3 ms·
Hacker Says He Could Access 70,000 Healthcare.Gov Records In 4 Minutes
- sp332 13y agoOriginal link http://blogs.computerworld.com/cybercrime-and-hacking/23412/insecure-healthcaregov-allowed-hacker-access-70000-records-4-minutes http://blogs.computerworld.com/cybercrime-and-hacking/23412/... Well, it's really a collection of interesting links to other sources, but at least it's useful. Or, given the numerous vulnerabilities, perhaps a breach already has happened. These are exactly the kind of security flaws bad guys exploit in large-scale breaches. That's exactly what I've been wondering. Hackers have certainly had enough time to get in there and look around. How much data has been taken, and where will it show up?
- deleted 13y ago[deleted]
- pacificmint 13y agoAccording to the post the white hats that found these and other holes testified in front of congress. I think it is safe to tell their parents at this point.
- fournm 13y agohttp://boingboing.net/2014/01/21/70000-healthcare-gov-record.html http://boingboing.net/2014/01/21/70000-healthcare-gov-record... Except not. This was misreported and spread like wildfire.
- theboss 13y agoNo....No he didn't. https://twitter.com/HackingDave/status/425640931690565632 https://twitter.com/HackingDave/status/425640931690565632
- sp332 13y agoThat says he didn't hack the site to access the data. In the video he says the information was collected using "passive reconnaissance" which means he could get the data without attacking it directly.
- theboss 13y agoYes. It does say he didn't access the data. There is a difference between passive and active attacks.