Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

81–90 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#81
Boy it sure does fill me with confidence to know that I am hearing about my personal information having been compromised through a news website rather than through the incompetent organization that allowed my information to be leaked in the first place...

Re: “Anthem was the target of a very sophisticated external cyber attack”

#82
post #72
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

>I worked for a small medical company that had access to 20,000 PHI records I can only imagine the data protection standards at small equipment manufacturers and old-school pharmacies. I'd guess their biggest security measure is keeping paper files in a locked office.

I think that might overall be a better strategy than a really half-assed digitization plan. Paper records aren't that high security, but they are moderately resistant to bulk theft: leaking 20,000 paper patient records takes a lot of physical effort.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#83

Earlier quoted context omitted.

What's unlikely about it? Maybe if the domain name was "anthemdatabreachinfo.com" or something more specific, but "anthemfacts.com"? Many companies register lots of variation of domain names that they aren't using. I don't think it's unlikely at all that this came up, and there was a meeting where they said "OK, do we have any existing domain names we can use for this?"

So what have they been using the domain for in the few weeks since registration? The domain doesn't appear in web.archive.org until today, and searching Google for the domain between December and the end of January shows nothing. The website itself says "we have created a dedicated website ... anthemfacts.com" for this incident. [Edit: replaced two egregious uses of "website" with "domain"]

website != domain

Re: “Anthem was the target of a very sophisticated external cyber attack”

#84
post #56

I can't believe it has been at least a full week since the last announcement of a massive data breach... I am concerned that if the industry doesn't fix this, regulation will.

Thank you for the idea. I'm going to pass some regulation for my Wordpress sites so they'll never get hacked again.

The question is not whether it will be efficient but whether it will happen.

It will mean licenses and certifications to have the right to store personal data, regulations to comply with in term of system architecture with audits and penalties for breaches. More bureaucracy and processes. You won't create a website over a week end.

Currently any idiot can create a database and store sensitive information without even knowing what a SQL injection or a rainbow table is.

Most professions are regulated: architects, doctors, pilots, farmers, bankers, even restaurants! And each time regulations come as a result of fk ups: banks or homes collapsing, conmen selling snake oil, food poisoning, etc. IT is the only sector where mild amateurism is not only acceptable but rather the norm more than the exception.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#86
Curious if the HN community has any recommendations for identity-theft monitoring services?

Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach.

Are there better alternatives to ProtectMyID?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#87
post #72
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

>I worked for a small medical company that had access to 20,000 PHI records I can only imagine the data protection standards at small equipment manufacturers and old-school pharmacies. I'd guess their biggest security measure is keeping paper files in a locked office.

A lot of those size companies are offloading their EMR security to larger EMR cloud providers. While it helps to protect the smaller companies, and is more cost effective then trying to manage it internally, I still wonder about security of those records, being how most of those are a web login that most if not everybody on the Internet has access too.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#88
post #47

Earlier quoted context omitted.

Who cares about credit card numbers when you are protected for free and your credit card can be reissued unlike your SSN. I can't believe than in 2015 there's no modern way to verify and protect your identity! There are still so many stupid system relying on your last 4 of your SSN or DoB as authentication!

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

Sweden's entire population is about the size of the Chicagoland area. Now imagine 320+ million people all living in different semi-autonomous states all with their own bureaucracies and hundreds of taxing authorities. Now imagine proposing a national ID card to these people. Yeah, its not that easy. The US isn't centralized like a lot of European nations. Governance of very critical things are done on the state level and that isn't going to change anytime soon.

>I'm guessing its some kind of privacy issue behind there not being a similar system in US?

The social security system, which is a federal program, produced a unique number for all citizens. The states quickly started using this number in their own bureaucracy and everyone else followed (banks, etc). Now its a defacto numeric identifier.

The big problem here is how easy it is to get credit in my name if you have my SSN, like its the root password to my finances. Credit is far too easy to get in the states from a paperwork perspective. I should not fear other people getting my SSN. Banks and other organizations need to realize that if someone presents my SSN, that doesn't mean its me. More numbers or psuedo-SSN's aren't the fix here. The fix is due diligence and better fraud protections.

Not to mention everyone already carries a unique identifier thats easy to verify - your fingerprint. I think SSN + fingerprint plus a letter sent to my home that needs to be signed should be the minimum to open any line of credit. SSN alone should be worthless.

Its also bothersome that PCI-DSS and other regulations treat credit cards like NSA secrets, which is fine as they should be encrypted, but there's no legislation or guidelines to make SSN's encrypted. SSN's sit as plain-text in every database in the US. That's kind of scary and probably invites hacks.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#89
post #86

Curious if the HN community has any recommendations for identity-theft monitoring services? Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach. Are there better alternatives to ProtectMyID?

Go to any of the three credit reporting agencies and fill out the "fraud alert" form. That will place a hold on your credit report at all three credit agencies and anyone applying for credit under your name will be blocked. The entity that the person is applying for credit with has to contact you using the contact information you provide to verify that it is indeed you that's applying for credit.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#90
post #86

Curious if the HN community has any recommendations for identity-theft monitoring services? Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach. Are there better alternatives to ProtectMyID?

I use this. https://m.zanderins.com/identity-theft-plans

I have had several scares, and each time I just call them and they give me the steps to verify if it has been breached. I like the terms of their contract better as well. Just be advised that this is identity insurance. Not protection. It is designed to be reactive rather then proactive. I feel that everybody will have their identity stolen at some point, so instead of trying to prevent it. I chose to insure the consequences of it happening. I feel it's a much better return on my investment, as a lot of the protection cosines don't do much for you if they miss a theft.

P.S. A million dollar reimbursement clause really helps me sleep at night.

Post reply on HN