China involvement suspected in hack of US health insurer Anthem
bloomberg.com
bloomberg.com
What I don't want to see is knee-jerk legislation that erodes our privacy and rights further.
Really, just mandate by an act of congress that companies need to rely on public key cryptography within 5 years for everything and you'll see user-friendly solutions appear really friggin quick.
I remember back when I was in banking when they announced some crazy retention policies on all communication (written and voice) that wasn't technically feasible at the time congress passed the laws requiring those retention policies. Within a few years, there were a bunch of vendors with solutions for the banks to implement. Necessity is the mother of invention. Invent a necessity through an act of Congress and people will invent.
The first suggestion would be much more secure but would be difficult and very lengthy to implement, and the second would not have helped in a situation like this.
Identity Theft is a completely made up thing, that used to be called fraud. When it was called fraud it was the responsibility of the institutions to protect themselves. Instead they use the word identity theft to make it the problem of the victim. If someone goes to the bank and pretends to be me and gets a line of credit, spends a ton of money, I am left holding the bag since it destroys my credit rating. Yet, I didn't do anything at all wrong. These institutions rely on woefully inadequate measures to determine identity and when something goes wrong, the person who should pay for inadequately verifying identity is the financial institution that messed up and gave credit to the wrong person under false pretenses.
Anthem is my insurer and now I'm responsible for dealing with the fallout from every institution's completely inadequate processes for verifying identity. How is that fair?
The solution isn't hard, you'd get an account with an identity signing service that goes to great lengths to confirm your identity. Once your identity has been confirmed, you either generate your own private and public keys and upload your public key to them or they can generate both on your behalf. After that, you either host your own service to sign with your private key or you redirect signing to the identity provider if they generated a key for you.
This is not a pipe dream. It just requires mandating that companies need to require that you sign off on things cryptographically. If you have not signed off, then the losses and consequences from fraud are their responsibility, not yours.
So maybe in the Sony hack case it was NK, however I'd love to see the US's evidence. If they have two dozen proxies, one of which happened to come from NK thus that "proves" it was NK, then sorry, but no. However if they can prove that one connection was not proxied somehow and originated from NK then fair call.
I doubt they'll ever release technical information however.
I don't see how this is even technically possible
[Edit: I just noticed these are government and not private analysts making the claims, so my comment is now a bit cynical for my own taste... but I think it's still effective PR and I expect private security companies to field more "So you're not saying is WASN'T North Korea, right?" kinds of questioning from corporate clients.]
> I just noticed these are government and not private
> analysts making the claims, so my comment is now a bit
> cynical for my own taste...
Not for mine... casting these issues as a threat to national sovereignty is a great way to raise defense funding.This is SSN data that was stolen, it's a whole different beast that the FBI's kerfuffle (to put it lightly) with the Sony Pictures hack.
I can't tell which one you think is more serious. It sounds like you think it'd be a very serious matter if SSN data was stolen. But haven't the vast majority of SSNs been available on the various blackhat markets for many years?
"Chinese" = we saw an Asian IP address.
"state-sponsored hackers" = This is war!
"Sophisticated attack by Chinese state-sponsored hackers" = force majeure.
Force majeure = We don't owe you a penny.
Rather than responding to hacks with counterattacks or an attempt at diplomacy, the first priority ought to be to strengthen the defences of companies handling sensitive data.
While a large system may never be made impenetrable, it could certainly be a lot harder and more costly to pull off an attack against most of these companies than it is today.
If this is considered a crisis, redirecting a few of those billions earmarked for NSAs offensive capabilities towards vetting and improving the security of US companies would make a good strategy.
USA Today, 10/07/14: "Report: Russian hackers behind JPMorgan Chase attack"
Reuters, 10/20/14: "Russia ruled out as culprit in Chase cyber security breach, U.S. officials say"
[1]: http://www.bloomberg.com/news/articles/2014-08-27/fbi-said-t...
[2]: http://www.reuters.com/article/2014/10/21/cybersecurity-jpmo...
Just as an example, the Target and Home Depot breaches were almost certainly conducted by the same fairly well-known group of Russian hackers and fraudsters, but they have no known ties to the Russian government.
The fact that Anthem could not be bothered to spend the time or money to secure their data until it was stolen has nothing to do with it. Not at all.
This is a ploy to get out from under the HIPAA liabilities.
Two things can be true: you should have locks on your door AND you shouldn't enter someone else's unlocked door.
(Ironically, not locking your doors could also increase your insurance rate...)
In that case, we should just put trespassing and breaking and entering laws on the books and call it a day, that should stamp out the problem immediately.
a) much harder to attribute,
b) impossible to prosecute (Assume it is Russia or China, what is your recourse? the U.S. is already hacking them too, under slightly different rules, and any other response is just a needless international incident. If it is people in another country, not associated with their government, there is even less you can do), and
c) possible, at least in theory, to defend against robustly (compared to doors and locks which are always vulnerable to literal brute force, without the need to be particularly clever about it).
So, given that punishment is impossible and prevention is possible, focusing on the second is a good idea. Or, at least, in some combination of prevention and mitigation (including insurance, or say, ways of detecting and changing stolen SSNs or credit card numbers with minimal disruption). Now, I am not saying it's the fault of a single insurance company. Security is pretty hard to get right and we systematically under-prioritize it when developing the technologies and systems we use. But as a society, making our computer systems more secure is more cost effective than keeping pilling up cyber crime laws that are unenforceable unless you happen to get lucky enough that the hacker is among the 1/20th of the world population you have jurisdiction over, or getting into a harmful retaliatory mode under ideas like "cyber-warfare".
p.s. By "possible to defend against robustly", I mean when you trust the suppliers of your computing base to be non-malicious and you have ensured physical security (which you can enforce by law and national defense and whatever other age tested methods people/groups/nations have used to secure their property for millenia).
However, the criminals lately always seem to be "China" or "Russia" rather than "Chinese individuals" or "Russian individuals". The reason for this is that practically every contract includes an escape clause for "Act of War" by a foreign state but not for foreign individuals.
To further your analogy, if someone burgled an apartment complex because the manager left the skeleton key under his doormat, you can be sure that the apartment manager would be getting prosecuted for gross negligence as well as the individual who burgled the apartments.
It's time that an IT breach carry a charge of gross negligence against the CEO. Suddenly, IT will have lots of funding and importance.
HIPPA violations should be like Sarbox. The CEO should be held personally responsible, ideally by being terminated and then prosecuted. Then, and only then, will the average CEO take any of this seriously.
It really seemed to make sense at the time.
The usual motivation for stuff like spying and data theft is the acronym MICE - Money, Ideology, Coercion, and Ego. It's unlikely to be money - we're already shipping dollars over there like crazy. It's also unlikely to be Ideology - the Central Committee are closet capitalists these days. Coercion - I don't see them trying to trade this for reducing our support for Taiwan. Ego. Ego is a possibility - but they're not teen-aged boys.
I mean, I'm not a government worker or contractor. Even if I was, my password is randomly generated and not used elsewhere. If it wasn't for profit hackers, identify theft with social security numbers is perhaps less of a concern. And my password was randomly generated, so they can't get into any other accounts, so identity theft and fraud based on it is probably the biggest threat.
I really wish there was a good health insurance company (or a single payer system) I could switch to, but anthem is honestly the least bad company currently available to me.
As others have pointed out, running a whois on the anthemfacts webpage returns a registration date of 12/13/2014 [1] which is most likely when the breach occurred. Not January 29th.
The company just changed its name from Wellpoint to Anthem in December and could have bought up a bunch of "anthem*.com" domain names around then to keep in reserve.
Also I'm sure a major healthcare company that handles tens of millions of sensitive personal records has enough foresight to see a data breach coming. HIPAA and ACA probably mandate healthcare companies having this exact kind of plan ready to deploy in the event of a hack.
Did anyone record any downtime of their public-facing systems in this time? You know when you're a sysadmin and you notice something really bad happening, you shut down the affected systems immediately and try to minimize the damage? You never know what kind of back doors have been put in place, after you are breached.
It is also entirely plausible that the breach is still ongoing now, after a month and a half why not, but they are just no longer able to detect it. These people are some of the most important cogs in the health care machine, the insurance providers! If they had some kind of downtime that was actually affecting their ability to provide services, well then they might actually be subject to some real form of legal action, maybe even pay serious damages to their customers. Thank heavens that didn't happen!
They are paying lip service to security because it's not as important to them as, you know, basically anything else. Like say, receivables. It's only identity theft!
"The company also confirmed Friday that it found that unauthorized data queries with similar hallmarks started as early as Dec. 10 and continued sporadically until Jan. 27."