Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

91–100 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#91
post #30

Earlier quoted context omitted.

The whois[1] records for http://anthemfacts.com was registered in December. It took them months to create that PR report and prepare for damage control. They should have notified victims much earlier. [1] http://whois.icann.org/en/lookup?name=anthemfacts.com

THAT is some clever detective work! To give 'em the benefit of the doubt-- perhaps perhaps perhaps they needed that particular domain in anticipation of some other instance where they dropped the ball but your conclusion is more compelling.

They recently changed their name. Could be that they wanted to use the domain for something else initially.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#92
post #90
post #86

Curious if the HN community has any recommendations for identity-theft monitoring services? Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach. Are there better alternatives to ProtectMyID?

I use this. https://m.zanderins.com/identity-theft-plans I have had several scares, and each time I just call them and they give me the steps to verify if it has been breached. I like the terms of their contract better as well. Just be advised that this is identity insurance. Not protection. It is designed to be reactive rather then proactive. I feel that everybody will have their identity stolen at some point, so in…

What a great deal for them. They know that in almost all cases you won't be liable for the losses suffered due to identity theft (e.g. loans, credit cards, etc), so they "insure" you that if, somehow, you ever are liable they'll pay it...

However what are the situations where the person for whose identity was stolen is asked to pay back the fraudulently obtained goods? I can think of no examples.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#93
post #47

Earlier quoted context omitted.

Who cares about credit card numbers when you are protected for free and your credit card can be reissued unlike your SSN. I can't believe than in 2015 there's no modern way to verify and protect your identity! There are still so many stupid system relying on your last 4 of your SSN or DoB as authentication!

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

Well, the US has States and that complicates things quite a bit for this type of thing. Most states will give you a driver's license number as an id (with the appropriate "ID Only" mark).

There is also the Real ID Act[1] that trying to establish federal id requirements. This is going to cause some problems and look for it in the news. It is a DHS enforced national ID law.

And yes, some of the folks in the US believe a national ID that is needed to buy, sell, or get a job would be a little too close to the Bible's mark of the beast. That gives quite a lot of friction to any national id.

1) http://en.wikipedia.org/wiki/REAL_ID_Act

Re: “Anthem was the target of a very sophisticated external cyber attack”

#94

For those not aware, Anthem is also the insurance provider for the entire University of California system ( http://www.ucop.edu/ucship/ ).

It would be responsible of them to alert their current students and alumni of the breach, because as of now, I don't think they have. At UCB, there is a medical facility on campus and when you have ship insurance it almost feels as if your provider is the school itself. Dues are paid as part of tuition and most services can be rendered on campus, as well as, most questions about your insurance answered at their front desk. Easy to forget that you're actually a client of Anthem.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#95
post #39
post #26

Earlier quoted context omitted.

I've actually had the exact opposite experience. Security Engineers at most companies have no idea what they're doing beyond running the scanner and parroting whatever it spits out. "The scanner says your server is vulnerable" "Ya, we patched that vulnerability weeks ago" "The scanner says it's vulnerable" "OK.... looks at scanner - oh, it's just reading the banner, and not taking into account that the major rev didn…

>Do you really want to be the guy who gets thrown under the bus because you had to disable strong passwords because the CEO was angry he needed both upper and lower case letters in his AD password? Except those strong password policies don't strengthen security at all, neither in theory nor practice. Congratulations, the CEO's password is now "qweRTY" and it's written on a yellow sticky-note on his monitor.

A post-it note on his monitor of a secure password (they generally require a number or special character, as well as being 8 characters long), is actually better security than an extremely simple password. I can have him lock his office door... I can't prevent someone from brute forcing the password he's re-used on every site on the internet.

I literally tell my parents to have a secure password they write on a post-it note. The odds of someone breaking into their house for their password is about 1/10000th the odds of someone cracking their simple password on a website and getting the keys to the kingdom.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#96
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

You seem to be implying that the domain was registered in response to the breach. Could it be that the anthemfacts.com domain was intended for a different use, or to prevent someone else from registering it, and was re-purposed after the intrusion to present Anthem's case? I don't know much about SEO, but quarantining negative information on a separate, immediately available domain might be the motivation here.

Perhaps? In August 2014, they registered stanfordanthemfacts.com on which they've posted the November 11. 2014 announcement that they have continued their contract with Stanford Health Care: http://stanfordanthemfacts.com/

Maybe after the Stanford (and other such announcements), they had decided in mid-December to snag anthemfacts.com and then, after learning of the breach, decided to put it into action for this monumental event. However, what are the chances that it took one week for a health insurer, upon discovering the breach, to launch its PR campaign, nevermind fully understand the nature of the breach to be able to publicly announce it. Given the delicate nature of the situation, as well as its historic size, this is not something that a health insurer would want to prematurely make an announcement on without being very sure that the damage is contained. And they contained it within a week? I realize that I'm slightly begging the question here, but yes, part of my skepticism comes from how quickly they were able to move...One week would make it one of the fastest discoveries-to-announcements, which given the scope of the breach, is pretty amazing.

Edit: It's worth pointing out though that there would be records of them contacting the FBI and Mandiant, and I would give them the benefit of the doubt that they would make such contacts upon discovery of the breach...so if the FBI confirms that the contact happened a week ago, I would take Anthem at their word.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#97
post #36

Turned 26 in January. Purchased Anthem medical insurance so I don't get penalized by Obamacare. Surprised how expensive it is, but bit my tongue and continue. Anthem gets hacked. My Name + SSN is probably somewhere it shouldn't be; ugh.

Are you really trying to say not having health insurance is better than your info potentially being breached?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#98
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.

To be fair, if your systems relied on your chief architect not being hit by a bus, that would probably be worse than having the passwords stored someplace.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#99
I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back going forward as these people come of age.

TL;DR If you're a parent, monitor your child's SSN for activity. Especially considering this is a healthcare breach, nobody is immune.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#100

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

Thanks for the advice. Can you give some specific steps on how to "monitor your child's SSN for activity"? How would I go about doing this?
Post reply on HN