Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

171–180 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#171
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

Domain registration doesn't necessarily mean anything; my employer owns similar domains, just in case we need them. This is standard crisis plan stuff these days.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#172
post #154

Earlier quoted context omitted.

I am not saying that regulation is desirable. In fact it is going to be a major obstacle to innovation. What I am saying is that we pretty much see a major data breach every week. There are some instances where one can call them force majeure, like a zero day on a major security component in windows or linux. But there is no excuse for SQL injections vulnerabilities, unencrypted personal data, IT professionals loggin…

"Complaining about budgets to fix these issues is like saying that the problems with collapsing bridges is that we don't spend enough fixing the structure. Well, it should have been built properly in the first place." I'd like to think that engineers do want to build things properly, however to build something properly it usually involves more resources. The problem is when it comes down to brass tax the low bidder w…

I am not questioning intention. I am questioning competence.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#173
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

During an auto accident & court case everyone- doctors, lawyers, insurance- used my SS# as a case identifier even though I never gave it out. If a few percent of these are sloppy, them one could be screwed. Some meth people like to dumster dive insurance companies and the like.

I'm waiting for a case of plausible deniability through abstraction of identity to cause the whole SSN based system to collapse. As sloppy as our government and corporations have gone about handling our SSN, there is ever increasing lack of confidence that it individually and uniquely identifies anyone.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#174

Earlier quoted context omitted.

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

Sweden's entire population is about the size of the Chicagoland area. Now imagine 320+ million people all living in different semi-autonomous states all with their own bureaucracies and hundreds of taxing authorities. Now imagine proposing a national ID card to these people. Yeah, its not that easy. The US isn't centralized like a lot of European nations. Governance of very critical things are done on the state level…

Your point about US being larger doesn't really stick. My ID is a valid identity card in 26 countries with 420 million people, aka Schengen.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#175

Earlier quoted context omitted.

SSN is not some secret number - they're actually public information and can be obtained through legal channels with minimal effort. SSN is simply used as a "primary key" to differentiate one John Smith from another; it's not a private passcode or anything (even though many places treat it as one). The main benefit of an SSN is that it's a unique identifier of a person, but it's not sufficient for establishing identit…

A company and it's customers are both victims when it gets hacked, but when it has millions of customers the external cost of poor security is so great the bad outcomes seem inevitable. However, there would be less harm from these kinds of breaches if consumers were not obliged to prove their own innocence whenever someone loaned money in their name without rigorously verifying their identity. If someone claims to ha…

I agree completely with this.

SSN should not be worth anything because it's really not different from a name. Instead of saying "hi my name is exelius", you're saying "hi my name is 302-45-9522". You wouldn't trust me if I said the former, so why the latter?

I don't know any solution to this problem that would realistically be any better. Crypto isn't a good long-term solution -- any crypto we use today will be trivially cracked by a cell phone 20 years from now. Trust mechanisms seem better, but even then they can be simulated (see: twitter bots, facebook bots, click fraud, etc.)

Identity theft is far too easy today, but even if we had an effective system that could prove identity... I'm not sure we would want that societally. It basically guarantees big brother and wraps it in the guise of security.

Tldr: this is a tricky problem where the situation caused by the solution may actually be worse than the original situation.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#176
Most companies only focus on perimeter defense and are soft bellies once opened up or to an internal job #sonylearning

And as long as it is not practice to sue companies and Cxx for negligence when they do not internally protect the data (no unencrypted data at rest) this will not change.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#177
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

During an auto accident & court case everyone- doctors, lawyers, insurance- used my SS# as a case identifier even though I never gave it out. If a few percent of these are sloppy, them one could be screwed. Some meth people like to dumster dive insurance companies and the like.

If you are ever unfortunate enough to be unemployed in California, and claim unemployment benefits, they print your social security number right at the top of every correspondence. Idiotic.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#178
post #71

I'm just thrilled to recently be downgraded to an Anthem customer. I miss my old insurance.

They're fantastically better than any other insurance I've had. What they cover for my family is easily another income every year. What did you have before?

Unity Health Insurance which is localized to Wisconsin -- run by the UW Hospitals. It's far better.

http://en.wikipedia.org/wiki/University_of_Wisconsin_Hospita...

https://unityhealth.com/

edit: I had group insurance with Unity for like 8 years. Never once had a scrap of paper to review or a bill to squabble over; everything always covered. Now I'm on a group plan for Anthem and I almost choked when I received the summary of benefits which was greatly reduced in scope.

I guess I had it good.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#179
post #73

Earlier quoted context omitted.

I don't know, even Wikipedia seems to agree with me. http://en.wikipedia.org/wiki/Doxing And didn't the GGers "dox" Randi, Anita, Brianna, etc? But I'm even more old school because I'd just call it skiptracing instead of doxing....

You're ignoring the bits of that article you don't like: Essentially, doxing is revealing and releasing records of an individual, which were previously private, to the public. Where's the "reveal" in this hack? They'll use the hacked info privately or sell it.

What are you talking about? I never said this was "doxing"; I know there was no reveal. I was referring to the definition of "doxing" which I felt didn't fit.

Did you read the comments completely? If Randi, Anita, and Brianna weren't anonymous but they were "doxed" it seems to me that "doxing" doesn't have to refer to revealing info of an anonymous person.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#180

Earlier quoted context omitted.

They're fantastically better than any other insurance I've had. What they cover for my family is easily another income every year. What did you have before?

Anthem is very schizophrenic about their group vs. individual plans. I was covered by them under Google's group plan and they were easily the best insurance company I've had. They paid for all sorts of things that other insurers wouldn't bother for, no questions asked, and were great to deal with. Then I tried continuing with one of their individual plans after leaving, and they were easily the worst insurer I've eve…

That is an interesting point of view. Thanks!
Post reply on HN