Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Someone the other day wrote an excellent comment explaining why you can't just replace Windows with Linux in some professional environments like hospitals: medical hardware drivers that are only available for Windows.

I'll try to find and link that comment that managed to make a better point than I did.



You can unplug the ethernet cable, however. Or at least firewall it.


This is what we did 10 years ago when I worked in a hospital.

We knew these devices were insecure by default. Some even shipped with a network enabled MS SQL Server with a blank sa-password. Quite literally a free root-kit.

Scientists and doctors working on these machines were forced to use portable storage (floppies, ZIP-drives or CD-RWs).

It was cumbersome, but no network was a strict policy, and it was there for a reason.


That's refreshing to hear that whoever had the authority in that situation also had a brain.

I wonder how tricky it would have been to set up a MAC- and plug-location-based VLAN to isolate those devices onto, with a very very carefully locked down machine sitting between the devices and the rest of the network. Deep packet inspecting firewall, copious logging, antivirus turned up to 11, the works.

I ask because I'm curious how well a theoretical setup like the above would have worked out for the described scenario - I'm sure there are similar environments where it may be impossible to get having no network approved by management.


Do we even know medical devices were affected, the reporting has been so shallow I'm not sure whether they have or it was just administration.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: