PDA

View Full Version : Security hole found in Obamacare website


UltimateHoboW/Shotgun
11-02-2013, 10:28 AM
http://money.cnn.com/2013/10/29/technology/obamacare-security/


The Obamacare website has more than annoying bugs. A cybersecurity expert found a way to hack into users' accounts.
Until the Department of Health fixed the security hole last week, anyone could easily reset your Healthcare.gov password without your knowledge and potentially hijack your account.

The glitch was discovered last week by Ben Simo, a software tester in Arizona. Simo found that gaining access to people's accounts was frighteningly simple. You could have:
guessed an existing user name, and the website would have confirmed it exists.
claimed you forgot your password, and the site would have reset it.
viewed the site's unencrypted source code in any browser to find the password reset code.
plugged in the user name and reset code, and the website would have displayed a person's three security questions (your oldest niece's first name, name of favorite pet, date of wedding anniversary, etc.).
answered the security questions wrong, and the website would have spit out the account owner's email address -- again, unencrypted.
Armed with the account holder's email address, a person with malicious intent could easily track down their target on social media, where they'd likely discover the answers to those security questions.
It wouldn't have even taken a skilled hacker. Anyone with bad intentions -- and a minimal understanding of how to read a website's code -- could have figured it out. While such an attack might not have yielded your Social Security number or health information, it would have exposed your address and phone number.
Related story: Obamacare 'hub' back online after malfunction
By Friday, that dent in security was gone. But security consultants say it's disconcerting that such a privacy concern remained unaddressed for more than three weeks after the federal government launched the Obamacare website Oct. 1.
Obama ex-aide: Valley would've done better
Obama ex-aide: Valley would've done better
The Department of Health and Human Services, which is rolling out the health care overhaul, confirmed the flaws existed. After being contacted for this story, the department said changes were made that would prevent outsiders from seeing someone's password reset code.
"We have taken great care to ensure that people's usernames and information are kept secure," said health spokeswoman Joanne Peters.
Simo tried to report the defect as soon as he found it, but the Obamacare hotline operator referred him to law enforcement -- which was neither helpful nor relevant. While attempting to retrace Simo's steps on Friday, CNNMoney found that some of the issues had been fixed -- but not all.
Still, Simo fears that a savvy hacker could find other holes and Obamacare applicants' data will be compromised on a mass scale.
"This seems really sloppy," Simo said. "Either the developers were incompetent and did not know how to do the basic things to protect user information, or the development was so fractured that the individuals building the system didn't understand how they fit into the bigger picture."
Related story: Obamacare website: 6 biggest contractors
The flaw wasn't mentioned at last week's congressional hearing, when government contractors CGI Federal and Quality Software Services Inc. testified about their responsibilities in the project. But another point was made by Congressman Mike Rogers, R-Mich.: companies keep patching up the website's holes, and adding thousands of new lines of computer code, exposing the entire system to unforeseen security problems.
Cyberattacks on Obamacare exchange websites are already underway. At least one state, Connecticut, has seen outsiders attempt to gain "irregular" access, according to Jim Wadleigh, chief information officer of Access Health CT.
Congress' inquiries continued Tuesday, when the Ways and Means Committee posed questions about the site's glitches and security to Marilyn Tavenner, head of the health department's Centers for Medicare & Medicaid Services.
The security hole is just the latest in a series of mishaps for the Obamacare website's launch. In the first weeks, system errors prevented people from signing up to the newly launched insurance exchanges. Over the past weekend, a government contractor's network failure again left users unable to apply.
Monday brought the latest worrisome disclosure: that the entire Obamacare website operates on a single computer server in Virginia -- without any backup, according to Congressman Rogers. To top of page




<script src='http://i.cdn.turner.com/money/.element/script/6.0/players/embed.js?videoid=/video/technology/2013/10/25/t-obama-cio-obamacare-site.cnnmoney'></script>

http://nation.foxnews.com/2013/10/03/ny-obamacare-website-hacked

Hackers blamed for NY’s ObamaCare breakdown

By Bruce Golding | New York Post

The numbers just don’t add up.

The “abnormally high traffic” that crippled New York’s ObamaCare Web site for two days may have resulted from a malicious attack by hackers, computer-security experts said Wednesday.

The NY State of Health site recorded an astounding 10 million visits after opening for business Tuesday — although there are only about 1.1 million state residents without health insurance and just 330,000 are expected to buy ObamaCare for next year.

By comparison, the federal government’s heavily promoted HealthCare.gov site — a portal to the sites for all 50 states, the District of Columbia and America’s territories and commonwealths — drew just 4.7 million visitors the first day.


:thumbs: Obama

Mecklomaniac
11-02-2013, 02:52 PM
https://pbs.twimg.com/media/BYA1XZfCEAAZdEi.jpg:large
Maybe Sebelius should read the book

Rohirrim
11-02-2013, 02:57 PM
What we need around here are ten more Obamacare threads. Geez, Michele. Let's try to conserve the bandwidth. :oyvey:

barryr
11-03-2013, 07:00 AM
This whole things is a mess and a joke, but as typical, the liberals will pretend it's not happening. Or blame republicans. Or blame Bush. Or blame the evil capitalists, well only those that give to republicans of course since the ones that donate to democrats are "good." They don't want to shown to be wrong in thinking government can handle everyone's healthcare just fine.

Rohirrim
11-03-2013, 07:05 AM
This whole things is a mess and a joke, but as typical, the liberals will pretend it's not happening. Or blame republicans. Or blame Bush. Or blame the evil capitalists, well only those that give to republicans of course since the ones that donate to democrats are "good." They don't want to shown to be wrong in thinking government can handle everyone's healthcare just fine.

You realize that you've posted this same post about nearly every subject that comes up for years on here? How can we be sure you're not some kind of Right Wing bot?

Fedaykin
11-03-2013, 03:58 PM
You realize that you've posted this same post about nearly every subject that comes up for years on here? How can we be sure you're not some kind of Right Wing bot?

The gig is up, I'll have to start working on barryr-bot 2.0

UltimateHoboW/Shotgun
11-05-2013, 02:39 PM
https://pbs.twimg.com/media/BYA1XZfCEAAZdEi.jpg:large
Maybe Sebelius should read the book

Rep!

UltimateHoboW/Shotgun
11-08-2013, 11:57 AM
<iframe title="MRC TV video player" width="640" height="360" src="http://www.mrctv.org/embed/123854" frameborder="0" allowfullscreen></iframe>

B-Large
11-08-2013, 02:04 PM
Its going to work for me and my needs, it will get fixed. But the sideshow is fun to watch... another solid thread.

UltimateHoboW/Shotgun
11-17-2013, 01:00 AM
http://shark-tank.net/wp-content/uploads/2013/05/obamacare.jpg

barryr
11-17-2013, 05:31 AM
You realize that you've posted this same post about nearly every subject that comes up for years on here? How can we be sure you're not some kind of Right Wing bot?

You do realize you libs have posted your typical crap for years? Oh, of course you don't, you guys really think your posts are full of originality. Simplicity should be making you comfortable.

barryr
11-17-2013, 05:33 AM
Its going to work for me and my needs, it will get fixed. But the sideshow is fun to watch... another solid thread.

600 million and it still doesn't work? 600 million and hackers can easily get people's ID and other personal information? Yes, solid work by our government.

UltimateHoboW/Shotgun
11-17-2013, 08:59 AM
<iframe width="560" height="315" src="http://www.nbc.com/assets/video/widget/widget.html?vid=n43343" frameborder="0"></iframe>

L.A. BRONCOS FAN
11-18-2013, 12:45 AM
Just a heads-up for UltimateSpammer, barryr, Beavis, and the rest:

Your hero Smirky McFlightsuit is going to be on Leno this week.

http://www.bartcop.com/palin-turkeyfest.jpg