funsec mailing list archives

Re: London hospitals nearly back nline after worm infection


From: "Michael Simpson" <mikie.simpson () gmail com>
Date: Tue, 2 Dec 2008 13:07:48 +0000

On 12/2/08, David Harley <david.a.harley () gmail com> wrote:
It's a bit more complicated than that:
http://www.eset.com/threat-center/blog/?p=193,
http://www.eset.com/threat-center/blog/?p=213.

--
David Harley BA CISSP FBCS CITP
Director of Malware Intelligence
ESET LLC

As long as we have paper records and paper prescribing then the IT
infrastructure is (and always has been) an unnecessary inconvenience
within the NHS.

ie A&E (ER) systems are used mostly to check that departments are
meeting the 4hr "seen and treated" target set by government rather
than gathering useful data.
- even this is badly used as the figures are munged by most managers
in order to protect their performance related pay bonuses.

Where i work we have 5 separate unlinkable systems that i am meant to
use (3 health, 1 social work and 1 both) none of which are of any use
to me whatsoever due to having no relevant data on them therefore i
ignore them. The boxen we use could be on fire and i would only be
warmer and less inconvenienced.

One of the more interesting points wrt NHS IT is the fact that the
majority of systems are stuck on (at best) IE6 so will mean that even
when that badly written piece of vomitus is no longer supported by
microsoft then it (like many of the win95 and 98 boxen liberally
scattered around hospitals) will still be in use for many years.

Every couple of years a hospital has its systems shut down by some old
worm and this will continue as long as the powers that be in NHS IT
rely on their firewalls to protect the soft fleshy networks within.
It wouldn't surprise me if this recent outbreak was due to some
manager plugging his preinfected laptop into the network as within NHS
management you generally rise to the level of your incompetence.

I know that there are some good folk within the connecting for health
service but in the main NHS IT and NHS management is just a massive
clusterf**k of incompetence.

/rant

mike simpson
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: