Anthem Breach May Have Started in April 2014
krebsonsecurity.com
krebsonsecurity.com
If a bank got screwed on a loan deal by someone, and all they have to claim it was youis that the person told them your name and SSN? Really, at this point, with so many SSNs leaked, how can they justify blacklisting you with a credit check bureau?
I think you're right. Publish them all. Force banks to come up with a better solution.
On the last Anthem story, someone linked this Mitchell & Webb audio clip: https://www.youtube.com/watch?v=CS9ptA3Ya9E which completely nails it.
But then banks would incur additional expenses, and they would have to, like, reduce executive bonuses or something. That would be terrible!
/s
However, when they are tied in with other identifying information this is when they become unique identifiers. The more associated information that is tied to the SSN the "more secure" the mechanism of identification is. I have noticed this proposal of just not using SSN at all and incorporating something else. An alternative is the password which has been proven to not be the best case scenario as users pick easy passwords to remember. Then 2fa become popular and is becoming much easier to use. Then there were gaps in the sms or voicemail method of 2fa. My point being that no matter the mechanism put into place to uniquely identify an individual there is no silver bullet. The more layers a company adds on the better. Not to say I support HIPPA or any other archaic legislation (PCI etc) these organizations are tasked with instituting laws or guidelines that are being outdated as fast as they are implemented and are required to make it as reasonable for every entity that is covered under these laws.
Possible solution advertise all SSN's in card format invalidate them all and force hand of government? Implausible but not improbable.
Or possibly advertise your own once it is known to be hacked...just throwing wet spaghetti at wall but there may be something that sticks.
Apparently in 2011 they changed this, and now none of the numbers are significant.
The benefit to use of SSNs is that they're assigned by a central authority which does a pretty good (though not perfect) job of ensuring that there's a 1:1 correspondence of SSN to person.
The issues of how they were to be used _other_ than by the Social Security Administration has been up in the air for a long time. I remember in college when "student identifiers" were just SSNs, and grades and other student data would be posted on office doors by Student ID (that is: SSN). That started getting phased out in the 1990s. There's the matter of the namespace -- it was kept intentionally small, and SSN exhaustion is something that will be faced eventually -- the space is sufficient for "several generations", some 450 million have been issued. The total namespace is around 890 million numbers.
The problem is that when you sign up for new services (online, financial, other), there's a desire though often not a specific need, to associated an account with a specific person. And so the SSN gets drafted to serve that purpose, as a proof of identity, not as an identifier based on other proven identity.
It's a misuse of the identifier
What you describe is ideal, but it's not what actually happened. The social security number has been used as identifier and proof of identification for a long time. Part of the problem is that it's from a time when technology did not allow anything more complicated. That's no longer an excuse though. Social security numbers should have been upgraded long ago.
>Does this impact Blue Cross and Blue Shield plans not owned by Anthem?
>Yes, BlueCard members are impacted. The Blue Cross and Blue Shield Association's BlueCard is a national program that enables members of one Blue Cross and Blue Shield Plan to obtain healthcare services while traveling or living in another Blue Cross and Blue Shield Plan's service area. The program links participating healthcare providers with the independent Blue Cross and Blue Shield Plans across the country and in more than 200 countries and territories worldwide through a single electronic network for claims processing and reimbursement.
Check out the Wikipedia article... There are dozens of affiliated health insurance providers. http://en.m.wikipedia.org/wiki/Blue_Cross_and_Blue_Shield_As...
I am part of Anthem and I have heard literally nothing directly about this, it's all been through news/tech sites.
"Members who may have been impacted by the cyber attack against Anthem, should be aware of scam email campaigns targeting current and former Anthem members. These scams, designed to capture personal information (known as "phishing") are designed to appear as if they are from Anthem and the emails include a "click here" link for credit monitoring. These emails are NOT from Anthem."
If you do get contacted personally it's a safe bet it's a phishing attack.
Our Company is affected and all our interaction has been through HR. I would contact your HR department.
Anthem will not be emailing individuals, but apparently will be sending a snail-mail packet of information including an offer for credit-monitoring services. And they have been contacting, via email, the benefits/HR people of client companies which used Anthem for group health plans for their employees.
(that all comes via my employer, which has been sending me updates about this)
CC numbers are far less important than any of those identifiers - unlike your SSN or address, they're easy to change. Someone with all that info can just apply for their own CC or loan in your name...
I already locked my credit and now I'm thinking it's time to freeze my credit so no one can take out new lines without me unfreezing it or increased authentication.
I am learning how this is all working, but if you think about it, it's silly to wait for a breach to have your data locked down.
Ftc has the best info for this sort of thing
If you need to unfreeze (eg. applying for a new credit card or a loan), you need to pay another fee per credit bureau, so you should find out which bureau will be used. You can unfreeze permanently, unfreeze for a short time period, or get an authorization code that you can give to whoever needs to check your credit report.
In addition to reading that, I signed up for one of those credit monitoring/protection sites. The one I chose was TransUnion, but I'm still learning about this stuff. I suggest you look around.
subject line:
Important Update from Anthem, Inc.
And the first paragraph is: Safeguarding your personal, financial and medical information is one of our
top priorities, and because of that, we have state-of-the-art information
security systems to protect your data. However, despite our efforts, Anthem
Blue Cross was the target of a very sophisticated external cyber attack.
These attackers gained unauthorized access to Anthem’s IT system and have
obtained personal information from our current and former members such as
their names, birthdays, medical IDs/social security numbers, street
addresses, email addresses and employment information, including income
data. Based on what we know now, there is no evidence that credit card or
medical information (such as claims, test results or diagnostic codes) were
targeted or compromised.
So yeah, safeguarding is apparently not that much of a priority.This from a fucking company that uses an online payment system that limits your password to 8 characters.
Today we received a second notice warning of phishing scams that was passed down from Anthem.
Since that part of the data should be the most locked down, it seems like a complete lie to me. I think the health info was compromised completely.
obviously that's broken logic since..
- you're not compromised by default/when the business starts
- when you're compromised, you probably don't even know it. you might find out in a few years if lucky.
One way to have not allowed this is to force the database to restrict queries to use two pieces of information in the where clause. This means that they would have to search for name = "John Smith" and MRN = "xyz". This would prevent mass queries and database dumps.
In the case that they stored SSN and MRN together, which I believe is highly likely, the attackers also gained access to the MRN.
If the most highly protected data demographic data (the name and identifying information about the individual patient) is unencrypted and easily compromised, I believe that patient data was very likely compromised as well.
It is possible, however, that the attackers were only after information that could be used to commit identity theft so they may have ignored the health information, however, this does not mean that the health information was properly protected.
Money begets money, power begets power. Either begets the other. The great vicious cycle of our civilization.
Much of the data I presume that Google deals with is not sensitive enough to warrant the kinds of encryption that a health provider company should use. My search data and even my Google+/YouTube/Gmail accounts are enough to tie them to my person, but not my identity. I, or someone masquerading as me, cannot open a line of credit with my Google account at a bank.
Edit: This wasn't it, but interesting nonetheless: https://news.ycombinator.com/item?id=2254394
If enough companies are destroyed, eventually they will start taking security seriously.