SingHealth’s database has experienced a major cyber-attack. 1.5 million patients have had their personal particulars stolen. Of these, 160,000 also had their outpatient medication data compromised. I am personally affected, and not just incidentally. The attackers targeted my own medication data, specifically and repeatedly.
I don’t know what the attackers were hoping to find. Perhaps they were hunting for some dark state secret, or at least something to embarrass me. If so, they would have been disappointed. My medication data is not something I would ordinarily tell people about, but there is nothing alarming in it.
When SingHealth digitised its medical records, they asked me whether to computerise my own personal records too, or to keep mine in hardcopy for security reasons. I asked to be included. Going digital would enable my doctors to treat me more effectively and in a timely manner. I was confident that SingHealth would do their best to protect my patient information, just as it did for all their other patients in the database.
Of course, I also knew that the database would be attacked, and there was a risk that one day despite our best efforts it might be compromised. Unfortunately that has now happened.
The security and confidentiality of patient information is a top priority. I have ordered the Cyber Security Agency of Singapore - CSA and the Smart Nation and Digital Government Group (SNDGG) to work together with the Ministry of Health, Singapore to tighten up their defences and processes across the board. We are convening a Committee of Inquiry to look thoroughly into this incident. It will doubtless have valuable conclusions and recommendations, which will help us do better.
This will be a ceaseless effort. Those trying to break into our data systems are extremely skilled and determined. They have huge resources, and never give up trying. Government systems come under attack thousands of times a day. Our goal has to be to prevent every single one of these attacks from succeeding. If we discover a breach, we must promptly put it right, improve our systems, and inform the people affected.
This is what we are doing in this case. We cannot go back to paper records and files. We have to go forward, to build a secure and smart nation. – LHL
同時也有10000部Youtube影片,追蹤數超過62萬的網紅Bryan Wee,也在其Youtube影片中提到,...
「data confidentiality」的推薦目錄:
- 關於data confidentiality 在 Lee Hsien Loong Facebook
- 關於data confidentiality 在 OSSLab Geek Lab Facebook
- 關於data confidentiality 在 Dr 文科生 Facebook
- 關於data confidentiality 在 Bryan Wee Youtube
- 關於data confidentiality 在 Travel Thirsty Youtube
- 關於data confidentiality 在 スキマスイッチ - 「全力少年」Music Video : SUKIMASWITCH / ZENRYOKU SHOUNEN Music Video Youtube
data confidentiality 在 OSSLab Geek Lab Facebook 八卦
OSSLab Geek Lab解讀一下最近鬧的滿城風雨的公民實驗室的Zoom安全報告
這是篇非常棒的如何拆解加密封包還原視訊跟音訊資安文...
1. H.264視訊碼流最小單位為NALU
一個NALU = 一組對應於視頻編碼的NALU頭部信息+ 一個原始字節序列負荷(RBSP,Raw Byte Sequence Payload).
這邊nal_unit_type都為0 ,無法判定類型.
不過最後有分析出NAL Payload有後面數據大小,為data slice解密後,組合後為H.264 video stream.
2.對電腦DRAM 做數位鑑識,發現名為conf.skey此為AES 128 key 全部使用者跟會議內容都用此key加密傳送跟接收後解密.
3.錄到封包後,要考慮到一個client都用同個SSRC,另外用時間戳組來拼順序,用key解密再組合成完整視訊raw檔案.
4.音訊一樣加密,推測用啥音訊codec ,是利用RTP間隔時間戳相隔多大來判定.640所以應該為Silk16 codec.
5.在Linux版本Zoom設定proxy上設為自建的mitmproxy, 會報警告說未驗證.從mitmproxy也可得到密鑰AES-128 conf.skey
6.測試中發現在加拿大跟美國通訊用戶 AES-key 是由52.81.151.250位於北京Server配送的
因此最終懷疑,確實有可能.若中國政府要求可取得此密鑰若有測錄封包就可解密還原內容.
7.最後Zoom官方的回應是
中國以外的用戶,會立即將中國大陸的數據中心從服務器中刪除。
圖片引用
UniHub 有你好棒
參考
https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/
http://0rz.tw/HOiaK
https://commons.erau.edu/cgi/viewcontent.cgi?article=1174&context=jdfsl
http://blog.gitdns.org/2017/03/14/h264/
#OSSLab #數位鑑識 #拜託國家訂的資安檢測要這樣水準
data confidentiality 在 Dr 文科生 Facebook 八卦
【聯合聲明:強烈讉責醫管局向警方洩漏病人私隱】
今日下午,醫學界立法會議員陳沛然醫生召開記者會,展示證據,揭發醫管局內電腦系列內設有「後門」,令任何人可在毋須登入下取得病人資料。系統當中更有列明「For Police」,專為警方而設的版面,當中載有英文全名、身份證號碼、年齡、性別、電話號碼、出入院時間及住院病房等病人資料,更有標籤將部份病人分類至「立法會外大型集會」人士。陳議員亦取得醫管局內部通訊電郵,要求員工於電腦系統內標籤參加「立法會外大型集會」的求醫人士。
我等一眾醫學生組織,謹此對醫管局洩漏病人私隱一事予以強烈讉責。醫學院教導同學,維護病人私隱為最重要的醫學倫理之一,更時常強調醫患關系乃醫療工作之基石。今日,醫管局管理全港公立醫院,卻在無任何臨床需要及未得病人同意下將病人私隱拱手交予警方,違背專業道德。上周起,因應警方進入醫院拘捕傷者,已有不少市民對醫護失去信心,甚至有市民因此避免到醫院求醫。為挽回事件對醫患關係的破壞,醫管局必須盡速公開向廣大市民及受影響病人致歉、交待事件,並修補漏洞。同時,個人資料私隱專員公署亦應介入調查,保障市民權益。
青醫匡時 香港大學醫學生時政組織
香港大學學生會醫學會
香港大學學生會醫學會護理學會
香港中文大學學生會醫學院院會
香港中文大學那打素護理學院院會
香港中文大學教務會民選學生成員(醫學院)
————————————————————
【Joint Statement of Condemnation towards the Hospital Authority for Exposing Patient Information to the Police Force】
In a press conference held this afternoon, Dr Hon Pierre Chan, member of the Legislative Council for the Medical functional constituency, showcased evidence of a “backdoor” in the Hospital Authority’s electronic patient record (ePR) system that grants anyone access to patient information without the need of logging in. The interface is remarked with “For Police”, and exposes information including patients’ full name, HK Identity Card number, age, sex, phone number, admission time and ward, with indication of whether they have participated in the “mass gathering outside Legco”. Dr Hon Chan has also acquired an earlier email circulating in the Hospital Authority intranet showing frontline healthcare staff being requested to identify and label patients who have participated in the “mass gathering outside Legco”.
We, as medical students from the University of Hong Kong and The Chinese University of Hong Kong, hereby strongly condemn the Hospital Authority for infringing upon patients’ privacy. “Confidentiality” is one of the four pillars of medical ethics, and is the cornerstone of the doctor-patient relationship. As the largest public healthcare provider in Hong Kong, the Hospital Authority has violated the medical code of conduct by exposing patients’ information to the police without patient consent nor clinical necessity. Since last week, the police have been arresting injured protesters receiving medical care within Hospital Authority premises, sabotaging doctor-patient trust and deterring citizens from seeking medical attention in public hospitals.
The Hospital Authority must apologise to all affected citizens in Hong Kong, conduct a formal inquiry into the incident and block the backdoor immediately. We also call for investigatory action from the Office of the Privacy Commissioner for Personal Data of Hong Kong to protect citizens’ rights to privacy.
Eramedics, HKU Medical Students' Current Affairs Concern Group
Medical Society, HKUSU
Nursing Society, Medical Society, HKUSU
Medical Society, CUSU
Nursing Society, the Nethersole School of Nursing, CUSU
Elected Student Senator (Faculty of Medicine), CUHK
data confidentiality 在 Bryan Wee Youtube 的評價
data confidentiality 在 Travel Thirsty Youtube 的評價
data confidentiality 在 スキマスイッチ - 「全力少年」Music Video : SUKIMASWITCH / ZENRYOKU SHOUNEN Music Video Youtube 的評價
data confidentiality 在 DATA CONFIDENTIALITY - Glossary | CSRC - NIST Computer ... 的相關結果
Data Confidentiality deals with protecting against the disclostire of information by ensuring that the data is limited to those authorized or by ... ... <看更多>
data confidentiality 在 Data Confidentiality - an overview | ScienceDirect Topics 的相關結果
Data confidentiality indicates the guarantee that data can be accessed and modified only by authorized entities. Not only users, but authorized things may also ... ... <看更多>
data confidentiality 在 Managing data confidentiality - University of Delaware 的相關結果
Data confidentiality is about protecting data against unintentional, unlawful, or unauthorized access, disclosure, or theft. Confidentiality has to do with the ... ... <看更多>