Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.folklore.computers > #159496 > unrolled thread
| Started by | "Osmium" <r124c4u102@comcast.net> |
|---|---|
| First post | 2016-02-16 10:37 -0600 |
| Last post | 2016-02-19 12:55 -0600 |
| Articles | 20 on this page of 317 — 37 participants |
Back to article view | Back to alt.folklore.computers
Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-16 10:37 -0600
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-16 09:54 -0800
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-16 19:41 +0100
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-16 21:11 +0100
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-17 02:16 +0100
Re: Ransomware usenet@only.tnx (Questor) - 2016-02-17 22:05 +0000
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-17 23:35 +0100
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-18 13:58 +0000
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-17 18:41 -0700
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-16 18:52 -0700
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-17 14:13 +1100
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-17 04:53 +0100
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-17 04:21 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-17 17:24 +1100
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-17 15:07 +0100
Re: Ransomware usenet@only.tnx (Questor) - 2016-02-17 23:02 +0000
Re: Ransomware Huge <Huge@nowhere.much.invalid> - 2016-02-17 08:03 +0000
Re: Ransomware usenet@only.tnx (Questor) - 2016-02-17 23:02 +0000
Re: Ransomware Huge <Huge@nowhere.much.invalid> - 2016-02-17 08:01 +0000
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-17 18:07 +0000
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-17 14:01 -0500
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-17 18:41 -0700
Re: Ransomware Anne & Lynn Wheeler <lynn@garlic.com> - 2016-02-17 18:09 -0800
Re: Ransomware Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-02-17 20:45 -0700
Re: Ransomware Jon Elson <elson@pico-systems.com> - 2016-02-17 22:34 -0600
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-18 11:16 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 05:44 +1100
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-18 15:00 +1100
Re: Ransomware Roger Blake <rogblake@iname.invalid> - 2016-02-18 02:12 +0000
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-17 22:47 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-18 15:10 +1100
Re: Ransomware Anne & Lynn Wheeler <lynn@garlic.com> - 2016-02-17 21:29 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-18 17:56 +1100
Re: Ransomware Anne & Lynn Wheeler <lynn@garlic.com> - 2016-02-17 23:15 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-18 18:35 +1100
Re: Ransomware Anne & Lynn Wheeler <lynn@garlic.com> - 2016-02-18 17:58 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 13:44 +1100
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-17 20:44 -0800
Re: Ransomware Lawrence Statton <lawrence@senguio.mx> - 2016-02-18 08:03 -0600
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-18 17:14 -0600
Re: Ransomware Lawrence Statton <lawrence@senguio.mx> - 2016-02-18 19:10 -0600
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-18 20:13 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 15:26 +1100
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 09:34 -0600
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-19 16:26 +0000
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 14:58 -0600
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-19 18:21 -0500
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-19 18:43 -0700
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-19 23:32 -0500
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 19:34 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 19:59 +1100
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-20 07:25 -0500
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 10:30 -0600
Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-20 10:58 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 04:25 +1100
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-20 19:56 +0000
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-20 18:15 -0700
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 13:26 +1100
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 04:16 +1100
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-20 18:15 -0700
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 13:22 +1100
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-19 17:36 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 10:01 +1100
Re: Ransomware Gene Wirchenko <genew@telus.net> - 2016-02-20 16:26 -0800
Re: Ransomware Gene Wirchenko <genew@telus.net> - 2016-02-21 13:52 -0800
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-21 18:51 -0500
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 19:18 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 15:03 +1100
Re: Ransomware Andrew Swallow <am.swallow@btinternet.com> - 2016-02-20 16:12 +0000
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-19 15:59 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 09:59 +1100
Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-19 18:43 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 14:36 +1100
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 17:01 -0600
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-19 18:54 -0600
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 19:48 -0600
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-20 16:20 -0600
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 18:17 -0600
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 19:53 -0800
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-19 18:43 -0700
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-19 21:33 -0500
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 10:23 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 14:48 +1100
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 19:56 -0800
Re: Ransomware Michael Black <et472@ncf.ca> - 2016-02-19 23:18 -0500
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 10:35 -0600
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 10:12 -0600
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-20 15:33 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 12:11 +1100
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-19 18:43 -0700
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 20:00 -0800
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-20 01:51 -0700
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 10:34 -0600
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 10:19 -0600
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 19:40 -0800
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-20 15:18 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 03:46 +1100
Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-18 23:55 -0600
Re: Ransomware mausg@mail.com - 2016-02-19 10:48 +0000
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-19 05:56 -0500
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 09:50 -0600
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-19 16:29 +0000
Re: Ransomware Stan Barr <plan.b@bluesomatic.org> - 2016-02-19 16:54 +0000
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-19 17:55 +0000
Re: Ransomware Stan Barr <plan.b@bluesomatic.org> - 2016-02-20 08:30 +0000
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-20 15:29 +0000
Re: Ransomware Lawrence Statton NK1G <lawrence@senguio.mx> - 2016-02-20 10:06 -0600
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-20 11:03 -0600
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 16:14 -0600
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 16:27 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-23 09:49 +1100
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 05:29 +1100
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-19 18:53 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 09:42 +1100
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-19 14:24 -0500
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 14:58 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 05:24 +1100
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 04:53 +1100
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-19 18:15 +0000
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 17:55 -0800
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-18 11:19 -0500
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-18 10:19 -0600
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-18 11:46 -0500
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-18 18:01 +0000
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-18 14:36 -0500
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-19 11:23 +0000
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-19 09:28 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 05:19 +1100
Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-18 11:06 -0600
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-18 10:24 -0700
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-18 12:27 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 10:22 +1100
Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-19 00:07 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 18:34 +1100
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-19 05:41 -0500
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-19 07:43 -0600
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-19 16:13 +0000
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-19 08:01 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 04:50 +1100
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-18 21:34 +0000
Re: Ransomware Lawrence Statton <lawrence@senguio.mx> - 2016-02-18 13:34 -0600
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-18 17:34 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 10:33 +1100
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-18 21:04 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 13:46 +1100
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-19 05:34 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 04:47 +1100
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-19 14:24 +0000
Re: Ransomware Walter Banks <walter@bytecraft.com> - 2016-02-18 11:03 -0500
Re: Ransomware Ibmekon <Ibmekon> - 2016-02-18 19:21 +0000
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-18 20:56 +0000
Re: Ransomware Ibmekon <Ibmekon> - 2016-02-18 21:19 +0000
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-19 13:48 +0000
Re: Ransomware Ibmekon <Ibmekon> - 2016-02-19 14:12 +0000
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 09:54 -0600
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-20 15:18 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 03:29 +1100
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-20 10:42 -0600
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-21 15:48 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-22 03:43 +1100
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-21 12:55 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-22 07:53 +1100
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-23 13:13 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-24 04:49 +1100
Re: Ransomware Ibmekon <Ibmekon> - 2016-02-21 19:56 +0000
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-19 16:19 +0000
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 18:08 -0800
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-19 18:18 -0800
Re: Ransomware mausg@mail.com - 2016-02-19 18:10 +0000
Re: Ransomware Ibmekon <Ibmekon> - 2016-02-19 21:43 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 09:52 +1100
Re: Ransomware Anne & Lynn Wheeler <lynn@garlic.com> - 2016-02-19 16:53 -0800
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-18 18:37 -0600
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-18 13:58 +0000
Re: Ransomware "Rod Speed" <rod.speed.aaa@gmail.com> - 2016-02-19 05:32 +1100
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-17 11:13 -0600
Re: Ransomware Roger Blake <rogblake@iname.invalid> - 2016-02-16 17:57 +0000
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-16 14:19 -0600
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-17 03:42 +0000
Re: Ransomware Huge <Huge@nowhere.much.invalid> - 2016-02-17 08:05 +0000
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-17 12:03 +0000
Re: Ransomware Morten Reistad <first@last.name,invalid> - 2016-02-17 15:21 +0100
Re: Ransomware Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-02-17 07:38 -0700
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-17 18:07 +0000
Re: Ransomware "Charles Richmond" <numerist@aquaporin4.com> - 2016-02-18 12:10 -0600
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-18 21:34 +0000
Re: Ransomware "Charles Richmond" <numerist@aquaporin4.com> - 2016-02-18 12:06 -0600
Re: Ransomware Quadibloc <jsavard@ecn.ab.ca> - 2016-02-16 12:49 -0800
Re: Ransomware Lawrence Statton <lawrence@senguio.mx> - 2016-02-16 16:55 -0600
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-16 17:31 -0600
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-16 16:11 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-17 14:26 +1100
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-17 11:19 -0600
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-17 12:05 -0600
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-17 17:58 -0600
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-17 18:41 -0700
Re: Ransomware Anne & Lynn Wheeler <lynn@garlic.com> - 2016-02-17 18:39 -0800
Re: Ransomware Mike Spencer <mds@bogus.nodomain.nowhere> - 2016-02-16 16:44 -0400
Re: Ransomware Jon Elson <jmelson@wustl.edu> - 2016-02-16 15:30 -0600
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-17 00:20 +0100
Re: Ransomware usenet@only.tnx (Questor) - 2016-02-17 23:03 +0000
Re: Ransomware Michael Black <et472@ncf.ca> - 2016-02-17 18:48 -0500
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-18 13:58 +0000
Re: Ransomware Morten Reistad <first@Last.name.invalid> - 2016-02-18 16:46 +0100
Re: Ransomware Gene Wirchenko <genew@telus.net> - 2016-02-18 11:06 -0800
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-18 14:43 -0500
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-18 14:06 -0600
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-18 15:48 -0500
Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-18 15:36 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 10:30 +1100
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-18 19:38 -0500
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-18 21:43 +0000
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-19 00:51 +0100
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-19 13:45 +0000
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-19 15:00 +0100
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-19 07:01 -0700
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-19 10:16 -0500
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-19 11:15 -0700
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-19 11:19 -0700
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-19 18:55 +0000
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-19 12:54 -0700
Re: Ransomware Gene Wirchenko <genew@telus.net> - 2016-02-20 17:46 -0800
Re: Ransomware JimP <solosam90@gmail.com> - 2016-02-19 15:08 -0600
Re: Ransomware "Charles Richmond" <numerist@aquaporin4.com> - 2016-02-23 16:01 -0600
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-23 21:24 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-20 04:58 +1100
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-19 13:40 +0000
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-19 14:24 +0000
Re: Ransomware "Rod Speed" <rod.speed.aaa@gmail.com> - 2016-02-20 05:06 +1100
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-19 10:11 +1100
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-18 21:44 +0100
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-19 14:24 +0000
Re: Ransomware "Rod Speed" <rod.speed.aaa@gmail.com> - 2016-02-20 05:13 +1100
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-19 14:24 +0000
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-19 17:08 +0100
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-20 15:18 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 03:41 +1100
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-20 18:15 -0700
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-21 09:35 +0100
Re: Ransomware Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-21 10:18 +0000
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-21 16:48 +0100
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-21 18:40 -0600
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-22 01:53 +0100
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-21 18:36 -0700
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 00:12 -0600
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-22 09:37 +0100
Re: Ransomware Dan Espen <despen@verizon.net> - 2016-02-22 09:17 -0500
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-22 15:29 +0100
Re: Ransomware using libc Dan Espen <despen@verizon.net> - 2016-02-22 09:42 -0500
Re: Ransomware using libc Melzzzzz <mel@zzzzz.com> - 2016-02-22 15:52 +0100
Re: Ransomware using libc Dan Espen <despen@verizon.net> - 2016-02-22 10:23 -0500
Re: Ransomware using libc scott@slp53.sl.home (Scott Lurndal) - 2016-02-22 17:24 +0000
Re: Ransomware using libc Melzzzzz <mel@zzzzz.com> - 2016-02-22 20:29 +0100
Re: Ransomware using libc Ahem A Rivet's Shot <steveo@eircom.net> - 2016-02-22 19:38 +0000
Re: Ransomware using libc Melzzzzz <mel@zzzzz.com> - 2016-02-22 21:31 +0100
Re: Ransomware using libc Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-22 17:17 +0000
Re: Ransomware using libc Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 14:41 -0600
Re: Ransomware using libc Melzzzzz <mel@zzzzz.com> - 2016-02-22 22:07 +0100
Re: Ransomware Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-02-22 09:16 -0700
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-22 17:21 +0100
Re: Ransomware Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2016-02-22 09:34 -0700
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 11:11 -0600
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-22 18:25 +0100
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 15:15 -0600
Re: Ransomware Melzzzzz <mel@zzzzz.com> - 2016-02-22 22:28 +0100
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 21:46 -0600
Re: Ransomware "Rod Speed" <rod.speed.aaa@gmail.com> - 2016-02-20 05:05 +1100
Re: Ransomware "Rod Speed" <rod.speed.aaa@gmail.com> - 2016-02-19 05:31 +1100
Re: Ransomware Jon Elson <jmelson@wustl.edu> - 2016-02-18 13:56 -0600
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-19 14:24 +0000
Re: Ransomware "Rod Speed" <rod.speed.aaa@gmail.com> - 2016-02-20 05:16 +1100
Re: Ransomware Jon Elson <jmelson@wustl.edu> - 2016-02-19 17:09 -0600
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-20 15:18 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 03:55 +1100
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-20 19:56 +0000
Re: Ransomware Jon Elson <jmelson@wustl.edu> - 2016-02-22 14:07 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-23 07:15 +1100
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-22 18:30 -0500
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-23 01:49 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-23 13:09 +1100
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-23 13:03 +1100
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-19 13:12 -0600
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-18 06:29 -0500
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-19 13:35 -0600
Re: Ransomware Huge <Huge@nowhere.much.invalid> - 2016-02-20 09:55 +0000
Re: Ransomware Peter Flass <peter_flass@yahoo.com> - 2016-02-20 07:30 -0700
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-20 11:11 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-21 04:05 +1100
Re: Ransomware Huge <Huge@nowhere.much.invalid> - 2016-02-21 11:55 +0000
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-21 14:04 +0100
Re: Ransomware Huge <Huge@nowhere.much.invalid> - 2016-02-21 13:57 +0000
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-21 23:28 +0000
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-22 03:34 +1100
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-22 03:32 +1100
Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-21 12:14 -0600
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-22 07:47 +1100
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-17 14:03 +0000
Re: Ransomware Jon Elson <jmelson@wustl.edu> - 2016-02-17 15:20 -0600
Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-17 21:31 +0000
Re: Ransomware Stan Barr <plan.b@bluesomatic.org> - 2016-02-18 08:23 +0000
Re: Ransomware Jon Elson <elson@pico-systems.com> - 2016-02-18 11:42 -0600
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-18 06:23 -0500
Re: Ransomware Jon Elson <elson@pico-systems.com> - 2016-02-18 11:43 -0600
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-18 17:48 -0500
Re: Ransomware hancock4@bbs.cpcn.com - 2016-02-16 17:04 -0800
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-17 14:42 +1100
Re: Ransomware Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2016-02-17 04:17 +0000
Re: Ransomware Mike Spencer <mds@bogus.nodomain.nowhere> - 2016-02-17 04:08 -0400
Re: Ransomware usenet@only.tnx (Questor) - 2016-02-17 23:04 +0000
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-18 06:38 -0500
Re: Ransomware Morten Reistad <first@last.name.invalid> - 2016-02-18 13:38 +0100
Re: Ransomware "J. Clarke" <j.clarke.873638@gmail.com> - 2016-02-18 17:57 -0500
Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-17 14:24 +1100
Re: Ransomware usenet@only.tnx (Questor) - 2016-02-17 23:03 +0000
Re: Ransomware Anne & Lynn Wheeler <lynn@garlic.com> - 2016-02-17 16:43 -0800
Re: Ransomware jmfbahciv <See.above@aol.com> - 2016-02-18 13:58 +0000
Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-19 12:55 -0600
Page 1 of 16 [1] 2 3 … 16 Next page →
| From | "Osmium" <r124c4u102@comcast.net> |
|---|---|
| Date | 2016-02-16 10:37 -0600 |
| Subject | Ransomware |
| Message-ID | <dih1hlFr79aU1@mid.individual.net> |
Google news has an article today about "ransomware" against an LA hospital. The software has encrypted their files and offer to decrypt them for $3.6M payable in bitcoin. The price seems modest to me, but set that aside for the moment.. It seems to me that one of the side effects might require certification of software types, similar to the requirements for certain engineers. If you build a three story office building, there has to be a Registered Professional Engineer involved who has convinced the government that he knows what he is doing. Can protection of crucial data bases be far behind? I am not at all sure that such licensing would accomplish anything but it seems a "logical" cause for some politician, perhaps one who personally gets caught up in such a mess. http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s- computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
[toc] | [next] | [standalone]
| From | hancock4@bbs.cpcn.com |
|---|---|
| Date | 2016-02-16 09:54 -0800 |
| Message-ID | <b1b6a5ec-6f0f-42df-bfcb-ab9a8b628515@googlegroups.com> |
| In reply to | #159496 |
On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote: > Google news has an article today about "ransomware" against an LA hospital. > The software has encrypted their files and offer to decrypt them for $3.6M > payable in bitcoin. The price seems modest to me, but set that aside for > the moment.. It seems to me that the I.T. industry needs to do a lot more to secure its networks from malware. We've had so many instances of this sort of thing, like the Target attack. Individuals get sabotaged all the time. Businesses that supposedly have secure networks get invaded often. (A friend got a pop up warning he had to download an upgrade. Then he gets a phone call from some scam artist offering services. How do these people get his name and number?) It needs to make some tough decisions. If Microsoft products are too vulnerable, for whatever reason, they need to be tightened up. If we have too much automation that causes us to lose control, we need to curtail it. A supermarket has automatic doors to let us into the door. But they don't let the public into the back rooms nor the money room, which are kept securely locked. Also, we need to think about how open our networks should be. Patients in hospitals are able use their PCs to access stuff. While this alleviates some boredom, I wonder if that wide accessibility is necessary and a good idea. I've heard that some of the malware originates overseas. Maybe we need to secure our "electronic" borders. Yes, better protection will cost some folks serious money in higher expenses or lost sales. But do we really need things like instant credit (nice way for fraud and identify theft).
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-02-16 19:41 +0100 |
| Message-ID | <20160216194146.19857f89@maxa-pc> |
| In reply to | #159501 |
On Tue, 16 Feb 2016 09:54:19 -0800 (PST) hancock4@bbs.cpcn.com wrote: > On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote: > > Google news has an article today about "ransomware" against an LA > > hospital. The software has encrypted their files and offer to > > decrypt them for $3.6M payable in bitcoin. The price seems modest > > to me, but set that aside for the moment.. > > It seems to me that the I.T. industry needs to do a lot more to secure > its networks from malware. We've had so many instances of this sort > of thing, like the Target attack. Individuals get sabotaged all the > time. > > Businesses that supposedly have secure networks get invaded often. > > (A friend got a pop up warning he had to download an upgrade. Then he > gets a phone call from some scam artist offering services. How do > these people get his name and number?) > > It needs to make some tough decisions. If Microsoft products are > too vulnerable, for whatever reason, they need to be tightened up. Microsoft products are postulate for insecure. How would you tighten up? Forbid access to internet? Forbid users to plug in usb keys with games to computer ? ;) That's the only way. Microsoft has access to every Windows computer on the net. Operating system that constantly scans for malware cannot be remedied. > If we have too much automation that causes us to lose control, we > need to curtail it. How? By using Windows? ;) > > A supermarket has automatic doors to let us into the door. But they > don't let the public into the back rooms nor the money room, which are > kept securely locked. Operating system with intrusive copy protection cannot be securely locked... > > Also, we need to think about how open our networks should be. > Patients in hospitals are able use their PCs to access stuff. While > this alleviates some boredom, I wonder if that wide accessibility is > necessary and a good idea. That's not problem. Forbid user access to outside and problem solved. In my experience almost 100% of hacker break ins was from compromised user machine that had passwords for critical accounts. That is, account with possibility to upload and execute code. > > I've heard that some of the malware originates overseas. Maybe we > need to secure our "electronic" borders. How? By forbidding user access to internet? > > Yes, better protection will cost some folks serious money in higher > expenses or lost sales. But do we really need things like instant > credit (nice way for fraud and identify theft). >
[toc] | [prev] | [next] | [standalone]
| From | Morten Reistad <first@last.name.invalid> |
|---|---|
| Date | 2016-02-16 21:11 +0100 |
| Message-ID | <1dccpc-efr.ln1@sambook.reistad.name> |
| In reply to | #159509 |
In article <20160216194146.19857f89@maxa-pc>, Melzzzzz <mel@zzzzz.com> wrote: >On Tue, 16 Feb 2016 09:54:19 -0800 (PST) >hancock4@bbs.cpcn.com wrote: > >> On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote: >> > Google news has an article today about "ransomware" against an LA >> > hospital. The software has encrypted their files and offer to >> > decrypt them for $3.6M payable in bitcoin. The price seems modest >> > to me, but set that aside for the moment.. >> >> It seems to me that the I.T. industry needs to do a lot more to secure >> its networks from malware. We've had so many instances of this sort >> of thing, like the Target attack. Individuals get sabotaged all the >> time. >> >> Businesses that supposedly have secure networks get invaded often. >> >> (A friend got a pop up warning he had to download an upgrade. Then he >> gets a phone call from some scam artist offering services. How do >> these people get his name and number?) >> >> It needs to make some tough decisions. If Microsoft products are >> too vulnerable, for whatever reason, they need to be tightened up. > >Microsoft products are postulate for insecure. How would you tighten up? >Forbid access to internet? Forbid users to plug in usb keys with games >to computer ? ;) That's the only way. Microsoft has access to every >Windows computer on the net. Operating system that constantly scans for >malware cannot be remedied. > >> If we have too much automation that causes us to lose control, we >> need to curtail it. > >How? By using Windows? ;) > >> >> A supermarket has automatic doors to let us into the door. But they >> don't let the public into the back rooms nor the money room, which are >> kept securely locked. > >Operating system with intrusive copy protection cannot be securely >locked... Yes. Sandboxes. > >> >> Also, we need to think about how open our networks should be. >> Patients in hospitals are able use their PCs to access stuff. While >> this alleviates some boredom, I wonder if that wide accessibility is >> necessary and a good idea. > >That's not problem. Forbid user access to outside and problem solved. >In my experience almost 100% of hacker break ins was from compromised >user machine that had passwords for critical accounts. That is, >account with possibility to upload and execute code. You don't have to close down patient access to anything outside. Just have the wifi networks as an external security zone. >> >> I've heard that some of the malware originates overseas. Maybe we >> need to secure our "electronic" borders. > >How? By forbidding user access to internet? > > >> >> Yes, better protection will cost some folks serious money in higher >> expenses or lost sales. But do we really need things like instant >> credit (nice way for fraud and identify theft). Enforce the border between secure and insecure. If this requires dedicated OS machines for access to the internal network, so be it. Unthink windows for a moment. And unthink word, excel, ie etc too. The internal network of a hospital could very well be operated by dedicated pad style computers running a very stripped down, sandboxed OS and utilities, running a simple browser, text processor and image processor. No javascript. No autoexecute. And only very gatewayed access in/out; through some very restricted file transfers; but simple access for all staff through their personal pads. Then let them have their personal/corporate peecess, connected to the insecure side; with NO direct access to the inside, just some file import service with manual validation (from the inside) of every file going in or out. And thorough scans of it going in, It is not difficult. But it will enrage your Microsoft salescritter. -- mrr
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-02-17 02:16 +0100 |
| Message-ID | <20160217021659.3af80dff@maxa-pc> |
| In reply to | #159511 |
On Tue, 16 Feb 2016 21:11:45 +0100 Morten Reistad <first@last.name.invalid> wrote: > In article <20160216194146.19857f89@maxa-pc>, Melzzzzz > <mel@zzzzz.com> wrote: > >On Tue, 16 Feb 2016 09:54:19 -0800 (PST) > >hancock4@bbs.cpcn.com wrote: > > > >> On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote: > >> > Google news has an article today about "ransomware" against an LA > >> > hospital. The software has encrypted their files and offer to > >> > decrypt them for $3.6M payable in bitcoin. The price seems > >> > modest to me, but set that aside for the moment.. > >> > >> It seems to me that the I.T. industry needs to do a lot more to > >> secure its networks from malware. We've had so many instances of > >> this sort of thing, like the Target attack. Individuals get > >> sabotaged all the time. > >> > >> Businesses that supposedly have secure networks get invaded often. > >> > >> (A friend got a pop up warning he had to download an upgrade. > >> Then he gets a phone call from some scam artist offering > >> services. How do these people get his name and number?) > >> > >> It needs to make some tough decisions. If Microsoft products are > >> too vulnerable, for whatever reason, they need to be tightened > >> up. > > > >Microsoft products are postulate for insecure. How would you tighten > >up? Forbid access to internet? Forbid users to plug in usb keys with > >games to computer ? ;) That's the only way. Microsoft has access to > >every Windows computer on the net. Operating system that constantly > >scans for malware cannot be remedied. > > > >> If we have too much automation that causes us to lose control, we > >> need to curtail it. > > > >How? By using Windows? ;) > > > >> > >> A supermarket has automatic doors to let us into the door. But > >> they don't let the public into the back rooms nor the money room, > >> which are kept securely locked. > > > >Operating system with intrusive copy protection cannot be securely > >locked... > > Yes. Sandboxes. > > > > >> > >> Also, we need to think about how open our networks should be. > >> Patients in hospitals are able use their PCs to access stuff. > >> While this alleviates some boredom, I wonder if that wide > >> accessibility is necessary and a good idea. > > > >That's not problem. Forbid user access to outside and problem solved. > >In my experience almost 100% of hacker break ins was from compromised > >user machine that had passwords for critical accounts. That is, > >account with possibility to upload and execute code. > > You don't have to close down patient access to anything outside. Just > have the wifi networks as an external security zone. I didn;t mean patients, they probably don't have access to anything important. I mean employees. Machines used to access important accounts shouldn't be allowed to internet. You are talking by security zones ;) > > >> > >> I've heard that some of the malware originates overseas. Maybe we > >> need to secure our "electronic" borders. > > > >How? By forbidding user access to internet? > > > > > >> > >> Yes, better protection will cost some folks serious money in higher > >> expenses or lost sales. But do we really need things like instant > >> credit (nice way for fraud and identify theft). > > Enforce the border between secure and insecure. If this requires > dedicated OS machines for access to the internal network, so be it. > > Unthink windows for a moment. > > And unthink word, excel, ie etc too. > > The internal network of a hospital could very well be operated by > dedicated pad style computers running a very stripped down, sandboxed > OS and utilities, running a simple browser, text processor and image > processor. No javascript. No autoexecute. And only very gatewayed > access in/out; through some very restricted file transfers; but > simple access for all staff through their personal pads. > > Then let them have their personal/corporate peecess, connected to > the insecure side; with NO direct access to the inside, just some > file import service with manual validation (from the inside) of > every file going in or out. And thorough scans of it going in, > > It is not difficult. But it will enrage your Microsoft salescritter. Completely agree. > > -- mrr
[toc] | [prev] | [next] | [standalone]
| From | usenet@only.tnx (Questor) |
|---|---|
| Date | 2016-02-17 22:05 +0000 |
| Message-ID | <56c4ee7a.3224096@nntp2.rawbw.com> |
| In reply to | #159511 |
On Tue, 16 Feb 2016 21:11:45 +0100, Morten Reistad <first@last.name.invalid> wrote: >Enforce the border between secure and insecure. If this requires >dedicated OS machines for access to the internal network, so be it. > >Unthink windows for a moment. > >And unthink word, excel, ie etc too. > >The internal network of a hospital could very well be operated by >dedicated pad style computers running a very stripped down, sandboxed >OS and utilities, running a simple browser, text processor and image >processor. No javascript. No autoexecute. And only very gatewayed >access in/out; through some very restricted file transfers; but >simple access for all staff through their personal pads. > >Then let them have their personal/corporate peecess, connected to >the insecure side; with NO direct access to the inside, just some >file import service with manual validation (from the inside) of >every file going in or out. And thorough scans of it going in, > >It is not difficult. But it will enrage your Microsoft salescritter. It sounds like you've never worked in I.T. before, and certainly never worked in a hospital. (I think at least one of those isn't true.) Hospitals, perhaps more than most organizations, have to coordinate and communicate with literally hundreds of outside individuals and entities. Like it or not, that means exchanging e-mail and, yes, MS Office documents. And there dozens and dozens of third-party applications that are necessary to for different job functions. A portion of the complexity is due to the nature of the U.S. health care system (irrespective of the ACA) and the baroque classification and billing it requires. Many of these are specialized, shared databases tailored for a particular occupation, and one trend for more than a decade has been ditch the ad hoc applications and use a browser for access. So javascript and java are required. Most employees are going to need access to both internal and external resources, and at any rate, separate air-gapped "inside" and "outside" networks would be prohibitively expensive. Besides, it's all gone wireless these days. There are access points in every room, the crash carts communicate wirelessly, and soon the bedside monitoring stations. (Cords can be a hassle for the bed-ridden and mobility impaired.) I think the best you can do is tablets and disk-less workstations, all work files stored on servers, and as pointed out by others, a rigorous, tested backup regimen. Even so, there are significant bring-your-own-device issues in a hospital, as there are many kinds of consultants, contractors, vendors, etc., all of whom need to perform their duties largely independantly on the premises, and none of whom are direct employees. Implementing and enforcing I.T. policy in that environment is difficult. And I haven't even mentioned accommodations for the public.
[toc] | [prev] | [next] | [standalone]
| From | Morten Reistad <first@last.name.invalid> |
|---|---|
| Date | 2016-02-17 23:35 +0100 |
| Message-ID | <l59fpc-amv.ln1@sambook.reistad.name> |
| In reply to | #159610 |
In article <56c4ee7a.3224096@nntp2.rawbw.com>, Questor <usenet@only.tnx> wrote: >On Tue, 16 Feb 2016 21:11:45 +0100, Morten Reistad <first@last.name.invalid> >wrote: >>Enforce the border between secure and insecure. If this requires >>dedicated OS machines for access to the internal network, so be it. >> >>Unthink windows for a moment. >> >>And unthink word, excel, ie etc too. >> >>The internal network of a hospital could very well be operated by >>dedicated pad style computers running a very stripped down, sandboxed >>OS and utilities, running a simple browser, text processor and image >>processor. No javascript. No autoexecute. And only very gatewayed >>access in/out; through some very restricted file transfers; but >>simple access for all staff through their personal pads. >> >>Then let them have their personal/corporate peecess, connected to >>the insecure side; with NO direct access to the inside, just some >>file import service with manual validation (from the inside) of >>every file going in or out. And thorough scans of it going in, >> >>It is not difficult. But it will enrage your Microsoft salescritter. > > >It sounds like you've never worked in I.T. before, and certainly never >worked in a hospital. (I think at least one of those isn't true.) No, I have never worked in a (US) hospital. But I have worked in and for several dozen IT departments, mostly for operators of telecom, networks, electricity generation and financial institutions. >Hospitals, perhaps more than most organizations, have to coordinate >and communicate with literally hundreds of outside individuals and >entities. Like it or not, that means exchanging e-mail and, yes, MS >Office documents. And there dozens and dozens of third-party >applications that are necessary to for different job functions. A portion >of the complexity is due to the nature of the U.S. health care system >(irrespective of the ACA) and the baroque classification and billing >it requires. Many of these are specialized, shared databases tailored for >a particular occupation, and one trend for more than a decade has been >ditch the ad hoc applications and use a browser for access. So javascript >and java are required. Most employees are going to need access to both >internal and external resources, and at any rate, separate air-gapped >"inside" and "outside" networks would be prohibitively expensive. Besides, >it's all gone wireless these days. There are access points in every room, >the crash carts communicate wirelessly, and soon the bedside monitoring >stations. (Cords can be a hassle for the bed-ridden and mobility impaired.) For crissakes, use separate wifi networks at least for the process control, operational employee access, administrative employee access and everyone else. If you run everything on one network you deserve exactly what you will get. >I think the best you can do is tablets and disk-less workstations, all work >files stored on servers, and as pointed out by others, a rigorous, tested >backup regimen. Even so, there are significant bring-your-own-device >issues in a hospital, as there are many kinds of consultants, contractors, >vendors, etc., all of whom need to perform their duties largely independantly >on the premises, and none of whom are direct employees. Implementing >and enforcing I.T. policy in that environment is difficult. And I haven't even >mentioned accommodations for the public. Bring your own device, sure. But only to some wifi networks. Connected OUTSIDE the corporate firewall. Have the internal ones autorize by mac address if necessary. (Plus WPA secret). Also, keep everything operational, like phones, telemetrics, journals etc. on a SEPARATE network, possibly with read access to some servers from the outside. Or do the US doctors have to handle billing as part of operations? (Not done as journal notes and by separate, administrative staff? or at least by the office of that MD?) -- mrr
[toc] | [prev] | [next] | [standalone]
| From | jmfbahciv <See.above@aol.com> |
|---|---|
| Date | 2016-02-18 13:58 +0000 |
| Message-ID | <PM00052C0B7C1CFD39@aca4282e.ipt.aol.com> |
| In reply to | #159611 |
Morten Reistad wrote: > In article <56c4ee7a.3224096@nntp2.rawbw.com>, Questor <usenet@only.tnx> wrote: >>On Tue, 16 Feb 2016 21:11:45 +0100, Morten Reistad <first@last.name.invalid> >>wrote: >>>Enforce the border between secure and insecure. If this requires >>>dedicated OS machines for access to the internal network, so be it. >>> >>>Unthink windows for a moment. >>> >>>And unthink word, excel, ie etc too. >>> >>>The internal network of a hospital could very well be operated by >>>dedicated pad style computers running a very stripped down, sandboxed >>>OS and utilities, running a simple browser, text processor and image >>>processor. No javascript. No autoexecute. And only very gatewayed >>>access in/out; through some very restricted file transfers; but >>>simple access for all staff through their personal pads. >>> >>>Then let them have their personal/corporate peecess, connected to >>>the insecure side; with NO direct access to the inside, just some >>>file import service with manual validation (from the inside) of >>>every file going in or out. And thorough scans of it going in, >>> >>>It is not difficult. But it will enrage your Microsoft salescritter. >> >> >>It sounds like you've never worked in I.T. before, and certainly never >>worked in a hospital. (I think at least one of those isn't true.) > > No, I have never worked in a (US) hospital. But I have worked in and > for several dozen IT departments, mostly for operators of telecom, networks, > electricity generation and financial institutions. > >>Hospitals, perhaps more than most organizations, have to coordinate >>and communicate with literally hundreds of outside individuals and >>entities. Like it or not, that means exchanging e-mail and, yes, MS >>Office documents. And there dozens and dozens of third-party >>applications that are necessary to for different job functions. A portion >>of the complexity is due to the nature of the U.S. health care system >>(irrespective of the ACA) and the baroque classification and billing >>it requires. Many of these are specialized, shared databases tailored for >>a particular occupation, and one trend for more than a decade has been >>ditch the ad hoc applications and use a browser for access. So javascript >>and java are required. Most employees are going to need access to both >>internal and external resources, and at any rate, separate air-gapped >>"inside" and "outside" networks would be prohibitively expensive. Besides, >>it's all gone wireless these days. There are access points in every room, >>the crash carts communicate wirelessly, and soon the bedside monitoring >>stations. (Cords can be a hassle for the bed-ridden and mobility impaired.) > > For crissakes, use separate wifi networks at least for the process control, > operational employee access, administrative employee access and everyone > else. If you run everything on one network you deserve exactly what you > will get. > >>I think the best you can do is tablets and disk-less workstations, all work >>files stored on servers, and as pointed out by others, a rigorous, tested >>backup regimen. Even so, there are significant bring-your-own-device >>issues in a hospital, as there are many kinds of consultants, contractors, >>vendors, etc., all of whom need to perform their duties largely independantly >>on the premises, and none of whom are direct employees. Implementing >>and enforcing I.T. policy in that environment is difficult. And I haven't even >>mentioned accommodations for the public. > > Bring your own device, sure. But only to some wifi networks. Connected OUTSIDE > the corporate firewall. > > Have the internal ones autorize by mac address if necessary. (Plus WPA > secret). > > Also, keep everything operational, like phones, telemetrics, journals etc. > on a SEPARATE network, possibly with read access to some servers from the > outside. > > Or do the US doctors have to handle billing as part of operations? (Not done > as journal notes and by separate, administrative staff? or at least by the > office of that MD?) Even nurses do billing tasks. /BAH
[toc] | [prev] | [next] | [standalone]
| From | Peter Flass <peter_flass@yahoo.com> |
|---|---|
| Date | 2016-02-17 18:41 -0700 |
| Message-ID | <1756229136.477451728.917683.peter_flass-yahoo.com@news.eternal-september.org> |
| In reply to | #159610 |
Questor <usenet@only.tnx> wrote: > On Tue, 16 Feb 2016 21:11:45 +0100, Morten Reistad <first@last.name.invalid> > wrote: >> Enforce the border between secure and insecure. If this requires >> dedicated OS machines for access to the internal network, so be it. >> >> Unthink windows for a moment. >> >> And unthink word, excel, ie etc too. >> >> The internal network of a hospital could very well be operated by >> dedicated pad style computers running a very stripped down, sandboxed >> OS and utilities, running a simple browser, text processor and image >> processor. No javascript. No autoexecute. And only very gatewayed >> access in/out; through some very restricted file transfers; but >> simple access for all staff through their personal pads. >> >> Then let them have their personal/corporate peecess, connected to >> the insecure side; with NO direct access to the inside, just some >> file import service with manual validation (from the inside) of >> every file going in or out. And thorough scans of it going in, >> >> It is not difficult. But it will enrage your Microsoft salescritter. > > > It sounds like you've never worked in I.T. before, and certainly never > worked in a hospital. (I think at least one of those isn't true.) > > Hospitals, perhaps more than most organizations, have to coordinate > and communicate with literally hundreds of outside individuals and > entities. Like it or not, that means exchanging e-mail and, yes, MS > Office documents. And there dozens and dozens of third-party > applications that are necessary to for different job functions. A portion > of the complexity is due to the nature of the U.S. health care system > (irrespective of the ACA) and the baroque classification and billing > it requires. Many of these are specialized, shared databases tailored for > a particular occupation, and one trend for more than a decade has been > ditch the ad hoc applications and use a browser for access. So javascript > and java are required. Most employees are going to need access to both > internal and external resources, and at any rate, separate air-gapped > "inside" and "outside" networks would be prohibitively expensive. Besides, > it's all gone wireless these days. There are access points in every room, > the crash carts communicate wirelessly, and soon the bedside monitoring > stations. (Cords can be a hassle for the bed-ridden and mobility impaired.) Local hospital was separate public and internal wireless networks, but I would expect the "internal" network can still access outside. > > I think the best you can do is tablets and disk-less workstations, all work > files stored on servers, and as pointed out by others, a rigorous, tested > backup regimen. Even so, there are significant bring-your-own-device > issues in a hospital, as there are many kinds of consultants, contractors, > vendors, etc., all of whom need to perform their duties largely independantly > on the premises, and none of whom are direct employees. Implementing > and enforcing I.T. policy in that environment is difficult. And I haven't even > mentioned accommodations for the public. > > -- Pete
[toc] | [prev] | [next] | [standalone]
| From | Peter Flass <peter_flass@yahoo.com> |
|---|---|
| Date | 2016-02-16 18:52 -0700 |
| Message-ID | <1335429141.477364385.342781.peter_flass-yahoo.com@news.eternal-september.org> |
| In reply to | #159509 |
Melzzzzz <mel@zzzzz.com> wrote: > On Tue, 16 Feb 2016 09:54:19 -0800 (PST) > hancock4@bbs.cpcn.com wrote: > >> On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote: >>> Google news has an article today about "ransomware" against an LA >>> hospital. The software has encrypted their files and offer to >>> decrypt them for $3.6M payable in bitcoin. The price seems modest >>> to me, but set that aside for the moment.. >> >> It seems to me that the I.T. industry needs to do a lot more to secure >> its networks from malware. We've had so many instances of this sort >> of thing, like the Target attack. Individuals get sabotaged all the >> time. >> >> Businesses that supposedly have secure networks get invaded often. >> >> (A friend got a pop up warning he had to download an upgrade. Then he >> gets a phone call from some scam artist offering services. How do >> these people get his name and number?) >> >> It needs to make some tough decisions. If Microsoft products are >> too vulnerable, for whatever reason, they need to be tightened up. > > Microsoft products are postulate for insecure. How would you tighten up? > Forbid access to internet? Forbid users to plug in usb keys with games > to computer ? ;) That's the only way. Microsoft has access to every > Windows computer on the net. Operating system that constantly scans for > malware cannot be remedied. > >> If we have too much automation that causes us to lose control, we >> need to curtail it. > > How? By using Windows? ;) > >> >> A supermarket has automatic doors to let us into the door. But they >> don't let the public into the back rooms nor the money room, which are >> kept securely locked. > > Operating system with intrusive copy protection cannot be securely > locked... > >> >> Also, we need to think about how open our networks should be. >> Patients in hospitals are able use their PCs to access stuff. While >> this alleviates some boredom, I wonder if that wide accessibility is >> necessary and a good idea. > > That's not problem. Forbid user access to outside and problem solved. > In my experience almost 100% of hacker break ins was from compromised > user machine that had passwords for critical accounts. That is, > account with possibility to upload and execute code. > >> >> I've heard that some of the malware originates overseas. Maybe we >> need to secure our "electronic" borders. > > How? By forbidding user access to internet? Switch to SNA. -- Pete
[toc] | [prev] | [next] | [standalone]
| From | "hgww" <hgww@gmail.com> |
|---|---|
| Date | 2016-02-17 14:13 +1100 |
| Message-ID | <dii6riF5voaU1@mid.individual.net> |
| In reply to | #159509 |
"Melzzzzz" <mel@zzzzz.com> wrote in message news:20160216194146.19857f89@maxa-pc... > On Tue, 16 Feb 2016 09:54:19 -0800 (PST) > hancock4@bbs.cpcn.com wrote: > >> On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote: >> > Google news has an article today about "ransomware" against an LA >> > hospital. The software has encrypted their files and offer to >> > decrypt them for $3.6M payable in bitcoin. The price seems modest >> > to me, but set that aside for the moment.. >> >> It seems to me that the I.T. industry needs to do a lot more to secure >> its networks from malware. We've had so many instances of this sort >> of thing, like the Target attack. Individuals get sabotaged all the >> time. >> >> Businesses that supposedly have secure networks get invaded often. >> >> (A friend got a pop up warning he had to download an upgrade. Then he >> gets a phone call from some scam artist offering services. How do >> these people get his name and number?) >> >> It needs to make some tough decisions. If Microsoft products are >> too vulnerable, for whatever reason, they need to be tightened up. > > Microsoft products are postulate for insecure. How would you tighten up? Implement sandboxing like iOS does. > Forbid access to internet? Forbid users to plug in usb > keys with games to computer ? ;) That's the only way. No it is not. > Microsoft has access to every Windows computer on the net. No it does not if you don't want them to be. > Operating system that constantly scans for malware cannot be remedied. Have fun explaining how iOS did just that. >> If we have too much automation that causes us to lose control, we >> need to curtail it. > > How? By using Windows? ;) > >> >> A supermarket has automatic doors to let us into the door. But they >> don't let the public into the back rooms nor the money room, which are >> kept securely locked. > > Operating system with intrusive copy protection cannot be securely > locked... Wrong. iOS does just that. >> Also, we need to think about how open our networks should be. >> Patients in hospitals are able use their PCs to access stuff. While >> this alleviates some boredom, I wonder if that wide accessibility is >> necessary and a good idea. > That's not problem. Forbid user access to outside and problem solved. That solves nothing. > In my experience almost 100% of hacker break ins was from > compromised user machine that had passwords for critical accounts. > That is, account with possibility to upload and execute code. iOS handles that fine. >> I've heard that some of the malware originates overseas. Maybe we >> need to secure our "electronic" borders. > > How? By forbidding user access to internet? > > >> >> Yes, better protection will cost some folks serious money in higher >> expenses or lost sales. But do we really need things like instant >> credit (nice way for fraud and identify theft). >> > >
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-02-17 04:53 +0100 |
| Message-ID | <20160217045337.10730219@maxa-pc> |
| In reply to | #159555 |
On Wed, 17 Feb 2016 14:13:50 +1100 "hgww" <hgww@gmail.com> wrote: > > iOS handles that fine. > I am not talking about cell phone operating system here... Perhaps if they used iOS they wouldn't be compromised but I can't imagine all those personel working with iPhones ;)
[toc] | [prev] | [next] | [standalone]
| From | Charlie Gibbs <cgibbs@kltpzyxm.invalid> |
|---|---|
| Date | 2016-02-17 04:21 +0000 |
| Message-ID | <na0sh102e10@news6.newsguy.com> |
| In reply to | #159566 |
On 2016-02-17, Melzzzzz <mel@zzzzz.com> wrote: > On Wed, 17 Feb 2016 14:13:50 +1100 > "hgww" <hgww@gmail.com> wrote: > >> iOS handles that fine. > > I am not talking about cell phone operating system here... > Perhaps if they used iOS they wouldn't be compromised but I can't > imagine all those personel working with iPhones ;) They're too busy _playing_ with them. <g,d&r> -- /~\ cgibbs@kltpzyxm.invalid (Charlie Gibbs) \ / I'm really at ac.dekanfrus if you read it the right way. X Top-posted messages will probably be ignored. See RFC1855. / \ HTML will DEFINITELY be ignored. Join the ASCII ribbon campaign!
[toc] | [prev] | [next] | [standalone]
| From | "hgww" <hgww@gmail.com> |
|---|---|
| Date | 2016-02-17 17:24 +1100 |
| Message-ID | <diii18F8cv6U1@mid.individual.net> |
| In reply to | #159566 |
"Melzzzzz" <mel@zzzzz.com> wrote in message news:20160217045337.10730219@maxa-pc... > On Wed, 17 Feb 2016 14:13:50 +1100 > "hgww" <hgww@gmail.com> wrote: > >> >> iOS handles that fine. >> > I am not talking about cell phone operating system here... No reason why sandboxing can't be used in any OS. > Perhaps if they used iOS they wouldn't be compromised No perhaps about it. > but I can't imagine all those personel working with iPhones ;) Sandboxing works fine with any OS.
[toc] | [prev] | [next] | [standalone]
| From | Morten Reistad <first@last.name.invalid> |
|---|---|
| Date | 2016-02-17 15:07 +0100 |
| Message-ID | <6ebepc-dgt.ln1@sambook.reistad.name> |
| In reply to | #159572 |
In article <diii18F8cv6U1@mid.individual.net>, hgww <hgww@gmail.com> wrote: > > >"Melzzzzz" <mel@zzzzz.com> wrote in message >news:20160217045337.10730219@maxa-pc... >> On Wed, 17 Feb 2016 14:13:50 +1100 >> "hgww" <hgww@gmail.com> wrote: >> >>> >>> iOS handles that fine. >>> >> I am not talking about cell phone operating system here... > >No reason why sandboxing can't be used in any OS. A user-space one could work, but for commercial work I would insist on somthing like Linux vz or FreeBSD jails. These have tested and tried kernel support. >> Perhaps if they used iOS they wouldn't be compromised > >No perhaps about it. > >> but I can't imagine all those personel working with iPhones ;) > >Sandboxing works fine with any OS. iPads would do the trick, whould it not? It has everything you need for a pretty decent terminal. Wifi, acceptable browser, media support, and decent OS security. Decent, not stellar. -- mrr
[toc] | [prev] | [next] | [standalone]
| From | usenet@only.tnx (Questor) |
|---|---|
| Date | 2016-02-17 23:02 +0000 |
| Message-ID | <56c4fc14.6705822@nntp2.rawbw.com> |
| In reply to | #159586 |
On Wed, 17 Feb 2016 15:07:34 +0100, Morten Reistad <first@last.name.invalid> wrote: >iPads would do the trick, whould it not? It has everything you >need for a pretty decent terminal. Wifi, acceptable browser, >media support, and decent OS security. Decent, not stellar. The issue is ISV support. There is a lot of third-party s/w in use.
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2016-02-17 08:03 +0000 |
| Message-ID | <diinq1F9mlqU2@mid.individual.net> |
| In reply to | #159509 |
On 2016-02-16, Melzzzzz <mel@zzzzz.com> wrote:
> Forbid access to internet? Forbid users to plug in usb keys
Yep. And forbid them to have admin access to their machines. (Those machines aren't "theirs", they belong to the company).
--
I don't have an attitude problem. If you have a problem with my
attitude, that's your problem.
[toc] | [prev] | [next] | [standalone]
| From | usenet@only.tnx (Questor) |
|---|---|
| Date | 2016-02-17 23:02 +0000 |
| Message-ID | <56c4fc1f.6716898@nntp2.rawbw.com> |
| In reply to | #159574 |
On 17 Feb 2016 08:03:13 GMT, Huge <Huge@nowhere.much.invalid> wrote: >Yep. And forbid them to have admin access to their machines. (Those machines aren't "theirs", they belong to the company). Lots of places do this. I've seen businesses so locked-down that users can't even change their desktop image.
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2016-02-17 08:01 +0000 |
| Message-ID | <diinm0F9mlqU1@mid.individual.net> |
| In reply to | #159501 |
On 2016-02-16, hancock4@bbs.cpcn.com <hancock4@bbs.cpcn.com> wrote:
> On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote:
>> Google news has an article today about "ransomware" against an LA hospital.
>> The software has encrypted their files and offer to decrypt them for $3.6M
>> payable in bitcoin. The price seems modest to me, but set that aside for
>> the moment..
>
> It seems to me that the I.T. industry needs to do a lot more to secure
> its networks from malware.
IME (and I worked in IT Security for the last 16 years), the IT industry at large generally doesn't GAS. They regard security as a PITA to be bolted on as cheaply and quickly as possible at the very end of a project.
--
I don't have an attitude problem. If you have a problem with my
attitude, that's your problem.
[toc] | [prev] | [next] | [standalone]
| From | Charlie Gibbs <cgibbs@kltpzyxm.invalid> |
|---|---|
| Date | 2016-02-17 18:07 +0000 |
| Message-ID | <na2ct41a33@news4.newsguy.com> |
| In reply to | #159573 |
On 2016-02-17, Huge <Huge@nowhere.much.invalid> wrote: > On 2016-02-16, hancock4@bbs.cpcn.com <hancock4@bbs.cpcn.com> wrote: > >> On Tuesday, February 16, 2016 at 11:37:11 AM UTC-5, Osmium wrote: >> >>> Google news has an article today about "ransomware" against an LA hospital. >>> The software has encrypted their files and offer to decrypt them for $3.6M >>> payable in bitcoin. The price seems modest to me, but set that aside for >>> the moment.. >> >> It seems to me that the I.T. industry needs to do a lot more to secure >> its networks from malware. > > IME (and I worked in IT Security for the last 16 years), the IT industry > at large generally doesn't GAS. They regard security as a PITA to be bolted > on as cheaply and quickly as possible at the very end of a project. Furthermore, for many people (not just IT staff) security is just a way of giving yourself the warm fuzzies. It doesn't matter whether the measures are effective; what matters is the warm glow you get from the knowledge that Something Has Been Done. Security is difficult to measure, so many people fall back on a totally inappropriate metric: how much it inconveniences legitimate users. -- /~\ cgibbs@kltpzyxm.invalid (Charlie Gibbs) \ / I'm really at ac.dekanfrus if you read it the right way. X Top-posted messages will probably be ignored. See RFC1855. / \ HTML will DEFINITELY be ignored. Join the ASCII ribbon campaign!
[toc] | [prev] | [next] | [standalone]
Page 1 of 16 [1] 2 3 … 16 Next page →
Back to top | Article view | alt.folklore.computers
csiph-web