Jump to content

10 posts in this topic

Recommended Posts

Filed: K-1 Visa Country: China
Timeline
Posted (edited)

Obamacare website security called 'outrageous': How safe is it?

Glitches in the Obamacare website are well known, but some cyber experts are also raising red flags about the site's security. They point to a variety of concerns.

By Mark Clayton, Staff writer / October 14, 2013

  • 1014-Obamacare-website-hack_full_380.jpg

A man looks over the Affordable Care Act signup page on the HealthCare.gov website in New York in this photo illustration.

Mike Segar/Reuters

Cybersecurity professionals are voicing concerns about potential concerns in the new federal health care website system that could open the door to theft of personal information.

In the two weeks since the Affordable Healthcare Act site, www.healthcare.gov, went live, most complaints have centered on long wait times with sites initially overloaded by interested visitors. In response, government officials are scrambling to get more capacity for the main site and its satellites.

But potentially far more serious questions are emerging about cybersecurity. Experts have said that hackers could “spoof” the website with a look-alike website to collect personal information, or criminals could use an automated program to try repeatedly to enter the site even if it didn’t get a login correct.

Experts have stopped short of calling these concerns “vulnerabilities” – a term that means a proven weak spot to hackers. But they say these red flags need attention.

“I’ll ask you your Social Security, your date of birth, [so] an hour later I can empty your bank account,” John McAfee, who founded the cybersecurity company of the same name but is no longer associated with it, complained on Fox News. The Obamacare websites, he said, have “no safeguards,” and the main site's architecture is "outrageous."

Federal officials say they have made website security a “top priority,” said Marilyn Tavenner, administrator for the Centers for Medicare & Medicaid Service, which operates the system, during a congressional hearing in July. “We will use appropriate policies, procedures, standards, and implementation specifications to ensure the privacy and security of consumer data in accordance with applicable law.”

For example, the site is supposed to adhere to cybersecurity standards for the federal government set by the National Institute of Standards and Technologies.

But just because all the standards are met does not mean all the holes are plugged. Some cybersecurity experts have echoed Mr. McAfee's comments. Here are some of the red flags they raise.

Request forgery. One potential flaw with the Obamacare website would grant automated “all-Access Request For Other Sites” – which basically allows another site to make a certain kinds of request to healthcare.gov that could lead to “cross-site request forgery” and potentially fooling the government site into releasing restricted information, writes Nidhi Shah, who works on research and development for HP's Web Security Research Group, on a company blog. That red flag appeared on some of the site's pages, but she admits it could not be confirmed at the time on the site’s most secure areas because of high traffic volume.

Clickjacking.' The government site lacks defenses to prevent an attacker from putting an invisible layer over the legitimate website, Ms. Shah added. As a result, a user clicking on a link or button might end up at a renegade site that looked just the same – and end up divulging personal information to that site.

'Cookie theft.' The site appears not to use a feature that prevents access to cookies that are stored on a user’s personal computer. "Healthcare.gov uses cookies to maintain user history on the site and [for] user identification," Shah writes. At the very least, an attacker could grab "sensitive information such as ... possible health issues, income level, and marital status.”

Verification. A more fundamental problem is the way the website is set up, contends Christopher Budd, communications manager for Trend Micro, a Tokyo-based cybersecurity company. "The health insurance exchange isn't made up of a single, authoritative site where people can go and register for coverage," he wrote in a blog post. "In addition to the federal site, people can apply for coverage at sites run by individual states. Then, within each state, there can also be legitimate third-party sites that provide assistance and even broker coverage," he said.

While the main federal site uses a key security feature called SSL to verify itself, "a survey of state and third-party sites also shows that official sites aren't required to provide the ability to verify the site using SSL," he writes. Many of those sites don’t authenticate, he said.

"As people look for health care exchanges, they're going to be faced with potentially hundreds or thousands of sites that claim to be legitimate, but [they] won't be able to easily verify that claim," except based on how a site looks, Mr. Budd wrote.

Login fraud. Basic problems with the site could invite cybercriminals to use automated systems to hack individual accounts, according to researchers at TrustedSec in Strongsville, Ohio. They noted that there were no features to prevent an intruder from using an automated program to try repeatedly to enter the site even if it didn’t get a login try correct. Common tools are available to authenticate that a human is trying to make the attempted login, such as putting on the screen with a word that only a human can read – that would then have to be typed into a box.

“As you can imagine, the site is going to be a major target for hackers, other governments, and organized crime,” the TrustedSec researcher wrote. “There’s a lot of money to be made right now in an untapped market that is fresh for the picking.”

http://www.csmonitor.com/USA/Politics/2013/1014/Obamacare-website-security-called-outrageous-How-safe-is-it-video/(page

  • csmlogo_179x46.gif
Edited by lostinblue

If more citizens were armed, criminals would think twice about attacking them, Detroit Police Chief James Craig

Florida currently has more concealed-carry permit holders than any other state, with 1,269,021 issued as of May 14, 2014

The liberal elite ... know that the people simply cannot be trusted; that they are incapable of just and fair self-government; that left to their own devices, their society will be racist, sexist, homophobic, and inequitable -- and the liberal elite know how to fix things. They are going to help us live the good and just life, even if they have to lie to us and force us to do it. And they detest those who stand in their way."
- A Nation Of Cowards, by Jeffrey R. Snyder

Tavis Smiley: 'Black People Will Have Lost Ground in Every Single Economic Indicator' Under Obama

white-privilege.jpg?resize=318%2C318

Democrats>Socialists>Communists - Same goals, different speeds.

#DeplorableLivesMatter

Posted

"I swear by my life and my love of it that I will never live for the sake of another man, nor ask another man to live for mine."- Ayn Rand

“Your freedom to be you includes my freedom to be free from you.”

― Andrew Wilkow

  • 1 month later...
Filed: K-1 Visa Country: China
Timeline
Posted (edited)

http://www.cnbc.com/id/101225308 No security ever built into Obamacare site: Hacker

Text Size
Published: Monday, 25 Nov 2013 | 9:54 AM ET
By: Matthew J. Belvedere | Producer, CNBC's "Squawk Box"
The vulnerability of Healthcare.gov
Monday, 25 Nov 2013 | 7:14 AM ET
Dissecting the critical security problems with the website Healthcare.gov, with TrustedSec CEO David Kennedy. "It will take a long time to address some of the critical and high exposures on the website itself," he says.

It could take a year to secure the risk of "high exposures" of personal information on the federal Obamacare online exchange, a cybersecurity expert told CNBC on Monday.

"When you develop a website, you develop it with security in mind. And it doesn't appear to have happened this time," said David Kennedy, a so-called "white hat" hacker who tests online security by breaching websites. He testified on Capitol Hill about the flaws of HealthCare.gov last week.

"It's really hard to go back and fix the security around it because security wasn't built into it," said Kennedy, chief executive of TrustedSec. "We're talking multiple months to over a year to at least address some of the critical-to-high exposures on the website itself."

According to the Department of Health and Human Services, which oversaw the implementation of the website, the components used to build the site are compliant with standards set by Federal security authorities.

"The privacy and security of consumers' personal information are a top priority for us. Security testing happens on an ongoing basis using industry best practices to appropriately safeguard consumers' personal information," said the spokesperson.

Another online security expert—who spoke at last week's House hearing and then on CNBC—said the federal Obamacare website needs to be shut down and rebuilt from scratch. Morgan Wright, CEO of Crowd Sourced Investigations said: "There's not a plan to fix this that meets the sniff test of being reasonable."

(Read more: Fix Obamacare site? 'Better chance of seeing God')

Last month, a Sept. 27 government memorandum surfaced in which two HHS officials said the security of the site had not been properly tested before it opened, creating "a high risk."

HHS had explained then that steps were taken to ease security concerns after the memo was written, and that consumer information was secure. Technicians fixed a security bug in the password reset function in late October, the agency said.

But on CNBC, Kennedy disputed those claims, saying vulnerabilities remain on "everything from hacking someone's computer so when you visit the website it actually tries to hack your computer back, all the way to being able to extract email addresses, users names—first name, last name—[and] locations."

101225814-187238552.240x160.jpg?v=138539
Andrew Harrer | Bloomberg | Getty Images
Healthcare.gov

Government officials and contractors have been working around the clock for weeks, releasing fixes on HealthCare.gov nightly with the goal of meeting the Obama administration's self-imposed deadline of the end of the month to have the site working smoothly.

"When you look at the site itself, it could be really good. It could do really well. They're just not building the security into the site itself," said Kennedy. "Putting your information on there is definitely a risk."

The federal portal serves 36 states not operating their own health insurance exchanges. Fourteen other states and the District of Columbia run their own marketplaces. All of them launched on Oct. 1 as part of the Obamacare provision mandating most Americans have health-care coverage for next year or face tax penalties.

(Read more: Obamacare extensions for 2014 and 2015 deadlines)

Kennedy said those state-operated exchanges also face security risks. "These are going to be a large area for attack." He pointed to a problem on the Vermont website on Friday. Officials overseeing the Vermont Health Connect website confirmed a security breach on the system last month.

When it comes to securing personal information online, Kennedy cited Amazon, Facebook, and Twitter as models for the industry. He even said the IRS website does regular testing to help "ensure that when the websites come out they're protected."

By CNBC's Matthew J. Belvedere. Follow him on Twitter @Matt_SquawkCNBC

Edited by lostinblue

If more citizens were armed, criminals would think twice about attacking them, Detroit Police Chief James Craig

Florida currently has more concealed-carry permit holders than any other state, with 1,269,021 issued as of May 14, 2014

The liberal elite ... know that the people simply cannot be trusted; that they are incapable of just and fair self-government; that left to their own devices, their society will be racist, sexist, homophobic, and inequitable -- and the liberal elite know how to fix things. They are going to help us live the good and just life, even if they have to lie to us and force us to do it. And they detest those who stand in their way."
- A Nation Of Cowards, by Jeffrey R. Snyder

Tavis Smiley: 'Black People Will Have Lost Ground in Every Single Economic Indicator' Under Obama

white-privilege.jpg?resize=318%2C318

Democrats>Socialists>Communists - Same goals, different speeds.

#DeplorableLivesMatter

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
- Back to Top -

Important Disclaimer: Please read carefully the Visajourney.com Terms of Service. If you do not agree to the Terms of Service you should not access or view any page (including this page) on VisaJourney.com. Answers and comments provided on Visajourney.com Forums are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Visajourney.com does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. VisaJourney.com does not condone immigration fraud in any way, shape or manner. VisaJourney.com recommends that if any member or user knows directly of someone involved in fraudulent or illegal activity, that they report such activity directly to the Department of Homeland Security, Immigration and Customs Enforcement. You can contact ICE via email at Immigration.Reply@dhs.gov or you can telephone ICE at 1-866-347-2423. All reported threads/posts containing reference to immigration fraud or illegal activities will be removed from this board. If you feel that you have found inappropriate content, please let us know by contacting us here with a url link to that content. Thank you.
×
×
  • Create New...