Discussion about this post

User's avatar
Ismaele's avatar
7hEdited

I seriously doubt that Iranian hackers would ever target hospitals and the healthcare sector, based on Islamic law (Sharia). Other critical infrastructure maybe, depending on the type of cyberattack the Outlaw US Empire launches on Iran first, but hospitals definitively no! In order of decreasing probability (from high to low):

1. electricity

2. communication

3. logistics

4. water and wastewater

5. healthcare

Tom Welsh's avatar

"[T]he Pentagon and Wall Street are well protected, of course..."

I really, really would not count on that. Not for a moment. Do you believe that the Pentagon, which cannot even run its own core business of killing people competently, has taken the trouble to instil security into its many, many computers ranging from huge mainframes to smartphones and watches? Of course not. Moreover, the ethos of computer security is directly incompatible with that of military discipline and procedure. Few really good security people would be prepared to work for military officers who have no inkling of their world or the way they have to think.

As for Wall Street... the same in spades. Who is going to get promoted on Wall Street for fixing or improving - or even instituting - computer security? No one who matters. And why would anyone else care?

I used to lecture on computer security, and some of the basic axioms are fundamentally alien to both institutions. Read Cliff Stoll's classic 1989 book "The Cuckoo's Egg", take time out to weep briefly (or laugh uncontrollably, depending on your personality) - then ask yourself how likely it is that things have got better or worse, or stayed the same, in the intervening 37 years. I would guess "much worse" - and that's a very high bar.

Many years ago - decades, actually - I used to cite a story from the 1950s about a top-secret DoD system designed to protect against missile attacks. It was specified with the absolute maximum of everything - processor, memory, peripherals - because performance was hyper-critical. Then, when all that had been specified and actually tested, another department insisted that maximum security be added. Of course performance vanished into a black hole, and there were furious rows. Meanwhile, the staff got kudos for fixing the problem and restoring the expected performance. How? They systematically removed or disabled every single one of the expensive security features.

Today's computers are hopelessly insecure and cannot be made secure. The very processors and RAM chips, the network cards, the wireless systems, the firmware, the underlying libraries - everything is suspect and even if OK today may be subverted tomorrow.

I would bet big money that the Iranians already have a network of fine wires around the Pentagon's testicles - and Wall Street's too - ready to tug at a moment's notice.

It's the perfect deterrent against a nation with thermonuclear deterrent and powerful navy and air force. No need to go there to wreak havoc - just type in a few commands. They might even manage plausible deniability. "How could we have done all that, with our backward technology and complete lack of know-how?"

30 more comments...

No posts

Ready for more?