> In the real world we don't accept the argument that the victim is primarily at fault.
If you're worried about X, and Y promises to prevent X for a cost, you seek recourse against Y.
X: I can't miss this flight. Y: Pay this surcharge to reserve a seat. Overbooking ensues. I'm blaming Y and not the other passengers.
X: Really don't want this disease to kill me. Y: Take these pills to not die. Death ensues. I'm (well somebody else is) blaming Y and not the disease.
In life we can't always control the cause so we aim to minimize the effect. Thus, while the ransomers are culpable for the blast, IT security are accountable for the size of the blast radius.
They're not the same but when you can't control the cause what's the difference?
Due to the nature of the web, unless you unplug from the Internet, the risk is persistent. So although a cybercrime-free world would be swell, until that day arrives we must control the effects.
I'm not convinced this isn't the answer. What are we gaining by putting hospital networks on the Internet? Are those gains worth the cost in increased vulnerability?
How we talk about these situations and the expectations we have are very important. If we collectively signal that extortion is OK and just something everyone needs to get used to then you are de-stigmatizing criminal behavior. I don't think that is a good idea.
I agree, extortion is not OK. Simply saying that this could have been mitigated and if there's someone's job to mitigate things like this, it's on them.
In both those situations whilst it isn't the victims fault, it will invalidate their insurance and any loss is theirs to sort out. So when buying IT services you need to include in the contract the security of it too, a Ransomware attack such as this (and not just because one user infects one machine) would be the fault of the IT provider
Very few people would argue that it's "OK" to commit crimes that you are capable of getting away with. It's the victim's "fault" as it is the fault of a person who doesn't wear a seatbelt and dies a preventable death in a car accident that they died i.e. not a moral failure, just a failure.
Of course they're culpable, but crime is an environmental problem you have to deal with, just like bad weather. No amount of shaking your fist at the clouds is going to mitigate the problem of a leaky roof.
I'm am explicitly rejecting that analogy. Human behavior is not like weather at all. The expectations that we set for our community/society is important.
Bad weather is indifferent to the shaking fists. It won't get worse or more frequent if people fail to shake their fist. But human behavior is very much responsive to feedback from other humans. I'm arguing that we should all be shaking our fists when we see extortionists at work as well as tracking them down and punishing them. And we should also take care to protect ourselves from them. It isn't a binary choice.
The first words I wrote were 'of course they're culpable.' Human behavior is very much like the weather in that our actions today shape the environment of tomorrow, albeit by long and often obscure causal chains.
Nowhere id I assert that it's a binary choice, and that interpretation of ym words only make sense if you ignore chunks of what I'm saying. Over the near term, you're not going to eliminate crime by moral suasion so it's important to have a strategy to mitigate its predictable incidence while we also work on the problem of how to reduce crime through deterrence, reducing incentives, and so on.
Crime is a public health issue. It shares common causes with ill health, particularly poverty, and fear of violent crime is itself a major cause of anxiety. Community development in pre-school education, parental education, and among ethnic minorities, both reduces crime and promotes better health, for example in reducing the effects of alcohol and illicit drugs. Health workers should contribute in full to community development.
I note that I'm standing with my earlier characterisation of a public health domain rather than weather, but both carry very strong similarities, including a risk / forecast / mitigations approach.
I'd eschew the gun metaphor because rifht to bear arms, etc.
But if you find a cooler with a vial of Ebola on the street, take it home instead of turning it in, then have it stolen and have that strain implicated in an outbreak?
Yeah... that's definitely at least partly on your hands.
I never thought about it like that before. Interesting.
The 'arms' in 'right to bear arms' is not clearly defined, and the founders would not have had any concept of software or weaponised software, but I can't think of an argument against people owning malicious software if the argument for owning firearms is also in play.
It's more like finding out you can shoot someone's door knob off with your gun, creating a documented process to make that easier, and hiding it from the public despite your pledge to disclose door knob vulnerabilities.
It shouldn't be a surprise when someone else starts shooting off doorknobs.
How do product liability laws cover vulnerabilities no one knew exist. Let's say it isn't a case of lack of forethought or ignoring bug and vulnerability reports, how do these laws treat it then?
>Products liability law applied to IT security would put a quick end to most vulnerabilities
No, it would make IT security about as expensive as good lawyers. Just to cover the losses. A method to reliably produce vulnerability-free software is not invented yet.
> A method to reliably produce vulnerability-free software is not invented yet
That's not the goal. Well it is, but it's unachievable. We need to get people to care about security beyond ensuring that teenagers can't trivially get in—the current state of affairs for enterprise IT.
A law would at least require companies to give a fuck beyond the "can the CEO's niece break in" level.
On the lower end of the spectrum, sound type systems prevent a class of vulnerabilities including buffer overflows. On the upper end, https://sel4.systems/, a formally verified microkernel, is used in security-critical systems.
Software development seems to be one of the rare branches of engineering where people and businesses are ready to accept such low quality standards, both in terms of functionality and security.
We wouldn't accept from a civil engineer that "the bridge might collapse" but that it's "no big deal, takes a moment to rebuild".
It was one thing when software was controlling some random machinery in a basement or fueling our BBSes, but nowadays large-scale software failure can end a lot of lives, nothing less. And yet, society is largely oblivious to how fragile it all is...
Tbf, a lot of civil engineering is pretty basic physics with huge safety margins applied, and if the requisite test was "will it withstand a targeted attack at the most vulnerable point?" most structures would never have got off the ground.
I think most of society has experienced enough software crashes and had enough anti-virus warnings to realise computers are a wee bit unstable and insecure (as well as being well aware they can't judge secure software from insecure software). If anything, it's HN that's the outlier for faith in internet-connected software to do stuff like drive our cars safely.
Civil projects are certainly over engineered because the life safety risks are clearly understood by all parties making the decisions. Unfortunately the "most of society" argument is clearly not true yet. Otherwise they would be springing the cash for proper IT and software security.
When talking about bridges, roads, buildings, tunnels, power grids and sewage pipelines - just to name a few - there is one additional factor that we should always consider.
Once made available, all of these will see constant use and they become part of the fabric of society. Taking parts of core infrastructure out to fix then has severe repercussions. Total cost of invasive maintenance will be a lot higher than the fairly simply calculated cost of on-site fixes.
I will gladly accept overengineering and nearly ludicrous safety margins.
As someone who worked in Civil Engineering (EIT) who writes software now I'll agree.
When an engineer gets a license from the state they stamp the drawings. If anything goes wrong, they go write back to the engineer who stamped it. When I was in civil engineering we were asked to redo another firms calculations when things didn't go well (mostly slope stability).
Though for software, I did work on mission critical systems (radar), and they did have a pretty good review/testing regimen. They tested a lot.
For smaller shops, there is pressure to get it done fast and ship yesterday, quality isn't the first consideration. I think liability for attacks from your boxes that have been hacked is low, so even then people aren't as vigilant. See IOT devices..
A bridge is a largely static unmoving object, but even bridges require maintenance - some bridges require more maintenance frequent maintenance than others. It's not that bridges are necessarily of low quality.
If a the bridge maintainer instructed you that a column needed replacing it would be replaced.
Everything constructed in reality requires maintenance in one way or another. Your house, your car, your bridge and yourself for example. To suggest that software should be different is an interesting point of view.
> A bridge is a largely static unmoving object, but even bridges require maintenance - some bridges require more maintenance frequent maintenance than others. It's not that bridges are necessarily of low quality.
That's a laymans impression of what a bridge is. In reality bridges are in an extremely dynamic environment with loads changing magnitude and direction constantly, unpredictably. The fact that you think that a bridge is 'a largely static unmoving object' is a tribute to the engineers that designed it and the contractors that built it, it's whole function can be described as 'appear not to move'.
But if you looked at the bridge in a little bit more detail and you would see how the bridge copes with the load your estimate would change to 'a bridge is an extremely versatile structure that dynamically responds to a wide variety of loads by rejecting those loads onto the foundation and soil around it'.
Ok yes well. Mostly they can still be describe as largely static relatively, because thats the whole point of building them. Something stable to move across
Isn't one of the premises of modern engineering that you work within a regulatory framework to ensure safety for the public?
It seems to me that most software development is not engineering in this sense and I assume that we will get to that stage at some point, but right now things like public institutions being hacked, because their software security was not up to par, will happen.
I've also become a cynic. I welcome national services to lose control of their systems and their data. I have had countless talks with people here in Germany about why computers and therefore open and libre software and hardware are a matter of national interest. Obvious disaster, at least and last, will hopefully make them get what I mean.
Having said that, I feel bad, but I just don't see any other way.
You're frustrated, but what are you doing to provide a better alternative? If national services lose control of their systems, what then? What is it that you expect to happen? The same people in charge, but making better decisions? A revolution that will magically fix everything?
I understand that you've been trying to persuade people of the merits of openness, but as you have experienced it's very difficult for an individual to persuade people of things without being a politician or offering some commercial bargains. Managers keep making bad decisions because they can always find someone who will write the code instead, but for some reason developers are unwilling to act in concerted opposition to this and so find themselves endlessly ignored and overruled.
> Managers keep making bad decisions because they can always find someone who will write the code instead, but for some reason developers are unwilling to act in concerted opposition to this and so find themselves endlessly ignored and overruled.
A labor union that protects you when you refuse to implement things that should not be implemented?
IMHO it is a difficult thing to manage and integrate into the tech culture.
It suits the management class very well to minimize the formation of organizational structures among technologists.
While I'm not a big fan of unions or guilds - insofar as they rely on internal hierarchies that just reproduce existing and faulty control structures - those who resist or deny the possibility of organization among technologists are not necessarily disinterested in the outcome.
I agree as to that it sounds moronic. Maybe it even is.
However, think about a levee about which you know that it will not hold when a storm comes, but people don't believe you and are not even willing to listen to you. Would you think it's moronic to welcome a storm as a shot across the bows so people realized what you are talking about?
The constructive solution to this problem is to find a way to convey the message such that people are willing to listen. But that can be very difficult.
In a similar vein Karl Marx is said to have been pro free trade, as it would lead to what he believed would happen to capitalism much faster. Also the colloquial expression "kick in the teeth". Often actual change requires drastic consequences.
I don't feel you're moronic and I absolutely get your sense of frustration, but welcoming a storm is implicitly saying that you think the suffering of some others is an acceptable price to pay for opening the eyes of the higher-ups. I'd like to suggest that the reason people in management don't listen to people in IT is because the people in IT aren't willing to make them, despite having direct and often primary access to the organizational levers of power.
Have you ever considered the possibility that management deliberately selects for this kind of passivity and conflict aversion when staffing IT departments, hiring exactly the sort of people who might roll their eyes or grumble at things but will reliably do what they're told?
You do realise that very nearly every engineering standard ever established, or regulation imposed, is written in the blood and memorialises the souls of those who died because it wasn't in place.
Turn on your gas stove for a moment, but don't light it.
That smell you detect is a memorial to the 295 students and teachers of the New London School:
Early in 1937, the school board canceled their natural gas contract and had plumbers install a tap into Parade Gasoline Company's residue gas line to save money. This practice—while not explicitly authorized by local oil companies—was widespread in the area. The natural gas extracted with the oil was considered a waste product and was flared off. As there was no value to the natural gas, the oil companies turned a blind eye. This "raw" or "wet" gas varied in quality from day to day, even from hour to hour.
I disagree. Every day we become more and more dependent on computers, and more specifically, networked computers. The IoT is exploding with horrific security implications. Everyone is focused on the next big thing, and no one is paying attention to the house of cards we are building.
So for something like this to happen now is much better than it happening later, because people need events like this to wake up and motivate action.
It's so easy to throw up a veil of security while doing absolutely nothing at all.
Just today I was helping somebody retrieve an export of older transactions from PayPal, and they were forced to go through a series of steps to sign up for "secure" access to a special account in order to download a "secure" zip file that PayPal had uploaded containing the transactions.
Which doesn't just mean that file had a crap password; I'd be willing to bet it means a whole bucket or type of files has the same password. So at least there's that.
Have you considered going on strike along with the other IT people? I can well imagine how draining 20 years of management BS is (I grew up with one), but one of the reasons I decided to get out of corporate IT after a decade in it was the realization that the IT were frequently used as a buffer between management and the rest of the workforce.
I certainly don't blame you for making popcorn, but surely part of why poor operating practices and decisions get entrenched if that the people doing the work passively go along with whatever bad idea management is proposing while hoping that either inevitable failure or some higher level of management will intervene to vindicate the initial objections of the technical people and topple a few of the more inept managers from their perches. Because IT people tend not to be organized into a union or professional association, they have little to no political leverage of their own so any personal sense of organizational mission or ethical scruples don't count for much in the event of a conflict with the management people, who may sweep aside objections on the basis that the IT person 'doesn't understand the big picture' or somesuch.
I don't mean to suggest that you should be reiterating old faulty models of social organization like unions or guilds; if anything the lesson of technology is that we should be restructuring our pyramidal structures of control and authority (whether corporate, political or whatever) into more effective network paradigms. But I do think that if you just munch on popcorn and hope to see some bad managers ousted and some technical people finally lifted up to positions of seniority within the existing decision structure, then it will just be more of the same until the system is forced into a state of collapse.
Why leave everything to he management and consulting types 'sweeping up the mess, and creating the next failure-to-be' as you eloquently put it, when you have one of those rare opportunities to force change?
Just as in the performance review process, Management (aka "the winners", be default and decree) write the story.
I remember spending more time pushing against the inertia and self-interest, than actually solving the problems. Solutions that, in a fairly straightforward and rather conservative fashion, stopped problems like these.
We are already seeing the uptake of the "rubber hose" in IT/IS oversight. Up to the Federal level, in the U.S.
It's not going to be a matter of who is responsible and who is technically capable. It's going to be the rubber hose and the lead pipe.
The alternative is massive investment in security, which would raise costs to insurers/patients, and introducing procedures that would slow down the speed of medical practice, which is already too slow. One example i've seen is the "medical system", a conglomerate of healthcare providers under one brand.
At a high level, the priority is simply to swallow up as many healthcare solutions as you can, to reduce cost and increase profit, and make healthcare process more seamless for the patients.
At a medium level, this means you have 50 different organizations connected to your network, and you may or may not have centralized control over any of them. You don't have the cash, time or resources to go in and overhaul all the networks. So you tell them all to connect through your central office and throw every single transparent filter or proxy at them to try to catch all the crap flying out the door (and there is a lot of it).
At a local level, doctors are already stymied by the complex process of providing care to patients. I've worked with them to try to find tailored solutions to speed up simple things like returning lab results. It's surprisingly difficult to improve on. Add new security procedures and their time shrinks even more, adding on top of all their existing procedure.
Healthcare is just always going to suck at security. The alternative is more costly and slower healthcare.
People will have to die before that happens without a regulation push. Possibly in a horrific way but done remotely. A few entered my mind. The risk is there. Thing is, it took things like THERAC poisoning in the past to establish importance of software safety. Security will probably be similar as it has been damage first, correct behavior second in other sectors.
Honestly, I would be glad if a high impact issue like this, would change any of that for the better. I am unfortunately also a cynic (after 20 years in, well anywhere really) so I doubt it will. This means it will only negatively impact people who need the healthcare, and a bunch of consultants will make millions on sweeping up the mess, and creating the next failure-to-be.
I'm making popcorn.