
OpenSSH now warns about “non-post-quantum” connections
Quantum computers may never get there, but the regulators in many countries are preparing just in case they do.


Healthcare financial services provider Craneware has reported itself to the FBI in the US, and to the Information Commissioner’s Office (ICO) in the UK, over a cyberattack.
Craneware doesn’t directly provide health care such as nursing, doctoring, and actual treatment; instead it offers:
[A]pplications and [an] industry-leading team of experts [that] contextualize operational, financial, and clinical data, providing insights that clearly demonstrate realistic revenue integrity and 340B compliance opportunities for our customers.
In a document submitted to the London Stock Exchange (LSE), the company offers the curious admission that “a significant volume of file names were viewed and exfiltrated,” which at first reading makes it sound as though file contents (the data in the files themselves) were not stolen in the breach.
But the admission continues by saying that “a large element of the data involved is non-sensitive or already public regulatory data.”
This suggests that, in the breach, the attackers not only created a list of available file names, but also stole all the files on that list.
Remember that even non-sensitive data retained by a company for its own commercial benefit or regulatory compliance isn’t supposed to be accessible to outsiders at will.
And the disclosure statement continues by noting that “a percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.”
Simply put, although some of the stolen data might be considered “harmless” even though it’s now in the hands of cybercriminals, some of it sounds very personal and private indeed.
In this context, the words percentage and subset aren’t helpful, given that the percentage could be 100%, and in mathematical parlance, a set in its entirety is considered to be a subset of itself.
Don’t forget, when talking about cyberattacks, that a breach of N critical records of personal information isn’t somehow mitigated just because 10N or even 100N non-personal and apparently “harmless” records were stolen at the same time.
After all, the cumulative damage caused by a breach can’t get smaller as the breach itself gets bigger!
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Quantum computers may never get there, but the regulators in many countries are preparing just in case they do.

For those of you who are just joining us, I’m retired Marine and security expert Scot Hutton and I’ve been invited by my friends at SolCyber to write a blog series on security that matters. So far, I’ve covered why ransomware has forever changed the security landscape for small and mid-sized businesses (SMEs) and explained why now is the time for SMEs to invest in cybersecurity. In this post, I’ll cover security frameworks and why in many cases, they don’t […]

As a small business, you probably think you’re small potatoes to hackers. Unfortunately, the opposite can often be true. Smaller businesses that are part of supply chains are frequently chosen by hackers because they are an easy target as a valuable foot in the door to a substantially larger company. In fact, in 2022, businesses reported that about 1 in 5 data breaches came from a supplier. You want to be seen as an asset to the companies you serve, […]

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






