Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

11–20 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#12
post #3

Good job issuing the release in the middle of the night to try to avoid the PR, too. What a trainwreck. Anthem basically passed out identity theft kits, and you can even sort by income to go after the rich ones first! (Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products.)

"Why does Anthem know your income?"

Possibly Affordable Care Act compliance? Calculating income-based health care subsidies appropriately?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#13
"A very sophisticated external cyber attack" which is a "security vulnerability"... The more "sophisticated" they claim this "cyber attack" is, the more I think it's a garden-variety SQL injection fuck-up.

They've done a bad job of protecting their customer's data, and an even worse job of explaining what actually happened.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#14
I like the two Anthem job reqs that were very recently added:

2/4/15 (umm, today): http://www.careers.antheminc.com/jobs/cloud-encryption-secur...

1/30/15: http://www.careers.antheminc.com/jobs/checkpoint-firewall-ex...

Could be a coincidence, but I wouldn't be surprised if they were compromised several days before this press release.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#15
post #13

"A very sophisticated external cyber attack" which is a "security vulnerability"... The more "sophisticated" they claim this "cyber attack" is, the more I think it's a garden-variety SQL injection fuck-up. They've done a bad job of protecting their customer's data, and an even worse job of explaining what actually happened.

+1 on the "sophisticated" == 'SQL injection', though it's all speculation at this point.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#16

I hate the tone of that letter, has the typical PR tone all over it. Basically to sum it up: "Your Social Security Number, Name, Birthdate, Address, and everything else needed to steal your identity is at risk. But don't worry! Your credit card number is safe."

The whois[1] records for http://anthemfacts.com was registered in December. It took them months to create that PR report and prepare for damage control. They should have notified victims much earlier.

[1] http://whois.icann.org/en/lookup?name=anthemfacts.com

Re: “Anthem was the target of a very sophisticated external cyber attack”

#17
post #10

The security industry/products seriously need a make over. So much money spent and yet, hacks just keep getting bigger and worse. [edit]: Disclaimer - I'm CTO at @menlosecurity.

The security products arent great, true, but the ppl working as security engineers in companies are often quite decent.

It seems to me that its the usual issue. People don't see the need for protection until they've been hit. It seems to be a cost that doesn't make sense to them. They don't even care anymore.

Then they get hit hard. But it can take years.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#18
Privacy Rights Clearinghouse has a couple of excellent fact sheets on identity theft

https://www.privacyrights.org/how-to-deal-security-breach covers situations like this where there's been a security breach - how to order and monitory credit reports, put in a security freeze (which makes it harder to open up new credit cards or credit lines in your name), etc.

https://www.privacyrights.org/content/identity-theft-what-do... covers when you've actually been the victim of an identity theft

Re: “Anthem was the target of a very sophisticated external cyber attack”

#19
post #17
post #10

The security industry/products seriously need a make over. So much money spent and yet, hacks just keep getting bigger and worse. [edit]: Disclaimer - I'm CTO at @menlosecurity.

The security products arent great, true, but the ppl working as security engineers in companies are often quite decent. It seems to me that its the usual issue. People don't see the need for protection until they've been hit. It seems to be a cost that doesn't make sense to them. They don't even care anymore. Then they get hit hard. But it can take years.

True that about the security engineers, but they are at the mercy of products that claim to distinguish good from bad and this has never worked, IMHO. How the hell can you write signatures against malware/documents/web-sites/files/attacks/blah when there's so much diversity and quantity of stuff to keep up with?

Disclaimer: I built the first IPS to be commercialized and yes we used signatures amongst other things.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#20
It makes me wonder. For several years the US government, Medicare, and private insurers have been pushing hard for health care providers to adopt Electronic Health Record systems. Now in the current phase "interoperability" of EHR systems is the catchword.

A question to ask is how secure is a large network of EHRs going to be? I don't know of data showing the frequency or severity of EHR security breaches but it would be surprising if there were not at least some. In any case, this kind of info would probably not be made available to the public, even though it should be.

Anthem's poor job of keeping confidential info private is especially distressing given the fact that many health insurers are also health care providers (e.g., hospital systems). Computer systems are very hard to operate securely, and after what happened, it's hard to trust these corporations will take the task seriously.

I've been quietly predicting that security of health information is going to become the Next Big Privacy Issue as the Internet of Medical Records grows ever larger.

Post reply on HN