Comments on: Conficker infected critical hospital equipment, expert says
Hundreds of PCs and medical devices at hospitals in the U.S. were found to be infected with the Conficker worm recently, a security expert says.
Hundreds of PCs and medical devices at hospitals in the U.S. were found to be infected with the Conficker worm recently, a security expert says.
Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.
Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.
Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.
Add this feed to your online news reader
it's partly Microsoft's fault afterall
who cares about patches etc.
when your paying for something you expect it to work and yo don't get that with Microsoft I'm afraid !
So is it okay if I get pissed off at Apple when they release security updates and patches for their offerings? I mean, I paid for this mac and I expect it to just work. Why should I have to patch it ever? They must use lousy developers.
Most equipment of this type (I happen to know more than a few biomedical engineers) can't simply be patched due to a lot of factors:
* custom app software that needs to be rigorously tested more than most
* the constant use of the equipment makes downtime far harder to schedule and put to use
* the vendor of the equipment may not allow in-house patching (often enforced by contract) due to the desire/need to have the vendor do the servicing (and charge obscene amounts of cash for doing so).
* The version of Windows used is often the embedded version with a ton of custom drivers, which complicates things a bit more than your typical Dell. ;)
Hope that helps a little, kids.
The problem with your argument is that the computers infected were "too old" to be patched. Meaning it doesn't matter if the patch is out or not.
Oh, wait, that lazy equivalency doesn't work when you apply it to the real world.
I am willing to bet 5 million bucks and my balls that this happened like that.
I don't see anything about a USB stick in there, do you?
Well, there you go. There's the problem.
"The computers are older machines running Windows NT and Windows 2000 in a local area network that was not supposed to have access to the Internet, however, the network was connected to one that has direct Internet access and so they were infected, he said."
I'll send you an address for the check and your heuvos.
The security community gets sleepier the more of these reports come out that anyone could make up and nobody is believing.
Hard, facts and evidence or ****.
Besides, the definition of critical, in this era of new software to replace paper, has morphed into a "gray area". We commonly get calls from floors unable to get meds for their patients, and a first response I always give is "don't let the computer prevent you from performing your job!".
Apparently, that is not part of the training...
Anyway, how damn complicated is it..... I worked in a hospital (Johns Hopkins) that was one of the first to go to computerized prescriptions, and it was 'punch in amount of pills, punch in dosage of pills, get doctor to sign off.... DONE!"
Then the pills were delivered in foil covered small trays with the patients name printed on the bottom of the tray, with the bottom facing up!
And people wonder why medical services are so expensive.
Oh wait, its not just hospitals, but all of IT.
The bean counters save a couple of bucks a year, but at what cost? How much did TJX has to shell out? How much do you think a medical malpractice suit will cost when a piece of equipment fails and someone dies? Oh there's more, but then again, looking at our government, their top CIO was a political hack who couldn't run a city's IT dept....
The alarming subsystem failed in a unix-based scada system used by the utility company in Akron, OH (FirstEnergy). The problem persisted for over an hour. During this time, FirstEnergy?s system operators where unaware of the condition of their electric system and allowed transmission lines to overheat and sag into trees (due in part to FirstEnergy?s poor tree trimming practices). The instability of the electric system in Ohio caused overloads in adjacent services areas, which caused automatic protection systems on undamaged equipment to isolate itself from the grid. The cascading events moved north into Canada, around in the great lakes, and back into the northeast US, with the majority of the blackout occurring in ~9 seconds.
Specific software bugs were identified in the GE XA/21 scada system (used by FirstEnergy) which caused the initial failure of the alarm/event subsystem.
The cause of the blackout is known and was not related to an Internet worm. Please stop perpetuating this falsehood.
If it is a critical system, it needs to be reliable, stable and secure. Three things Windows is not and never will be.
It only took me 2 hours to hack a VMS system one night when our stupid system manager edited the system startup file incorrectly and left town for the weekend. I got the call because I knew more about the OS than anyone else in the company.
- by fwjs28 April 30, 2009 4:30 PM PDT
- somebody most likely sent a dos attack to the servers, and Microshit is trying to cover it up, and blame it on the ****** servers...DUH!
- Like this Reply to this comment
-
(26 Comments)