Slashdot Mirror


Medicaid Hacked: Over 181,000 Records and 25,000 SSNs Stolen

An anonymous reader writes "The Utah Department of Health has been hacked. 181,604 Medicaid and CHIP recipients have had their personal information stolen. 25,096 had their Social Security numbers (SSNs) compromised. The agency is cooperating with law enforcement in a criminal investigation. The hackers, who are believed to be located in Eastern Europe, breached the server in question on March 30, 2012."

181 comments

  1. if you can't beat them by Anonymous Coward · · Score: 0

    secure your servers.

    1. Re:if you can't beat them by jellomizer · · Score: 5, Interesting

      I wish the media will focus on how idiotic Heal Insurance companies are, especially in their IT usage.
      I work for a hospital and previously I worked for a start-up that did cutting edge medical technology. And let me tell you the insurance companies IT is just pure insane and stupid.

      The government pushed a new electronic Bill form called 5010 which is an upgrade of 4010. These billforms are sent via EDI (Kinda of a Star Deliminator with a Tilda line feed, a throw back to old punch card technology) the difference between 4010 and 5010 are for the most part minor, and these changes were due January 1st. We are now in April. Now most of the insurance companies are compliment but there are other who are not, their test environment and production are very different and the test will allow different rules then production. So when a Hospital goes live after testing and getting clean tests they get rejection after rejection because they are not sending the right rules to the insurance company.
      Then they stick to the lie (The electronic format has the same data as the paper form) this is a Lie and absolute Lie! You call them on the lie and they will flat out deny you. Until you send the data and they reject you claims because there is data that isn't on the paper form, and some filds are on the paper from you Cannot fill in the electronic. Their checking system is insane. If they don't need that field you better not send it or your claim will get rejected.

      Now lets go over the transmission to the insurance companies...
      Method one. The old BBS. Yes thats right the old dial up BBS is still active. when writing scripts to automate connecting to the companies I see those old DOS base BBS's of the olden days, most of them have upgraded to allow ZMODEM transfer. Now the more modern one use Secure FTP. Secure FTP (not to be confused with sftp) as in you data channel is encrypted but not always your command channel. Or worse there are these VPN groups that many insurance companies get on where after you connect to the VPN then you normally FTP to the site... (where a rogue billing company can monitor the ports and see what goes on, because they happen to be in the VPN network)

      Everyone worries about HIPAA violations from the Health Care organization. For the most part now health care organizations have fare more modern and secure systems then the Insurance companies do. And if there are going to be a hack it will be in the insurance companies.

      Now you are going to say. This hack was with medicaid not a private insurance company. Well Medicare and Medicaid are operated by each state, and a lot of states in essence sold them off to an Insurance companies to do all the work. Because of the big numbers these companies often do it at a discount. However they will also cut corners to give more service to their higher paying premium customers. The reason why Medicaid and Medicare have the lowest percentage for administration costs, is because they are operated so lightly and push the work to the health care organization to do all the administration. Then they will pass the costs to their customers. And it make is that much more expensive because you have a bunch of smaller organization doing advanced administration who cannot do it as optimally as a larger company who can scale the administration costs.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    2. Re:if you can't beat them by gstrickler · · Score: 5, Informative

      You say they are compliant. However, if they're rejecting claims because you're including information that they don't use, they're not compliant with the standard. From the X096/X097/X098 4010 837 transaction set implementation guides:

      1.3 Business Use and Definition
      ...
      Trading partners agreements are not allowed to set data specifications that conflict with the HIPAA implementations. Payers are required by law to have the capability to send/receive all HIPAA transactions. For example, a payer who does not pay claims with certain home health information must still be able to electronically accept on their front end an 837 with all the home health data. The payer cannot up-front reject such a claim. However, that does not mean that the payer is required to bring that data into their adjudication system. The payer, acting in accordance with policy and contractual agreements, can ignore data within the 837 data set. In light of this, it is permissible for trading partners to specify a subset of an implementation guide as data they are able to process or act upon most efficiently. A provider who sends the payer in the example above, home health data, has just wasted their resources and the resources of the payer. Thus, it behooves trading partners to be clear about the specific data within the 837 (i.e., a subset of the HIPAA implementation guide data) they require or would prefer to have in order to efficiently adjudicate a claim. The subset implementation guide must not contain any loops, segments, elements or codes that are not included in the HIPAA implementation guide. In addition, the order of data must not be changed. Trading partners cannot up-front, reject a claim based on the standard HIPAA transaction.

      I don't have the 5010 guides, but I'm sure you'll find the same or similar language

      --
      make imaginary.friends COUNT=100 VISIBLE=false
    3. Re:if you can't beat them by gstrickler · · Score: 1

      Follow-up: On the other hand, if you're sending data that is defined as unused in the HIPAA (as opposed to the payer's) Implementation Guide, then they are correct in rejecting it as your transaction isn't compliant.

      --
      make imaginary.friends COUNT=100 VISIBLE=false
    4. Re:if you can't beat them by Anonymous Coward · · Score: 4, Funny

      "Well Medicare and Medicaid are operated by each state, and a lot of states in essence sold them off to an Insurance companies to do all the work."

      But private business always does things better than government agencies. The Republicans told me so!

    5. Re:if you can't beat them by Dunbal · · Score: 4, Funny

      To be fair, he said they are compliment.

      --
      Seven puppies were harmed during the making of this post.
    6. Re:if you can't beat them by jamstar7 · · Score: 4, Interesting

      Actually, insurance companies want the uploads to fail. If they don't fail, then they actually have to pay money on a claim. They'd rather not do that, it goes against the bottom line.

      Why anybody would wanna steal Medicaid ids is beyond me. To qualify for Medicaid you have to be poor. No way you'll be able to identity theft up a Gold Card with that info. If they weren't so broke they couldn't pay attention, they couldn't get Medicaid.

      --
      Understanding the scope of the problem is the first step on the path to true panic.
    7. Re:if you can't beat them by MichaelSmith · · Score: 1

      Yeah its like when I worked for our road authority we had a B2B link to pass road service jobs to a contractor. To test the link we put test in every field and the contractor still dispatched the job and billed us. They want to get paid, duh.

    8. Re:if you can't beat them by Anonymous Coward · · Score: 0

      Yes. I work for a company that supports the software for small doctors offices. This change over has been a fuster cluck. The best part is that all the insurance companies require you to transmit via SFTP, but MEDICARE, still goes over good old phone lines. Nothing more secure than plain text over a phone line eh?

    9. Re:if you can't beat them by Anonymous Coward · · Score: 1

      Yep pretty much. We went from them requiring all sorts of random crap and numbers that they were not LEGALLY ALLOWED TO, to them getting pissed if you send extra data... Great and all but their testing has been terrible. I have had so many clients that the testing is either overly sensitive, or lets anything through. Not to mention the fact that I can send the same data to two carriers and get two different results, even two separate rejections. Its all in the name of deny, deny, deny. The longer they don't pay the more money they keep on interest. Or better yet, they just won't pay ever.

    10. Re:if you can't beat them by baegucb · · Score: 1

      The teens' info would be useful for identity theft in a few years. I presume the records would include SSN, DOB, mother's name, etc. And if they were to die in the intervening years, maybe you could create a whole new persona (I don't know if Social Security is checked when issuing new docs, to see if people have died).

    11. Re:if you can't beat them by Anonymous Coward · · Score: 1

      Why anybody would wanna steal Medicaid ids is beyond me. To qualify for Medicaid you have to be poor.

      Because most of those people are old, living on fixed incomes, and are perfect targets for running a wide variety of scams. Just because their income is low does not mean they don't have other financial resources, for example savings accounts and many own their own homes. Many of them are also drawing social security, and with access to all their information payments could potentially be diverted, etc.

    12. Re:if you can't beat them by Anonymous Coward · · Score: 1

      Because poor people don't check for identity theft as diligently. And there are many easy ways to temporarily build credit up and take advantage of said poor people's credit. I mean stealing Bill gates ssn is next to worthless, but stealing john doe can net you hundreds of thousands if it;s used right.

    13. Re:if you can't beat them by jamstar7 · · Score: 2

      Why anybody would wanna steal Medicaid ids is beyond me. To qualify for Medicaid you have to be poor.

      Because most of those people are old, living on fixed incomes, and are perfect targets for running a wide variety of scams. Just because their income is low does not mean they don't have other financial resources, for example savings accounts and many own their own homes. Many of them are also drawing social security, and with access to all their information payments could potentially be diverted, etc.

      You're thinking Medicare not Medicaid Medicare is the old people's medical insurance you pay on your entire working career, and now that it went private, they take 'your' premiums directly out of your Social Security check to give to your 'Medicare provider' along with the money the government gives them. By looting your Social Security check, the government doesn't need to kick in as much.

      Medicaid is the medical insurance provided by the various states for people on Welfare and such. Two totally different things.

      --
      Understanding the scope of the problem is the first step on the path to true panic.
    14. Re:if you can't beat them by Larryish · · Score: 2

      The hackers, who seem to have bounced their final hop off location(s) in Eastern Europe...

      FTFY

    15. Re:if you can't beat them by 1s44c · · Score: 1

      secure your servers.

      We know already.

      Sadly the world is full of idiot professional manager types who can't tell a prototype from a finished version. These are the people who need to know the risks they create by their idiot behavior.

    16. Re:if you can't beat them by Anonymous Coward · · Score: 0

      There's quite a lot in the 5010 that basically says "only send this if you know the insurance company needs it for processing". The majority of those fields also say "if you are sent this and don't need it, ignore it".

      There's no way I, as a software developer for software used by thousands of doctors to bill thousands of insurance companies can possibly know when those fields are needed, thus I write the software to send them all the time, then deal with the support headaches when something goes wrong.

    17. Re:if you can't beat them by Anonymous Coward · · Score: 0

      "Compliant" is a very loose term. I'm sure they tested their software with claredi or the like and got a nice seal of approval. I suspect the real problem are the edits the insurance companies employ. For whatever reason, they can't just set them and leave them, they have to dick with them on a regular basis and they usually end up fucking them up.

      Last week we started getting this tasty one here from an insurance company: SERVICE FACILITY INFORMATION: REQUIRED; SERVICE FACILITY NAME, NPI, AND ADDRESS MUST BE ENTERED WHEN ANY SERVICE FACILITY INFORMATION IS ENTERED FOR PAYER.

      Per the 5010 documentation for the service facility location name loop, the NPI is:

      Required when the service location to be identified has an NPI and is not a component or subpart of the Billing Provider entity.

      What's that, you're a Billing Provider who owns multiple clinics? Well FUCK YOU.

    18. Re:if you can't beat them by zraider · · Score: 1

      Actually, you don't know what you're talking about. Insurance companies pay claims based on contracts with their members and providers. I've worked with scores of insurance companies and every single one is trying to adjudicate and pay claims as fast as they can. Ignoring the claims does not release them of their obligation to pay according to the contract. In other words, the claim WILL be paid if they have contractual responsibility. It's just a matter of if it will be paid with penalties, lost discounts, and unhappy customers or not.

      The additional issue with this breach is the exposure of medical data. Thousands of claims transactions were lifted. Claims contain identifying information (demographics), medical diagnosis data, medical procedure data, etc. That information can be used for blackmail and discrimination purposes.

    19. Re:if you can't beat them by jamstar7 · · Score: 1

      Actually, I worked in that 'industry' for 15 years. Yes, I do know what I'm talking about. Insurance companies only have to pay on claims that have been 'filed in a timely manner', the filing deadline is specified in the policy. Improperly filed claims are considered to be 'no claim' until they have been 'properly refiled', and if the filing deadline is passed before this happens, no payment is made on that claim. It's in the policy, which is considered to be a contract under the law.

      --
      Understanding the scope of the problem is the first step on the path to true panic.
    20. Re:if you can't beat them by zraider · · Score: 1

      Failed uploads do not constitute incorrectly filed or non-timely claims. The payers are not off the hook for them. This is especially true if the systems at fault are owned by the payer or its vendor. I have personally been involved with cases where delays due to technical issues delivering the claims caused payment penalties. If the provider's systems are at fault, that's a different story. In most cases, the claims are resubmitted by providers until paid, or their billing office intervenes and contacts the payer directly.

  2. Too bad for the crooks that the people are poor. by gmanterry · · Score: 3, Interesting

    Medicaid is for poor people. stealing their identity won't gain them access to much money. However the SS numbers might be useful for illegal alien ID cards.

    --
    Since when is "public safety" the root password to the Constitution?
  3. And who will be held responsible? by Eightbitgnosis · · Score: 5, Insightful

    Survey says..............

    No one!

    1. Re:And who will be held responsible? by Kawahee · · Score: 5, Insightful

      The cynic in me says the hackers will be held responsible.

      --
      I'll subscribe to Slashdot when I see a month without a dupe, a typo, or an article the "editors" didn't read.
    2. Re:And who will be held responsible? by Anonymous Coward · · Score: 0

      The cynic in me says the hackers will be held responsible.

      If your cynic has heard it once, it has heard it 1,000 times...

      Good luck with that shit.

    3. Re:And who will be held responsible? by c0lo · · Score: 3, Funny

      The cynic in me says the hackers will be held responsible.

      Seconded.

      FTFA adjusted with a link

      Director Michael Hales said in a statement. “But we also hope they understand we are doing everything we can to protect them from further harm.”

      --
      Questions raise, answers kill. Raise questions to stay alive.
    4. Re:And who will be held responsible? by jamstar7 · · Score: 1

      Yes, the hackers will be held responsible. But will they be caught? Track record says 'no'. Unless they do something seriously stupid.

      --
      Understanding the scope of the problem is the first step on the path to true panic.
    5. Re:And who will be held responsible? by Anonymous Coward · · Score: 0

      You're right. If the hackers didn't exist the network would be secure. Why databases with this information are forward-facing still boggles the mind.

    6. Re:And who will be held responsible? by Anonymous Coward · · Score: 0

      Survey says..............

        No one!

      DING!

    7. Re:And who will be held responsible? by Anonymous Coward · · Score: 0

      Did the Personal Data Protection and Breach Accountability Act of 2011 ever get through? It would be highly amusing to see the government in court after breaching one of their own laws.

    8. Re:And who will be held responsible? by Anonymous Coward · · Score: 0

      Actually, Anonymous. If you don't know who they are, then the curlprits are simply everyone who doesn't want to be known.

  4. Re:One more reason against Obama-care by Charliemopps · · Score: 0

    I didn't even know they drank tea in Azerbaijan.

  5. We must stop pretending SSNs are secret! by Anonymous Coward · · Score: 5, Insightful

    We have to stop pretending that the SSN is something only the owner knows. It cannot be an identifier and a password at the same time. It's because of our retarded system that SSNs are such a juicy theft target. Other countries have similar personal identification numbers and no rampant "identity theft" problems like we have here in the US.

    Simply put, someone should not be able to pretend they are you just by knowing your SSN and name and date of birth. All should be public info and not security questions. Someone can't go in and get a loan just because they found my name in the phone book, it should be the same with the SSN. Leave it be an identifier and only an identifier. The cat's out of the bag with the secret part.

    1. Re:We must stop pretending SSNs are secret! by erroneus · · Score: 1

      By owner, do you mean "government"? As the person identified by such a number, I am powerless to determine the use of that number and meanwhile, to live a "normal life" that doesn't involve putting everything I can carry into a shopping cart and sleeping on park benches, I have to surrender this "secret" to every business and government agency everywhere. And we were "told" the social security number was just for tracking your social security account. Instead it's also your Tax ID (yeah, I know you can request a Tax ID...) and is the number someone who is NOT government has decided will be used to track your credit-worthyness and has the protection of law saying that if I falsify my credit informaiton that I have committed fraud.

      Who is the "owner"?

    2. Re:We must stop pretending SSNs are secret! by Anonymous Coward · · Score: 1

      Of the card or of you?

    3. Re:We must stop pretending SSNs are secret! by Anonymous Coward · · Score: 0

      You said Utah? isn't there where the NSA has his data center? It's probably them on initial tests for information gathering. No worries. ;-)

    4. Re:We must stop pretending SSNs are secret! by Mongo+T.+Oaf · · Score: 0

      You are correct. How far I they gonna get without a picture ID.

    5. Re:We must stop pretending SSNs are secret! by kqs · · Score: 5, Insightful

      I have no idea what you mean by "owner".

      The government assigns them. Each number is supposed to uniquely identify a citizen and is used mostly for SS (and a few other governmental uses). So far so good; the government assigns them and (apparently) uses them appropriately as a unique ID number.

      Now we have dozens of private businesses using them as a password. Fine, I guess it's a free country. But somehow, if someone finds out my number and uses it to open a loan in my name, *I'm* liable for the loan. It's my phone that rings with creditors and my credit score which is damaged. It seems to me that the problem is these corporations which use these numbers as passwords but disclaim liability for fraud. Make it clear that financial institutions have the liability for bad loans they originate, that bad credit reports MUST be cleared unless the financial institution can prove they are true, and that there are very strict penalties for companies which abuse these rules, and the "identity theft" problem will vanish very quickly.

    6. Re:We must stop pretending SSNs are secret! by c0lo · · Score: 1

      I have no idea what you mean by "owner".

      1. However can sell or donate it.

      2. Or, not exactly owning, but here's a quote from the "future history":

      He who can destroy a thing, controls a thing

      Following the first definition: whatever entity you used your SSN number with... (employers, tax office, your local pharmacy and possible big-pharma, the Utah Department of Health).
      Following the second definition: hackers in East Europe, no-such-agency's data center in Utah, men-in-black, etc

      --
      Questions raise, answers kill. Raise questions to stay alive.
    7. Re:We must stop pretending SSNs are secret! by Anonymous Coward · · Score: 0

      Just goes to show you that making promises to accommodate the superstitious and paranoid among us is more costly than dealing with them in an appropriate manner.

      But seriously, you want impunity for falsification of a document?

      This is why we would be better off with an effective Identity System and screwing the Revelation reading nincompoops.

    8. Re:We must stop pretending SSNs are secret! by swalve · · Score: 1

      Just use a tax ID number for business purposes.

    9. Re:We must stop pretending SSNs are secret! by TheLink · · Score: 1

      Actually you have this problem because people and organizations call it and treat it as "identity theft".

      If someone is using your SSN to pretend to be you, because it's considered "identity theft" it becomes mainly YOUR problem.

      Whereas if it's considered fraud, then it's no longer really your problem but that of the Bank or other Organization that's been tricked.

      Then they'd have more motivation to not be tricked so easily - and they are the ones who shouldn't be tricked so easily.

      Whereas you have no reasonable way of preventing an attacker from getting your SSN or other ID.

      --
    10. Re:We must stop pretending SSNs are secret! by jaymemaurice · · Score: 1

      25,000 social security numbers with medical files... ought to be a way to track down some photos and missing information for a good number of them... find facebook accounts etc... few photoshops here and there or maybe a few look-a-likes who can commit the actual fraud... the beautiful thing about information such as this is that it does not change. Maybe it is not useful now... but a few more breaches and the defence in depth approach with common information gets shallow.

      --
      120 characters ought to be enough for anyone
    11. Re:We must stop pretending SSNs are secret! by Anonymous Coward · · Score: 0

      Each number is supposed to uniquely identify a citizen

      Wrong. A combination of number and date of birth uniquely identify a citizen.

    12. Re:We must stop pretending SSNs are secret! by Anonymous Coward · · Score: 0

      Are you really having difficulty comprehending who the OP was referring to, or are just being obtuse intentionally to derail the topic ? I don't know even if he said the right word you expect ("bearer" maybe ?) if that would have stopped you from ignoring the main point and sidetracking the conversation.

      The SSN visibility should be no different than your name's. Imagine if the article said "the breach... compromised over 25,000 names". Leaking SSNs should sound as silly as leaking names, and not be a life-altering event. We all know how it is today. We're just saying how it should be changed to improve the situation. If other countries have better systems, why not learn from them.

    13. Re:We must stop pretending SSNs are secret! by sjames · · Score: 1

      We could get there a lot faster if we stopped recognizing identity theft as a crime. The crime being committed is NOT identity theft against individuals, it is the crime of fraud against the banks followed by the crimes of fraud and extortion by the banks against the individuals.

      Ethically, it should not matter one bit that BozoBank thinks they loaned me $1,000,000. What should matter is that they have no evidence whatsoever that I am the person they foolishly handed a wad of cash to without adequate verification of ID. If they try reporting me to the credit agencies, they are guilty of libel. If the credit agencies repeat that idle gossip, they become guilty of libel as well. If they continue trying to collect money from me in any way after I tell them they have the wrong guy, they are guilty of harassment, fraud, and (if they try too hard) extortion. End of story.

      Actually enforce that and you better believe they'll come up with a better form of authentication.

  6. Re:Too bad for the crooks that the people are poor by GmExtremacy · · Score: 3, Funny

    It's too hard. I give up! What's the answer?

  7. Re:Too bad for the crooks that the people are poor by Anonymous Coward · · Score: 0

    You're a fucking retard. Steal $100 from 181000 people and how much did you just get?

    You're sitting here calculating a 100% success rate for the criminals, and yet you've got the nerve to call someone else a fucking retard...

  8. There ought to be a security certification by Beeftopia · · Score: 2

    There ought to be a security-related certification, along the lines of CMMI Level X, for websites that want to put sensitive information online. A group goes in and audits the network and the office, does penetration testing, and gives you a rating based on corporate practices, user knowledge and potential and actual weaknesses.

    Before these sites feel like they can put up my social security number and health records behind passwords like admin/admin, or allow contractors to download entire social security databases and leave them on USB drives or laptops which can be/are stolen, they should first obtain some minimum level of security-related competence certification.

    1. Re:There ought to be a security certification by Anonymous Coward · · Score: 1

      There ought to be a security-related certification, along the lines of CMMI Level X, for websites that want to put sensitive information online. A group goes in and audits the network and the office, does penetration testing, and gives you a rating based on corporate practices, user knowledge and potential and actual weaknesses.

      Before these sites feel like they can put up my social security number and health records behind passwords like admin/admin, or allow contractors to download entire social security databases and leave them on USB drives or laptops which can be/are stolen, they should first obtain some minimum level of security-related competence certification.

      There is. FISMA.

  9. Re:Too bad for the crooks that the people are poor by Anonymous Coward · · Score: 0

    How is this stealing from them?

    It'll be misusing their identity but actual theft from them? No.

  10. Effective technology by bdabautcb · · Score: 2

    This brings up an interesting question as to whether the advantages of storing massive amounts of personal data on public facing servers (or any server at all, res cent reports have me convinced that if anybody including governments, foreign hackers, or anyone else that wants the data bad enough will be able to find a way to get it) creates large enough benefits to balance the damages caused by breaches like this.

    --
    Koalas. They're telepathic. Plus, they control the weather. -Margaret
    1. Re:Effective technology by Beeftopia · · Score: 1

      The vendors push the failure risk onto the consumer. X number of failures/compromises is going to be miserable for the individual, but the corporation is able to keep making a net profit from it. Until the cost of failure becomes significant for the corporation, outweighing the benefits from using the online system, they'll stay with their current business model.

      This is true of any consumer product.

  11. Re:Too bad for the crooks that the people are poor by c0lo · · Score: 2, Insightful

    Medicaid is for poor people.

    TFA quotes:

    25,096 appear had their Social Security numbers (SSNs) compromised

    ... many of them feel violated

    “But we also hope they understand we are doing everything we can to protect them from further harm.”

    Poor people... have their SSN compromised, feeling violated (bordering to "raped" in one meaning of the term) and asked for understanding with promises of "best effort" towards a better future.
    However... are the East European hackers the primary cause of their situation?

    --
    Questions raise, answers kill. Raise questions to stay alive.
  12. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    I didn't even know they drank tea in Azerbaijan.

    I didn't even know Uzbekistan is in Europe :)

  13. Re:One more reason against Obama-care by Sniper98G · · Score: 0

    Because without "Obama-care" government agencies would not have your social security number?

  14. Headlines? by Shoten · · Score: 5, Insightful

    Okay, Slashdot seems to be getting worse and worse about distorting things in the titles of the topics. "Medicaid Hacked" is NOT what happened here. Not even close. And when the first line of the topic's body is "The Utah Department of Health has been hacked," then you can't even excuse the poster as having been a little confused; it's flagrant tabloid-like sensationalism. Cut it out, already.

    --

    For your security, this post has been encrypted with ROT-13, twice.
    1. Re:Headlines? by JSG · · Score: 2

      Note the name of the submitter of the article and then ignore in future. You'll find /. much more fun then.

    2. Re:Headlines? by the+eric+conspiracy · · Score: 1

      An anonymous reader?

      Better yet note the name of the poster.

    3. Re:Headlines? by blackraven14250 · · Score: 1

      As Medicaid is a program wholly managed by the states, it's not unreasonable to say that Medicaid was hacked. It's a subset of the whole Medicaid program, sure, but it's also the largest meaningful subunit of Medicaid that can be hacked.

    4. Re:Headlines? by Shoten · · Score: 1

      The people's social security numbers were compromised...should we say that Social Security got hacked? Hey, when Global Payments got breached, does that mean that Visa and MasterCard both got hacked? No. Because when you refer to just "Visa," you refer to the organization that underpins Visa cards...and saying that they got hacked refers to an organization that is entirely different and separate. The fact that some of the people who got hacked were on Medicaid (the others were on CHIP) does not mean that the Medicaid organization got hacked.

      Utah's state department of health is NOT Medicaid, nor is it a subset of the 'program' that is called Medicaid. Their procurement is different, their mandate is different and they can only follow the standards and policies put down to them by the Medicaid program (which is federal in nature, not run by Utah), as opposed to determining or setting them. These are just a few of the "subtle hints" that the two organizations are entirely separate and distinct from each other...and that, relevant to my point, their IT security measures are controlled entirely differently from each other (Utah's program isn't even subject to FISMA), and thus hacking one is not the same as hacking the other.

      --

      For your security, this post has been encrypted with ROT-13, twice.
    5. Re:Headlines? by Anonymous Coward · · Score: 0

      Aww, come on....timothy is not near as bad as "unknown lamer"

    6. Re:Headlines? by Anonymous Coward · · Score: 0

      Words can have multiple meanings. When I hear Medicaid, I think of the medicare system, the entire system, including the states. Same with VISA. The processors are part of they system. MasterCard hardly even exists any more and is just a shill designed to stop the feds from ending VISA's monopoly. Global Payments is part of VISA, sure not legally, because that's how they game the system. You break it up into lots of parts and then no part is liable for the mistakes of the others. Some people are even fooled. They actually think when one of the three payment processors for VISA screws up, VISA isn't responsible. Silly sheep.

    7. Re:Headlines? by blackraven14250 · · Score: 1

      For the record, Medicaid is jointly funded by federal and state governments and COMPLETELY run by the states. The federal government has no role in administering the program, and only sets guidelines for eligibility and coverage. There is no overarching federal Medicaid administration system to be hacked.

      I didn't RTFA, and was under the impression that the Utah Dept of Health was breached but it only affected Medicaid recipients - which makes it the largest meaningful unit of Medicaid that can be hacked.

  15. Where was the US Cyber Command? by Anonymous Coward · · Score: 0

    I've seen the fancy commercials. From what I learned, they are supposed to be preventing this crap. Oh, you mean it doesn't really work that way?

    1. Re:Where was the US Cyber Command? by HBI · · Score: 0

      It's another government boondoggle. The government lacks a capability, remember? Sure, they spend a ton on salaries and office space, but in terms of actually accomplishing anything? Nothing.

      --
      HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
    2. Re:Where was the US Cyber Command? by c0lo · · Score: 1

      It's another government boondoggle.

      FTFY by including the proper citation (and attribution).

      --
      Questions raise, answers kill. Raise questions to stay alive.
  16. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    No, it's because they want to bring us back to the time before computers.

  17. Re:Too bad for the crooks that the people are poor by Anonymous Coward · · Score: 0

    Oust! Go make a new account shill :-)

  18. Good job all! by Anonymous Coward · · Score: 0

    Lets fuck the poor even more!

    Hoorayyy!

  19. SSN should not need be secret by zr · · Score: 2

    Because de-facto its not. So we shouldnt assume that its secret and never use it as means of authentication. About as secret as your zip code.

    In other words, if a bank gives out a load based on SSN alone, let _them_ hold the bag on it.

    How long do you think SSN theft will remain profitable after we do that?

    1. Re:SSN should not need be secret by Anonymous Coward · · Score: 0

      Amazingly, gas stations use your zip code as a second factor authentication.

    2. Re:SSN should not need be secret by swalve · · Score: 2

      But multiple factors increase the entropy greatly. If someone guesses my number and burns a card with it, or steals my card, they have to know my zip code to be able to use it. If they got my wallet, it's probably easy. (Not in my case, as my CC stuff is billed to a different zip code, but I digress.) But it adds a level of complication to the transaction.

    3. Re:SSN should not need be secret by zr · · Score: 1

      not exactly. the're using zip code to deter a very specific case of drive-by CC test, popular among CC thieves. its not meant to be perfect. if zip code wasnt available they could just as well have used the street number of your billing address.

  20. Utah IT pro by eclectro · · Score: 1

    Password: Admin

    --
    Take the cheese to sickbay, the doctor should see it as soon as possible - B'Elanna Torres, "Learning Curve"
  21. Online records "hindenburg moment?" by GameboyRMH · · Score: 4, Insightful

    I wonder if at some point there will be a breach so bad that certain critical records will be moved to airgapped systems and never go back, just because of the horrible memory of that disaster.

    --
    "When information is power, privacy is freedom" - Jah-Wren Ryel
    1. Re:Online records "hindenburg moment?" by Anonymous Coward · · Score: 1

      "Oh the humanity" -- what happened with the Hindenberg was /not/ that airships were fixed, but that they were abandoned.

      Let's try for a different kind of moment, perhaps? Although I do like the poetry of an acrobat leaping from the inferno.

    2. Re:Online records "hindenburg moment?" by Anonymous Coward · · Score: 0

      In Utah ocal news stations reported shortly after the hack that the data was stolen from "development machines" that were not behind the same security firewalls as the production servers. Hmmm, seems like the developers downloaded live data, probably for testing, onto their work machines and just didn't bother with necessary security. I suspect there may be some changes made.

    3. Re:Online records "hindenburg moment?" by DigiShaman · · Score: 1

      You mean like an event that happens to those in power to actually care? Because last I checked, we've had plenty of "Hindenburg moments". Just none of them mattered unless you were a victim.

      --
      Life is not for the lazy.
    4. Re:Online records "hindenburg moment?" by Anonymous Coward · · Score: 0

      Here's a better idea, rather than waiting for that to happen... why not just enact a federal law that reads that any organization extending credit, etc., has to be able to prove that they positively verified you are who you say you are, or you don't have to pay, and they can't recover anything you might owe. Meaning, they have to see you, IN PERSON, with ID, and verify the ID is VALID, is YOURS, and that all the things you've alleged in the application are TRUE before issuing credit, etc.?

      "Oh, that would make credit harder to obtain, and would tend to dissuade potential customers from applying for and using credit" some people might whine... well, tough shit. Businesses should not have the ability, for the sake of accruing more wealth to themselves, of endangering me or my good name (or anyone else's for that matter,) by failing to verify the identity of someone claiming to be me (or any of you). If that business cannot prove they DID, in fact, verify the identity of whomever is trying to pose as you, NO ONE should be liable for payment, and they should not be permitted to besmirch anyone's good name, nor harass them, etc., when the people posing as someone else obtained credit, etc., from them when they could have prevented it by verifying whom they were entering into arrangements with.

      Likewise at the supermarket checkout counter. Cashiers of all businesses should be required to verify (whenever a PIN is NOT used,) that the person using "plastic" is who he/she says he/she is, and annotate proof of that verification on the retailer's copy of the receipt. If I were in charge, if you used a credit or debit card (without PIN) at a store, and they didn't ensure it was, IN FACT, your card, you should not have to pay. The onus should be on them to prove they ensured it was YOU who tendered payment with YOUR card. Same principle applies.

    5. Re:Online records "hindenburg moment?" by Jah-Wren+Ryel · · Score: 1

      what happened with the Hindenberg was /not/ that airships were fixed, but that they were abandoned.

      Let's try for a different kind of moment, perhaps?

      No, let us not. Abandoning the use of centralized databases is the only fix - airgapping just protects against remote attacks. It does not protect against abuse by insiders, be it in violation of the rules, or the creation of new rules that encourages official misuse of the data.

      The solution is to decentralize. Let everyone hold their own data. Be it on a portable device like a pda/smartphone or on some sort of dropbox-like system with account-specific encryption. The idea being to maintain as much useful functionality of electronic records on a case by case basis, but to design in barriers that make wholesale misuse extremely difficult.

      --
      When information is power, privacy is freedom.
    6. Re:Online records "hindenburg moment?" by sosume · · Score: 1

      No, thhe solution io much easier. Just block access to all IP addresses not registered to Utah. For the few users outside the state, exceptions can be set up.

    7. Re:Online records "hindenburg moment?" by Anonymous Coward · · Score: 0

      You are joking right?
      As if there are no bad guys in Utah and proxies don't exist.

    8. Re:Online records "hindenburg moment?" by sosume · · Score: 1

      Maybe. But the simple fact is that measures like blocking entire IP blocks makes it much harder to break into such systems unpunished.
      Local bad guys are so much easier to track down and bring to justice.
      Besides - I don't get why anyone in China or Eastern Europe needs to be able to access Utah's Medicaid. So just shut down access
      from foreign IPs by default to most sites.

    9. Re:Online records "hindenburg moment?" by Anonymous Coward · · Score: 0

      Breaking out your botnet to get a Utah address isn't even approaching much more difficult. Unless this was some hack job it's a standard part of the toolkit. I might work with your low profile targets, but have some damn imagination.

    10. Re:Online records "hindenburg moment?" by halcyon1234 · · Score: 1

      I wonder if at some point there will be a breach so bad that certain critical records will be moved to airgapped systems and never go back, just because of the horrible memory of that disaster.

      I wonder if at some point there will be a breach so bad that every single identity will be stolen, and there's nothing left to protect.

  22. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    What part of America is Europe in?

  23. It is kind of weird by geoffrobinson · · Score: 0, Troll

    You have a ton of liberals claiming there is a right to privacy which guarantees a right to an abortion... but we have to have a single payer health insurer that knows practically everything about us.

    --
    Except for ending slavery, the Nazis, communism, & securing American independence, war has never solved anything.
    1. Re:It is kind of weird by Anonymous Coward · · Score: 0

      You have a ton of liberals claiming there is a right to privacy which guarantees a right to an abortion... but we have to have a single payer health insurer that knows practically everything about us.

      Ehh... such a lukewarm attitude... that's not a clear direction a grass root movement can follow. Let me help:
      This cannot continue... what we need is multiple health insurers knowing practically everything about us and corporations can help. Bring them on - but no before destroying the first one! (if possible, in a war... it is known to have solved slavery, the Nazis, communism and PMS)

  24. Re:We must stop pretending SSNs are secret! roxy by Anonymous Coward · · Score: 1

    I agree! If a bank or company gives someone a loan based on a name, birthday, and SSN, then it is the bank's fault. Because they did not take steps to properly verify who they gave money to, it is the bank's fault. I was not involved in anyway. Any damage to my credit rating and the time I spent cleaning things up, the bank must reimburse me for.

    I have been notified twice that my info was stolen from university servers, so they gave me one year free credit monitoring each time. The info is still valid after one year, dumbazzes. If someone gives out a loan based on my info, I will contact a lawyer and have them send a letter to that bank and demand that they cover all costs related to cleaning up after their error. No one should give out a loan without seeing the person face to face and take a photograph, and fingerprints when it exceeds $1000 or something. I am so sick of everyone being allowed to push it off to the innocent party.

  25. That's retarded businesses and government's fault. by Anonymous Coward · · Score: 0

    If businesses weren't so stupid as to just require those things to identify someone, then it would be a problem - for individuals.

    When someone's identity is stolen, the victim is the one who goes through hell for a very long time dealing with collectors, lawyers suing and in some cases actually being arrested by someone posing as them. The moronic bank, credit card company, or whoever just write it off and passes the costs on to everyone else.

  26. As they should be by Sycraft-fu · · Score: 5, Interesting

    You should not hack in to systems you don't have permission to access. It is illegal, for the same reason it is illegal to break in to a house you don't have permission to access. It doesn't matter if you are capable of doing it, you shouldn't do it. Thus if you do, expect to be held criminally accountable.

    This idea of blame the victims don't blame the criminals that so many on Slashdot have is stupid. Fine, I'll be ok with that so long as you are ok with it applying to the real world. You are ok with me being legally allowed to break in to your house, so long as I am able.

    Thing is, I'd be very able. Your physical security is shit, as is everyone's. Individuals never bother with good security. You'll have a regular lock that is vulnerable to bumping, ice picking, and so on. That aside a shotgun with door breaching rounds will take it off the hinges no problem since you have no reinforcement on them. Your walls are probably made of drywall, wood framing and stucco, so a Sawzall can easily take care of that.

    You don't choose to spend the time money or effort to secure your house further... Nor should you have to. Yet you think that if people don't have perfect computer security, well someone should be allowed in.

    Also this is funny because show me this perfect security. Kernel.org was hacked, gnu.org was hacked, GitHub was hacked, BIND was hacked, and so on. So it isn't like just being open source and all that makes you immune. It seems that security holes happen, and that is just life.

    1. Re:As they should be by Kawahee · · Score: 2

      I am not sure that it's illegal to "hack in to systems you don't have permission to access" in all parts of the world. For this reason, I think the onus falls to the implementer to make sure that any system they develop and make available on the public internet is secure.

      --
      I'll subscribe to Slashdot when I see a month without a dupe, a typo, or an article the "editors" didn't read.
    2. Re:As they should be by Anonymous Coward · · Score: 5, Insightful

      "Your physical security is shit, as is everyone's. "

      No one is arguing that hackers who hack into a system and subsequently either damage the system or leak confidential information from the system out onto the rest of the Internet (or communicate that information to people other than employees of the company to report it to them to fix it) shouldn't be held accountable. They absolutely should.

      But there is a huge difference between a residential house (my computer with my info on it) and a bank (a service provider). When I go to a bank, I don't see them leaving unguarded money out in the open for anyone to easily grab. No, they have safes, they have bullet proof glass, they have cameras, they have security guards, they have security switches to alert cops of a robber, they have all sorts of security. Even liquor stores are careful with money, having those huge armored vehicles transporting money from place to place. We expect and require them to take measures to ensure your money is safe.

      A service provider is like a bank of information, they should also hold some responsibility and accountability if they store your personal information in such a way that it can easily get hacked into.

      and corporations are part of the problem as well. Historically, white hat hackers used to report security vulnerabilities to corporations long before leaking them on the Internet. A while back I remember someone reported a 2wire vulnerability to 2Wire and they did absolutely nothing about it for six whole months before the person who discovered the vulnerability communicated it over the Internet and 2wire finally fixed it with a firmware upgrade (due to public pressure). Many times when people communicate vulnerabilities to corporations privately they simply ignore them. Or they sue. So now people no longer put up with that and they simply leak the information onto the Internet. Which, in some ways, is even better than allowing this information to be kept secret and discovered by black hat hackers who will buy and sell it in the black market and use it nefariously against unsuspecting victims. because by the time a white hat hacker who doesn't profit as much from discovering the vulnerabilities discovers them, chances are black hat hackers who stand to profit (and are hence far more determined to discover these vulnerabilities) already have. Black hat hackers who know very well how to get away with what they do. So in some ways it's better that the vulnerabilities and potential victims be made aware of the vulnerabilities early so they can respond before something happens.

      IIRC, Google will even pay a white hat hacker to privately report a vulnerability in its system so they can fix it. That's how security should work. We're not just criticizing that these corporations make mistakes and allow vulnerabilities to exist in their systems. We're also criticizing their response when a vulnerability is privately reported. That needs to change.

    3. Re:As they should be by arth1 · · Score: 4, Informative

      This idea of blame the victims don't blame the criminals that so many on Slashdot have is stupid.

      I don't see this much. I see a lot of blaming the criminals and those who made it easy for the criminals.
      That B is responsible too doesn't take any blame away from A. Just like if your handyman forgets to lock the door, it doesn't make the burglar any less responsible; it only adds blame to the handyman.

      Remember, the victim here isn't the Utah Department of Health, it's the users of the services. The Utah Department of Health gets some blame too, not instead.
      If any of the victims are to blame for anything, it's voting for a system that puts everything to the lowest bidder, making shit like this common occurrence and impossible to safeguard against.

    4. Re:As they should be by Anonymous Coward · · Score: 0

      (and black hat hackers who are also likely considerably more experienced at finding these vulnerabilities than white hat hackers and so they are better at it).

    5. Re:As they should be by betterunixthanunix · · Score: 1

      This idea of blame the victims don't blame the criminals that so many on Slashdot have is stupid. Fine, I'll be ok with that so long as you are ok with it applying to the real world. You are ok with me being legally allowed to break in to your house, so long as I am able.

      "Waahh waahhh I left my front door unlocked and someone stole my valuables!"

      Thing is, I'd be very able. Your physical security is shit, as is everyone's

      If I kept enough information to hijack hundres of thousans of identities in my home, I would beef up my security.

      Also this is funny because show me this perfect security

      Who said anything about perfect security? The problem is that most attacks exploit the same security problems that have been exploited over and over and which people have been warned about over and over again. The fact that techniques for securing information exist and go unused is the problem here; there are criminals in the world, and law enorcement agencies cannot preempt those criminals.

      --
      Palm trees and 8
    6. Re:As they should be by c0lo · · Score: 2

      (and black hat hackers who are also likely considerably more experienced at finding these vulnerabilities than white hat hackers and so they are better at it).

      Did they extend the black belt ranking to hats as well?

      --
      Questions raise, answers kill. Raise questions to stay alive.
    7. Re:As they should be by Cajun+Hell · · Score: 1

      Kernel.org was hacked, gnu.org was hacked, GitHub was hacked, BIND was hacked, and so on.

      And in all of those cases, the victim was considered responsible, having done a dumb thing.

      I don't think anyone is saying criminals are responsible for their crimes; it's that if our government knowing puts data in a situation where it's easily compromised, they share blame too.

      If government were to legalize drunk driving and then people got killed as a result of drunk drivers, yes, the drunk drivers would bear blame. But plenty of people would also be bitching that the government did a bad thing too, and that the legislators who voted for the legalization should be fired. This isn't an unusual attitude; it's why TSA exists, for example.

      --
      "Believe me!" -- Donald Trump
  27. if only by Anonymous Coward · · Score: 0

    they stored the data in that super secret nsa data center out there.

  28. Re:One more reason against Obama-care by jellomizer · · Score: 1

    You could bring up many states farm out medicare and medicaid to private companies.

    --
    If something is so important that you feel the need to post it on the internet... It probably isn't that important.
  29. These hacks wouldn't matter... by justcauseisjustthat · · Score: 5, Interesting

    These hacks and all hacks that steal information but no money, etc would be made pointless if the banking system and credit bureaus, had better validation requirements!!! But instead they want to defraud their customers and by selling credit and identity protection.

    1. Re:These hacks wouldn't matter... by JDS13 · · Score: 1

      People qualify for Medicaid because they can't afford to pay for their own medical care and haven't arranged for any insurance or other third party payment... so perhaps these hacks won't matter because these Social Security numbers aren't worth anything.

    2. Re:These hacks wouldn't matter... by justcauseisjustthat · · Score: 1

      Perhaps you don't understand how easy credit is to get in the United States.

      In my 20s I had income of under $13k, but credit lines totaling $110k. My mother in her 70s and income under $10k got a $15k line on a credit card.

      Now imagine the damage an identity thief would do to a person making under $20k, by simply getting 4x cards $5k apiece. Or imagine the long term con, where initially the thief pays off the debt to build better credit so they can steal larger amounts.

    3. Re:These hacks wouldn't matter... by justcauseisjustthat · · Score: 1

      The easiest way to grow your credit with little income is the shell game.

      Get one credit card to make purchases, then second to make monthly payments on the first, and then a third to make payments on the second, and so on and so on....

  30. Re:One more reason against Obama-care by c0lo · · Score: 1

    What part of America is Europe in?

    Why, that's obvious! You know that Europeans speak French, don't you? Therefore it must be a parish somewhere in Louisiana. Failing that, it's sure in Canada.

    --
    Questions raise, answers kill. Raise questions to stay alive.
  31. Re:One more reason against Obama-care by smittyoneeach · · Score: 1

    Isn't that the whole point of the noble savage myth?

    --
    Get thee glass eyes, and, like a scurvy politician, seem to see things thou dost not.--King Lear
  32. Air-Gapped secret computers mmkay? by Anonymous Coward · · Score: 0

    Then the bad guys have to social engineer or use force to steal the secrets such computers contain.

    CAPTCHA: blackout (lol! :D )

  33. Yeah! And the same with banks! by khasim · · Score: 1

    Banks don't need security once we get over this "blame the victim" mentality.

    After all, I'm sure we all store thousands of social security numbers at home.

    1. Re:Yeah! And the same with banks! by TheLink · · Score: 1

      After all, I'm sure we all store thousands of social security numbers at home.

      The hackers might. And maybe even at your home ;).

      --
    2. Re:Yeah! And the same with banks! by TheGratefulNet · · Score: 1

      After all, I'm sure we all store thousands of social security numbers at home.

      well, now someone does.

      --

      --
      "It is now safe to switch off your computer."
    3. Re:Yeah! And the same with banks! by c0lo · · Score: 1

      After all, I'm sure we all store thousands of social security numbers at home.

      well, now someone does.

      I bet the security of the system on which they store the SSN-es is better than the Utah Department of Health's one.

      --
      Questions raise, answers kill. Raise questions to stay alive.
    4. Re:Yeah! And the same with banks! by Anonymous Coward · · Score: 0

      Yeah! yeah! I've seen them in movies! It's like a bubble iMac with a PC keyboard and an external zip drive and a GUI you've never seen before that prints really big text on the screen!

      And there's always a cat!

    5. Re:Yeah! And the same with banks! by Anonymous Coward · · Score: 0

      Yeah! yeah! I've seen them in movies!

      Those ain't movies, those are documentaries. And watch out... I do have a cat.

  34. Re:Too bad for the crooks that the people are poor by Anonymous Coward · · Score: 0

    Medicaid is for poor people.

    TFA quotes:

    25,096 appear had their Social Security numbers (SSNs) compromised

    ... many of them feel violated

    “But we also hope they understand we are doing everything we can to protect them from further harm.”

    Poor people... have their SSN compromised, feeling violated (bordering to "raped" in one meaning of the term) and asked for understanding with promises of "best effort" towards a better future. However... are the East European hackers the primary cause of their situation?

    That's a rhetorical question and you know it. It would be better for you to answer it yourself.

    See it clearly and a certain virtuosity presents itself that you didn't know you had.

  35. So? by s0nicfreak · · Score: 2

    What exactly are they going to do with these? Identity theft? I'd be willing to bet that these people don't have good enough credit, assets, etc. to make it worthwhile.

    1. Re:So? by AHuxley · · Score: 1

      The digital worlds version of subprime? You roll a lot of "new" data into a big file and sell it in bulk as a US identity pack.
      Its then used, sorted, sold on by persons or groups interested in unique or state wide data.

      --
      Domestic spying is now "Benign Information Gathering"
  36. noobs got pwned by laserdog · · Score: 0

    get better intrent security mesasures or something if u cant stand the heat try to wear gloves and hope you dont get burned

  37. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    You could bring up many states farm out medicare and medicaid to private companies.

    Yes! This should be a good reason to trash them both. Hang on... except:

    1. profit is not a dirty word even when used in health case context...
    2. ... coupled with your insightful and coolheaded analysis on minority and profitability...

    ... suggests you wouldn't see farming out medicare and medicaid as necessary a bad thing, would you now? Or: is this a bad idea only because it is conducted by the states?

  38. Payback time already? by yanyan · · Score: 1

    http://yro.slashdot.org/story/12/04/08/1850249/innocent-or-not-the-nsa-is-watching-you

    Could be related, considering they're in the same state. Maybe the attackers wanted to hit home and hit hard.

    1. Re:Payback time already? by laserdog · · Score: 0

      tottaly what i thought dog tottaly

  39. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    How about both of you trying acting like adults?

  40. Re:Too bad for the crooks that the people are poor by c0lo · · Score: 1

    Medicaid is for poor people.

    TFA quotes:

    25,096 appear had their Social Security numbers (SSNs) compromised

    ... many of them feel violated

    “But we also hope they understand we are doing everything we can to protect them from further harm.”

    Poor people... have their SSN compromised, feeling violated (bordering to "raped" in one meaning of the term) and asked for understanding with promises of "best effort" towards a better future. However... are the East European hackers the primary cause of their situation?

    That's a rhetorical question and you know it. It would be better for you to answer it yourself.

    Somebody raised the question in a non-rhetorical manner. A suggestion of my position in this matter. If you'd like, let's close this thread and continue the discussion on the other one.

    --
    Questions raise, answers kill. Raise questions to stay alive.
  41. Not About US Health Insurance by Anonymous Coward · · Score: 0

    Utah is the home of the NSA's new "Data Center"; http://yro.slashdot.org/story/12/04/08/1850249/innocent-or-not-the-nsa-is-watching-you.

    The US Medicaid server in Utah, like all US Medicaid servers utilizes firewall and encryption from the NSA.

    Ah Ha! [Score: Insight Upgraded 200 pts]

    The hack of the US Medicaid server could have been a proof-of-concept experiment to verify that NSA's encryption is broken.

    Easy thing to spoof yourself to look like you are in Europe when in actuallity you are 5 km from Fort Meade, Maryland, the home of the NSA.

    LoL XD

  42. Re:One more reason against Obama-care by c0lo · · Score: 0

    How about both of you trying acting like adults?

    Ooooh muuum... but it is him that started first!

    (ducks - mod me offtopic, but I couldn't resist)

    --
    Questions raise, answers kill. Raise questions to stay alive.
  43. In other news... by maverick41 · · Score: 1

    ...there has been a run on illicit payday loans! Investigators believe there may be a link to the Medicaid breach.

  44. Re:One more reason against Obama-care by WaywardGeek · · Score: 4, Insightful

    What's the "Most religious state?" What's the most Republican state? What state can't host the Olympics without embarrassing the USA with their corruption? What state lost $2.5M to stupid Nigerian "You have been selected to win $100M dollars!" scams? What state bans effective sex-ed? Banning D&D in public schools... polygamy... and these people are too innocent to know that the religious right GOP crowd they want to join knows for sure that every Mormon will burn in Hell.

    And after yet another epic f--kup, I have to listen to posts like this... on an article about how Utah can't keep track of their Medicare records, and this somehow is an opportunity to blame Obamacare? Give me a break.

    --
    Celebrate failure, and then learn from it - Nolan Bushnell
  45. Big Deal by Murdoch5 · · Score: 1

    Why do I say Big Deal, medical records aren't safe in any kind of form or capacity. I've have 5 different entire sets of medical results lost, misplaced and never found. I've had medical records lost in shipment from one doctor to another. So whats the big deal? The medical industry doesn't give a rats ass to keeping your data safe, losing one medical result is bad enough, losing two is unacceptable and losing 5 is just beyond insane. If doctors, hospitals and front desk personal really cared what happened to your medical documents they would guard them with there life and they don't.

    I would like to add that over the last 15 years NONE of the missing results have been found or even traces of the documents, London general even admitted they were sorry after the first time they lost the documents, they didn't give a shit after losing the second and Grand River Hospital in Kitchener Ontario has never once stood up and told me it's there fault for losing the other 3 documents. If you want a great insecure place to put documents and personal information then the medical association is the place for you!

  46. More diversion? by Anonymous Coward · · Score: 0

    The paranoia in me is wondering if the governments are staging these attacks so that the SOPA, ACTA, and various other copy cat bills can be pushed through the legislative process with little resistance on the grounds of treachery. Again, the paranoid person in me, but there have been an awful lot of attacks so close together in the last 6 months or so(especially with a focus on sensitive data being stolen), all during the heated SOPA debates and the pressure of the MPAA and the RIAA trying to push it through. It almost makes me wonder since they had such a hard time getting it through on the momentum of IP piracy, they may feel they have a better chance with personal data being compromised. We're seeing different versions of the same bill popping up rapidly as well, and flying under the radar for some part. Just a thought. Call me a conspiracy theorist. I don't care. Just sayin' is all.

  47. So... by Anonymous Coward · · Score: 0

    When will anonymous claim this as the next great blow against the %1?

  48. Re:Too bad for the crooks that the people are poor by SnarfQuest · · Score: 0, Insightful

    ... many of them feel violated

    Welcome to the TSA plus Obamacare? Bringing the air traffic experience to medicine.

    --
    Who would win this election: Andrew Weiner vs Andrew Weiner's weiner.
  49. Why? by Anonymous Coward · · Score: 0

    I could understand Medicare... retirees. But Medicaid and CHIP are for low income people. Why bother taking SS#'s of poor people? To ruin their credit? They probably already beat you to the punch.

  50. Due diligence by Anonymous Coward · · Score: 0

    They blame the victims in some cases for the same reasons the police won't waste a lot of time and effort (unless they're really bored or you're really important/rich) trying to find your stolen car when you admit, during the filing of the police report about the car being stolen, that you left it, (a nice new convertible Mercedes with the top down,) unlocked, with the keys in the ignition, running, with a pound brick of marijuana, a couple kilos of coke, and a bag with $100,000 cash sitting in the passenger seat, right outside a liquor store at 10:00 at night, double-parked, in South Central Los Angeles on a Saturday night, during the summer.

    They'll just piss themselves laughing about what a dumbass fucktard you are, then discuss whether or not they can bust you for admitting possession of the drugs, when the drugs are clearly gone, (with the car,) never to be seen again.

    If you have something that makes your computer system either a high value target because of how hard it should be to break in, (the challenge) or potentially worth money to someone (a bunch of SSN's, and associated personal info.,) etc., you have a duty to protect it, similarly to how a bank has a duty to protect your funds on deposit with it. Would you get steamed at someone blaming a bank for getting robbed when their "vault" turns out to be a room with gypsum board for walls and 18" centered studs? Protected by a hollow core door and a set of hardware you might see on a residential bathroom, with only one guard in the place with a fake gun? Of course not. You'd ask, what kind of bank has such pitiful protection for people's deposited money?

    Well, an organization like that DOES have a responsibility, and while I hesitate to rush to judgement before all the facts are in, it sounds like they DROPPED THE FUCKING BALL on this one. But I'll reserve judgement until the investigation is complete.

  51. Re:We must stop pretending SSNs are secret! roxy by jaymemaurice · · Score: 1

    I had this friend once, the real tinfoil hat kind of friend/acquaintance who:
    - refused to use the internet
    - lined his house in chicken wire/lead drywall
    -I stopped talking to when he called me the enemy for working for a wireless internet company

    He spoke of a day when we would all have the choice to take a national ID with a smart card and register our finger prints or be denied all government services.

    errr..

    --
    120 characters ought to be enough for anyone
  52. Relax! by guttentag · · Score: 1

    It wasn't hackers from another country. It was just a test run of the new NSA Utah Data Center. The Utah Department of Health just happened to be the nearest available guinea pig from which to steal sensitive personal data on thousands of Americans. It did what it was supposed to do.

    I know it sounds crazy, but remember: You can't spell insane without the NSA.

  53. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    How about both of you trying acting like adults?

    Why do you assume either one of them is actually an adult?

  54. insane by w4r0nc0re · · Score: 1

    Those Hackers should now have a lot of information about me. I was deported into homelessness in 2008 when two other ladies decided I wasn't responsive. Amid threats of Hospitalization, I signed back onto Medicaid. Haven't been off of it since. If you wonder what the State Insane Asylum is like, it is essentially a prison where you can't see the stars ever, and the most important thing is a policy against yelling. Papers and personal items are routinely stolen from their admits. I now live in a nursing facility because of the option I was given: face a diagnosis which was not invasive, or put the diagnosis back into limbo because of perscriptions, with an escape to potential freedom. I chose the former. Now there is no one watching me. No one cares. At the Asylum there was constant visibility, roomate pairs, and mind control. Showing affection was impossible. And it is done to them for no crime. Bottom line I support the Hack. I still have my own bank account. There was information accessed which should be troubling to the public (information about shot brutality) which I don't really have access to myself unless I could afford to correspond with the entity via FOIA. If there was interest, there should be investigative reporting. Utah separated the department of Health from a new department of Drug Addiction and Safety(sp?) in the news last year. So the Department of Health isn't housing a bunch of druggies one should suspect. There is a girl there, Allison, who has been there for years and no one would ever know her name. She's just a young girl absorbed in scientology. It really feels unfair to me to lock them away from the stars.

  55. Re:We must stop pretending SSNs are secret! roxy by Culture20 · · Score: 1

    A stopped clock is right twice a day.

  56. Re:One more reason against Obama-care by Intrepid+imaginaut · · Score: 1

    What state lost $2.5M to stupid Nigerian "You have been selected to win $100M dollars!" scams?

    Nooo! No way. You are kidding me. That cannot be serious.

  57. shanghai shunky by Anonymous Coward · · Score: 0

    Shanghai Shunky Machinery Co.,ltd is a famous manufacturer of crushing and screening equipments in Chinahttp://www.sandmaker.biz provide our customers complete crushing plant, including cone crusher, jaw crusher, impact crusher, VSI sand making machine, mobile crusher and vibrating screen. http://www.shunkycrusher.com What we provide is not just the high value-added products, but also the first class service team and problems solution suggestions.http://www.jaw-breaker.org Our crushers are widely used in the fundamental construction projects. The complete crushing plants are exported to Russia, Mongolia, middle Asia, Africa and other regions around the world.

  58. virtual server by WindBourne · · Score: 1

    Mini virtual server. Seriously, this will sound like a weird idea, but rather than having a webserver that connects to a DB which requires secured code, how about an instance level virtual server? Basically, when you log-in, you create a virtual server, with your personal information. Nothing else. For this to work, it requires the ability to spin up quickly virtual servers, OR an 'instances' of a DB with its copy of data, but only with the data tied to that login or key.

    Also, it is long past time to push IPv6. With it, comes decent security. Give a key. Yes, we can do a key tied to the web server, but, this is the ability to tie it to the network.

    --
    I prefer the "u" in honour as it seems to be missing these days.
  59. Soon by Anonymous Coward · · Score: 0

    these east european hackers don't need to hack that far from their home, Germany is already deploying a system to spread medical information.

    cb

  60. Re:Too bad for the crooks that the people are poor by c0lo · · Score: 1

    ... many of them feel violated

    Welcome to the TSA plus Obamacare? Bringing the air traffic experience to medicine.

    Sorry mate, not here. For Obamacare there's a special thread, with the special note that the thread is modded Offtopic.

    --
    Questions raise, answers kill. Raise questions to stay alive.
  61. Re:Well said I must admit (adding fuel 2 a fire) by c0lo · · Score: 1
    (offtopic - I know)

    Mate, you forgot to post a whinge about insta-downmodding... how can you get that sloppy lately?

    --
    Questions raise, answers kill. Raise questions to stay alive.
  62. I just don't know... by John+Pfeiffer · · Score: 1

    Is it wrong that my first thought-- after "Oh good, it's not HERE." --was to wonder why the hell someone would hack the medicaid records for Utah? I mean, really. Utah?

    --

    Friend: "The NIC is misconfigured..." Me: "No prob, I'll just telnet in and fix it." *Silence*
  63. Re:No, I let YOU point it out for me by arth1 · · Score: 1

    There is no "+1 Facts". Unless facts are interesting, insightful or otherwise bring something positive to the discussion, they don't deserve a modding up. And if they are written solely to enrage others or illicit a response, they deserve "-1 Flamebait" or "-1 Troll".

    What I want now is a heuristic filter that will downmod any post that appears to be a list of posts, links, or quotes with bolding. That would increase the signal to noise level here, because quite frankly, these irrelevant lists are NOISE.

  64. The new Utah data center will allow more ID theft! by Anonymous Coward · · Score: 0

    Soon, scammers will be able to steal a complete record of my late night TV viewing as well as my Social Security info thanks to the new NSA Utah anti-citizen data center.

    Chinese companies will have one stop shopping for stealing all our projects before they're even done.

    NSA = we steal your info so criminals don't have to!

  65. It' by Anonymous Coward · · Score: 0

    There is no "+1 Facts". Unless facts are interesting, insightful or otherwise bring something positive to the discussion, they don't deserve a modding up. by arth1 (260657) on Monday April 09, @07:24AM (#39617461) Homepage

    He used verifiable facts quoting Sycraft-Fu's +5 interesting material adding on to it here http://news.slashdot.org/comments.pl?sid=2773441&cid=39615913 , which thus is on topic and continuing a discussion that was rated +5 interesting.

    Odd his was rated -1 for posting the same type of thing as was already posted and rated up to +5 for it.

    What I want now is a heuristic filter that will downmod any post that appears to be a list of posts, links, or quotes with bolding. That would increase the signal to noise level here, because quite frankly, these irrelevant lists are NOISE. by arth1 (260657) on Monday April 09, @07:24AM (#39617461) Homepage

    I found being able to verify statements with links supporting them far more interesting actually than the parent post with the same type of material, albeit minus supporting links from good sources, less interesting in fact.

    And if they are written solely to enrage others or illicit a response, they deserve "-1 Flamebait" or "-1 Troll". by arth1 (260657) on Monday April 09, @07:24AM (#39617461) Homepage

    First of all, it's ELICIT. Secondly, eliciting responses is what forums are about.Moderating down verifiably truthful statements is not. That's what I am seeing happen in this case. It appears that the Linux people around here cannot stand when truths are posted with verifying links and downmoderate such comments indiscriminately in some poor attempt to hide truths in them.

  66. ELICIT vs. ILLICIT (check your spelling) by Anonymous Coward · · Score: 0

    And if they are written solely to enrage others or illicit a response, they deserve "-1 Flamebait" or "-1 Troll". by arth1 (260657) on Monday April 09, @07:24AM (#39617461) Homepage

    First of all, it's ELICIT -> http://www.thefreedictionary.com/elicit not ILLICIT -> http://wiki.answers.com/Q/What_does_illicit_mean

    Please - learn to use the english language properly. Thank you.

    Secondly, eliciting responses is what forums are about - Moderating down verifiably truthful statements is not, and is the illicit part going on here. A "near 'freudian slip'" from you, perhaps, in regards to unjust and unjustifiable downmoderation going on here?

    That's what I am seeing happen in this case. To wit:

    There is no "+1 Facts". Unless facts are interesting, insightful or otherwise bring something positive to the discussion, they don't deserve a modding up. by arth1 (260657) on Monday April 09, @07:24AM (#39617461) Homepage

    He used verifiable facts quoting Sycraft-Fu's +5 interesting material adding on to it here http://news.slashdot.org/comments.pl?sid=2773441&cid=39615913 , which thus is on topic and continuing a discussion that was rated +5 interesting.

    Odd his response posting was down moderated -1 for posting the same type of thing as was already posted and rated up to +5 for it by Sycraft-Fu.

    What I want now is a heuristic filter that will downmod any post that appears to be a list of posts, links, or quotes with bolding. That would increase the signal to noise level here, because quite frankly, these irrelevant lists are NOISE. by arth1 (260657) on Monday April 09, @07:24AM (#39617461) Homepage

    I found being able to verify statements with links supporting them far more interesting actually than the parent post with the same type of material, albeit minus supporting links from good sources, less interesting in fact.

    It appears that the Linux people around here cannot stand when truths are posted with verifying links and downmoderate such comments indiscriminately in some poor attempt to hide truths in them.

  67. Re:Too bad for the crooks that the people are poor by Anonymous Coward · · Score: 1

    Welcome to the TSA plus Obamacare? Bringing the air traffic experience to medicine.

    Obamacare, Romneycare, what's the difference?
    "The two laws are, in the words of Jonathan Gruber, who helped design both the Romney and Obama plans, “the same fucking bill.”

    Now go fuck off and spread your uninformed opinion somewhere more appropriate, the sewer for example.

  68. Wow by eyenot · · Score: 1

    We need this to be universal !

    --
    "Stratigraphically the origin of agriculture and thermonuclear destruction will appear essentially simultaneous" -- Lee
  69. UR off-topic & "guilty of murder", LMAO! by Anonymous Coward · · Score: 0

    ILLICIT murder of the English language, LOL -> http://news.slashdot.org/comments.pl?sid=2773441&cid=39617909 hahahahahahahahaha which ELICITS this reply!

  70. Re:Too bad for the crooks that the people are poor by Anonymous Coward · · Score: 0, Flamebait

    Welcome to the TSA plus Obamacare? Bringing the air traffic experience to medicine.

    Obamacare, Romneycare, what's the difference?
    "The two laws are, in the words of Jonathan Gruber, who helped design both the Romney and Obama plans, “the same fucking bill.”

    Now go fuck off and spread your uninformed opinion somewhere more appropriate, the sewer for example.

    One is run by the state and the other violates the 10th Amendment. Anything else I can help you with?

  71. Rated 0 "offtopic"? by Anonymous Coward · · Score: 0

    Sycraft-Fu said same (w/ no proof vs. the post I noted) & was upmodded +5 interesting. How's the post I replied to offtopic then, by it continuing the topic posted by Sycraft-Fu??

  72. Re:Too bad for the crooks that the people are poor by Whorhay · · Score: 2

    It may not give access to much in the way of immediate cash funds. But like any random SSN they can be used in other frauds. Maybe on a one for one basis they aren't as valuable to a criminal as say my SSN would be, but they got away with more than 25 thousand of them. So even if they only get a few hundred bucks each worth of fraudulant activity out of each it'll add up. So now those 25 thousand people who were probably already having a rough time of it have the added excitement of probably being the victims of ID theft in the near future. And it's not like you can just go get a new SSN, so once it's out there it'll be a spectre for the rest of your life.

  73. Why would you want these peoples' info? by ski9826 · · Score: 1

    They're on Medicaid - they get their money from people who actually work for it. Most probably have awful credit as well.

  74. Another unjustified moddown? LMAO! by Anonymous Coward · · Score: 0

    My posts downmodded but an admitted off topic troll's not -> http://news.slashdot.org/comments.pl?sid=2773441&cid=39617167

    ?

    * Please: How obvious can you make it that the "moderation system" here needs revision & to make those doing unjustifiable moddowns accountable?

    (In other words, to allow identifying WHO is doing the bogus downmods (or downmods/upmods in general too)).

    ---

    Additionally - Sycraft Fu posts pretty much what I did in reply to he (making ME ON TOPIC no less), and got a +5 "interesting" rating!

    Where by way of comparison?

    My post here on the same note/topic http://news.slashdot.org/comments.pl?sid=2773441&cid=39615913 and merely followed up on his with the same general material & yet it was "modded down" as "off topic")

    (Funny, but the topic was established by Sycraft Fu, & I merely supplemented what he posted with additional valid material supporting his claims - he wasn't rated "off topic" for it, but I was... please, give us a break: Keep making this site & it's bogus moderation system look worse than it is... you only make my case for me doing that!)

    1. Re:Another unjustified moddown? LMAO! by c0lo · · Score: 1

      he wasn't rated "off topic" for it, but I was... please, give us a break: Keep making this site & it's bogus moderation system look worse than it is... you only make my case for me doing that!)

      Wish granted, here's the one for you: Guys, you are allowed to take a break!

      Offtopic, I know, but I must admit that the whinge was exquisite, mate (hear this one: LMAO... and this: you only make my case for me doing that!) Brilliant, I tell you... absolutely brilliant, sincere thanks for it. In return, I'll tell you that life isn't supposed to be fair, but at most interesting enough to worth living - and you should see what's happening here as very interesting... nay, scratch that... intriguing at its most (be it only for the mystery of the /. modding).

      Until next time, I'll remain yours...

      --
      Questions raise, answers kill. Raise questions to stay alive.
  75. Why moddown on parent post to this one? by Anonymous Coward · · Score: 0

    Arth1's off topic & "murdered the english language" too (lol, that's no lie).

  76. Re:One more reason against Obama-care by narcberry · · Score: 0

    Yeah, blaming Obamacare is a stretch. But I don't understand how bashing Utah/Mormons/Republicans explains anything. It seems like just a general partisan answer.

    Most religious.. Are you saying that's an "epic f--kup"? If so, why are you asserting every Mormon will burn in hell? (Or put another way, why is your religious answer "burn in Hell" tolerable when arguing against religion?)
    Most republican.. That's an "epic f--kup"? Is that because they disagree with you?
    I agree, the SLC Olympic committee embarrassed the USA. But then Romney, a religious republican, cleaned up the mess. Does that fit your narrative?
    And what does any of that have to do with IT security, or Obamacare? Wait, now you're talking about polygamy? I don't get it.

    --
    Modding me -1 troll doesn't make me wrong.
  77. You're making /. & urself look bad by Anonymous Coward · · Score: 0

    Ur offtopic admittedly, & obviously downmodding unjustly. You said it:

    "Offtopic, I know," - by c0lo (1497653) on Monday April 09, @12:36PM (#39619963)

    Yes, you are. Badly so.

    * If your goal is to drive others from this website's forums, it's people like you that do!

    It's also obvious you either have alternate registered 'sockpuppet' accounts to do so, or, you work in collusion with others to do so - after all, again? YOU SAID IT:

    "Wish granted, here's the one for you: Guys, you are allowed to take a break!" - by c0lo (1497653) on Monday April 09, @12:36PM (#39619963)

    And yes, I've got even got MULTIPLE quotes of others like you that said "Get an account APK so we can 'mod you down to obliviion'"... LOL - wtf? Is THAT the "best" /. technically challenged wannabe computer gurus have?? LOL, evidently so!

    Stuff like that here, it's made me LAUGH in the past before, as I do NOT "live for mod points"!

    (I could care less about them as I simply tell folks in replies "good job" etc./et al, AND, I don't get them to give posting as ac is why, & I have plenty of "upmods" even for an AC poster (which is harder on us, as we start @ zero/hidden generally for most viewers)).

    APK

    P.S.=> If you wish to go on looking like some juvenile stooge that cheats the mod system here, AND, to make this forums look poorly? Keep on doing what you're doing...

    Disproving points I make MIGHT "bother me" some, if done with valid facts from reputable sources that disprove my words BUT would also make me stronger!

    (As I would be made aware of a 'mistake' & it wouldn't happen again - I'd "grow" by it & even appreciate it in fact)

    However, nothing else bugs me that weaklings like you do - especially unjust downmoderations!

    I mean - to me?

    That'd be ALL that'd matter (IF I posted outright incorrect crap), but nobody ever "gets the best of me" on that account here... ever (not once in what? 8 yrs. since I've been here??)

    Hence - because of your words & others here making threats to downmod me to 'oblivion' & more?

    It's WHY I suspect fools like you do downmods of myself for no justifiable reasons - your "geek angst" was injured @ some point vs. myself, & 'effete downmods' are all you have as "retaliation" vs. my shaming you (you shame yourselves around here with technically ERRONEOUS postings, quite a lot in fact), lol... apk

  78. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    Yeah, blaming Obamacare is a stretch. But I don't understand how bashing Utah/Mormons/Republicans explains anything. It seems like just a general partisan answer.

    Most religious.. Are you saying that's an "epic f--kup"? If so, why are you asserting every Mormon will burn in hell? (Or put another way, why is your religious answer "burn in Hell" tolerable when arguing against religion?)
    Most republican.. That's an "epic f--kup"? Is that because they disagree with you?
    I agree, the SLC Olympic committee embarrassed the USA. But then Romney, a religious republican, cleaned up the mess. Does that fit your narrative?
    And what does any of that have to do with IT security, or Obamacare? Wait, now you're talking about polygamy? I don't get it.

    I think you're reading too much into his comments about what it means to be "most religious" and "most republican." His point, as I read it, is NOT that either of those is inherently wrong in itself. It just makes it that much more ludicrous to blame Obamacare and claim that religious/republican candidates are the answer.

  79. Re:Too bad for the crooks that the people are poor by SmurfButcher+Bob · · Score: 1

    Well duh, my new crime-as-a-cloud service can now offer a feature that screens these people from your card lists, at only half the cost of the traditional merchant-account leasing service.

    --

    help me i've cloned myself and can't remember which one I am

  80. Re:We must stop pretending SSNs are secret! roxy by jaymemaurice · · Score: 1

    I suppose so...

    --
    120 characters ought to be enough for anyone
  81. Re:One more reason against Obama-care by WaywardGeek · · Score: 1

    Yes, you are correct. One of my best friends is a conservative Mormon, and being Unitarian, I'd be ashamed to belittle others for their faith, though stupid political beliefs are fair game. I don't believe Mormons are higher or lower on the Holy Ladder, but I read the Book of Mormon (my friend gave me a copy), and I read that the innocent people who had not read the book are still possibly going to Heaven, but now that I've read it and did not convert (I'm still Unitarian), I am in fact quite clearly banned from the presence of God, according to the book. However, our local Baptists here in NC will waste no time explaining why Jews and Mormons are damned, so we can all enjoy damnation together.

    --
    Celebrate failure, and then learn from it - Nolan Bushnell
  82. Re:One more reason against Obama-care by Anonymous Coward · · Score: 0

    though stupid political beliefs are fair game.

    = Mormonism. Look up Joseph Smith, the scammer who founded mormonism. Don't bother with wikipedia though; his entry has been heavily sanitised. If you take any aspect of that "religion" seriously you are being naive.

  83. Re:Too bad for the crooks that the people are poor by Anonymous Coward · · Score: 0

    Oh how clever. This coming from the person who posted the following fine example of rational thought:

    These amateurs! These amateurs! These amateurs! These amateurs! These amateurs need to use Gamemaker!