Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

21–30 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#21
Looks like they misled the New York Times:

http://www.nytimes.com/2015/02/05/business/hackers-breached-...

> Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously.

As user jakejohns has pointed out (https://news.ycombinator.com/item?id=9002003), the WHOIS points to a creation date for ANTHEMFACTS.com of `2014-12-13` with GoDaddy.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#22
post #20

It makes me wonder. For several years the US government, Medicare, and private insurers have been pushing hard for health care providers to adopt Electronic Health Record systems. Now in the current phase "interoperability" of EHR systems is the catchword. A question to ask is how secure is a large network of EHRs going to be? I don't know of data showing the frequency or severity of EHR security breaches but it woul…

Ultimately, the web is an attack vector that no one is immune to. Did you read the Syria hack recently? Just a skype chat with an attractive opposite-gender is enough to download a piece of malware masquerading as a picture you really want to see. While the human aspect has always been a key element of getting hacked, products that claim to distinguish the good vs. bad are failing big time. And this has been the pillar of enterprise security (classifying good against bad) for the last 20 years and is starting to show its age.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#23
post #15
post #13

"A very sophisticated external cyber attack" which is a "security vulnerability"... The more "sophisticated" they claim this "cyber attack" is, the more I think it's a garden-variety SQL injection fuck-up. They've done a bad job of protecting their customer's data, and an even worse job of explaining what actually happened.

+1 on the "sophisticated" == 'SQL injection', though it's all speculation at this point.

That's really my problem -- that they're leaving their victims to speculate.

It's great that they "made every effort to close the security vulnerability". How's that going?

They hired Mandiant to "evaluate our systems and identify solutions based on the evolving landscape." Is "evolving landscape" CEO-speak for "Oh, god, we're still leaking customer data like a sieve, make it stop!"?

I'm just going to keep speculating, because if Anthem's not going to bother speaking plainly, I'm just going to assume the worst.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#25
post #23
post #15

Earlier quoted context omitted.

+1 on the "sophisticated" == 'SQL injection', though it's all speculation at this point.

That's really my problem -- that they're leaving their victims to speculate. It's great that they "made every effort to close the security vulnerability". How's that going? They hired Mandiant to "evaluate our systems and identify solutions based on the evolving landscape." Is "evolving landscape" CEO-speak for "Oh, god, we're still leaking customer data like a sieve, make it stop!"? I'm just going to keep speculatin…

>It's great that they "made every effort to close the security vulnerability".

I love that quote, they try to cover their asses by saying we closed the vulnerability. My question is why did you wait till it was taken advantage of?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#26
post #17
post #10

The security industry/products seriously need a make over. So much money spent and yet, hacks just keep getting bigger and worse. [edit]: Disclaimer - I'm CTO at @menlosecurity.

The security products arent great, true, but the ppl working as security engineers in companies are often quite decent. It seems to me that its the usual issue. People don't see the need for protection until they've been hit. It seems to be a cost that doesn't make sense to them. They don't even care anymore. Then they get hit hard. But it can take years.

I've actually had the exact opposite experience. Security Engineers at most companies have no idea what they're doing beyond running the scanner and parroting whatever it spits out.

"The scanner says your server is vulnerable"

"Ya, we patched that vulnerability weeks ago"

"The scanner says it's vulnerable"

"OK.... looks at scanner - oh, it's just reading the banner, and not taking into account that the major rev didn't change, it's patched"

"The scanner says it's vulnerable"

"OK... so what if I change the banner so it doesn't pick it up as vulnerable?"

"The scanner says it's secure now, thanks!!"

The guys who know their stuff in security generally have a desire to actually get paid well, and have time to do legitimate research. They don't really have a desire to sit in a corporate job dealing with the mountains of bureaucratic bullshit that goes along with security in a corporation. Do you really want to be the guy who gets thrown under the bus because you had to disable strong passwords because the CEO was angry he needed both upper and lower case letters in his AD password?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#29

I hate the tone of that letter, has the typical PR tone all over it. Basically to sum it up: "Your Social Security Number, Name, Birthdate, Address, and everything else needed to steal your identity is at risk. But don't worry! Your credit card number is safe."

They stopped taking automatic credit card payments ~3.5 years ago, so even that last bit isn't much of an accomplishment.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#30

I hate the tone of that letter, has the typical PR tone all over it. Basically to sum it up: "Your Social Security Number, Name, Birthdate, Address, and everything else needed to steal your identity is at risk. But don't worry! Your credit card number is safe."

The whois[1] records for http://anthemfacts.com was registered in December. It took them months to create that PR report and prepare for damage control. They should have notified victims much earlier. [1] http://whois.icann.org/en/lookup?name=anthemfacts.com

THAT is some clever detective work!

To give 'em the benefit of the doubt-- perhaps perhaps perhaps they needed that particular domain in anticipation of some other instance where they dropped the ball but your conclusion is more compelling.

Post reply on HN