• Amused
  • Angry
  • Annoyed
  • ArrgPirate
  • atwork
  • Awesome
  • Bemused
  • Cocky
  • Cool
  • Crazy
  • Crying
  • deejayn
  • Depressed
  • Down
  • drinking
  • Drunk
  • eating
  • editing
  • Embarrased
  • Enraged
  • Friendly
  • gamingpc
  • gamingps
  • gamingsteam
  • gamingxbox
  • Geeky
  • Godly
  • Happy
  • hatemailing
  • Hungry
  • Innocent
  • lagging
  • livestreaming
  • loving
  • lurking
  • Meh
  • netflix
  • nostatus
  • Poorly
  • raging
  • Sad
  • Secret
  • Shy
  • Sneaky
  • Tired
  • trolling
  • Wtf
  • youtuber
  • zombies
  • Results 1 to 6 of 6

    Thread: No security ever built into Obamacare site: Hacker

    1. #1
      BOP ADMINISTRATOR
      is BOPn
       
      I am:
      Cocky
       
      PAiN's Avatar
      Join Date
      Oct 2010
      Posts
      17,282
      Post Thanks / Like
      Rep Power
      6128

      No security ever built into Obamacare site: Hacker

      No security ever built into Obamacare site: Hacker


      The vulnerability of Healthcare.gov

      Dissecting the critical security problems with the website Healthcare.gov, with TrustedSec CEO David Kennedy. "It will take a long time to address some of the critical and high exposures on the website itself," he says.

      It could take a year to secure the risk of "high exposures" of personal information on the federal Obamacare online exchange, a cybersecurity expert told CNBC on Monday.


      "When you develop a website, you develop it with security in mind. And it doesn't appear to have happened this time," said David Kennedy, a so-called "white hat" hacker who tests online security by breaching websites. He testified on Capitol Hill about the flaws of HealthCare.gov last week.

      "It's really hard to go back and fix the security around it because security wasn't built into it," said Kennedy, chief executive of TrustedSec. "We're talking multiple months to over a year to at least address some of the critical-to-high exposures on the website itself."
      According to the Department of Health and Human Services, which oversaw the implementation of the website, the components used to build the site are compliant with standards set by Federal security authorities.

      "The privacy and security of consumers' personal information are a top priority for us. Security testing happens on an ongoing basis using industry best practices to appropriately safeguard consumers' personal information," said the spokesperson.

      Another online security expert—who spoke at last week's House hearing and then on CNBC—said the federal Obamacare website needs to be shut down and rebuilt from scratch. Morgan Wright, CEO of Crowd Sourced Investigations said: "There's not a plan to fix this that meets the sniff test of being reasonable."

      Last month, a Sept. 27 government memorandum surfaced in which two HHS officials said the security of the site had not been properly tested before it opened, creating "a high risk."

      HHS had explained then that steps were taken to ease security concerns after the memo was written, and that consumer information was secure. Technicians fixed a security bug in the password reset function in late October, the agency said.

      But on CNBC, Kennedy disputed those claims, saying vulnerabilities remain on "everything from hacking someone's computer so when you visit the website it actually tries to hack your computer back, all the way to being able to extract email addresses, users names—first name, last name—[and] locations."

      Healthcare.gov Government officials and contractors have been working around the clock for weeks, releasing fixes on HealthCare.gov nightly with the goal of meeting the Obama administration's self-imposed deadline of the end of the month to have the site working smoothly.
      "When you look at the site itself, it could be really good. It could do really well. They're just not building the security into the site itself," said Kennedy. "Putting your information on there is definitely a risk."

      The federal portal serves 36 states not operating their own health insurance exchanges. Fourteen other states and the District of Columbia run their own marketplaces. All of them launched on Oct. 1 as part of the Obamacare provision mandating most Americans have health-care coverage for next year or face tax penalties.

      Kennedy said those state-operated exchanges also face security risks. "These are going to be a large area for attack." He pointed to a problem on the Vermont website on Friday. Officials overseeing the Vermont Health Connect website confirmed a security breach on the system last month.

      When it comes to securing personal information online, Kennedy cited Amazon, Facebook, and Twitter as models for the industry. He even said the IRS website does regular testing to help "ensure that when the websites come out they're protected."
      COC RULES: https://brotherhoodofpain.com/anabolic-ster...e-conduct.html

      e-mail: [email protected]

      >>>WE WILL NEVER EMAIL ABOUT SPONSORSHIP INFORMATION!<<<

    2. Thanks beanlicker thanked for this post
      Likes beanlicker liked this post
    3.    Sponsored Links

      ----
    4. #2
      Member
      is at mid-life crisis defcon-1
       
      I am:
      zombies
       
      ironmako's Avatar
      Join Date
      May 2013
      Posts
      436
      Post Thanks / Like
      Rep Power
      1011
      OMFG these people are unbelievable!

    5. ----
    6. #3
      Super Moderator
      This user has no status.
       
      I am:
      nostatus
       
      beanlicker's Avatar
      Join Date
      Jul 2012
      Posts
      5,825
      Post Thanks / Like
      Rep Power
      6224
      Quote Originally Posted by ironmako View Post
      OMFG these people are unbelievable!
      My thoughts exactly!

    7. ----
    8. #4
      Senior Member
      This user has no status.
       
      I am:
      Cocky
       
      315 BEAST's Avatar
      Join Date
      Mar 2012
      Location
      NY
      Posts
      2,656
      Post Thanks / Like
      Rep Power
      495
      Quote Originally Posted by ironmako View Post
      OMFG these people are unbelievable!
      couldnt have said it any better myself

    9. ----
    10. #5
      BOP ADMINISTRATOR
      is BOPn
       
      I am:
      Cocky
       
      PAiN's Avatar
      Join Date
      Oct 2010
      Posts
      17,282
      Post Thanks / Like
      Rep Power
      6128
      Yea be sure and sign up and have your identity stolen. Enjoy.
      COC RULES: https://brotherhoodofpain.com/anabolic-ster...e-conduct.html

      e-mail: [email protected]

      >>>WE WILL NEVER EMAIL ABOUT SPONSORSHIP INFORMATION!<<<

    11. ----
    12. #6
      BOP VETERAN
      is SAVVY
       
      I am:
      ArrgPirate
       
      bigsam's Avatar
      Join Date
      Nov 2013
      Posts
      1,351
      Post Thanks / Like
      Rep Power
      1387
      this doesn't surprise me one bit.

      I will never sign up for that bullshit.

    13. ----

    Similar Threads

    1. Hacker Conference Asks Federal Agents to Keep Out
      By beanlicker in forum Computer Tech Support, Safety/Security, & Downloads
      Replies: 3
      Last Post: 07-12-2013, 09:17 PM
    2. Arnold wasn't built in a day.
      By chrisotpherm in forum Bodybuilding
      Replies: 17
      Last Post: 06-09-2013, 12:49 PM

    Tags for this Thread

    Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •