Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

51–60 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#51
post #47

Earlier quoted context omitted.

Who cares about credit card numbers when you are protected for free and your credit card can be reissued unlike your SSN. I can't believe than in 2015 there's no modern way to verify and protect your identity! There are still so many stupid system relying on your last 4 of your SSN or DoB as authentication!

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

It's not really a privacy thing, the problem is that people consuming the SSN (banks and such) treat it as authentication.

That forces individuals to treat it as sensitive information.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#53
post #20

It makes me wonder. For several years the US government, Medicare, and private insurers have been pushing hard for health care providers to adopt Electronic Health Record systems. Now in the current phase "interoperability" of EHR systems is the catchword. A question to ask is how secure is a large network of EHRs going to be? I don't know of data showing the frequency or severity of EHR security breaches but it woul…

This is why, increasingly, my view is that people should be in charge of their own data, and only what is specifically required to complete a transaction should be disclosed.

How to implement that technically becomes an interesting question, but between pocket spies with storage measured in tens of GB to TB, and various forms of key authentication, it seems that there are several possible options.

The whole discussion above regarding the false crime of "identity theft" (it's impersonation fraud facilitated by the data holder's negligence) is another point of increasing frustration for me.

I've been having a few related discussions with David Brin (a data cornucopian) on Google+. Brin, hardly to my surprise, responds with extreme derision.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#54
post #42

According to the media, even their CEO's records were taken: http://www.nytimes.com/2015/02/05/business/hackers-breached-...

It's mentioned in the CEO's letter on anthemfacts.com: Anthem’s own associates’ personal information – including my own – was accessed during this security breach.

That's very vicious PR to me. By acknowledging some guys thre were hacked too, they implicitely say that : "we're in the same boat, anthema and their customers, we'll fight together". Which, at least for me, is completely wrong. They fucekd up and they put the customers in the siht.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#55

Earlier quoted context omitted.

Could this be any more patronizing and offensive? Look, if you are Anthem member, or if you were an Anthem member, you've been doxxed... and quite comprehensively: have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data And you were doxxed nearly two m…

That's not what doxxing is. This is a privacy breach. Doxxing is taking an anonymous user account and turning it in to a real person. A pertinent example of doxxing is what the FBI did to linking DPR to Ross Ulbricht due to the mistake he made on a bulletin board.

Dox -> documents -> publishing personal information, no?

Why does the victim have to be anonymous?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#57
post #47

Earlier quoted context omitted.

Who cares about credit card numbers when you are protected for free and your credit card can be reissued unlike your SSN. I can't believe than in 2015 there's no modern way to verify and protect your identity! There are still so many stupid system relying on your last 4 of your SSN or DoB as authentication!

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

What we really need is a barcode tattoo!

Re: “Anthem was the target of a very sophisticated external cyber attack”

#58
post #55

Earlier quoted context omitted.

That's not what doxxing is. This is a privacy breach. Doxxing is taking an anonymous user account and turning it in to a real person. A pertinent example of doxxing is what the FBI did to linking DPR to Ross Ulbricht due to the mistake he made on a bulletin board.

Dox -> documents -> publishing personal information, no? Why does the victim have to be anonymous?

In modern usage of the term they don't. The term originated in underground circles where anonymity by all participants was assumed, and where there were probably legal or criminal revenge consequences for tying a pseudonym to a real identity.

Kind of like how troll now means 'person who is an asshole on the internet' instead of 'post designed to rile up and elicit frivolous responses'. The meaning has changed over time for better or worse.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#59
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

You seem to be implying that the domain was registered in response to the breach. Could it be that the anthemfacts.com domain was intended for a different use, or to prevent someone else from registering it, and was re-purposed after the intrusion to present Anthem's case? I don't know much about SEO, but quarantining negative information on a separate, immediately available domain might be the motivation here.

A domain name that is being used exclusively to address to data breach, and was registered within the past 2 months. And it's just a coincidence?

Seems very unlikely.

And I'm sure they're quarantining negative info on an unrelated domain, but why would they even need to consider repurposing an existing domain name, instead of buying one? We're not talking about somebody doing a side project and hoping to save a few bucks by repurposing another domain name. And it takes all of a few hours to buy a domain name and have it propogate.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#60
post #59

Earlier quoted context omitted.

You seem to be implying that the domain was registered in response to the breach. Could it be that the anthemfacts.com domain was intended for a different use, or to prevent someone else from registering it, and was re-purposed after the intrusion to present Anthem's case? I don't know much about SEO, but quarantining negative information on a separate, immediately available domain might be the motivation here.

A domain name that is being used exclusively to address to data breach, and was registered within the past 2 months. And it's just a coincidence? Seems very unlikely. And I'm sure they're quarantining negative info on an unrelated domain, but why would they even need to consider repurposing an existing domain name, instead of buying one? We're not talking about somebody doing a side project and hoping to save a few b…

What's unlikely about it? Maybe if the domain name was "anthemdatabreachinfo.com" or something more specific, but "anthemfacts.com"? Many companies register lots of variation of domain names that they aren't using. I don't think it's unlikely at all that this came up, and there was a meeting where they said "OK, do we have any existing domain names we can use for this?"
Post reply on HN