Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

101–110 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#101

Boy it sure does fill me with confidence to know that I am hearing about my personal information having been compromised through a news website rather than through the incompetent organization that allowed my information to be leaked in the first place...

When I woke up this morning they had sent me and my spouse an email overnight with the same letter that's posted on the anthemfacts.com site. Maybe they don't have your email address?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#102

Earlier quoted context omitted.

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

Sweden's entire population is about the size of the Chicagoland area. Now imagine 320+ million people all living in different semi-autonomous states all with their own bureaucracies and hundreds of taxing authorities. Now imagine proposing a national ID card to these people. Yeah, its not that easy. The US isn't centralized like a lot of European nations. Governance of very critical things are done on the state level…

Not to mention everyone already carries a unique identifier thats easy to verify - your fingerprint.

Actually a surprising number of people don't. For either medical (dermatitis), work (manual laborer wearing them out, operation room personnel scrubbing them out...) or age related reasons.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#103

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

Had never really thought of that angle. Being a father it does shake me up a bit more than usual as it seems my peers and I are quite used to these headlines being the norm. Imagining a future in which you have already been "doxed" prior to elementary school is a bit disturbing.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#104
post #89
post #86

Curious if the HN community has any recommendations for identity-theft monitoring services? Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach. Are there better alternatives to ProtectMyID?

Go to any of the three credit reporting agencies and fill out the "fraud alert" form. That will place a hold on your credit report at all three credit agencies and anyone applying for credit under your name will be blocked. The entity that the person is applying for credit with has to contact you using the contact information you provide to verify that it is indeed you that's applying for credit.

It looks like it's sufficient to do it with one as the alert propagates to the other two. And it lasts 90 days.

"Ask 1 of the 3 credit reporting companies to put a fraud alert on your credit report. They must tell the other 2 companies. An initial fraud alert can make it harder for an identity thief to open more accounts in your name. The alert lasts 90 days but you can renew it."

[http://www.consumer.ftc.gov/articles/0275-place-fraud-alert]

Re: “Anthem was the target of a very sophisticated external cyber attack”

#105

I like the two Anthem job reqs that were very recently added: 2/4/15 (umm, today): http://www.careers.antheminc.com/jobs/cloud-encryption-secur... 1/30/15: http://www.careers.antheminc.com/jobs/checkpoint-firewall-ex... Could be a coincidence, but I wouldn't be surprised if they were compromised several days before this press release.

To add to this a bit searching for 'security' jobs at anthem only reveals 12 jobs which to me seemed rather low.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#106

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

Thanks for the advice. Can you give some specific steps on how to "monitor your child's SSN for activity"? How would I go about doing this?

Start with Trans Union, they have a child specific application so you can find out if your child's SSN has been used by identity thieves: http://www.transunion.com/corporate/personal/fraudIdentityTh... If they don't have any reports, there's a good chance you're probably ok.

You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/research/security-freeze/

And then there's the myriad of companies who can give you protection for a monthly fee:

AllClearID: https://www.allclearid.com/

LifeLock Junior: http://www.safety4yourkids.com

Also, Experian has a monitoring service as well specifically for kids: http://www.familysecure.com/

Hope this helps.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#107

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully.

I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#108

Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.

Proof of coverage can be important.

It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that.

Health care in the US is . . . the phrase "utterly broken" isn't strong enough. We need a good fifteen syllable German word for how fantastically fucked up it is.

Of course I'm trying to explain Anthem hanging onto data. Probably it was totally selfish ("we can send them spam") or sheer laziness.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#109
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

Most security decisions aren't taken by senior management. I am sure it is not Sony's senior management who decided to store passwords in clear text in the PSN.

Management focus would ensure everyone in the organisation focuses on security but most security breaches are the result of IT people doing stupid things or making stupid decisions on the ground. It's not senior management's role to check that you didn't introduce a SQL injection risk in your code. Like it is not senior management's role to check that the accounting department followed properly the latest US GAAP guidelines. It's down to employees being competent at what they do.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#110

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

Maybe we should get a public/private key pair at birth instead.
Post reply on HN