Live data from Hacker News

UnitedHealth says data of 100M stolen in Change Healthcare hack

bleepingcomputer.com

31–40 of 41 posts

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#31
post #19

Earlier quoted context omitted.

> Look at "inflation" - every business was able to blame "supply chain issues" (that they caused by removing redundancies) during COVID to extract unthinkable price increases out of the public. Are you implying there were no supply chain difficulties? China wasn't under heavy lockdown for months on end? There weren't ports with months of backlog? Factories weren't closed due to lockdowns or outbreaks all around the w…

"The biggest study of ‘greedflation’ yet looked at 1,300 corporations to find many of them were lying to you about inflation" – https://fortune.com/europe/2023/12/08/greedflation-study/

headline: "many of them were lying to you about inflation"

actual article:

>A joint study by think tanks IPPR and Common Wealth found profiteering by some of the world’s biggest companies forced prices up significantly higher than costs during 2022.

>[...]

>While this obviously contributed to rising prices, the report finds that company profits increased at a much faster rate than costs did, in a process often dubbed “greedflation.”

Where's the "lying"?

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#32

Earlier quoted context omitted.

"The biggest study of ‘greedflation’ yet looked at 1,300 corporations to find many of them were lying to you about inflation" – https://fortune.com/europe/2023/12/08/greedflation-study/

Doesn’t everyone sell at the highest price they can, without regard for their COGS? I don’t break out my household expenses when I negotiate pay at a new employer.

The meat of the article is basically "profit margins went up". The same arguably happened for software engineers. By the same logic, there should be headlines of "The biggest study of ‘greedflation’ yet looked at 1,300 software engineers to find many of them were lying to you about inflation".

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#33

So would this count as 1 instance or 100M instances of HIPAA violations? Last I checked the penalty is $50k per violation...

Does getting data stolen through no fault of your own count as a HIPPA violation? If negligent security counts, what's the bar?

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#35

Earlier quoted context omitted.

"The biggest study of ‘greedflation’ yet looked at 1,300 corporations to find many of them were lying to you about inflation" – https://fortune.com/europe/2023/12/08/greedflation-study/

Doesn’t everyone sell at the highest price they can, without regard for their COGS? I don’t break out my household expenses when I negotiate pay at a new employer.

Imagine you own a grocery store in a small town. The only one, in fact, and the nearest competitor is a 30 minute drive.

You, being a free market enthusiast, decide to test how much the market will bear, and raise your prices across the board.

Your customers, who are also your neighbors and friends, respond by socially ostracizing you.

This doesn’t exist at scale, because the people responsible for the unnecessary price hikes live far away from their customers, and do not intend to ever meet them, much less explain themselves.

People should price products to make a fair profit, one where both parties are satisfied. I don’t begrudge a car salesperson for selling me a car at above their cost, but I do if it’s wildly marked up.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#36
post #33

So would this count as 1 instance or 100M instances of HIPAA violations? Last I checked the penalty is $50k per violation...

Does getting data stolen through no fault of your own count as a HIPPA violation? If negligent security counts, what's the bar?

It does, actually. There are four tiers [0], with unknowing violation at the bottom, followed by reasonable cause. Personally I’d place this at least at the reasonable cause tier.

[0]: https://www.ama-assn.org/practice-management/hipaa/hipaa-vio...

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#37

I always wonder that maybe someone can convince these health companies, clinics, etc... to start using Qubes OS for their network connected office computers. Maybe that could prevent a sizeable number of these ransomware attacks? TLDR Qubes OS is a security focused operating system that is geared towards end users. It relies on isolation via the Xen hypervisor (has much less privileged code than Linux, Windows, or Ma…

Think how many companies have been found to have world-accessible S3 buckets. And you think they’re capable of administering Linux, let alone a niche OS like Qubes?

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#38
post #19

Earlier quoted context omitted.

> Look at "inflation" - every business was able to blame "supply chain issues" (that they caused by removing redundancies) during COVID to extract unthinkable price increases out of the public. Are you implying there were no supply chain difficulties? China wasn't under heavy lockdown for months on end? There weren't ports with months of backlog? Factories weren't closed due to lockdowns or outbreaks all around the w…

"The biggest study of ‘greedflation’ yet looked at 1,300 corporations to find many of them were lying to you about inflation" – https://fortune.com/europe/2023/12/08/greedflation-study/

> The biggest perpetrators were energy companies like Shell, Exxon Mobil, and Chevron, which were able to enjoy massive profits last year as demand moved away from Russian oil and gas.

> Food producers including Kraft Heinz realized their own profit surges. The war in Ukraine rocked global grain supplies and fertilizer prices, significantly increasing the cost of food, which remains sticky.

Funny, in both cases external causes made the global prices go up, so specific companies used the opportunity to increase their prices because there was less competition on the market.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#39

Earlier quoted context omitted.

Doesn’t everyone sell at the highest price they can, without regard for their COGS? I don’t break out my household expenses when I negotiate pay at a new employer.

Imagine you own a grocery store in a small town. The only one, in fact, and the nearest competitor is a 30 minute drive. You, being a free market enthusiast, decide to test how much the market will bear, and raise your prices across the board. Your customers, who are also your neighbors and friends, respond by socially ostracizing you. This doesn’t exist at scale, because the people responsible for the unnecessary pr…

I don’t have to imagine, I do it every day. I sell my services for the most amount of money I think I can get.

Of course, if I am selling services or goods with lots of repeat business, it might behoove me to not piss off the customers and hence incentivize me to keep my price lower (which is still optimizing for the most money I think I can get, just over the long term rather than short term). If I am selling land or a business, then I am maximizing for that specific transaction, even if my profit margin is 100,000%.

When you get a job offer, and you respond back with a request for an additional $20k per year or whatever, that is doing the same thing.

> make a fair profit

What is fair is an opinion. For people living in huts, a 1,000 sq ft Soviet style apartment bloc with plumbing is unfair. And for people living in Soviet style apartment blocs, a modern 5 over 1 apartment building is unfair. And then you might find a detached single family home unfair. And then you might find a 3k sq ft home unfair.

And so on and so forth.

Re: UnitedHealth says data of 100M stolen in Change Healthcare hack

#40
post #25

I always wonder that maybe someone can convince these health companies, clinics, etc... to start using Qubes OS for their network connected office computers. Maybe that could prevent a sizeable number of these ransomware attacks? TLDR Qubes OS is a security focused operating system that is geared towards end users. It relies on isolation via the Xen hypervisor (has much less privileged code than Linux, Windows, or Ma…

Not sure using a different OS helps the issue, if not making it worse -- * These days hackers have a lot of resources and are often nation state actors. They utilize 0 day vulnerabilities. I don't see how an obscure OS will do any better than mainstream OS in terms of detecting and responding to exploits * Many hacks actually start with social engineering, and human becomes the weakest point (well, in some sense, it…

Less privileged code would mean less zero day exploits. Qubes relies on an order of magnitude less privileged code than Linux, and I believe Xen has had far fewer escalation of privilege exploits than Linux kernel

"Open suspicious links in disposable VMs" change that to "Open all links using the appropriate process"

But yeah, the social engineering though...

Post reply on HN