Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

181–190 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#181
How about if companies holding sensitive data were required to subject themselves to pen test attacks by properly incentivized third parties? Even if an attack were not successful the deliverables would quickly tell an experienced hand whether the attempt had been sufficiently rigorous. And that would allow for a good audit mechanism.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#182

How about if companies holding sensitive data were required to subject themselves to pen test attacks by properly incentivized third parties? Even if an attack were not successful the deliverables would quickly tell an experienced hand whether the attempt had been sufficiently rigorous. And that would allow for a good audit mechanism.

you wouldnt happen to be a pen tester, would you?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#183
post #148

Earlier quoted context omitted.

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

Already in the works: National Strategy for Trusted Identities in Cyberspace (NSTIC) http://www.nist.gov/nstic/ Combine this with a smartcard. I guess a lot of European countries already do something like this?

See also http://en.wikipedia.org/wiki/Estonian_ID_card

Re: “Anthem was the target of a very sophisticated external cyber attack”

#184
post #142

I'm in the process of getting Anthem to pay for my credit monitoring now. If you're in the same boat of not wanting to wait for a snail mail letter, call 1-877-263-7995 and escalate twice.

Did you have any luck with this? I spoke to a few different people and got stonewalled every time.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#185

Earlier quoted context omitted.

A company and it's customers are both victims when it gets hacked, but when it has millions of customers the external cost of poor security is so great the bad outcomes seem inevitable. However, there would be less harm from these kinds of breaches if consumers were not obliged to prove their own innocence whenever someone loaned money in their name without rigorously verifying their identity. If someone claims to ha…

I agree completely with this. SSN should not be worth anything because it's really not different from a name. Instead of saying "hi my name is exelius", you're saying "hi my name is 302-45-9522". You wouldn't trust me if I said the former, so why the latter? I don't know any solution to this problem that would realistically be any better. Crypto isn't a good long-term solution -- any crypto we use today will be trivi…

> any crypto we use today will be trivially cracked by a cell phone 20 years from now.

This is completely false for correctly implemented crypto unless mobile phones of the future are made of something other than matter and occupy something other than space. It could also be that fundamental understandings of math and physics are incorrect. But the idea that just because of improved technology we'll be able to crack today's crypto is ludicrous

http://i.imgur.com/CzyO1yv.jpg

Re: “Anthem was the target of a very sophisticated external cyber attack”

#187
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

Don't lose heart - working in the industrial safety business, the 'just check the boxes' tactic is very familiar. Things are finally coming around after many years (and many, many incidents) though, as companies, and the courts, realise that ticking boxes isn't the be all and end all.

At the moment, it's very easy for companies like Anthem to claim that they were the victim of a 'very sophisticated' cyber attack, when in reality they were probably just wilfully negligent. As understanding seeps into the regulators and law-makers minds, businesses will start to comply with the spirit of security / HIPAA, not just the boxes. In the mean time, the best you can do is continue to advise clearly and calmly why things should be done. If the management doesn't accept your reasoning, at least you have done your due diligence.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#188
If they had been using the free UAQUAS system license this attack would have never succeeded!

UAQUAS not only eliminates passwords, it also examines the IP addresses that connect to a host and ensure that they are connected to an authorized program or a current web session, and if not kills the connects and blocks that IP address.

Visit the uaquas.com website to learn how to protect yourself.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#189
If they had been using the free UAQUAS system license this attack would have never succeeded!

UAQUAS not only eliminates passwords, it also examines the IP addresses that connect to a host and ensure that they are connected to an authorized program or a current web session, and if not kills the connects and blocks that IP address.

Visit the uaquas.com website to learn how to protect yourself.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#190
post #108

Earlier quoted context omitted.

Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…

> they'd say stuff like "Oh, that horrible cancer you have? > Yeah, we're not paying for it because it was a 'pre- > existing condition' that you got during that weekend you > had between two jobs six years ago." Can you give a link to an article about this? I didn't know "pre-existing condition" worked like that.

The example is a little bit exaggerated, but basically if you have a major medical problem with huge bills, the insurance companies will look for a ways to get out of paying. It may not be right or even legal, but the process of disputing claims is a confusing hassle. I can tell you from personal experience that it takes a lot of determination to dispute with an insurance company and I can imagine a lot of people just give up.

This is just a random link describing one scenario - http://www.yourwisconsininjurylawyers.com/library/claim-deni...

Post reply on HN