Previous Thread
Next Thread
Print Thread
Joined: Feb 2008
Posts: 6,370
A
Hall of Famer
OP Offline
Hall of Famer
A
Joined: Feb 2008
Posts: 6,370
No security ever built into Obamacare site: Hacker

Published: Monday, 25 Nov 2013 | 9:54 AM ET
By: Matthew J. Belvedere | Producer, CNBC's "Squawk Box"

It could take a year to secure the risk of "high exposures" of personal information on the federal Obamacare online exchange, a cybersecurity expert told CNBC on Monday.

"When you develop a website, you develop it with security in mind. And it doesn't iËpear to have happened this time," said David Kennedy, a so-called "white hat" hacker who tests online security by breaching websites. He testified on Capitol Hill about the flaws of HealthCare.gov last week.

"It's really hard to go back and fix the security around it because security wasn't built into it," said Kennedy, chief executive of TrustedSec. "We're talking multiple months to over a year to at least address some of the critical-to-high exposures on the website itself."

According to the Department of Health and Human Services, which oversaw the implementation of the website, the components used to build the site are compliant with standards set by Federal security authorities.

"The privacy and security of consumers' personal information are a top priority for us. Security testing happens on an ongoing basis using industry best practices to appropriately safeguard consumers' personal information," said the spokesperson.

Another online security expert—who spoke at last week's House hearing and then on CNBC—said the federal Obamacare website needs to be shut down and rebuilt from scratch. Morgan Wright, CEO of Crowd Sourced Investigations said: "There's not a plan to fix this that meets the sniff test of being reasonable."

Last month, a Sept. 27 government memorandum surfaced in which two HHS officials said the security of the site had not been properly tested before it opened, creating "a high risk."

HHS had explained then that steps were taken to ease security concerns after the memo was written, and that consumer information was secure. Technicians fixed a security bug in the password reset function in late October, the agency said.

But on CNBC, Kennedy disputed those claims, saying vulnerabilities remain on "everything from hacking someone's computer so when you visit the website it actually tries to hack your computer back, all the way to being able to extract email addresses, users names—first name, last name—[and] locations."

Government officials and contractors have been working around the clock for weeks, releasing fixes on HealthCare.gov nightly with the goal of meeting the Obama administration's self-imposed deadline of the end of the month to have the site working smoothly.

"When you look at the site itself, it could be really good. It could do really well. They're just not building the security into the site itself," said Kennedy. "Putting your information on there is definitely a risk."

The federal portal serves 36 states not operating their own health insurance exchanges. Fourteen other states and the District of Columbia run their own marketplaces. All of them launched on Oct. 1 as part of the Obamacare provision mandating most Americans have health-care coverage for next year or face tax penalties.

Kennedy said those state-operated exchanges also face security risks. "These are going to be a large area for attack." He pointed to a problem on the Vermont website on Friday. Officials overseeing the Vermont Health Connect website confirmed a security breach on the system last month.

When it comes to securing personal information online, Kennedy cited Amazon, Facebook, and Twitter as models for the industry. He even said the IRS website does regular testing to help "ensure that when the websites come out they're protected."

Joined: Oct 2006
Posts: 17,850
N
Legend
Offline
Legend
N
Joined: Oct 2006
Posts: 17,850
this is great news. the website is now working well enough to be on long enough to hack it. before, the security was built-in because it didn't even work.


#gmstrong
Joined: Sep 2006
Posts: 42,834
Likes: 158
Legend
Offline
Legend
Joined: Sep 2006
Posts: 42,834
Likes: 158
It's a piece of garbage..


#GMSTRONG

“Everyone is entitled to his own opinion, but not to his own facts.”
Daniel Patrick Moynahan

"Alternative facts hurt us all. Think before you blindly believe."
Damanshot
Joined: Feb 2007
Posts: 3,405
I
Hall of Famer
Offline
Hall of Famer
I
Joined: Feb 2007
Posts: 3,405
They should have used Web.com. They advertise on the radio they'll build your site for free! "You say it. We build it!"


"My signature line goes here."
Joined: Mar 2013
Posts: 12,635
D
Legend
Offline
Legend
D
Joined: Mar 2013
Posts: 12,635
If it's not getting hacked, they're hiring ex-cons and felons as "navigators" so feel comfortable giving your personal info to a likely criminal.

This system is the utmost joke. I cannot believe this is what our government has come up with and implemented.

Joined: Sep 2006
Posts: 15,015
Likes: 147
F
Legend
Offline
Legend
F
Joined: Sep 2006
Posts: 15,015
Likes: 147
Quote:

If it's not getting hacked, they're hiring ex-cons and felons as "navigators" so feel comfortable giving your personal info to a likely criminal.

This system is the utmost joke. I cannot believe this is what our government has come up with and implemented.




That doesn't bother me as much as they paid for that crap...


We don't have to agree with each other, to respect each others opinion.
Joined: Sep 2006
Posts: 19,126
Likes: 1048
Legend
Offline
Legend
Joined: Sep 2006
Posts: 19,126
Likes: 1048
...or who they paid for that crap. The first lady's Princeton classmate is a top executive for the company that got the no bid contract to develop it.


And into the forest I go, to lose my mind and find my soul.
- John Muir

#GMSTRONG
Joined: Sep 2006
Posts: 1,346
Dawg Talker
Offline
Dawg Talker
Joined: Sep 2006
Posts: 1,346
This is the hip tech Prez. He probably still doesn't understand why he had to give up his Blackberry.

Voted into office by people that like shiny things.

"All your base are belong to us" is relevant on both sides.

Yeah, lots of lulz for everyone.

DawgTalkers.net Forums DawgTalk Everything Else... Hacker: Obamacare website never had security built-in

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.5