Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

121–130 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#121

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

If you live in California, you have the right to put a security freeze on your child's credit file. This will prevent one of the most serious types of identity theft with a stolen SSN. Other states might have similar laws.

http://oag.ca.gov/idtheft/facts/freeze-your-credit

Re: “Anthem was the target of a very sophisticated external cyber attack”

#122
post #121

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

If you live in California, you have the right to put a security freeze on your child's credit file. This will prevent one of the most serious types of identity theft with a stolen SSN. Other states might have similar laws. http://oag.ca.gov/idtheft/facts/freeze-your-credit

I'd just like to point out that you can put a freeze on your and your children's credit files in any state.

In most states it will cost in the neighborhood of $10 for each of the three bureaus, unless you're already the documented victim of identity theft (ask me how I know this).

Re: “Anthem was the target of a very sophisticated external cyber attack”

#123

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

SSN is not some secret number - they're actually public information and can be obtained through legal channels with minimal effort. SSN is simply used as a "primary key" to differentiate one John Smith from another; it's not a private passcode or anything (even though many places treat it as one). The main benefit of an SSN is that it's a unique identifier of a person, but it's not sufficient for establishing identity and should not be used for that purpose.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#124
post #109

Earlier quoted context omitted.

Most security decisions aren't taken by senior management. I am sure it is not Sony's senior management who decided to store passwords in clear text in the PSN. Management focus would ensure everyone in the organisation focuses on security but most security breaches are the result of IT people doing stupid things or making stupid decisions on the ground. It's not senior management's role to check that you didn't intr…

That's just not true. The direction of IT certainly is set by upper management, as well as the budget. If IT says 'we need an IDS' and management says 'it's not in the budget', what can IT do about it? If IT says 'it will take this long and this much money to change our password policy' and management say 'work on new things, not changing old things', what can IT do about it? Senior management might not directly set…

Well, somehow engineers and architects manage to resist management pressures in favor for security, you don't see many bridges collapsing but they have financial constraints too. And accountants resist management pressures to bend the accounting standard, or they go to prison too.

IT is in many respect an unregulated profession. Pretty much anyone can declare himself a programmer. There are some regulations on certain systems but not on people.

I am not a fan of regulation but the current pace of data breaches is just unacceptable. If we don't find a solution, some old lawmaker will.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#125

Earlier quoted context omitted.

Well, the US has States and that complicates things quite a bit for this type of thing. Most states will give you a driver's license number as an id (with the appropriate "ID Only" mark). There is also the Real ID Act[1] that trying to establish federal id requirements. This is going to cause some problems and look for it in the news. It is a DHS enforced national ID law. And yes, some of the folks in the US believe…

some of the folks in the US believe a national ID that is needed to buy, sell, or get a job would be a little too close to the Bible's mark of the beast. You're exaggerating a bit into a strawman. I strongly oppose REAL ID (which, by the way, was around for a while before the DHS existed). And as a "tooth fairy agnostic" as Dawkins would say, I'm not the least bit concerned about the number of the beast. What I am co…

"You're exaggerating a bit into a strawman."

Perhaps I should have separated that from the DHS stuff, but it is a belief of some folks (enough who vote to have made a long difference) and it goes to why we don't currently have a national id. It is part of the history in the US and the original poster is not from the US and wanted some reasons.

DHS is the agency currently charged with Real ID Act oversight. I'm not sure the who is important before the law is implemented.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#126

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

SSNs are already public information. There are numerous legal ways online to enter a person's name and 1 or 2 past addresses and get their SSN back.

Their main purpose is to serve as a primary key - many people have the same name, but SSN is unique. It should never be used for establishing identity - it's about as effective as asking someone for their middle name.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#127
post #36

Turned 26 in January. Purchased Anthem medical insurance so I don't get penalized by Obamacare. Surprised how expensive it is, but bit my tongue and continue. Anthem gets hacked. My Name + SSN is probably somewhere it shouldn't be; ugh.

Are you really trying to say not having health insurance is better than your info potentially being breached?

At 26, quite possibly.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#128
post #109
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

Most security decisions aren't taken by senior management. I am sure it is not Sony's senior management who decided to store passwords in clear text in the PSN. Management focus would ensure everyone in the organisation focuses on security but most security breaches are the result of IT people doing stupid things or making stupid decisions on the ground. It's not senior management's role to check that you didn't intr…

Actually in most cases they are, Most security issues are shown on the yearly/quarterly/weekly compliance scans. A majority of the time this gets forwarded to senior management requesting resources to fix said security issue. I've seen first hand senior management direct IT teams to sweep it under the rug so to say. Any competent IT team is well aware of their security concerns, however if management isn't on board it just becomes another skeleton in their closet.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#129

Earlier quoted context omitted.

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

There have been some attempts at a National ID, but it keeps getting shot down because people believe it's the Mark of the Beast.

Just rename it Patriot ID and I'm sure people will come around :/

Seriously, if California is giving driver's licenses to whoever wants them (and who's 16 and can learn to drive), I don't see the harm sending out centrally verifiable identity cards. The costs of implementing such a system have gone way down over the years, but to be sure, bid out the job and finance it with surcharges on credit report checks, and any other transaction that involves verifying identity. There are surcharges everywhere else in the transaction. What probably concerns a lot of people is that they don't want the government to know every time they get a credit check. Not sure how you solve that, other than making this a GSE or legal monopoly.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#130

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

SSN is not some secret number - they're actually public information and can be obtained through legal channels with minimal effort. SSN is simply used as a "primary key" to differentiate one John Smith from another; it's not a private passcode or anything (even though many places treat it as one). The main benefit of an SSN is that it's a unique identifier of a person, but it's not sufficient for establishing identit…

But it is private and it does unlock keys to lines of credit. It is not simply a "primary key" as stated, whether or not that was the original intent is not the argument here however. Recall the LifeLock CEO* plastered his SSN publicly and felt the repercussions. While I won't suggest you do that here - just knowing that if you did the assumption is bad things will happen in due time. Keeping SSNs private today is a risk organizations have to deal with and it does impact people, sometimes to an extensive length.

Also, for clarification, the breach involved all of the information required to establish identity - which was my main point in the protection and monitoring of the SSN, with special regard to children/minors.

* http://www.wired.com/2010/05/lifelock-identity-theft/

Post reply on HN