Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

141–150 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#141

Earlier quoted context omitted.

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

> We really do need to find a better way of authenticating and identifying people What about not doing that at all? Hear me out. Not relying on "identity" would cost many orders of magnitude less. And besides, why should I care who you are-- what does your identity matter to me? And why should anyone else care?

It sounds like you're putting the bait out so somebody will disagree with you and then you'll explain the alternative to using identity as a form of authorization.

Can you save us a long and stupid discussion and simply explain your plan to practically deploy a better authorization system that will cost many orders of magnitude less?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#143

Earlier quoted context omitted.

But it is private and it does unlock keys to lines of credit. It is not simply a "primary key" as stated, whether or not that was the original intent is not the argument here however. Recall the LifeLock CEO* plastered his SSN publicly and felt the repercussions. While I won't suggest you do that here - just knowing that if you did the assumption is bad things will happen in due time. Keeping SSNs private today is a…

I heard about that, but when you publicly tell a bunch of hackers "come at me bro", you have to expect that kind of reaction. But realistically, the cat is out of the bag with regards to SSNs. Legally you can obtain someone's SSN for very little money. If you go the illegal route, I'd be willing to bet that there is black-market identity data on over half of Americans. We really need to treat SSNs as about as secret…

Conversely getting 100k SSNs vs spending a significant amount of time and/or money on a handful is a different story. I'm not disputing that SSNs might be easy to obtain, but obtaining them at scale via breaches as this are apples and oranges. One is targeting a company because it is known to handle this information, the other is targeting an individual.

The difference is simply data dispersion. If a breach dump ends up on the public Internet everyone has access to that data, worst case scenario, infinitely. Individual targeting has a similar risk but the overall impact is smaller.

Not sure what your point is with the "head in the sand" comment - I happen to work for a security company in an engineering role. I'm not, in any way, defending security through obscurity or the way SSNs are used or (mis)handled. Reading through these comments it is apparent credit agencies don't even get it - and that is disturbing in itself.

But stating that you "doubt a whole lot of SSNs were gathered in this hack that weren't already effectively disseminated widely" is, in fact, a head-in-sand approach compared to doing everything you can to preserve and prevent in the mean time. I, personally, don't agree.

edit: added "compared" to second to last sentence for clarification

Re: “Anthem was the target of a very sophisticated external cyber attack”

#144
post #37

High five to all the CISAs, CISMs, CGEITs, CRISCs and CISSPs at Anthem.

It's important to remember that many of the security folks at these companies are actually pretty good. This is more of a C-Suite problem than a security team problem - security people can't get much done if senior management doesn't prioritize a good information security program.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#145
post #124

Earlier quoted context omitted.

That's just not true. The direction of IT certainly is set by upper management, as well as the budget. If IT says 'we need an IDS' and management says 'it's not in the budget', what can IT do about it? If IT says 'it will take this long and this much money to change our password policy' and management say 'work on new things, not changing old things', what can IT do about it? Senior management might not directly set…

Well, somehow engineers and architects manage to resist management pressures in favor for security, you don't see many bridges collapsing but they have financial constraints too. And accountants resist management pressures to bend the accounting standard, or they go to prison too. IT is in many respect an unregulated profession. Pretty much anyone can declare himself a programmer. There are some regulations on certai…

There are certain regulations about IT, enforced not by the government but by private companies (such as PCI).

I'm just going to have to disagree with you and move on about regulating the people, though. I see your point, but I just don't agree. If anything, I feel managers should be regulated, so they are only allowed to oversee positions where they have the knowledge to fully understand what their direct reports are doing, from front-line to c-level. That's what I feel is the problem.

SOX isn't a regulation of the programmer, it's a verification that his management actually doing their job overseeing him.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#146
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

If they misled the New York Times, then they've also misled the Wall Street Journal[1]:

> "Anthem’s Mr. Miller said the first sign of the attack came in the middle of last week, when a systems administrator noticed that a database query was being run using his identifier code although he hadn’t initiated it."

AnthemFacts was registered 54 days ago, which would be within the legal timeframe for disclosure that the Wall Street Journal notes in their article:

> "Federal law requires health-care companies to inform consumers and regulators when they suffer a data breach involving personally identifiable information, but they have as many as 60 days after the discovery of an attack to report it."

Lastly, some more "specifics" that NY Times didn't mention:

> "Investigators tracked the hacked data to an outside Web-storage service and were able to freeze it there, but it isn't yet clear if the hackers were able to earlier remove it to another location, Mr. Miller said. The Web storage service used by the hackers, which Mr. Miller declined to name, was one that is commonly used by U.S. companies, which may have made the initial data theft harder to detect."

[1] http://www.wsj.com/articles/health-insurer-anthem-hit-by-hac...

Re: “Anthem was the target of a very sophisticated external cyber attack”

#147

Earlier quoted context omitted.

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

> We really do need to find a better way of authenticating and identifying people What about not doing that at all? Hear me out. Not relying on "identity" would cost many orders of magnitude less. And besides, why should I care who you are-- what does your identity matter to me? And why should anyone else care?

How in the world did society even function before we had a unique number to identify people? It must have been utter chaos! Before 1935 (when the first SSN was issued), there was no way to borrow money, go to college, buy land, open any kind of account anywhere, or do any of the things that somehow we need a unique number for today.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#148

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

Already in the works: National Strategy for Trusted Identities in Cyberspace (NSTIC)

http://www.nist.gov/nstic/

Combine this with a smartcard. I guess a lot of European countries already do something like this?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#149

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

SSN is not some secret number - they're actually public information and can be obtained through legal channels with minimal effort. SSN is simply used as a "primary key" to differentiate one John Smith from another; it's not a private passcode or anything (even though many places treat it as one). The main benefit of an SSN is that it's a unique identifier of a person, but it's not sufficient for establishing identit…

A company and it's customers are both victims when it gets hacked, but when it has millions of customers the external cost of poor security is so great the bad outcomes seem inevitable.

However, there would be less harm from these kinds of breaches if consumers were not obliged to prove their own innocence whenever someone loaned money in their name without rigorously verifying their identity. If someone claims to have loaned a bunch of money to me without ever interacting with me, the recovery of that foolish loan should really not be my problem. It would still be bad for an insurance company to expose private information, but there wouldn't be such a tremendous incentive to steal, agregate, and distribute this kind of data if there wasn't so much easy money in it.

Stolen credentials of the kind described in this breach are valuable largely because there is an asymmetry of effort favoring thieves: it's so much easier to borrow money in my name than it is for me prove my innocence that the process of borrowing money with other peoples' identity can be done in bulk, and to some extent automated. This situation is only sustainable because the lenders have shifted the responsibility of authentication onto their customers, retroactive to the issueance of credit. Identity verification prior to extending credit to a debtor is trivial and automated, while retroactively proving fraud has a large cost to the debtor in actual human labor.

It seems like payment systems and consumer creditors have colluded to force a Faustian bargain on us: to gain access to utilities and payment systems you have use credit, even if you don't want it. Therefore, if you want to be able to have municipal water, a place to live, or a phone, all of which are practically contingent on credit rating even if you pay with cash, you have to protect your credit rating.

It would be nice to decouple payment systems from consumer credit, but we won't. Nobody, whether they are a buissiness or the state, can afford to cross the credit card companies or the ratings agencies. They are buisiness titans with big lobbying clout. If you get taken by theives, it doesn't mattter if you're a consumer, a big corporation like Target, or a government agency like the VA, you're going under the bus because the status quo is too profitible to fix, and security is your problem. Nothing can be allowed to slow down the issuance of easy credit, or to create the slightest friction in CC transactions. Look what just happened with chip and pin? We can't even _opt into_ a pin for CC transactions because it might confuse us. While we're on the subject, go read about what happens to people who to try to build alternative payment systems that cut out MCVISA...

How many data breaches would there be if bad actors had to take the trouble to personally hassle each of the millions of people they had data on before they could take our money?

Probably some, but how much would we care who knew our SSN's or addresses if they couldn't easily be monetized?

Some, but less, I think.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#150

Earlier quoted context omitted.

Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.

To be fair, if your systems relied on your chief architect not being hit by a bus, that would probably be worse than having the passwords stored someplace.

In reality he always played the "hero" as the only person who could fix the primary system, only because he built it so terribly in the first place.
Post reply on HN