TIL: Axel Health (axelhealth.com/) is still using Debian 8 - From 2015 💀
I don't know if they are actually using it only for the displays (that show patient numbers etc) or for the central configuration server, but in either case that's diabolical.
Holy shit
Tehokkuutta terveydenhuollon tuotantoon | Axel Health
Axel Healthin ratkaisut helpottavat potilaiden asiointia, tukevat ammattilaisten päivittäistä työtä sekä auttavat organisaatioita tehostamaan toimintaansa.www.axelhealth.com
CyberFrog
in reply to Koutsie • • •CyberFrog
in reply to CyberFrog • • •once saw a dentist chair running outdated windows 7 (yes, after EOL) with an anti-virus security alert popup which was ignored, and a horribly outdated Java version installed that was begging for updates
this person was doing minor surgery with that machine daily, I had no choice but to let them use a probably malware'd device on my face, or leave and pray the next guy isn't as stupid
nothing about this is fun
vxo
in reply to CyberFrog • • •vxo
in reply to vxo • • •vxo
in reply to vxo • • •@froge on one side of this, the good news is that a lot of the devices have no reason to be online for normal functionality and can be air gapped to hell
on the other side though, even if a network is air gapped, lateral movement of scum like ransomware can still disable the devices and if nobody took a disk image of it while it was still working, it's toast
vxo
in reply to vxo • • •CyberFrog
in reply to vxo • • •I don't really consider hospitals to ever be correctly air-gapped because in reality there are like 6,000 endpoints literally a single hop away from the "air gapped" devices with full internet access, and hacking the firmware of something like an insulin or drug pump is laughably easy because they simply ignored computer security for 30 years, you can still buffer overflow to RCE on those things without any issues
@pluralistic@mamot.fr wrote about this in 2014/15 and from the new research I've seen very little has improved since then
boingboing.net/2014/04/27/hack…
zombiewarrior
in reply to CyberFrog • • •CyberFrog
in reply to vxo • • •