Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not even sure that hospitals are under-investing in security so much as that the current security paradigms are dysfunctional for hospitals (and a few other key industries).

The current security paradigm includes a lot of rapid adjustment. Upgrade this package immediately, ship a new binary using an upgraded library, firewall this off right now, etc.

I think that might be fundamentally incompatible with an environment where downtime can be counted in human lives. The risk calculations are a lot harder when death is a potential outcome of downtime caused by upgrades.

I don't have a magic bullet solution to that, but I do think that gets lost in a lot of the armchair security discussions around hospitals. They operate under very different expectations than the rest of us.



Pay for university professors to be experts in maintaining this civil infrastructure, for the maintenance of the commons. Reward bounties to students and volunteers who triage and resolve issues.

Have an expressly stated set of goals about the above as well as a core set of stable priority maintained software that gets extra security vetting. Formal analysis, whole classes of students in different locations scrutinizing and learning every line of code, function, and the overall design. Formal validation where possible.


Have you seen the kind of code professors write?


Yes, we should in theory have an option for a completely secure platform for such critical infrastructure.

Several attempts at creating such systems have been made in the past, but little effort has been put into actually leveraging them in the wider world.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: