logoalt Hacker News

dflocktoday at 4:35 PM4 repliesview on HN

No one knows how many vulnerabilities there are in closed source medical record software - because we can't check. There are _probably_ loads though, because that medical software is super terrible in every way that we _can_ check.


Replies

nradovtoday at 6:50 PM

Well the closed-source EHR applications that use NoSQL databases such as MUMPS (InterSystems Caché) probably don't have many SQL injection vulnerabilities.

oatmeal1today at 4:56 PM

Or voting machines.

show 1 reply
1970-01-01today at 5:45 PM

Isn't anything closed-source by definition this? Why speak of the subset of closed-source medical record software when it's just the entire class of software?

0xdeadbeefbabetoday at 4:59 PM

SQL injection and XSS come up in dynamic analysis too.