Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Hacking HealthCare.gov: Affordable Health Care Sites Could Be at Risk

    Written by

    Sean Michael Kerner
    Published November 1, 2013
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The Obama administration hasn’t had the easiest of times in the rollout of its Affordable Health Care for America Act (commonly referred to as Obamacare) and its associated Websites led by Heathcare.gov. In addition, to site accessibility delays that have plagued Obamacare Websites since day one, security researchers are now also warning about potential risks.

      Obamacare Websites include the primary U.S. government site at Healthcare.gov as well as individual state Websites. Kyle Adams, chief software architect for Junos WebApp Secure at Juniper Networks, told eWEEK that he has concerns about many of the Obamacare sites and expects them to be juicy targets for attackers.

      Adams stressed that he did not complete a comprehensive penetration testing exercise against any Obamacare site, as he did not have permission from the sites. However, he was able to passively ascertain security posture via a number of noninvasive activities.

      At a high level, Adams said that the core Healthcare.gov site is built mostly on a Java stack and doesn’t have any obvious security red flags. When it comes to individual states, however, Adams has some concerns about the Kentucky health care site which he referred to as being “fairly buggy.”

      “The biggest indicator is they expose a whole lot of information about how the back end is implemented through the client interface,” Adams said. “They’re also passing around implementation details like the private object names that are used throughout the application.”

      The state of Vermont also exposes back-end details, and the state of Maryland was found in Adams’ analysis to not be using Secure Sockets Layer (SSL) encryption for some of its traffic. The use of SSL is critical as it limits the risk of data being read in the open by anyone.

      XSS and SQL Injection

      Two of the most common forms of Web attack today are cross-site scripting (XSS) and SQL injection, and Obamacare sites might well be at risk from both. Adams said that while he didn’t conduct a full analysis, he did throw some invalid inputs into the Obamacare sites to see what would happen.

      An example of the invalid input is the use of letters instead numbers in a form field for phone numbers. Security researchers can learn a lot from how a system responds to invalid inputs.

      “I got some strange error messages back that would indicate that things aren’t being validated properly,” Adams said. “If you see signs of bad input validation in one place, it’s usually an indicator that bad input validation exists elsewhere across the site.”

      Without proper input validation, an attacker could potentially perform a SQL injection attack. Adams said he found evidence of bad input validation for the Vermont Obamacare site as well as the main Healthcare.gov site.

      The error that Adams got on the Healthcare.gov site to the bad input was an “unhandled exception” error.

      “If you can throw something at an application and it results in an error, then there is a good chance that if you craft the input value correctly, you can get the application to handle it improperly,” Adams said.

      The Big Picture

      Eric Cowperthwaite, vice president of advanced security and strategy at CORE Security (and former CISO at Providence Health) told eWEEK that healthcare.gov either maintains a significant amount of personally identifiable information or it is the gateway or interface to systems that do.

      “Any system that contains large amounts of personally identifiable information could be the source of a massive breach,” Cowperthwaite said. “And the more complex the system is, the more likely there are significant vulnerabilities that can breached.”

      In Cowperthwaite’s view, the even bigger smoking gun about Obamacare Website security is the various glitches, bugs and issues that are impacting system functionality today.

      “Security is often defined as the confidentiality, integrity and availability of systems and data,” Cowperthwaite said. “Healthcare.gov has had quite well-documented problems with both availability and integrity.”

      Issues with Healthcare.gov site availability however might also potentially be a good thing for security. Craig Carpenter, vice president of strategy at AccessData, told eWEEK that he would be surprised if the site’s security hadn’t already been compromised, perhaps many times over—even with a small population of users actually being able to get in.

      “In fact, the site’s stability issues and lack of usability to this point may be its best security: Even hackers haven’t been able to get in long enough to make it work,” Carpenter said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.