Earlier quoted context omitted.
The whois[1] records for http://anthemfacts.com was registered in December. It took them months to create that PR report and prepare for damage control. They should have notified victims much earlier. [1] http://whois.icann.org/en/lookup?name=anthemfacts.com
THAT is some clever detective work! To give 'em the benefit of the doubt-- perhaps perhaps perhaps they needed that particular domain in anticipation of some other instance where they dropped the ball but your conclusion is more compelling.
“Anthem was the target of a very sophisticated external cyber attack”
91–100 of 206 posts
Re: “Anthem was the target of a very sophisticated external cyber attack”
#92Curious if the HN community has any recommendations for identity-theft monitoring services? Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach. Are there better alternatives to ProtectMyID?
I use this. https://m.zanderins.com/identity-theft-plans I have had several scares, and each time I just call them and they give me the steps to verify if it has been breached. I like the terms of their contract better as well. Just be advised that this is identity insurance. Not protection. It is designed to be reactive rather then proactive. I feel that everybody will have their identity stolen at some point, so in…
However what are the situations where the person for whose identity was stolen is asked to pay back the fraudulently obtained goods? I can think of no examples.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#93Earlier quoted context omitted.
Who cares about credit card numbers when you are protected for free and your credit card can be reissued unlike your SSN. I can't believe than in 2015 there's no modern way to verify and protect your identity! There are still so many stupid system relying on your last 4 of your SSN or DoB as authentication!
In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.
There is also the Real ID Act[1] that trying to establish federal id requirements. This is going to cause some problems and look for it in the news. It is a DHS enforced national ID law.
And yes, some of the folks in the US believe a national ID that is needed to buy, sell, or get a job would be a little too close to the Bible's mark of the beast. That gives quite a lot of friction to any national id.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#94For those not aware, Anthem is also the insurance provider for the entire University of California system ( http://www.ucop.edu/ucship/ ).
Re: “Anthem was the target of a very sophisticated external cyber attack”
#95Earlier quoted context omitted.
I've actually had the exact opposite experience. Security Engineers at most companies have no idea what they're doing beyond running the scanner and parroting whatever it spits out. "The scanner says your server is vulnerable" "Ya, we patched that vulnerability weeks ago" "The scanner says it's vulnerable" "OK.... looks at scanner - oh, it's just reading the banner, and not taking into account that the major rev didn…
>Do you really want to be the guy who gets thrown under the bus because you had to disable strong passwords because the CEO was angry he needed both upper and lower case letters in his AD password? Except those strong password policies don't strengthen security at all, neither in theory nor practice. Congratulations, the CEO's password is now "qweRTY" and it's written on a yellow sticky-note on his monitor.
I literally tell my parents to have a secure password they write on a post-it note. The odds of someone breaking into their house for their password is about 1/10000th the odds of someone cracking their simple password on a website and getting the keys to the kingdom.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#96Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…
You seem to be implying that the domain was registered in response to the breach. Could it be that the anthemfacts.com domain was intended for a different use, or to prevent someone else from registering it, and was re-purposed after the intrusion to present Anthem's case? I don't know much about SEO, but quarantining negative information on a separate, immediately available domain might be the motivation here.
Maybe after the Stanford (and other such announcements), they had decided in mid-December to snag anthemfacts.com and then, after learning of the breach, decided to put it into action for this monumental event. However, what are the chances that it took one week for a health insurer, upon discovering the breach, to launch its PR campaign, nevermind fully understand the nature of the breach to be able to publicly announce it. Given the delicate nature of the situation, as well as its historic size, this is not something that a health insurer would want to prematurely make an announcement on without being very sure that the damage is contained. And they contained it within a week? I realize that I'm slightly begging the question here, but yes, part of my skepticism comes from how quickly they were able to move...One week would make it one of the fastest discoveries-to-announcements, which given the scope of the breach, is pretty amazing.
Edit: It's worth pointing out though that there would be records of them contacting the FBI and Mandiant, and I would give them the benefit of the doubt that they would make such contacts upon discovery of the breach...so if the FBI confirms that the contact happened a week ago, I would take Anthem at their word.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#97Turned 26 in January. Purchased Anthem medical insurance so I don't get penalized by Obamacare. Surprised how expensive it is, but bit my tongue and continue. Anthem gets hacked. My Name + SSN is probably somewhere it shouldn't be; ugh.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#98Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…
Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#99TL;DR If you're a parent, monitor your child's SSN for activity. Especially considering this is a healthcare breach, nobody is immune.
Re: “Anthem was the target of a very sophisticated external cyber attack”
#100I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…