Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

131–140 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#131
Enterprise hacks are sadly becoming more common, and more sadly, it appears security is abysmal in all cases of large scale hacks. Many attacks of the past 24 months included simple exploits, social engineering or both. These are the kind of attacks a small group of rogue individuals can accomplish from computers anywhere in the world.

If small groups of individual "hackers" are capable of executing high-profile operations, just imagine the capabilities of nation-state cyberwarfare forces. The intelligence agencies of large governments employ thousands of professionals, all at least as qualified as the hackers behind these attacks. The difference is that government employees (or contractors!!) have no fear of legal repercussion restraining their operational activities.

When attacks like this move the market, any scrutiny of the attack must include analysis of market trading in the days following. Who profits from the drop in Anthem stock price? I imagine the SEC investigates this as part of due course, but one should consider that nation states are active investors in the stock market, whether directly or through hedge fund proxies. If a nation state can hack a large enterprise, and a nation state can trade large volumes of securities against that enterprise, then it follows that nation states can profit from cyber warfare.

The next five years are going to be very interesting.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#132

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

> We really do need to find a better way of authenticating and identifying people

What about not doing that at all? Hear me out. Not relying on "identity" would cost many orders of magnitude less. And besides, why should I care who you are-- what does your identity matter to me? And why should anyone else care?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#133
post #3

Good job issuing the release in the middle of the night to try to avoid the PR, too. What a trainwreck. Anthem basically passed out identity theft kits, and you can even sort by income to go after the rich ones first! (Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products.)

> (Why does Anthem know your income? It doesn't seem relevant to offer you health > insurance products.)

It's because they offer disability benefits, which tend to be a percentage of one's income.

http://www.anthem.com/wps/portal/ahplife?content_path=life/n...

My employer uses Anthem for health insurance but another company for disability, so if our data leaked our income data should be safe. We'll see!

Re: “Anthem was the target of a very sophisticated external cyber attack”

#134
post #108

Why were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.

Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…

Don't forget having to deal with billing nightmares even after you're no longer using an insurance company. You still could end up fighting with them over their failure to pay for something.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#135
post #56

I can't believe it has been at least a full week since the last announcement of a massive data breach... I am concerned that if the industry doesn't fix this, regulation will.

Right. Because there's no US law that covers storage of personal data by health providers. And there's no legal penalties for things like this.

(Hint: http://www.ecfr.gov/cgi-bin/text-idx?SID=9e10f619aa05225aef1... Subpart C—Security Standards for the Protection of Electronic Protected Health Information)

Re: “Anthem was the target of a very sophisticated external cyber attack”

#136

Earlier quoted context omitted.

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

> We really do need to find a better way of authenticating and identifying people What about not doing that at all? Hear me out. Not relying on "identity" would cost many orders of magnitude less. And besides, why should I care who you are-- what does your identity matter to me? And why should anyone else care?

I couldn't care less, but someone who is granting you credit has a legitimate reason to know who they're giving money to and how likely you are to pay it back, and who to chase after if you fail to do so.

Let's not pretend there aren't valid reasons for identity to be established.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#137

Earlier quoted context omitted.

SSN is not some secret number - they're actually public information and can be obtained through legal channels with minimal effort. SSN is simply used as a "primary key" to differentiate one John Smith from another; it's not a private passcode or anything (even though many places treat it as one). The main benefit of an SSN is that it's a unique identifier of a person, but it's not sufficient for establishing identit…

But it is private and it does unlock keys to lines of credit. It is not simply a "primary key" as stated, whether or not that was the original intent is not the argument here however. Recall the LifeLock CEO* plastered his SSN publicly and felt the repercussions. While I won't suggest you do that here - just knowing that if you did the assumption is bad things will happen in due time. Keeping SSNs private today is a…

I heard about that, but when you publicly tell a bunch of hackers "come at me bro", you have to expect that kind of reaction.

But realistically, the cat is out of the bag with regards to SSNs. Legally you can obtain someone's SSN for very little money. If you go the illegal route, I'd be willing to bet that there is black-market identity data on over half of Americans. We really need to treat SSNs as about as secret as your e-mail address, because for all intents and purposes they are already. I wouldn't be surprised if online ad networks were using your SSN as a primary key in the background - the information is so easy to get and it would solve a lot of problems.

I guess I'm saying that sticking your head in the sand and pretending that SSNs are secure won't make them any more so. I'd doubt that a whole lot of SSNs were gathered in this hack that weren't already effectively disseminated widely in black market circles or marketing databases already.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#139
post #127

Earlier quoted context omitted.

Are you really trying to say not having health insurance is better than your info potentially being breached?

At 26, quite possibly.

Yeah, cause accidents don't happen in your 20s.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#140

Earlier quoted context omitted.

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

> We really do need to find a better way of authenticating and identifying people What about not doing that at all? Hear me out. Not relying on "identity" would cost many orders of magnitude less. And besides, why should I care who you are-- what does your identity matter to me? And why should anyone else care?

Identity is tantamount to verifying education. Colleges need to know who you are, and potential employers need to be able to identify that yes this John Smith is the one that graduated from Stanford w/a 3.8 GPA and a degree in computer science.
Post reply on HN