Boy it sure does fill me with confidence to know that I am hearing about my personal information having been compromised through a news website rather than through the incompetent organization that allowed my information to be leaked in the first place...
“Anthem was the target of a very sophisticated external cyber attack”
101–110 of 206 posts
Re: “Anthem was the target of a very sophisticated external cyber attack”
#102Earlier quoted context omitted.
In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.
Sweden's entire population is about the size of the Chicagoland area. Now imagine 320+ million people all living in different semi-autonomous states all with their own bureaucracies and hundreds of taxing authorities. Now imagine proposing a national ID card to these people. Yeah, its not that easy. The US isn't centralized like a lot of European nations. Governance of very critical things are done on the state level…
Actually a surprising number of people don't. For either medical (dermatitis), work (manual laborer wearing them out, operation room personnel scrubbing them out...) or age related reasons.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#103I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…
Re: “Anthem was the target of a very sophisticated external cyber attack”
#104Curious if the HN community has any recommendations for identity-theft monitoring services? Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach. Are there better alternatives to ProtectMyID?
Go to any of the three credit reporting agencies and fill out the "fraud alert" form. That will place a hold on your credit report at all three credit agencies and anyone applying for credit under your name will be blocked. The entity that the person is applying for credit with has to contact you using the contact information you provide to verify that it is indeed you that's applying for credit.
"Ask 1 of the 3 credit reporting companies to put a fraud alert on your credit report. They must tell the other 2 companies. An initial fraud alert can make it harder for an identity thief to open more accounts in your name. The alert lasts 90 days but you can renew it."
[http://www.consumer.ftc.gov/articles/0275-place-fraud-alert]
Re: “Anthem was the target of a very sophisticated external cyber attack”
#105I like the two Anthem job reqs that were very recently added: 2/4/15 (umm, today): http://www.careers.antheminc.com/jobs/cloud-encryption-secur... 1/30/15: http://www.careers.antheminc.com/jobs/checkpoint-firewall-ex... Could be a coincidence, but I wouldn't be surprised if they were compromised several days before this press release.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#106I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…
Thanks for the advice. Can you give some specific steps on how to "monitor your child's SSN for activity"? How would I go about doing this?
You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/research/security-freeze/
And then there's the myriad of companies who can give you protection for a monthly fee:
AllClearID: https://www.allclearid.com/
LifeLock Junior: http://www.safety4yourkids.com
Also, Experian has a monitoring service as well specifically for kids: http://www.familysecure.com/
Hope this helps.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#107I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…
I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#108Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.
It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that.
Health care in the US is . . . the phrase "utterly broken" isn't strong enough. We need a good fifteen syllable German word for how fantastically fucked up it is.
Of course I'm trying to explain Anthem hanging onto data. Probably it was totally selfish ("we can send them spam") or sheer laziness.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#109Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…
Management focus would ensure everyone in the organisation focuses on security but most security breaches are the result of IT people doing stupid things or making stupid decisions on the ground. It's not senior management's role to check that you didn't introduce a SQL injection risk in your code. Like it is not senior management's role to check that the accounting department followed properly the latest US GAAP guidelines. It's down to employees being competent at what they do.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#110I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…