Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

31–40 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#31
Greeeeeeeeat. Anthem just became my health care provider. This fills me with confidence.

I'm especially unimpressed by Anthem's failure to hire a good copy editor for such a vital message, as evidenced by the painfully obvious error at the end of the penultimate paragraph: "share that information you" should read "share that information with you".

Re: “Anthem was the target of a very sophisticated external cyber attack”

#32
Identity Theft is not a thing. Others have pointed this out in the past here on HN.

https://news.ycombinator.com/item?id=7369725

https://news.ycombinator.com/item?id=6583776

https://news.ycombinator.com/item?id=7369713

https://news.ycombinator.com/item?id=3482991

https://news.ycombinator.com/item?id=6583879

https://news.ycombinator.com/item?id=3483009

Re: “Anthem was the target of a very sophisticated external cyber attack”

#33
post #25
post #23

Earlier quoted context omitted.

That's really my problem -- that they're leaving their victims to speculate. It's great that they "made every effort to close the security vulnerability". How's that going? They hired Mandiant to "evaluate our systems and identify solutions based on the evolving landscape." Is "evolving landscape" CEO-speak for "Oh, god, we're still leaking customer data like a sieve, make it stop!"? I'm just going to keep speculatin…

>It's great that they "made every effort to close the security vulnerability". I love that quote, they try to cover their asses by saying we closed the vulnerability. My question is why did you wait till it was taken advantage of?

Even better is that they didn't explicit state that they did close the vulnerability -- simply that they put forth every effort to do so.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#34
post #4

I know my credit card company allows me to set a password to prevent unauthorized access from someone who might have stolen this kind of data. Is there a similar system in place to make it harder for an identity thief to open accounts in my name or do other things that might damage my reputation?

I am certainly not endorsing nor do I use it personally, but Lifelock does exactly this. There are a few others as well.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#35

Identity Theft is not a thing. Others have pointed this out in the past here on HN. https://news.ycombinator.com/item?id=7369725 https://news.ycombinator.com/item?id=6583776 https://news.ycombinator.com/item?id=7369713 https://news.ycombinator.com/item?id=3482991 https://news.ycombinator.com/item?id=6583879 https://news.ycombinator.com/item?id=3483009

Mitch and Webb sketch on identity theft not being a thing https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: “Anthem was the target of a very sophisticated external cyber attack”

#38
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

Could this be any more patronizing and offensive? Look, if you are Anthem member, or if you were an Anthem member, you've been doxxed... and quite comprehensively:

have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data

And you were doxxed nearly two months ago. Or maybe not, because Anthem goes out of its way to NOT tell you when this occurred. If you were affected here's how they will notify you:

We continue working to identify the members who are impacted. We will begin to mail letters to impacted members in the coming weeks.

So sometime within the next month you will get a snail mail telling you that you were doxxed... and that letter will probably be extremely vague about the details, but will be quite heavy on the PR and perhaps even have a nice picture of Grandpa CEO at the top.

Anthem is not taking this seriously. No matter what they are trying to communicate with their PR gloss, they seem to care about covering their asses first and really don't seem to give a hoot about all your personal data that is out there in the wild.

More like AnthemLies.com...

Re: “Anthem was the target of a very sophisticated external cyber attack”

#39
post #26
post #17

Earlier quoted context omitted.

The security products arent great, true, but the ppl working as security engineers in companies are often quite decent. It seems to me that its the usual issue. People don't see the need for protection until they've been hit. It seems to be a cost that doesn't make sense to them. They don't even care anymore. Then they get hit hard. But it can take years.

I've actually had the exact opposite experience. Security Engineers at most companies have no idea what they're doing beyond running the scanner and parroting whatever it spits out. "The scanner says your server is vulnerable" "Ya, we patched that vulnerability weeks ago" "The scanner says it's vulnerable" "OK.... looks at scanner - oh, it's just reading the banner, and not taking into account that the major rev didn…

>Do you really want to be the guy who gets thrown under the bus because you had to disable strong passwords because the CEO was angry he needed both upper and lower case letters in his AD password?

Except those strong password policies don't strengthen security at all, neither in theory nor practice. Congratulations, the CEO's password is now "qweRTY" and it's written on a yellow sticky-note on his monitor.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#40
post #20

It makes me wonder. For several years the US government, Medicare, and private insurers have been pushing hard for health care providers to adopt Electronic Health Record systems. Now in the current phase "interoperability" of EHR systems is the catchword. A question to ask is how secure is a large network of EHRs going to be? I don't know of data showing the frequency or severity of EHR security breaches but it woul…

"A question to ask is how secure is a large network of EHRs going to be?"

LOL, everyone 'on the inside' (by that I mean: at least anyone who works on computers, software or networks professionally) knows the answer to that question: it's going to be a train wreck. There is not a single person on this planet who really understands just 1% of the software, hardware and network infrastructure they/we work on every day; let alone how all of these interact. Computers, in 2015, are so complex, and our 'engineering' is so shoddy, that there is no way to safeguard networked data for anyone but the most determined and resourceful parties (by which I mean organizations of which there are but a handful in the whole world, and even those can't seem to keep secrets really secret.) Either way, there is no way at all that a non-IT focused organization like a healthcare insurer or provider will be able to keep data secure, and it's only a matter of time before incidents like this will become commonplace.

Consider: I have an in-law who is a partner in a largish practice in my area. We talked a bit about the business aspects of the practice when she became a partner because she had to put up with all the management crap all of a sudden and it was nice for her to vent to people who had similar issues. Anyway, point being I know a bit about the finance and management of a rather typical organization like that. These people will in the next 5 years somehow get access to our, by then, country-wide EHR system. They work on computers they buy from the local computer shop because the prices 'seem reasonable' and Jimmy who works there dates the secretary or whatever; so Jimmy (whose training was in swapping out hard disks and reinstalling Windows) is the one who 'maintains' their systems, too. Their cash flow is so precarious that some months they can't pay full wages to the partners. How will an organization like that ever be able to secure their network? Their 'security' consists of the cable guy setting a non-default WPA key on their wireless router.

And of course, they're required by the organization that maintains the EHR system to have 'regular auditing of their systems' to ensure security. Which consists of a couple of big 4 consultants who interview the management, tick some boxes on their checklist and make a 50-page CYA report out of that, without ever having touched a server or network.

I got out of the security game 10 years ago, and it was already scary back then. Maybe somebody who still works there will feel otherwise, but computer security (on the blue team) is like FEMA sending two guys with a shovel and a Walmart plastic bucket to a dike breach. (whereas on the red team it's shooting fish in a barrel, of course.) We are truly fucked, because too few people understand the magnitude of the problem and as long as there are no problems and you don't look too closely at the robustness of things, using computers is much cheaper than the alternatives.

Post reply on HN