“Anthem was the target of a very sophisticated external cyber attack”
11–20 of 206 posts
Re: “Anthem was the target of a very sophisticated external cyber attack”
#12Good job issuing the release in the middle of the night to try to avoid the PR, too. What a trainwreck. Anthem basically passed out identity theft kits, and you can even sort by income to go after the rich ones first! (Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products.)
Possibly Affordable Care Act compliance? Calculating income-based health care subsidies appropriately?
Re: “Anthem was the target of a very sophisticated external cyber attack”
#13They've done a bad job of protecting their customer's data, and an even worse job of explaining what actually happened.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#142/4/15 (umm, today): http://www.careers.antheminc.com/jobs/cloud-encryption-secur...
1/30/15: http://www.careers.antheminc.com/jobs/checkpoint-firewall-ex...
Could be a coincidence, but I wouldn't be surprised if they were compromised several days before this press release.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#15"A very sophisticated external cyber attack" which is a "security vulnerability"... The more "sophisticated" they claim this "cyber attack" is, the more I think it's a garden-variety SQL injection fuck-up. They've done a bad job of protecting their customer's data, and an even worse job of explaining what actually happened.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#16I hate the tone of that letter, has the typical PR tone all over it. Basically to sum it up: "Your Social Security Number, Name, Birthdate, Address, and everything else needed to steal your identity is at risk. But don't worry! Your credit card number is safe."
Re: “Anthem was the target of a very sophisticated external cyber attack”
#17The security industry/products seriously need a make over. So much money spent and yet, hacks just keep getting bigger and worse. [edit]: Disclaimer - I'm CTO at @menlosecurity.
It seems to me that its the usual issue. People don't see the need for protection until they've been hit. It seems to be a cost that doesn't make sense to them. They don't even care anymore.
Then they get hit hard. But it can take years.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#18https://www.privacyrights.org/how-to-deal-security-breach covers situations like this where there's been a security breach - how to order and monitory credit reports, put in a security freeze (which makes it harder to open up new credit cards or credit lines in your name), etc.
https://www.privacyrights.org/content/identity-theft-what-do... covers when you've actually been the victim of an identity theft
Re: “Anthem was the target of a very sophisticated external cyber attack”
#19The security industry/products seriously need a make over. So much money spent and yet, hacks just keep getting bigger and worse. [edit]: Disclaimer - I'm CTO at @menlosecurity.
The security products arent great, true, but the ppl working as security engineers in companies are often quite decent. It seems to me that its the usual issue. People don't see the need for protection until they've been hit. It seems to be a cost that doesn't make sense to them. They don't even care anymore. Then they get hit hard. But it can take years.
Disclaimer: I built the first IPS to be commercialized and yes we used signatures amongst other things.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#20A question to ask is how secure is a large network of EHRs going to be? I don't know of data showing the frequency or severity of EHR security breaches but it would be surprising if there were not at least some. In any case, this kind of info would probably not be made available to the public, even though it should be.
Anthem's poor job of keeping confidential info private is especially distressing given the fact that many health insurers are also health care providers (e.g., hospital systems). Computer systems are very hard to operate securely, and after what happened, it's hard to trust these corporations will take the task seriously.
I've been quietly predicting that security of health information is going to become the Next Big Privacy Issue as the Internet of Medical Records grows ever larger.